Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Napadl me asi hacker

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Napadl me asi hacker

#1 Příspěvek od DuVenBlejt »

Zdravim,
muj problem je ten ze po zapnuti pc byl jazyk prenastaven na rustinu (psal jsem azbukou). poprve jsem si myslel ze jsem to udelal nejakym preklepem. Po druhe uz to bylo podezrele. A ted to projizdim uz tretim antivirakem protoze me najednou zacal psat google ze me zablokovali pristup nekde z ruska. A u EA acces me zas posilaji bezpecnostni kody. Proto prosim jestli by nekdo koukl na Log nebo mam rovnou preinstalovat windows. Děkuji moc za vasi ochotu a rady.

LOG:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:22:56, on 14. 3. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: NormalLogfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:22:56, on 14. 3. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal

Running processes:
C:\Users\PC-DĚLO\AppData\Local\Facebook\Games\FacebookGameroom.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\MultiKeyboard Driver\KbdDrv.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
C:\Users\PC-DĚLO\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe
C:\Users\PC-DĚLO\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\PC-DĚLO\Downloads\hijackthis (1).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: PDF Architect 3 Helper - {06E08260-0695-4EC1-A74B-1310D8899D93} - C:\Program Files (x86)\PDF Architect 3\creator-ie-helper.dll
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [Raptr] "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
O4 - HKLM\..\Run: [PlaysTV] "C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe" --startup
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_24FEC2ECB57787A648A75215DB5B0ADC] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [OneDrive] "C:\Users\PC-DĚLO\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent
O4 - HKCU\..\Run: [TeamSpeak 3 Client] "C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\PC-DĚLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\PC-DĚLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
O4 - Startup: Facebook Gameroom.lnk = ?
O4 - Startup: MutiKeyboard Driver.lnk = C:\Program Files (x86)\MultiKeyboard Driver\KbdDrv.exe
O4 - Global Startup: O&O Defrag Tray.lnk = ?
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{1c390444-7b79-4f45-bfe4-16850b2953f2}: NameServer = 77.234.40.79
O17 - HKLM\System\CS1\Services\Tcpip\..\{1c390444-7b79-4f45-bfe4-16850b2953f2}: NameServer = 77.234.40.79
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: adaware antivirus service (adawareantivirusservice) - Unknown owner - C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AdobeFlashPlayerUpdateSvc - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: ACP User Service (amdacpusrsvc) - Advanced Micro Devices - C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall Service (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: gupdate - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: gupdatem - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MozillaMaintenance - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: PDF Architect 3 - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\ws.exe
O23 - Service: PDF Architect 3 CrashHandler - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\crash-handler-ws.exe
O23 - Service: PDF Architect 3 Creator - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\creator-ws.exe
O23 - Service: Plays.tv Update Service (PlaysService) - Plays.tv, LLC - C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe
O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - c:\postgreSQL\bin\pg_ctl.exe
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: Realtek11nSU - Realtek Semiconductor Corp. - C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12911 bytes

Roli píše:Log odstraněn z CODE pro lepší čitelnost

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Napadl me asi hacker

#2 Příspěvek od Roli »

Zdravím, potřeboval bych log.txt z Rsit protože je podrobnější než HJT.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#3 Příspěvek od DuVenBlejt »

Logfile of random's system information tool 1.16 (written by random/random)
Run by PC-DÄšLO at 2017-03-15 23:02:00
Microsoft Windows 10 Home
System drive C: has 32 GB (26%) free of 121 GB
Total RAM: 16322 MB (74% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:02:00, on 15. 3. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal

Running processes:
C:\Users\PC-DÄšLO\AppData\Local\Facebook\Games\FacebookGameroom.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\MultiKeyboard Driver\KbdDrv.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
C:\Users\PC-DÄšLO\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe
C:\Users\PC-DÄšLO\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\PC-DÄšLO_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: PDF Architect 3 Helper - {06E08260-0695-4EC1-A74B-1310D8899D93} - C:\Program Files (x86)\PDF Architect 3\creator-ie-helper.dll
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [Raptr] "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
O4 - HKLM\..\Run: [PlaysTV] "C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe" --startup
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_24FEC2ECB57787A648A75215DB5B0ADC] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [OneDrive] "C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent
O4 - HKCU\..\Run: [TeamSpeak 3 Client] "C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3959593766-1101095669-3702493713-1005\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'postgres')
O4 - HKUS\S-1-5-21-3959593766-1101095669-3702493713-1005\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'postgres')
O4 - Startup: Facebook Gameroom.lnk = ?
O4 - Startup: MutiKeyboard Driver.lnk = C:\Program Files (x86)\MultiKeyboard Driver\KbdDrv.exe
O4 - Global Startup: O&O Defrag Tray.lnk = ?
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{1c390444-7b79-4f45-bfe4-16850b2953f2}: NameServer = 77.234.40.79
O17 - HKLM\System\CS1\Services\Tcpip\..\{1c390444-7b79-4f45-bfe4-16850b2953f2}: NameServer = 77.234.40.79
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: adaware antivirus service (adawareantivirusservice) - Unknown owner - C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AdobeFlashPlayerUpdateSvc - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: ACP User Service (amdacpusrsvc) - Advanced Micro Devices - C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall Service (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: gupdate - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: gupdatem - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MozillaMaintenance - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: PDF Architect 3 - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\ws.exe
O23 - Service: PDF Architect 3 CrashHandler - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\crash-handler-ws.exe
O23 - Service: PDF Architect 3 Creator - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\creator-ws.exe
O23 - Service: Plays.tv Update Service (PlaysService) - Plays.tv, LLC - C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe
O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - c:\postgreSQL\bin\pg_ctl.exe
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: Realtek11nSU - Realtek Semiconductor Corp. - C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13159 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-aa16c46f-1d7f-48df-916f-0a3a0f157100 -SystemEventPortName:HostProcess-3e903561-b7ab-4d02-bdbf-3b91bc3fff01 -IoCancelEventPortName:HostProcess-7c33e311-ee54-404f-b776-89990bd9697e -NonStateChangingEventPortName:HostProcess-14fbb311-226d-4e46-8f34-82b4df613928 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:8efe3694-2f7a-403b-989a-9167e6816702 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe"
"C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\OO Software\Defrag\oodag.exe"
"C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe"
"C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe"
C:\WINDOWS\system32\dashost.exe
"C:\Program Files (x86)\PDF Architect 3\creator-ws.exe"
C:\WINDOWS\system32\IProsetMonitor.exe
"c:\postgreSQL\bin\pg_ctl.exe" runservice -N "postgresql-8.4" -D "c:/postgreSQL/data" -w
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"c:\postgreSQL\bin\postgres.exe" -D "c:/postgreSQL/data"
\??\C:\WINDOWS\system32\conhost.exe 0x4
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\System32\WScript.exe "C:\Users\PC-DÄšLO\AppData\Roaming\Origin\update.vbe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\AUDIODG.EXE 0x688
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
C:\WINDOWS\System32\dwm.exe
C:\WINDOWS\system32\atieclxx.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtWlan.exe" /H
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun
"C:\Program Files\OO Software\Defrag\oodtray.exe"
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareTray.exe"
C:\WINDOWS\System32\fontdrvhost.exe
"C:\Users\PC-DÄšLO\AppData\Local\Facebook\Games\FacebookGameroom.exe" fbgames://windows_startup/
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\MultiKeyboard Driver\KbdDrv.exe"
"C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
"C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe" -sync_complete
"C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe"
"C:\Users\PC-DÄšLO\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe" --type=gpu-process --channel="10276.0.1358078639\1003640163" --no-sandbox --lang=en-US --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x67b1 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.137.514 --lang=en-US /prefetch:822062411
C:\Users\PC-DÄšLO\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.693_none_42ff55c9655f38bf\TiWorker.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=56.0.2924.87 --initial-client-data=0x260,0x264,0x268,0x25c,0x26c,0x631c7598,0x631c75bc,0x631c75a4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=8656 --on-initialized-event-handle=884 --parent-handle=748 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,19,20,23,26,40,71 --gpu-vendor-id=0x1002 --gpu-device-id=0x67b1 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.137.514 --gpu-driver-date=11-21-2016 --service-request-channel-token=0CD9CE9F187711A7BAC1BA8D251B7BD5 --mojo-platform-channel-handle=1544 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=EC96D4D3E10DD3D0E32068A18BE4AC8A --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=EC96D4D3E10DD3D0E32068A18BE4AC8A --renderer-client-id=10 --mojo-platform-channel-handle=2528 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=273BE4F91EBD91C6182CC823303820B6 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=273BE4F91EBD91C6182CC823303820B6 --renderer-client-id=11 --mojo-platform-channel-handle=2716 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=8619BBF3CF561E72F102BD84F4F823D7 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=8619BBF3CF561E72F102BD84F4F823D7 --renderer-client-id=12 --mojo-platform-channel-handle=2748 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=3F557ED89B61B307D9E90711A5EE173C --lang=cs --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=3F557ED89B61B307D9E90711A5EE173C --renderer-client-id=14 --mojo-platform-channel-handle=2780 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=47170C5E61623FD1D60FDDCC1A046446 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=47170C5E61623FD1D60FDDCC1A046446 --renderer-client-id=5 --mojo-platform-channel-handle=4152 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=88E548E0F8C94F8F8200FF203F30ED14 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=88E548E0F8C94F8F8200FF203F30ED14 --renderer-client-id=6 --mojo-platform-channel-handle=4116 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=63E84769F4DB59D18523CE000D7678D1 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=63E84769F4DB59D18523CE000D7678D1 --renderer-client-id=7 --mojo-platform-channel-handle=4352 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=08B4F9EA3555337EADFB85D03A29E97D --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=08B4F9EA3555337EADFB85D03A29E97D --renderer-client-id=8 --mojo-platform-channel-handle=4488 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=C7756E5C5D2D2222BDAC35C7345667D3 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=C7756E5C5D2D2222BDAC35C7345667D3 --renderer-client-id=9 --mojo-platform-channel-handle=4508 /prefetch:1
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
C:\WINDOWS\splwow64.exe 12288
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/SEI_Control2/*InstanceID/Enabled/*MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/*SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/*WebFontsInterventionV2/Default/ --primordial-pipe-token=5DFFF672A04D07EEFCEB23DF7AC5B1AE --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=5DFFF672A04D07EEFCEB23DF7AC5B1AE --renderer-client-id=19 --mojo-platform-channel-handle=7116 /prefetch:1
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\PC-DÄšLO\Downloads\RSITx64.exe"

