Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosím o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

prosím o kontrolu

#1 Příspěvek od HINEGB »

Dobrý den,
PC je pomalý, nefunguje tlačítko windows...
Prosím Vás o kontrolu logu a radu co dál... Děkuji

Logfile of random's system information tool 1.10 (written by random/random)
Run by Hynek at 2017-04-26 12:20:46
Microsoft Windows 10 Home
System drive C: has 385 GB (85%) free of 450 GB
Total RAM: 4020 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:20:57, on 26.04.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Okidata\ActKey\Network Configuration.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Hynek\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Hynek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hp13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com/?cid={2A5378AC ... 2016-04-27 08:12:57&v=4.2.9.726&pid=wtu&sg=&sap=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [DropboxOEM] "C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe" auto
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Hynek\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\RunOnce: [Uninstall 17.3.6798.0207\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Hynek\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64"
O4 - HKCU\..\RunOnce: [Uninstall 17.3.6798.0207] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Hynek\AppData\Local\Microsoft\OneDrive\17.3.6798.0207"
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {B8FB8104-FDC9-4339-8AFF-2EE4C8C92998} (AMCCtrl Class) - http://192.168.10.32:8080/AVC_AX_NVR.cab
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: @oem43.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Security Assist - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
O23 - Service: Intel(R) Security Assist Helper (isaHelperSvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12337 bytes

======Listing Processes======







winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
dashost.exe {38e7963e-0a49-47dc-8491e827bbf837ba}
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe"
C:\WINDOWS\system32\BtwRSupportService.exe
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
"C:\Program Files\Bonjour\mDNSResponder.exe"

"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"

C:\WINDOWS\system32\WLANExt.exe 2976380326992
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation

"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe"
igfxEM.exe
igfxHK.exe
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer11_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer11_Logfile.log
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f291be27-cd27-4a72-9387-632883132d6b -SystemEventPortName:HostProcess-969c3871-c237-4eff-b0af-0e9dcb13ecc8 -IoCancelEventPortName:HostProcess-d510a14a-0297-43fb-bad5-740f6aedea83 -NonStateChangingEventPortName:HostProcess-b7a85ac4-ec9a-4294-8457-b5cc9347e5f2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0865fec6-a627-4fec-bded-e941a302a4cd -DeviceGroupId:WpdFsGroup
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\Okidata\ActKey\Network Configuration.exe" /RunWithOS
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
taskhostw.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L Analysis
/updateInstalled /background
"C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe"
"c:\program files (x86)\teamviewer\TeamViewer_Desktop.exe" --IPCport 5939
C:\WINDOWS\system32\AUDIODG.EXE 0x324
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Hynek\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Hynek\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=57.0.2987.133 --initial-client-data=0x234,0x238,0x23c,0x230,0x240,0x63617dc8,0x63617dbc,0x63617dd4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=6384 --on-initialized-event-handle=692 --parent-handle=696 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1512 --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,19,23,41,61,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x0a06 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=20.19.15.4360 --gpu-driver-date=12-21-2015 --service-request-channel-token=ADB2A10AF1B951A265B4A58B1B683630 --mojo-platform-channel-handle=1524 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1512 --primordial-pipe-token=57F6166E0BCF069BE77F883A4412AEE6 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=57F6166E0BCF069BE77F883A4412AEE6 --renderer-client-id=14 --mojo-platform-channel-handle=6968 /prefetch:1
"C:\Program Files\Windows Defender\\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 5DE015E9-8C12-FF66-F12B-9F7CD85669B5 -Reinvoke
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 640 644 652 8192 648
"C:\Users\Hynek\Desktop\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-03-06 213704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-03-06 3002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21 440712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-07-25 585568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21 416320]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-01-15 8790264]
"Network Configuration"=C:\Program Files (x86)\Okidata\ActKey\Network Configuration.exe [2014-09-15 728640]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-28 631808]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2016-10-13 3942864]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Hynek\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-04-26 1518808]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-09-12 29635712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall 17.3.6798.0207\amd64"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]
"Uninstall 17.3.6798.0207"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-04-26 12:20:46 ----D---- C:\rsit
2017-04-26 12:20:46 ----D---- C:\Program Files\trend micro
2017-04-11 20:03:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-04-11 20:03:23 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-04-11 20:03:22 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-04-11 20:03:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-04-11 20:03:21 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-04-11 20:03:21 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-04-11 20:03:20 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-04-11 20:03:20 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-04-11 20:03:20 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-04-11 20:03:19 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-04-11 20:03:19 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-04-11 20:03:19 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-04-11 20:03:19 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-04-11 20:03:19 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-04-11 20:03:18 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2017-04-11 20:03:18 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-04-11 20:03:18 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-04-11 20:03:18 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-04-11 20:03:18 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2017-04-11 20:03:17 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2017-04-11 20:03:16 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-04-11 20:03:16 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-04-11 20:03:16 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-04-11 20:03:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-04-11 20:03:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-04-11 20:03:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-04-11 20:03:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-04-11 20:03:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-04-11 20:03:15 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-04-11 20:03:15 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-04-11 20:03:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-04-11 20:03:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-04-11 20:03:14 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-04-11 20:03:14 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-04-11 20:03:14 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-04-11 20:03:14 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2017-04-11 20:03:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-04-11 20:03:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-04-11 20:03:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-04-11 20:03:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-04-11 20:03:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-04-11 20:03:13 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\CompPkgSup.dll
2017-04-11 20:03:12 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2017-04-11 20:03:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-04-11 20:03:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-04-11 20:03:11 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-04-11 20:03:11 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-04-11 20:03:11 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\wscapi.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-04-11 20:03:10 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-04-11 20:03:09 ----A---- C:\WINDOWS\SYSWOW64\asycfilt.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-04-11 20:03:08 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\dlnashext.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-04-11 20:03:07 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-04-11 20:03:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-04-11 20:03:06 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-04-11 20:03:06 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-04-11 20:03:06 ----A---- C:\WINDOWS\SYSWOW64\dialclient.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\wlidcli.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\msdtcprx.dll
2017-04-11 20:03:05 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-04-11 20:03:05 ----A---- C:\WINDOWS\system32\drivers\BasicRender.sys
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.InkControls.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-04-11 20:03:04 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.UserDeviceAssociation.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-04-11 20:03:03 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-04-11 20:03:02 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-04-11 20:03:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-04-11 20:03:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-04-11 20:03:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-04-11 20:03:02 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-04-11 20:03:02 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\mfmjpegdec.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\Geolocation.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-04-11 20:03:01 ----A---- C:\WINDOWS\SYSWOW64\AppointmentActivation.dll
2017-04-11 20:03:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2017-04-11 20:03:00 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-04-11 20:03:00 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-04-11 20:03:00 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-04-11 20:03:00 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-04-11 20:03:00 ----A---- C:\WINDOWS\SYSWOW64\ipsecsnp.dll
2017-04-11 20:03:00 ----A---- C:\WINDOWS\SYSWOW64\apds.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Devices.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Lights.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Core.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerUI.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\SYSWOW64\sbe.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\SYSWOW64\ipsmsnap.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-04-11 20:02:59 ----A---- C:\WINDOWS\system32\drivers\BasicDisplay.sys
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\enrollmentapi.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-04-11 20:02:58 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2017-04-11 20:02:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-04-11 20:02:57 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-04-11 20:02:57 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-04-11 20:02:57 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-04-11 20:02:57 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2017-04-11 20:02:57 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-04-11 20:02:57 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-04-11 20:02:56 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2017-04-11 20:02:55 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-04-11 20:02:54 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-04-11 20:02:53 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-04-11 20:02:53 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-04-11 20:02:53 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-04-11 20:02:52 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-04-11 20:02:52 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-04-11 20:02:52 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-04-11 20:02:52 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-04-11 20:02:52 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-04-11 20:02:52 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-04-11 20:02:52 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-04-11 20:02:51 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-04-11 20:02:51 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2017-04-11 20:02:51 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-04-11 20:02:51 ----A---- C:\WINDOWS\system32\Windows.Media.Ocr.dll
2017-04-11 20:02:51 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-04-11 20:02:51 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2017-04-11 20:02:50 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-04-11 20:02:50 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-04-11 20:02:50 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-04-11 20:02:50 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-04-11 20:02:49 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-04-11 20:02:48 ----A---- C:\WINDOWS\system32\shell32.dll
2017-04-11 20:02:47 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-04-11 20:02:46 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-04-11 20:02:45 ----A---- C:\WINDOWS\system32\mos.dll
2017-04-11 20:02:44 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-04-11 20:02:44 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-04-11 20:02:43 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2017-04-11 20:02:43 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-04-11 20:02:42 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-04-11 20:02:42 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-04-11 20:02:42 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-04-11 20:02:41 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2017-04-11 20:02:41 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-04-11 20:02:41 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-04-11 20:02:41 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-04-11 20:02:40 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-04-11 20:02:40 ----A---- C:\WINDOWS\system32\usocore.dll
2017-04-11 20:02:40 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2017-04-11 20:02:40 ----A---- C:\WINDOWS\system32\puiobj.dll
2017-04-11 20:02:40 ----A---- C:\WINDOWS\system32\oleaut32.dll
2017-04-11 20:02:40 ----A---- C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-04-11 20:02:39 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-04-11 20:02:39 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2017-04-11 20:02:39 ----A---- C:\WINDOWS\system32\smartscreen.exe
2017-04-11 20:02:39 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-04-11 20:02:39 ----A---- C:\WINDOWS\system32\LsaIso.exe
2017-04-11 20:02:39 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2017-04-11 20:02:38 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-04-11 20:02:38 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-04-11 20:02:38 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-04-11 20:02:38 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-04-11 20:02:38 ----A---- C:\WINDOWS\system32\MSVP9DEC.dll
2017-04-11 20:02:38 ----A---- C:\WINDOWS\system32\EmailApis.dll
2017-04-11 20:02:37 ----A---- C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-04-11 20:02:37 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-04-11 20:02:37 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-04-11 20:02:37 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2017-04-11 20:02:37 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-04-11 20:02:36 ----A---- C:\WINDOWS\system32\wscapi.dll
2017-04-11 20:02:36 ----A---- C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-04-11 20:02:36 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-04-11 20:02:36 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-04-11 20:02:36 ----A---- C:\WINDOWS\system32\rdpudd.dll
2017-04-11 20:02:36 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2017-04-11 20:02:35 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2017-04-11 20:02:35 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2017-04-11 20:02:35 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-04-11 20:02:34 ----A---- C:\WINDOWS\system32\wpnapps.dll
2017-04-11 20:02:34 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-04-11 20:02:34 ----A---- C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-04-11 20:02:34