====== Scheduled tasks folder ======

C:\WINDOWS\tasks\Adobe Flash Player PPAPI Notifier.job - C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe -check pepperplugin
C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe -check pepperplugin
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task v2 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\Opera scheduled Autoupdate 1438528395 - C:\Program Files (x86)\Opera\launcher.exe --scheduledautoupdate $(Arg0)
C:\WINDOWS\system32\tasks\Origin - C:\Users\PC-DÄšLO\AppData\Roaming\Origin\update.vbe
C:\WINDOWS\system32\tasks\Overwolf Updater Task - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe /RunningFrom Schedule
C:\WINDOWS\system32\tasks\SafeZone scheduled Autoupdate 1457788371 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{0FF34E7E-F36C-457F-A788-31F59F5B0090} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval - %systemroot%\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe Reboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - C:\windows\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - C:\windows\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Setup\8.1 auto install ping - %windir%\system32\AutoUpdate.exe /Ping
C:\WINDOWS\system32\tasks\Microsoft\Windows\Setup\8.1 auto install v2 - C:\Windows\system32\AutoUpdate.exe /Auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs

=========Mozilla firefox=========

ProfilePath - C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\PDF Architect 3]
"Description"=
"Path"=C:\Program Files (x86)\PDF Architect 3\np-previewer.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll


C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default\addons.json
Firefox Hello Beta (discontinued) - extension - loop@mozilla.org
Mozilla Firefox hotfix - extension - firefox-hotfix@mozilla.org

C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default\extensions.json
PDF Architect 3 Creator - extension - pdf_architect_3_conv@pdfarchitect.org - C:\Program Files (x86)\PDF Architect 3\resources\pdfarchitect3firefoxextension
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Firefox Hello - extension - loop@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\loop@mozilla.org.xpi
Websense Helper - extension - websensehelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\websensehelper@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Avast Online Security - extension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF
Avast SafePrice - extension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF

C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default\pluginreg.dat
Plugin - PDF Architect 3 - 3.1.1.24851 - C:\Program Files (x86)\PDF Architect 3\np-previewer.dll
Plugin - Adobe Acrobat - 15.23.20053.15062 - C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
Plugin - VLC Web Plugin - 2.2.4.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
Plugin - Google Update - 1.3.32.7 - C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll
Plugin - Silverlight Plug-In - 5.1.50901.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll
Plugin - Shockwave Flash - 24.0.0.221 - C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll

=========Google Chrome=========

C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aciahcmjmecflokailenpkdchphgkefd 1 Entanglement Web App 3.4.9
Extension afpkfhjegipdjlgjfhhbcgohmnmhkicb 1 Death Racing 1.1.0
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod 0.2
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension bfpfdjclhabpjncikdngdoldjjjegnbe 1 American Racing 2 2.4
Extension cfhdojbkjhnklbpkdaibdccddilifddb 1 Adblock Plus 1.13
Extension cnpcnikknpblcjhaffbignljidlfhppp 1 Jagged Alliance Online 1.0.0.0
Extension dcpkjgdjjdcpjkanhpcjajnoliociigi
Extension ecdnoeebfjlplfkljdedokbcmebojbpb 1 Rush Team 1.2
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension egcldgpekkbhbdelknamfcahbimgnhji 1 Despicable Me 2 - Mission Impopsible 2.3.1
Extension ejjicmeblgpmajnghnpcppodonldlgfn 1 Kalendář Google 4.5.10
Extension ennkphjdgehloodpbhlhldgbnhmacadg Settings 0.2
Extension eofcbnmajmjmplflapaojjnihcjkigck 1 Avast SafePrice 12.0.155
Extension epnpeeikflalghohklkcgoifjcglfpch 1 The Amazing Spiderman 1.7
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension gjgkjeheegjnnmheaflhdocglkiegoni 1 Cesta skrz Středozem 0.0.1.8
Extension gomekmidlodglbbmalcneegieacbdmki 1 Avast Online Security 12.0.199
Extension hcojamkdafohfkedgkejobdgjofbokij 1 Mortal Kombat 3D 2.0.2
Extension iajlkcpgcnbhfhpdeooockfaincfkjjj 1 Isoball 3 1.4.0
Extension ifbhccdddhenjmeamogpjhicnoffdood 1 Šílené střelby 1.0.0
Extension ippmichjjjfjjmnkbclfldkglieafone
Extension jjiilfceogcmeegaomjeobpjfdfdkgef 1 Star Wars™: The Old Republic™ 1.0.5
Extension jmjbgcjbgmcfgbgikmbdioggjlhjegpp 1 Clipular! Research, save & share screenshot 10.8.29.2046
Extension keembkgclppcbilkekfgpobhldjjhpmn 1 Cargo Bridge 1.5.7
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension lejliakmhcfhakneflmicaoikhbicggc 1 Blogger 1
Extension lndokegkpdlafochibjpgjglkcamdpip 1 Currency Converter 1.0.4
Extension lneaknkopdijkpnocmklfnjbeapigfbh 1 Mapy Google 5.4.1
Extension lplcapojdeaodljfcmipfhkdlipkpkaf 1 Batman Games 1.0
Extension mcbpblocgmgfnpjjppndjkmgjaogfceg 1 Take Webpage Screenshots Entirely - FireShot 0.98.91
Extension mdiapnkglobpcfafhmcoecifdkegnkgi 1 Rising Cities 2.6
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension onhpbpcgnoglkojnigjlpjcblljfkakc
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh Google Now 1.2.0.1
Extension pcbpnafmoifnhegnebhcaioogohibnbf 1 On The Run The Getaway 3.2
Extension pgphcomnlaojlmmcjmiddhdapjpbgeoc 1 Send from Gmail (by Google) 1.16
Extension pkakfdfjgbihkcbkamikaoogblcagnih 1 Super Hero Games 2.3.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5616.1121.0.3
Homepage:
default_search_provider.search_url:
C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06E08260-0695-4EC1-A74B-1310D8899D93}]
PDF Architect 3 Helper - C:\Program Files (x86)\PDF Architect 3\creator-ie-helper.dll [2015-09-17 38112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-05-28 8483032]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-10-01 825184]
"Windows Mobile Device Center"=C:\WINDOWS\WindowsMobile\wmdc.exe [2007-05-31 660360]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe [2016-12-21 5134400]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2016-10-28 176440]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-11-21 8027016]
"AdAwareTray"=C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareTray.exe [2017-02-21 4461016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2016-07-26 3639280]
"GoogleChromeAutoLaunch_24FEC2ECB57787A648A75215DB5B0ADC"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2017-02-01 945496]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-02-08 27427808]
"OneDrive"=C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-01-27 1517280]
"Overwolf"=C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [2017-03-05 1058360]
"TeamSpeak 3 Client"=C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe [2017-02-22 14729496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"Raptr"=C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [2016-05-23 58640]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-08 205512]
"TrojanScanner"=C:\Program Files (x86)\Trojan Remover\Trjscan.exe [2016-02-19 3753016]
"PlaysTV"=C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [2016-08-24 71440]
""= []
"Razer Synapse"=C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [2017-03-02 596640]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O&O Defrag Tray.lnk - C:\WINDOWS\Installer\{1D952425-335E-4586-AAEC-56DA0CDB01D9}\app_icon.ico

C:\Users\PC-DÄšLO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Facebook Gameroom.lnk - C:\Users\PC-DÄšLO\AppData\Local\Facebook\Games\FacebookGameroom.exe
MutiKeyboard Driver.lnk - C:\Program Files (x86)\MultiKeyboard Driver\KbdDrv.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\adawareantivirusservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\adawareantivirusservice]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"undockwithoutlogon"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
"StubPath" = %SystemRoot%\inf\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2017-03-15 23:00:33 ----D---- C:\rsit
2017-03-15 23:00:33 ----D---- C:\Program Files\trend micro
2017-03-15 11:30:57 ----D---- C:\ProgramData\SWCUTemp
2017-03-14 12:02:26 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\adaware
2017-03-14 12:00:31 ----D---- C:\Program Files\adaware
2017-03-14 11:59:35 ----D---- C:\Program Files\Common Files\adaware
2017-03-14 11:59:10 ----D---- C:\ProgramData\adaware
2017-03-14 01:59:50 ----D---- C:\WINDOWS\system32\f741354d56665b62bdd13..bin
2017-03-10 20:47:04 ----D---- C:\WINDOWS\system32\32db7163a0ddbff0b7089..bin
2017-03-09 00:42:43 ----D---- C:\WINDOWS\system32\˙˙˙˙˙˙˙˙
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbuniva.sys
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbloga.sys
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbidsha.sys
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbidsdrivera.sys
2017-03-08 21:38:14 ----A---- C:\WINDOWS\system32\aswBoot.exe
2017-03-08 21:38:13 ----A---- C:\WINDOWS\system32\drivers\aswHdsKe.sys
2017-02-24 00:39:40 ----A---- C:\WINDOWS\system32\drivers\rzpnk.sys
2017-02-24 00:39:35 ----A---- C:\WINDOWS\system32\drivers\rzpmgrk.sys
2017-02-23 23:28:41 ----D---- C:\ProgramData\Razer
2017-02-23 23:28:37 ----AD---- C:\Program Files (x86)\Razer
2017-02-19 23:03:11 ----D---- C:\PokerStars
2017-02-19 23:03:10 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\Roaming

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#4 Příspěvek od DuVenBlejt »

====== List of files/folders modified in the last 1 month ======

2017-03-15 23:01:57 ----D---- C:\WINDOWS\WinSxS
2017-03-15 23:00:38 ----D---- C:\WINDOWS\Prefetch
2017-03-15 23:00:33 ----RD---- C:\Program Files
2017-03-15 22:59:49 ----D---- C:\WINDOWS\CbsTemp
2017-03-15 22:59:21 ----D---- C:\WINDOWS\system32\config
2017-03-15 22:59:21 ----D---- C:\WINDOWS\system32\catroot2
2017-03-15 22:59:07 ----D---- C:\WINDOWS\Temp
2017-03-15 22:58:05 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\TS3Client
2017-03-15 22:57:32 ----D---- C:\WINDOWS\system32\sru
2017-03-15 13:17:57 ----D---- C:\WINDOWS\system32\SleepStudy
2017-03-15 11:37:56 ----D---- C:\WINDOWS\system32\drivers
2017-03-15 11:37:34 ----HD---- C:\Program Files\WindowsApps
2017-03-15 11:37:34 ----D---- C:\WINDOWS\AppReadiness
2017-03-15 11:35:25 ----D---- C:\WINDOWS\System32
2017-03-15 11:35:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-15 11:30:57 ----HD---- C:\ProgramData
2017-03-15 02:30:32 ----D---- C:\Program Files (x86)\Steam
2017-03-15 02:20:51 ----RD---- C:\WINDOWS\Microsoft.NET
2017-03-15 01:30:09 ----D---- C:\WINDOWS\Tasks
2017-03-15 01:30:09 ----D---- C:\WINDOWS\SysWOW64
2017-03-15 01:30:06 ----D---- C:\WINDOWS\system32\Macromed
2017-03-15 01:30:05 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-03-14 12:08:56 ----SHD---- C:\System Volume Information
2017-03-14 12:01:08 ----SHDC---- C:\WINDOWS\Installer
2017-03-14 12:01:08 ----SHD---- C:\Config.Msi
2017-03-14 11:59:35 ----D---- C:\Program Files\Common Files
2017-03-14 11:57:04 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\uTorrent
2017-03-14 10:45:01 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\vlc
2017-03-13 23:04:39 ----D---- C:\WINDOWS\LiveKernelReports
2017-03-12 17:49:16 ----D---- C:\WINDOWS\system32\DriverStore
2017-03-12 17:49:16 ----D---- C:\WINDOWS\INF
2017-03-11 07:24:39 ----D---- C:\WINDOWS\system32\Tasks
2017-03-10 22:09:49 ----D---- C:\ProgramData\AVAST Software
2017-03-10 13:45:38 ----AD---- C:\Program Files (x86)\Overwolf
2017-03-10 12:59:57 ----D---- C:\ProgramData\Package Cache
2017-03-09 12:55:02 ----AD---- C:\Program Files (x86)\Opera
2017-03-09 11:08:30 ----D---- C:\WINDOWS\system32\NDF
2017-03-07 14:09:11 ----RSD---- C:\WINDOWS\assembly
2017-03-07 14:09:07 ----D---- C:\WINDOWS\Logs
2017-02-24 01:01:48 ----D---- C:\WINDOWS\system32\CatRoot
2017-02-24 00:39:06 ----D---- C:\Windows
2017-02-23 23:30:01 ----D---- C:\WINDOWS\system32\MRT
2017-02-23 23:28:37 ----RD---- C:\Program Files (x86)
2017-02-23 12:46:30 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-02-22 23:08:08 ----D---- C:\ProgramData\Skype
2017-02-22 12:19:55 ----AD---- C:\Program Files\TeamSpeak 3 Client
2017-02-19 23:04:46 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\HoldemManager
2017-02-19 23:03:11 ----AD---- C:\Program Files (x86)\PokerStars
2017-02-19 23:02:15 ----D---- C:\Program Files (x86)\Holdem Manager 2

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [2017-03-08 189768]
R0 aswblog;aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [2017-03-08 334600]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [2017-03-08 48528]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2017-03-08 75704]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2017-03-15 337592]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992]
R1 AsIO;AsIO; SysWow64\drivers\AsIO.sys []
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [2017-03-08 309272]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2017-03-08 32088]
R1 aswNetSec;aswNetSec; C:\WINDOWS\system32\drivers\aswNetSec.sys [2017-03-08 461640]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2017-03-08 100640]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2017-03-08 993608]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2017-03-10 548928]
R1 dtsoftbus01;@oem34.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-06-13 283064]
R2 amdacpksd;ACP Kernel Service Driver; \??\C:\WINDOWS\system32\drivers\amdacpksd.sys [2014-11-21 294600]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2017-03-08 126600]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2017-03-08 162528]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 rzpmgrk;rzpmgrk; \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys [2016-09-17 44144]
R2 rzpnk;rzpnk; \??\C:\WINDOWS\system32\drivers\rzpnk.sys [2016-10-08 137840]
R3 amdkmdag;amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys [2017-01-25 26568848]
R3 amdkmdap;amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys [2017-01-25 536600]
R3 AtiHDAudioService;@oem10.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2016-02-11 111120]
R3 rzendpt;@oem52.inf,%rzendpt.SvcDesc%;rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [2015-08-13 50392]
R3 rzudd;@oem64.inf,%Razer.SvcDesc%;Razer Mouse Driver; C:\WINDOWS\System32\drivers\rzudd.sys [2015-08-13 202952]
S0 amdkmafd;@oem42.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 64352]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 aswHdsKe;aswHdsKe; \??\C:\WINDOWS\system32\drivers\aswHdsKe.sys [2017-03-07 85552]
S3 aswHwid;aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [2017-03-08 38296]
S3 aswTap;@oem7.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\WINDOWS\System32\drivers\aswTap.sys [2015-04-09 44640]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-10-02 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S3 Trufos;Trufos; C:\WINDOWS\system32\DRIVERS\Trufos.sys [2017-02-08 442848]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdaptiveSleepService;AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [2016-11-21 155016]
R2 adawareantivirusservice;adaware antivirus service; C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe [2017-02-21 585784]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2017-01-25 305176]
R2 amdacpusrsvc;ACP User Service; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [2014-11-20 116224]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-09-22 83768]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [2013-07-04 936728]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [2014-04-24 1360016]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-08 262736]
R2 avast! Firewall;Avast Firewall Service; C:\Program Files\AVAST Software\Avast\afwServ.exe [2017-03-08 278784]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [2015-05-07 271632]
R2 OneSyncSvc_85c694;Hostitel synchronizace_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 OODefragAgent;O&O Defrag; C:\Program Files\OO Software\Defrag\oodag.exe [2016-12-21 1740864]
R2 PDF Architect 3 Creator;PDF Architect 3 Creator; C:\Program Files (x86)\PDF Architect 3\creator-ws.exe [2015-09-17 767712]
R2 PlaysService;Plays.tv Update Service; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [2016-08-24 32528]
R2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4; c:\postgreSQL\bin\pg_ctl.exe [2014-02-18 66048]
R2 Razer Game Scanner Service;Razer Game Scanner; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [2016-09-25 189264]
R2 Realtek11nSU;Realtek11nSU; C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe [2012-05-10 36864]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-08 7147320]
R3 PimIndexMaintenanceSvc_85c694;Data kontaktĹŻ_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\TimeBrokerServer.dll
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S2 CDPUserSvc_85c694;CDPUserSvc_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-01-16 317400]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-10-28 651576]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 MessagingService_85c694;Služba zasílání zpráv_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 MozillaMaintenance;MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-22 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-07-26 2122248]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-03-05 1325384]
S3 PDF Architect 3 CrashHandler;PDF Architect 3 CrashHandler; C:\Program Files (x86)\PDF Architect 3\crash-handler-ws.exe [2015-09-17 964832]
S3 PDF Architect 3;PDF Architect 3; C:\Program Files (x86)\PDF Architect 3\ws.exe [2015-09-17 2244832]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-03-13 1590560]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------
====== List of files/folders modified in the last 1 month ======

2017-03-15 23:01:57 ----D---- C:\WINDOWS\WinSxS
2017-03-15 23:00:38 ----D---- C:\WINDOWS\Prefetch
2017-03-15 23:00:33 ----RD---- C:\Program Files
2017-03-15 22:59:49 ----D---- C:\WINDOWS\CbsTemp
2017-03-15 22:59:21 ----D---- C:\WINDOWS\system32\config
2017-03-15 22:59:21 ----D---- C:\WINDOWS\system32\catroot2
2017-03-15 22:59:07 ----D---- C:\WINDOWS\Temp
2017-03-15 22:58:05 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\TS3Client
2017-03-15 22:57:32 ----D---- C:\WINDOWS\system32\sru
2017-03-15 13:17:57 ----D---- C:\WINDOWS\system32\SleepStudy
2017-03-15 11:37:56 ----D---- C:\WINDOWS\system32\drivers
2017-03-15 11:37:34 ----HD---- C:\Program Files\WindowsApps
2017-03-15 11:37:34 ----D---- C:\WINDOWS\AppReadiness
2017-03-15 11:35:25 ----D---- C:\WINDOWS\System32
2017-03-15 11:35:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-15 11:30:57 ----HD---- C:\ProgramData
2017-03-15 02:30:32 ----D---- C:\Program Files (x86)\Steam
2017-03-15 02:20:51 ----RD---- C:\WINDOWS\Microsoft.NET
2017-03-15 01:30:09 ----D---- C:\WINDOWS\Tasks
2017-03-15 01:30:09 ----D---- C:\WINDOWS\SysWOW64
2017-03-15 01:30:06 ----D---- C:\WINDOWS\system32\Macromed
2017-03-15 01:30:05 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-03-14 12:08:56 ----SHD---- C:\System Volume Information
2017-03-14 12:01:08 ----SHDC---- C:\WINDOWS\Installer
2017-03-14 12:01:08 ----SHD---- C:\Config.Msi
2017-03-14 11:59:35 ----D---- C:\Program Files\Common Files
2017-03-14 11:57:04 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\uTorrent
2017-03-14 10:45:01 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\vlc
2017-03-13 23:04:39 ----D---- C:\WINDOWS\LiveKernelReports
2017-03-12 17:49:16 ----D---- C:\WINDOWS\system32\DriverStore
2017-03-12 17:49:16 ----D---- C:\WINDOWS\INF
2017-03-11 07:24:39 ----D---- C:\WINDOWS\system32\Tasks
2017-03-10 22:09:49 ----D---- C:\ProgramData\AVAST Software
2017-03-10 13:45:38 ----AD---- C:\Program Files (x86)\Overwolf
2017-03-10 12:59:57 ----D---- C:\ProgramData\Package Cache
2017-03-09 12:55:02 ----AD---- C:\Program Files (x86)\Opera
2017-03-09 11:08:30 ----D---- C:\WINDOWS\system32\NDF
2017-03-07 14:09:11 ----RSD---- C:\WINDOWS\assembly
2017-03-07 14:09:07 ----D---- C:\WINDOWS\Logs
2017-02-24 01:01:48 ----D---- C:\WINDOWS\system32\CatRoot
2017-02-24 00:39:06 ----D---- C:\Windows
2017-02-23 23:30:01 ----D---- C:\WINDOWS\system32\MRT
2017-02-23 23:28:37 ----RD---- C:\Program Files (x86)
2017-02-23 12:46:30 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-02-22 23:08:08 ----D---- C:\ProgramData\Skype
2017-02-22 12:19:55 ----AD---- C:\Program Files\TeamSpeak 3 Client
2017-02-19 23:04:46 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\HoldemManager
2017-02-19 23:03:11 ----AD---- C:\Program Files (x86)\PokerStars
2017-02-19 23:02:15 ----D---- C:\Program Files (x86)\Holdem Manager 2

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [2017-03-08 189768]
R0 aswblog;aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [2017-03-08 334600]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [2017-03-08 48528]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2017-03-08 75704]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2017-03-15 337592]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992]
R1 AsIO;AsIO; SysWow64\drivers\AsIO.sys []
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [2017-03-08 309272]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2017-03-08 32088]
R1 aswNetSec;aswNetSec; C:\WINDOWS\system32\drivers\aswNetSec.sys [2017-03-08 461640]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2017-03-08 100640]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2017-03-08 993608]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2017-03-10 548928]
R1 dtsoftbus01;@oem34.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-06-13 283064]
R2 amdacpksd;ACP Kernel Service Driver; \??\C:\WINDOWS\system32\drivers\amdacpksd.sys [2014-11-21 294600]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2017-03-08 126600]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2017-03-08 162528]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 rzpmgrk;rzpmgrk; \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys [2016-09-17 44144]
R2 rzpnk;rzpnk; \??\C:\WINDOWS\system32\drivers\rzpnk.sys [2016-10-08 137840]
R3 amdkmdag;amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys [2017-01-25 26568848]
R3 amdkmdap;amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys [2017-01-25 536600]
R3 AtiHDAudioService;@oem10.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2016-02-11 111120]
R3 rzendpt;@oem52.inf,%rzendpt.SvcDesc%;rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [2015-08-13 50392]
R3 rzudd;@oem64.inf,%Razer.SvcDesc%;Razer Mouse Driver; C:\WINDOWS\System32\drivers\rzudd.sys [2015-08-13 202952]
S0 amdkmafd;@oem42.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 64352]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 aswHdsKe;aswHdsKe; \??\C:\WINDOWS\system32\drivers\aswHdsKe.sys [2017-03-07 85552]
S3 aswHwid;aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [2017-03-08 38296]
S3 aswTap;@oem7.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\WINDOWS\System32\drivers\aswTap.sys [2015-04-09 44640]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-10-02 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S3 Trufos;Trufos; C:\WINDOWS\system32\DRIVERS\Trufos.sys [2017-02-08 442848]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdaptiveSleepService;AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [2016-11-21 155016]
R2 adawareantivirusservice;adaware antivirus service; C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe [2017-02-21 585784]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2017-01-25 305176]
R2 amdacpusrsvc;ACP User Service; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [2014-11-20 116224]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-09-22 83768]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [2013-07-04 936728]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [2014-04-24 1360016]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-08 262736]
R2 avast! Firewall;Avast Firewall Service; C:\Program Files\AVAST Software\Avast\afwServ.exe [2017-03-08 278784]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [2015-05-07 271632]
R2 OneSyncSvc_85c694;Hostitel synchronizace_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 OODefragAgent;O&O Defrag; C:\Program Files\OO Software\Defrag\oodag.exe [2016-12-21 1740864]
R2 PDF Architect 3 Creator;PDF Architect 3 Creator; C:\Program Files (x86)\PDF Architect 3\creator-ws.exe [2015-09-17 767712]
R2 PlaysService;Plays.tv Update Service; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [2016-08-24 32528]
R2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4; c:\postgreSQL\bin\pg_ctl.exe [2014-02-18 66048]
R2 Razer Game Scanner Service;Razer Game Scanner; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [2016-09-25 189264]
R2 Realtek11nSU;Realtek11nSU; C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe [2012-05-10 36864]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-08 7147320]
R3 PimIndexMaintenanceSvc_85c694;Data kontaktĹŻ_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\TimeBrokerServer.dll
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S2 CDPUserSvc_85c694;CDPUserSvc_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-01-16 317400]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-10-28 651576]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 MessagingService_85c694;Služba zasílání zpráv_85c694; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 MozillaMaintenance;MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-22 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-07-26 2122248]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-03-05 1325384]
S3 PDF Architect 3 CrashHandler;PDF Architect 3 CrashHandler; C:\Program Files (x86)\PDF Architect 3\crash-handler-ws.exe [2015-09-17 964832]
S3 PDF Architect 3;PDF Architect 3; C:\Program Files (x86)\PDF Architect 3\ws.exe [2015-09-17 2244832]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-03-13 1590560]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Napadl me asi hacker

#5 Příspěvek od Roli »

V první řadě odinstaluj vše od Seznam.cz a Trojan Remover.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a spusť AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.


Pak použij Mbam z mého podpisu a dej mi sem z něj log po smazání nepořádku.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#6 Příspěvek od DuVenBlejt »

# AdwCleaner v6.044 - Log vytvořen 16/03/2017 v 23:09:44
# Aktualizováno dne 28/02/2017 z Malwarebytes
# Databáze : 2017-03-15.2 [Server]
# Operační systém : Windows 10 Home (X64)
# Uživatelské jméno : PC-DĚLO - PC
# Spuštěno z : C:\Users\PC-DĚLO\Downloads\adwcleaner_6.044.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ SluĹľby ] *****



***** [ SloĹľky ] *****

[-] Složka smazána: C:\Program Files (x86)\unisalEEss
[-] Složka smazána: C:\ProgramData\11936247955612823405


***** [ Soubory ] *****

[-] Soubor smazán: C:\END


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKU\S-1-5-21-3959593766-1101095669-3702493713-1001\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
[#] Klíč smazán po restartu: HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
[-] Klíč smazán: HKU\S-1-5-21-3959593766-1101095669-3702493713-1001\Software\Link64
[#] Klíč smazán po restartu: HKCU\Software\Link64
[-] Klíč smazán: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}
[#] Klíč smazán po restartu: [x64] HKCU\Software\Link64
[-] Klíč smazán: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Klíč smazán: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[#] Klíč smazán po restartu: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[#] Klíč smazán po restartu: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[-] Hodnota smazána: HKU\S-1-5-21-3959593766-1101095669-3702493713-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [VideoDownloaderUltimate]


***** [ ProhlĂ­ĹľeÄŤe ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2154 Bajty] - [16/03/2017 23:09:44]
C:\AdwCleaner\AdwCleaner[S0].txt - [2469 Bajty] - [16/03/2017 23:09:12]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [2300 Bajty] ##########

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#7 Příspěvek od DuVenBlejt »

info : Nic od Seznam.cz jsem nenasel takze ani neodinstaloval

Nikdy jsem nic od seznamu nepouzival ani neinstaloval. Email na seznamu nevlastnim.

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#8 Příspěvek od DuVenBlejt »

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacĂ­ho souboru-
Datum skenování: 16.03.17
Čas skenování: 23:16
LogovacĂ­ soubor: log.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.0.6.1469
Verze komponentĹŻ: 1.0.75
Aktualizovat verzi balĂ­ku komponent: 1.0.1518
Licence: Zkušební

-Systémová informace-
OS: Windows 10
CPU: x64
Systém souborů: NTFS
UĹľivatel: PC\PC-D\u00c4\u009aLO

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 413898
UplynulĂ˝ ÄŤas: 52 min, 7 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

KlĂ­ÄŤ registru: 10
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, Žádná uživatelská akce, [191], [169264],1.0.1518

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrĹŻ: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 2
PUP.Optional.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\ORIGIN, Žádná uživatelská akce, [253], [339240],1.0.1518
CrackTool.Agent, E:\DIRT3\PAUL.DLL, Žádná uživatelská akce, [385], [84096],1.0.1518

FyzickĂ˝ sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacĂ­ho souboru-
Datum skenování: 16.03.17
Čas skenování: 23:16
LogovacĂ­ soubor: log.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.0.6.1469
Verze komponentĹŻ: 1.0.75
Aktualizovat verzi balĂ­ku komponent: 1.0.1518
Licence: Zkušební

-Systémová informace-
OS: Windows 10
CPU: x64
Systém souborů: NTFS
UĹľivatel: PC\PC-D\u00c4\u009aLO

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 413898
UplynulĂ˝ ÄŤas: 52 min, 7 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

KlĂ­ÄŤ registru: 10
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, Žádná uživatelská akce, [191], [169264],1.0.1518
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, Žádná uživatelská akce, [191], [169264],1.0.1518

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrĹŻ: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 2
PUP.Optional.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\ORIGIN, Žádná uživatelská akce, [253], [339240],1.0.1518
CrackTool.Agent, E:\DIRT3\PAUL.DLL, Žádná uživatelská akce, [385], [84096],1.0.1518

FyzickĂ˝ sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Napadl me asi hacker

#9 Příspěvek od Roli »

DuVenBlejt píše:info : Nic od Seznam.cz jsem nenasel takze ani neodinstaloval

Nikdy jsem nic od seznamu nepouzival ani neinstaloval. Email na seznamu nevlastnim.
Je tam vidět software nebo doplněk prohlížeče Seznam-listicka který se spouští při startu PC.


Spusť skener Cure It podle TOHOTO návodu

po skončení skenu mi sem nakopíruj výsledky - stačí konec logu se souhrnem.

(Upozornění je úchylně pomalý a je zapotřebí ho sledovat občas se na něco ptá)
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#10 Příspěvek od DuVenBlejt »

Total 14637389431 bytes in 45849 files scanned (53194 objects)
Total 45915 files (53155 objects) are clean
There are no infected objects detected
Total 39 files are raised error condition
Scan time is 00:03:03.736

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Napadl me asi hacker

#11 Příspěvek od Roli »

Dej mi sem ještě aktuální log z Rsit, mrknu co tam zůstalo zbytečného.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#12 Příspěvek od DuVenBlejt »

Logfile of random's system information tool 1.16 (written by random/random)
Run by PC-DÄšLO at 2017-03-22 14:47:32
Microsoft Windows 10 Home
System drive C: has 33 GB (28%) free of 121 GB
Total RAM: 16322 MB (79% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:47:35, on 22. 3. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
C:\Users\PC-DÄšLO\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe
E:\WOT\WOTLauncher.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\PC-DÄšLO_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: PDF Architect 3 Helper - {06E08260-0695-4EC1-A74B-1310D8899D93} - C:\Program Files (x86)\PDF Architect 3\creator-ie-helper.dll
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [Raptr] "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_24FEC2ECB57787A648A75215DB5B0ADC] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [OneDrive] "C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent
O4 - HKCU\..\Run: [TeamSpeak 3 Client] "C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3959593766-1101095669-3702493713-1005\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'postgres')
O4 - HKUS\S-1-5-21-3959593766-1101095669-3702493713-1005\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'postgres')
O4 - Global Startup: O&O Defrag Tray.lnk = ?
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{1c390444-7b79-4f45-bfe4-16850b2953f2}: NameServer = 77.234.40.79
O17 - HKLM\System\CS1\Services\Tcpip\..\{1c390444-7b79-4f45-bfe4-16850b2953f2}: NameServer = 77.234.40.79
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: adaware antivirus service (adawareantivirusservice) - Unknown owner - C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AdobeFlashPlayerUpdateSvc - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: ACP User Service (amdacpusrsvc) - Advanced Micro Devices - C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall Service (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: gupdate - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: gupdatem - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: MozillaMaintenance - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: PDF Architect 3 - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\ws.exe
O23 - Service: PDF Architect 3 CrashHandler - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\crash-handler-ws.exe
O23 - Service: PDF Architect 3 Creator - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 3\creator-ws.exe
O23 - Service: postgresql-8.4 - PostgreSQL Server 8.4 (postgresql-8.4) - PostgreSQL Global Development Group - c:\postgreSQL\bin\pg_ctl.exe
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: Realtek11nSU - Realtek Semiconductor Corp. - C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12764 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6058c17b-d037-41ab-b7a7-092c052fc656 -SystemEventPortName:HostProcess-570a09a4-e2c1-4651-8139-d8dabd865ca0 -IoCancelEventPortName:HostProcess-ae3797de-fb05-46c4-965c-03c06ea2a88d -NonStateChangingEventPortName:HostProcess-94dd542f-ba8c-4265-a108-c1da1666896b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2211a925-3fd6-46ab-8a03-6587aeaa0bd3 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\system32\atieclxx.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe"
"C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe"
"C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\WINDOWS\system32\IProsetMonitor.exe
"C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\PDF Architect 3\creator-ws.exe"
"C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files\OO Software\Defrag\oodag.exe"
"c:\postgreSQL\bin\pg_ctl.exe" runservice -N "postgresql-8.4" -D "c:/postgreSQL/data" -w
"c:\postgreSQL\bin\postgres.exe" -D "c:/postgreSQL/data"
\??\C:\WINDOWS\system32\conhost.exe 0x4
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
c:\postgreSQL\bin\postgres.exe
C:\WINDOWS\system32\dashost.exe
"C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtWlan.exe" /H
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe" silentrun
"C:\Program Files\OO Software\Defrag\oodtray.exe"
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe"
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
C:\WINDOWS\system32\fontdrvhost.exe
"C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe" -sync_complete
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe"
"C:\Users\PC-DÄšLO\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe" --type=gpu-process --channel="10628.0.745450114\398715036" --no-sandbox --lang=en-US --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x67b1 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.137.514 --lang=en-US /prefetch:822062411
C:\Windows\System32\InstallAgent.exe -Embedding
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\WINDOWS\system32\compattelrunner.exe
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\CompatTelRunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun -cv:O4Z2MRLIGUKnTt2v.1
C:\WINDOWS\system32\wbem\wmiprvse.exe
"E:\WOT\WOTLauncher.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=56.0.2924.87 --initial-client-data=0x37c,0x380,0x384,0x374,0x388,0x54877598,0x548775bc,0x548775a4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=10848 --on-initialized-event-handle=1132 --parent-handle=1136 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,19,20,23,26,40,71 --gpu-vendor-id=0x1002 --gpu-device-id=0x67b1 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.137.514 --gpu-driver-date=11-21-2016 --service-request-channel-token=0A83BEA5C6A1E5FAD131139EEBF9A3EA --mojo-platform-channel-handle=1764 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=2A4F8FB14F13B90DD791736F9F77C546 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=2A4F8FB14F13B90DD791736F9F77C546 --renderer-client-id=10 --mojo-platform-channel-handle=2736 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=7C100E7BACA306C463D1BB24FACC58D2 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=7C100E7BACA306C463D1BB24FACC58D2 --renderer-client-id=11 --mojo-platform-channel-handle=2844 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=60B31656163C57983F787DFE3D379CA3 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=60B31656163C57983F787DFE3D379CA3 --renderer-client-id=12 --mojo-platform-channel-handle=2776 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=CB018851FF955885BF3FC4B305B630A1 --lang=cs --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=CB018851FF955885BF3FC4B305B630A1 --renderer-client-id=14 --mojo-platform-channel-handle=2780 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=920EDFE28B06554CB0783BA7E3BC28D8 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=920EDFE28B06554CB0783BA7E3BC28D8 --renderer-client-id=4 --mojo-platform-channel-handle=3152 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=26298A5D4EEB5E27F8E8AA7631F8E3D9 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=26298A5D4EEB5E27F8E8AA7631F8E3D9 --renderer-client-id=5 --mojo-platform-channel-handle=3124 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=5169DBC790DEDD7948BAEB525635D3C0 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=5169DBC790DEDD7948BAEB525635D3C0 --renderer-client-id=6 --mojo-platform-channel-handle=3120 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=63DC3D582C5AE0529383C925F42DA462 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=63DC3D582C5AE0529383C925F42DA462 --renderer-client-id=7 --mojo-platform-channel-handle=2980 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=BE8D6EAAC8C1681CD5C68772968D4A02 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=BE8D6EAAC8C1681CD5C68772968D4A02 --renderer-client-id=8 --mojo-platform-channel-handle=3220 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/SEI_Control2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/EnabledInMemory/PluginPowerSaverTiny/Enabled2/*QUIC/Enabled5RTOJuly/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_86/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=8F9F498779BA5D749ECD7409BF98A6B2 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=8F9F498779BA5D749ECD7409BF98A6B2 --renderer-client-id=9 --mojo-platform-channel-handle=3252 /prefetch:1
C:\WINDOWS\system32\AUDIODG.EXE 0x43c
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\PC-DÄšLO\Downloads\RSITx64.exe"

====== Scheduled tasks folder ======

C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_25_0_0_127_pepper.exe -check pepperplugin
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task v2 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\Opera scheduled Autoupdate 1438528395 - C:\Program Files (x86)\Opera\launcher.exe --scheduledautoupdate $(Arg0)
C:\WINDOWS\system32\tasks\Overwolf Updater Task - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe /RunningFrom Schedule
C:\WINDOWS\system32\tasks\SafeZone scheduled Autoupdate 1457788371 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{0FF34E7E-F36C-457F-A788-31F59F5B0090} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval - %systemroot%\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe RebootDialog
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - C:\windows\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - C:\windows\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Setup\8.1 auto install ping - %windir%\system32\AutoUpdate.exe /Ping
C:\WINDOWS\system32\tasks\Microsoft\Windows\Setup\8.1 auto install v2 - C:\Windows\system32\AutoUpdate.exe /Auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs

=========Mozilla firefox=========

ProfilePath - C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\PDF Architect 3]
"Description"=
"Path"=C:\Program Files (x86)\PDF Architect 3\np-previewer.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll


C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default\addons.json
Firefox Hello Beta (discontinued) - extension - loop@mozilla.org
Mozilla Firefox hotfix - extension - firefox-hotfix@mozilla.org

C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default\extensions.json
PDF Architect 3 Creator - extension - pdf_architect_3_conv@pdfarchitect.org - C:\Program Files (x86)\PDF Architect 3\resources\pdfarchitect3firefoxextension
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Firefox Hello - extension - loop@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\loop@mozilla.org.xpi
Websense Helper - extension - websensehelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\websensehelper@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Avast Online Security - extension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF
Avast SafePrice - extension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF

C:\Users\PC-DÄšLO\AppData\Roaming\Mozilla\Firefox\Profiles\0gk50u52.default\pluginreg.dat
Plugin - PDF Architect 3 - 3.1.1.24851 - C:\Program Files (x86)\PDF Architect 3\np-previewer.dll
Plugin - Adobe Acrobat - 15.23.20053.15062 - C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
Plugin - VLC Web Plugin - 2.2.4.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
Plugin - Google Update - 1.3.32.7 - C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll
Plugin - Silverlight Plug-In - 5.1.50901.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll
Plugin - Shockwave Flash - 24.0.0.221 - C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll

=========Google Chrome=========

C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod 0.2
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension cfhdojbkjhnklbpkdaibdccddilifddb 1 Adblock Plus 1.13.2
Extension dcpkjgdjjdcpjkanhpcjajnoliociigi
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension ejjicmeblgpmajnghnpcppodonldlgfn 1 Kalendář Google 4.5.10
Extension ennkphjdgehloodpbhlhldgbnhmacadg Settings 0.2
Extension eofcbnmajmjmplflapaojjnihcjkigck 1 Avast SafePrice 12.0.199
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension gomekmidlodglbbmalcneegieacbdmki 1 Avast Online Security 12.0.199
Extension ippmichjjjfjjmnkbclfldkglieafone
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension lneaknkopdijkpnocmklfnjbeapigfbh 1 Mapy Google 5.4.1
Extension mcbpblocgmgfnpjjppndjkmgjaogfceg 1 Take Webpage Screenshots Entirely - FireShot 0.98.91
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension onhpbpcgnoglkojnigjlpjcblljfkakc
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh Google Now 1.2.0.1
Extension pgphcomnlaojlmmcjmiddhdapjpbgeoc 1 Send from Gmail (by Google) 1.16
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5616.1121.0.3
Homepage:
default_search_provider.search_url:
C:\Users\PC-DÄšLO\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06E08260-0695-4EC1-A74B-1310D8899D93}]
PDF Architect 3 Helper - C:\Program Files (x86)\PDF Architect 3\creator-ie-helper.dll [2015-09-17 38112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-05-28 8483032]
"XboxStat"=C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2009-10-01 825184]
"Windows Mobile Device Center"=C:\WINDOWS\WindowsMobile\wmdc.exe [2007-05-31 660360]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe [2016-12-21 5134400]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2016-10-28 176440]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-11-21 8027016]
"Malwarebytes TrayApp"=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2017-01-20 2780112]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2016-07-26 3639280]
"GoogleChromeAutoLaunch_24FEC2ECB57787A648A75215DB5B0ADC"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2017-02-01 945496]
"OneDrive"=C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-01-27 1517280]
"Overwolf"=C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [2017-03-16 1058360]
"TeamSpeak 3 Client"=C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe [2017-02-22 14729496]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2017-03-03 9364696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\PC-DÄšLO\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"Raptr"=C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [2016-05-23 58640]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-08 205512]
""= []
"Razer Synapse"=C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [2017-03-02 596640]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
O&O Defrag Tray.lnk - C:\WINDOWS\Installer\{1D952425-335E-4586-AAEC-56DA0CDB01D9}\app_icon.ico

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\adawareantivirusservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\adawareantivirusservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"undockwithoutlogon"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
"StubPath" = %SystemRoot%\inf\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#13 Příspěvek od DuVenBlejt »

====== List of files/folders created in the last 1 month ======

2017-03-20 21:38:05 ----AD---- C:\Program Files (x86)\PokerStars.CZ
2017-03-20 19:55:39 ----D---- C:\ProgramData\SWCUTemp
2017-03-18 13:11:52 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-03-18 13:11:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-03-18 13:11:51 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-03-18 13:11:51 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-03-18 13:11:51 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-03-18 13:11:51 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-03-18 13:11:50 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-03-18 13:11:50 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-03-18 13:11:50 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-03-18 13:11:50 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-03-18 13:11:50 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-03-18 13:11:50 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-03-18 13:11:49 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-03-18 13:11:49 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-03-18 13:11:49 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-03-18 13:11:49 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-03-18 13:11:49 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-03-18 13:11:49 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\MapRouter.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-03-18 13:11:48 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\MapGeocoder.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-03-18 13:11:47 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\hevcdecoder.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-03-18 13:11:46 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\mprddm.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-03-18 13:11:45 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2017-03-18 13:11:44 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\TpmCoreProvisioning.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\gameux.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-03-18 13:11:43 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2017-03-18 13:11:42 ----A---- C:\WINDOWS\system32\drivers\storahci.sys
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\PCPTpm12.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\CompPkgSup.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-03-18 13:11:41 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\gpapi.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2017-03-18 13:11:40 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\netiohlp.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-03-18 13:11:39 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\netiougc.exe
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\MCCSEngineShared.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\imapi2fs.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\icm32.dll
2017-03-18 13:11:38 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\mssphtb.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-03-18 13:11:37 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\themecpl.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\sud.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\Pimstore.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\mtxclu.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\msutb.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2017-03-18 13:11:36 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\WsmWmiPl.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\wlanui.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.Search.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\UserLanguagesCpl.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\regedit.exe
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\MSPhotography.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\msdtcuiu.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\azroleui.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2017-03-18 13:11:35 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\WMVSENCD.DLL
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\wcnwiz.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\tcpipcfg.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\mscandui.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\LockAppBroker.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-03-18 13:11:34 ----A---- C:\WINDOWS\SYSWOW64\BrowserSettingSync.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\XInputUap.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.UI.GameBar.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\MSVP9DEC.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\mssitlb.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\DavSyncProvider.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\cemapi.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\CameraCaptureUI.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\accountaccessor.dll
2017-03-18 13:11:33 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\tapi32.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\msctfui.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\msctfp.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\fontext.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\ddrawex.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-03-18 13:11:32 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-03-18 13:11:31 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2017-03-18 13:11:31 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2017-03-18 13:11:31 ----A---- C:\WINDOWS\SYSWOW64\hgcpl.dll
2017-03-18 13:11:31 ----A---- C:\WINDOWS\SYSWOW64\GamePanelExternalHook.dll
2017-03-18 13:11:31 ----A---- C:\WINDOWS\SYSWOW64\ddraw.dll
2017-03-18 13:11:31 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-03-18 13:11:28 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-03-18 13:11:28 ----A---- C:\WINDOWS\SYSWOW64\wmpmde.dll
2017-03-18 13:11:28 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-03-18 13:11:28 ----A---- C:\WINDOWS\system32\wmpmde.dll
2017-03-18 13:11:28 ----A---- C:\WINDOWS\system32\tquery.dll
2017-03-18 13:11:28 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-03-18 13:11:27 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-03-18 13:11:27 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2017-03-18 13:11:27 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-03-18 13:11:27 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-03-18 13:11:27 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2017-03-18 13:11:27 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-03-18 13:11:26 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-03-18 13:11:26 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2017-03-18 13:11:25 ----A---- C:\WINDOWS\system32\XblGameSaveExt.dll
2017-03-18 13:11:25 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2017-03-18 13:11:23 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2017-03-18 13:11:22 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\wwanmm.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\mssvp.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\mssphtb.dll
2017-03-18 13:11:22 ----A---- C:\WINDOWS\system32\mssph.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\SYSWOW64\WPDShServiceObj.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\wwanconn.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\wlanui.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\wcnwiz.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-03-18 13:11:21 ----A---- C:\WINDOWS\system32\mssitlb.dll
2017-03-18 13:11:20 ----A---- C:\WINDOWS\system32\wmp.dll
2017-03-18 13:11:19 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2017-03-18 13:11:19 ----A---- C:\WINDOWS\system32\shell32.dll
2017-03-18 13:11:18 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-03-18 13:11:18 ----A---- C:\WINDOWS\system32\mos.dll
2017-03-18 13:11:18 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-03-18 13:11:18 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-03-18 13:11:17 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-03-18 13:11:17 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2017-03-18 13:11:17 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2017-03-18 13:11:17 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-03-18 13:11:17 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-03-18 13:11:17 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-03-18 13:11:17 ----A---- C:\WINDOWS\system32\BingMaps.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\system32\Wpc.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\system32\MapRouter.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\system32\MapGeocoder.dll
2017-03-18 13:11:16 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\mfplat.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\MapsStore.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\localspl.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-03-18 13:11:15 ----A---- C:\WINDOWS\system32\ContactApis.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\wpnapps.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\WpcMon.exe
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\wlansec.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\win32spl.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\usercpl.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\mmc.exe
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\LockAppBroker.dll
2017-03-18 13:11:14 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2017-03-18 13:11:13 ----A---- C:\WINDOWS\SYSWOW64\Wpc.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\wlansvc.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\spoolsv.exe
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\SpeechPal.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\ntshrui.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\msxml3.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\mprddm.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\drivers\WdiWiFi.sys
2017-03-18 13:11:13 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\usocore.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\rasgcw.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\Pimstore.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\PimIndexMaintenance.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\MMDevAPI.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\mf.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\EmailApis.dll
2017-03-18 13:11:12 ----A---- C:\WINDOWS\system32\AuthHost.exe
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\WlanMediaManager.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\wlanapi.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\UserDataService.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\moshost.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\mfds.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\InputService.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\ChatApis.dll
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2017-03-18 13:11:11 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\usoapi.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\RelPost.exe
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\RADCUI.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\puiobj.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\MSVP9DEC.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\MSPhotography.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\mfsvr.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\MCCSEngineShared.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\internetmail.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\FrameServer.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-03-18 13:11:10 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\Windows.Storage.Search.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\wfdprov.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\Unistore.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\sdengin2.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\puiapi.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\PrintRenderAPIHost.DLL
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\PrintDialogs3D.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\netshell.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\MSVPXENC.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\ExSMime.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\drivers\tcpipreg.sys
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\DavSyncProvider.dll
2017-03-18 13:11:09 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\wpninprc.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\VCardParser.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\tapi32.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\sdshext.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\pnidui.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\netiougc.exe
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\DuCsps.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\cemapi.dll
2017-03-18 13:11:08 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2017-03-18 13:11:07 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-03-18 13:11:07 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-03-18 13:11:06 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-03-18 13:11:05 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-03-18 13:11:05 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-03-18 13:11:04 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-03-18 13:11:04 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-03-18 13:11:03 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-03-18 13:11:02 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-03-18 13:11:02 ----A---- C:\WINDOWS\system32\wininet.dll
2017-03-18 13:11:02 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-03-18 13:11:02 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-03-18 13:11:02 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2017-03-18 13:11:01 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-03-18 13:11:01 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-03-18 13:11:01 ----A---- C:\WINDOWS\system32\DWrite.dll
2017-03-18 13:11:01 ----A---- C:\WINDOWS\system32\dwmcore.dll
2017-03-18 13:11:01 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-03-18 13:11:01 ----A---- C:\WINDOWS\system32\d3d11.dll
2017-03-18 13:11:01 ----A---- C:\WINDOWS\system32\comsvcs.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\vbscript.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\schannel.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\inetcomm.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\FntCache.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\dxgi.dll
2017-03-18 13:11:00 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\winmde.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\dnsapi.dll
2017-03-18 13:10:59 ----A---- C:\WINDOWS\system32\CloudBackupSettings.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\vpnike.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\uDWM.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2017-03-18 13:10:58 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\werconcpl.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\SHCore.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\SettingSync.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\quartz.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2017-03-18 13:10:57 ----A---- C:\WINDOWS\system32\DMRServer.dll
2017-03-18 13:10:57 ----A---- C:\WINDOWS\HelpPane.exe
2017-03-18 13:10:56 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-03-18 13:10:56 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-03-18 13:10:56 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2017-03-18 13:10:56 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-03-18 13:10:56 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-03-18 13:10:56 ----A---- C:\WINDOWS\system32\msftedit.dll
2017-03-18 13:10:56 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-03-18 13:10:55 ----A---- C:\WINDOWS\system32\wlidprov.dll
2017-03-18 13:10:55 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-03-18 13:10:55 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-03-18 13:10:55 ----A---- C:\WINDOWS\system32\IPHLPAPI.DLL
2017-03-18 13:10:55 ----A---- C:\WINDOWS\system32\evr.dll
2017-03-18 13:10:55 ----A---- C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-03-18 13:10:54 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2017-03-18 13:10:54 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-03-18 13:10:54 ----A---- C:\WINDOWS\system32\thumbcache.dll
2017-03-18 13:10:54 ----A---- C:\WINDOWS\system32\MFPlay.dll
2017-03-18 13:10:54 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2017-03-18 13:10:54 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-03-18 13:10:54 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\Tabbtn.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\PhotoScreensaver.scr
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\icm32.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\dialclient.dll
2017-03-18 13:10:53 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\SYSWOW64\PhotoScreensaver.scr
2017-03-18 13:10:52 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\shutdownux.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\Geolocation.dll
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\drivers\mskssrv.sys
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2017-03-18 13:10:52 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\WorkFolders.exe
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\TokenBrokerCookies.exe
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\tbauth.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\NaturalLanguage6.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\fhcfg.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\CameraCaptureUI.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\BrowserSettingSync.dll
2017-03-18 13:10:51 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-03-18 13:10:50 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-03-18 13:10:50 ----A---- C:\WINDOWS\system32\Windows.Networking.HostName.dll
2017-03-18 13:10:50 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2017-03-18 13:10:50 ----A---- C:\WINDOWS\system32\ddrawex.dll
2017-03-18 13:10:50 ----A---- C:\WINDOWS\system32\ddraw.dll
2017-03-18 13:10:46 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-03-18 13:10:45 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2017-03-18 13:10:45 ----A---- C:\WINDOWS\system32\twinui.dll
2017-03-18 13:10:45 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-03-18 13:10:45 ----A---- C:\WINDOWS\system32\aepic.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\mispace.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\bisrv.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-03-18 13:10:44 ----A---- C:\WINDOWS\explorer.exe
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\storagewmi.dll
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\msctf.dll
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\devinv.dll
2017-03-18 13:10:43 ----A---- C:\WINDOWS\system32\AppContracts.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\winload.exe
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\generaltel.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\dcntel.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\DataSenseHandlers.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\CspCellularSettings.dll
2017-03-18 13:10:42 ----A---- C:\WINDOWS\system32\CfgSPCellular.dll
2017-03-18 13:10:41 ----A---- C:\WINDOWS\system32\winresume.exe
2017-03-18 13:10:41 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2017-03-18 13:10:41 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2017-03-18 13:10:41 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2017-03-18 13:10:41 ----A---- C:\WINDOWS\system32\invagent.dll
2017-03-18 13:10:41 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-03-18 13:10:41 ----A---- C:\WINDOWS\system32\clusapi.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\wer.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\twinapi.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\resutils.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\ReAgent.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\imapi2fs.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\hvloader.exe
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-03-18 13:10:40 ----A---- C:\WINDOWS\system32\gameux.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\SYSWOW64\UIRibbon.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\wintrust.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\uReFS.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\UIRibbon.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\themecpl.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\atmfd.dll
2017-03-18 13:10:39 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\ubpm.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\reseteng.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\policymanager.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\ci.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\bootux.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\authui.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-03-18 13:10:38 ----A---- C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\winhttp.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\VSSVC.exe
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\UserLanguagesCpl.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\stobject.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\PCPTpm12.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\icsvcext.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\DXP.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\dui70.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\daxexec.dll
2017-03-18 13:10:37 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\WsmWmiPl.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\vssapi.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\systemreset.exe
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\sud.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\SensorDataService.exe
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\icfupgd.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\drivers\vmbkmcl.sys
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\drivers\hvsocket.sys
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\drivers\Classpnp.sys
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\CompPkgSup.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\combase.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\certprop.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\BootMenuUX.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\basecsp.dll
2017-03-18 13:10:36 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\wbengine.exe
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\spaceman.exe
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\scksp.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\netiohlp.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\input.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\gpapi.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\drivers\vmbkmclr.sys
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-03-18 13:10:35 ----A---- C:\WINDOWS\system32\AudioSes.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\tabcal.exe
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\msutb.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\hgcpl.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\gpsvc.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\ApplicationFrame.dll
2017-03-18 13:10:34 ----A---- C:\WINDOWS\system32\appinfo.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\XInputUap.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\wups.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\werui.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\vaultcli.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\oleacc.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\MultiDigiMon.exe
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\mscandui.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\system32\BluetoothDesktopHandlers.dll
2017-03-18 13:10:33 ----A---- C:\WINDOWS\regedit.exe
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\vds.exe
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\rascustom.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\mspaint.exe
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\msctfui.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\msctfp.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-03-18 13:10:32 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-03-18 13:10:31 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2017-03-18 13:10:31 ----A---- C:\WINDOWS\system32\GamePanelExternalHook.dll
2017-03-18 13:10:31 ----A---- C:\WINDOWS\system32\cdp.dll
2017-03-18 13:10:30 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-03-18 13:10:30 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-03-18 13:09:47 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSetup.exe
2017-03-17 19:45:36 ----D---- C:\WINDOWS\system32\a0ddbff0b7089..bin
2017-03-16 23:15:20 ----A---- C:\WINDOWS\system32\drivers\MBAMChameleon.sys
2017-03-16 23:15:03 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2017-03-16 23:15:03 ----A---- C:\WINDOWS\system32\drivers\farflt.sys
2017-03-16 23:15:00 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2017-03-16 23:14:57 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2017-03-16 23:14:53 ----A---- C:\WINDOWS\system32\drivers\mbae64.sys
2017-03-16 23:14:51 ----D---- C:\ProgramData\Malwarebytes
2017-03-16 23:14:51 ----D---- C:\Program Files\Malwarebytes
2017-03-16 23:08:05 ----D---- C:\AdwCleaner
2017-03-16 22:53:31 ----AD---- C:\Program Files\CCleaner
2017-03-15 23:26:14 ----RD---- C:\Program Files (x86)\Skype
2017-03-15 23:00:33 ----D---- C:\rsit
2017-03-15 23:00:33 ----D---- C:\Program Files\trend micro
2017-03-14 12:02:26 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\adaware
2017-03-14 12:00:31 ----D---- C:\Program Files\adaware
2017-03-14 11:59:35 ----D---- C:\Program Files\Common Files\adaware
2017-03-14 11:59:10 ----D---- C:\ProgramData\adaware
2017-03-14 01:59:50 ----D---- C:\WINDOWS\system32\f741354d56665b62bdd13..bin
2017-03-10 20:47:04 ----D---- C:\WINDOWS\system32\32db7163a0ddbff0b7089..bin
2017-03-09 00:42:43 ----D---- C:\WINDOWS\system32\˙˙˙˙˙˙˙˙
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbuniva.sys
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbloga.sys
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbidsha.sys
2017-03-08 21:38:16 ----A---- C:\WINDOWS\system32\drivers\aswbidsdrivera.sys
2017-03-08 21:38:14 ----A---- C:\WINDOWS\system32\aswBoot.exe
2017-03-08 21:38:13 ----A---- C:\WINDOWS\system32\drivers\aswHdsKe.sys
2017-02-24 00:39:40 ----A---- C:\WINDOWS\system32\drivers\rzpnk.sys
2017-02-24 00:39:35 ----A---- C:\WINDOWS\system32\drivers\rzpmgrk.sys
2017-02-23 23:28:41 ----D---- C:\ProgramData\Razer
2017-02-23 23:28:37 ----AD---- C:\Program Files (x86)\Razer

====== List of files/folders modified in the last 1 month ======

2017-03-22 14:46:56 ----D---- C:\WINDOWS\Prefetch
2017-03-22 14:46:55 ----HD---- C:\Program Files\WindowsApps
2017-03-22 14:46:51 ----D---- C:\WINDOWS\Temp
2017-03-22 14:46:51 ----D---- C:\WINDOWS\AppReadiness
2017-03-22 14:45:45 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\TS3Client
2017-03-22 14:45:36 ----D---- C:\WINDOWS\system32\sru
2017-03-22 14:43:13 ----D---- C:\WINDOWS\system32\SleepStudy
2017-03-21 23:34:34 ----D---- C:\WINDOWS\system32\drivers
2017-03-21 23:30:53 ----D---- C:\WINDOWS\System32
2017-03-21 23:30:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-21 23:26:12 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\vlc
2017-03-21 15:26:04 ----RD---- C:\WINDOWS\Microsoft.NET
2017-03-21 14:33:18 ----D---- C:\WINDOWS\system32\config
2017-03-21 14:26:08 ----D---- C:\Windows
2017-03-20 23:11:11 ----D---- C:\WINDOWS\WinSxS
2017-03-20 23:11:11 ----D---- C:\WINDOWS\system32\DriverStore
2017-03-20 23:09:51 ----D---- C:\WINDOWS\system32\catroot2
2017-03-20 23:01:23 ----RSD---- C:\WINDOWS\assembly
2017-03-20 22:59:47 ----D---- C:\WINDOWS\CbsTemp
2017-03-20 22:59:46 ----D---- C:\WINDOWS\system32\appraiser
2017-03-20 21:38:05 ----RD---- C:\Program Files (x86)
2017-03-20 19:55:39 ----HD---- C:\ProgramData
2017-03-20 19:54:06 ----D---- C:\WINDOWS\INF
2017-03-19 23:33:18 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-CS
2017-03-19 23:33:18 ----D---- C:\WINDOWS\SYSWOW64\setup
2017-03-19 23:33:18 ----D---- C:\WINDOWS\SYSWOW64\migration
2017-03-19 23:33:17 ----SD---- C:\WINDOWS\SYSWOW64\F12
2017-03-19 23:33:17 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-03-19 23:33:17 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-03-19 23:33:17 ----D---- C:\WINDOWS\SysWOW64
2017-03-19 23:33:16 ----SD---- C:\WINDOWS\system32\F12
2017-03-19 23:33:16 ----D---- C:\WINDOWS\system32\wbem
2017-03-19 23:33:16 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-03-19 23:33:16 ----D---- C:\WINDOWS\system32\setup
2017-03-19 23:33:16 ----D---- C:\WINDOWS\system32\oobe
2017-03-19 23:33:16 ----D---- C:\WINDOWS\system32\migration
2017-03-19 23:33:16 ----D---- C:\WINDOWS\system32\en-US
2017-03-19 23:33:16 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2017-03-19 23:33:15 ----D---- C:\WINDOWS\system32\cs-CZ
2017-03-19 23:33:15 ----D---- C:\WINDOWS\system32\Boot
2017-03-19 23:33:14 ----RD---- C:\WINDOWS\PrintDialog
2017-03-19 23:33:14 ----D---- C:\WINDOWS\ShellExperiences
2017-03-19 23:33:13 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-03-19 23:33:13 ----RD---- C:\Program Files\Windows Defender
2017-03-19 23:33:13 ----D---- C:\WINDOWS\bcastdvr
2017-03-19 23:33:13 ----D---- C:\WINDOWS\AppPatch
2017-03-19 23:33:13 ----D---- C:\Program Files\Windows Photo Viewer
2017-03-19 23:33:13 ----D---- C:\Program Files\Windows Mail
2017-03-19 23:33:13 ----D---- C:\Program Files\Internet Explorer
2017-03-19 23:33:13 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-03-19 23:33:13 ----D---- C:\Program Files (x86)\Windows Mail
2017-03-19 23:33:13 ----D---- C:\Program Files (x86)\Windows Defender
2017-03-19 23:33:13 ----D---- C:\Program Files (x86)\Internet Explorer
2017-03-19 18:04:44 ----D---- C:\Program Files (x86)\Steam
2017-03-19 03:15:03 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\uTorrent
2017-03-18 13:45:39 ----AD---- C:\Program Files (x86)\Overwolf
2017-03-17 17:19:25 ----D---- C:\WINDOWS\system32\MRT
2017-03-17 17:18:02 ----D---- C:\WINDOWS\debug
2017-03-17 17:17:55 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-03-17 00:56:27 ----D---- C:\WINDOWS\system32\WDI
2017-03-17 00:54:43 ----D---- C:\WINDOWS\system32\Tasks
2017-03-16 23:14:51 ----RD---- C:\Program Files
2017-03-16 23:00:43 ----D---- C:\Program Files (x86)\Raptr Inc
2017-03-16 22:54:49 ----D---- C:\Users\PC-DÄšLO\AppData\Roaming\DAEMON Tools Lite
2017-03-16 22:54:49 ----D---- C:\Program Files\PDFCreator
2017-03-16 22:54:41 ----DC---- C:\WINDOWS\Panther
2017-03-16 22:54:41 ----D---- C:\WINDOWS\Logs
2017-03-16 22:50:56 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2017-03-16 22:50:56 ----AD---- C:\Program Files\Microsoft Silverlight
2017-03-16 13:20:47 ----SHDC---- C:\WINDOWS\Installer
2017-03-16 13:20:47 ----SHD---- C:\Config.Msi
2017-03-16 01:30:07 ----D---- C:\WINDOWS\Tasks
2017-03-16 01:30:05 ----D---- C:\WINDOWS\system32\Macromed
2017-03-16 01:30:04 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-03-15 23:26:16 ----D---- C:\ProgramData\Skype
2017-03-15 23:26:15 ----D---- C:\Program Files (x86)\Common Files
2017-03-14 12:08:56 ----SHD---- C:\System Volume Information
2017-03-14 11:59:35 ----D---- C:\Program Files\Common Files
2017-03-13 23:04:39 ----D---- C:\WINDOWS\LiveKernelReports
2017-03-10 22:09:49 ----D---- C:\ProgramData\AVAST Software
2017-03-10 12:59:57 ----D---- C:\ProgramData\Package Cache
2017-03-10 06:17:56 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-03-09 12:55:02 ----AD---- C:\Program Files (x86)\Opera
2017-03-09 11:08:30 ----D---- C:\WINDOWS\system32\NDF
2017-03-04 08:09:22 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2017-02-24 01:01:48 ----D---- C:\WINDOWS\system32\CatRoot

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [2017-03-08 189768]
R0 aswblog;aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [2017-03-08 334600]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [2017-03-08 48528]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2017-03-08 75704]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2017-03-15 337592]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992]
R0 MBAMSwissArmy;MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2017-03-21 251840]
R1 AsIO;AsIO; SysWow64\drivers\AsIO.sys []
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [2017-03-08 309272]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2017-03-08 32088]
R1 aswNetSec;aswNetSec; C:\WINDOWS\system32\drivers\aswNetSec.sys [2017-03-08 461640]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2017-03-08 100640]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2017-03-08 993608]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2017-03-21 548928]
R1 dtsoftbus01;@oem34.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-06-13 283064]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\WINDOWS\system32\drivers\mbae64.sys [2017-02-24 77408]
R2 amdacpksd;ACP Kernel Service Driver; \??\C:\WINDOWS\system32\drivers\amdacpksd.sys [2014-11-21 294600]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2017-03-08 126600]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2017-03-08 162528]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 MBAMChameleon;MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [2017-03-21 186304]
R2 rzpmgrk;rzpmgrk; \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys [2016-09-17 44144]
R2 rzpnk;rzpnk; \??\C:\WINDOWS\system32\drivers\rzpnk.sys [2016-10-08 137840]
R3 amdkmdag;amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys [2017-01-25 26568848]
R3 amdkmdap;amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys [2017-01-25 536600]
R3 AtiHDAudioService;@oem68.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2016-09-28 110104]
R3 MBAMFarflt;MBAMFarflt; \??\C:\WINDOWS\system32\drivers\farflt.sys [2017-03-21 111544]
R3 MBAMProtection;MBAMProtection; \??\C:\WINDOWS\system32\drivers\mbam.sys [2017-03-21 43968]
R3 MBAMWebProtection;MBAMWebProtection; \??\C:\WINDOWS\system32\drivers\mwac.sys [2017-03-21 92088]
R3 rzendpt;@oem52.inf,%rzendpt.SvcDesc%;rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [2015-08-13 50392]
R3 rzudd;@oem64.inf,%Razer.SvcDesc%;Razer Mouse Driver; C:\WINDOWS\System32\drivers\rzudd.sys [2015-08-13 202952]
S0 amdkmafd;@oem42.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 64352]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 aswHdsKe;aswHdsKe; \??\C:\WINDOWS\system32\drivers\aswHdsKe.sys [2017-03-07 85552]
S3 aswHwid;aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [2017-03-08 38296]
S3 aswTap;@oem7.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\WINDOWS\System32\drivers\aswTap.sys [2015-04-09 44640]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-10-02 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdaptiveSleepService;AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [2016-11-21 155016]
R2 adawareantivirusservice;adaware antivirus service; C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.0.649.11190\AdAwareService.exe [2017-02-21 585784]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2017-01-25 305176]
R2 amdacpusrsvc;ACP User Service; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [2014-11-20 116224]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-09-22 83768]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [2013-07-04 936728]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [2014-04-24 1360016]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-08 262736]
R2 avast! Firewall;Avast Firewall Service; C:\Program Files\AVAST Software\Avast\afwServ.exe [2017-03-08 278784]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [2015-05-07 271632]
R2 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-01-20 4355024]
R2 OneSyncSvc_23b6aa;Hostitel synchronizace_23b6aa; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 OODefragAgent;O&O Defrag; C:\Program Files\OO Software\Defrag\oodag.exe [2016-12-21 1740864]
R2 PDF Architect 3 Creator;PDF Architect 3 Creator; C:\Program Files (x86)\PDF Architect 3\creator-ws.exe [2015-09-17 767712]
R2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4; c:\postgreSQL\bin\pg_ctl.exe [2014-02-18 66048]
R2 Razer Game Scanner Service;Razer Game Scanner; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [2016-09-25 189264]
R2 Realtek11nSU;Realtek11nSU; C:\Program Files (x86)\ASUS\USB-N13 WLAN Card Utilities\RtlService.exe [2012-05-10 36864]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-08 7147320]
R3 PimIndexMaintenanceSvc_23b6aa;Data kontaktĹŻ_23b6aa; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\TimeBrokerServer.dll
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S2 CDPUserSvc_23b6aa;CDPUserSvc_23b6aa; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-10-28 651576]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 MessagingService_23b6aa;Služba zasílání zpráv_23b6aa; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 MozillaMaintenance;MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-22 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-07-26 2122248]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2017-03-16 1325384]
S3 PDF Architect 3 CrashHandler;PDF Architect 3 CrashHandler; C:\Program Files (x86)\PDF Architect 3\crash-handler-ws.exe [2015-09-17 964832]
S3 PDF Architect 3;PDF Architect 3; C:\Program Files (x86)\PDF Architect 3\ws.exe [2015-09-17 2244832]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-03-13 1590560]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Napadl me asi hacker

#14 Příspěvek od Roli »

Spusť ještě jednou Mbam a vše co najde nech smazat.

Nemůžu si pomoct ale ten Seznam tam opravdu je :

C:\Program Files (x86)\Seznam.cz

Když není v seznamu instalovaných programů mrkni do jeho složky zda tam je odinstalátor (unistall).
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

DuVenBlejt
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 14 bře 2017 23:22

Re: Napadl me asi hacker

#15 Příspěvek od DuVenBlejt »

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacĂ­ho souboru-
Datum skenování: 27.03.17
Čas skenování: 18:34
LogovacĂ­ soubor: log1.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.0.6.1469
Verze komponentĹŻ: 1.0.75
Aktualizovat verzi balĂ­ku komponent: 1.0.1608
Licence: Zkušební

-Systémová informace-
OS: Windows 10
CPU: x64
Systém souborů: NTFS
UĹľivatel: PC\PC-D\u00c4\u009aLO

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 343251
UplynulĂ˝ ÄŤas: 30 min, 14 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

KlĂ­ÄŤ registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrĹŻ: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

FyzickĂ˝ sektor: 0
(Nebyly zjištěny žádné škodlivé položky)

Zamčeno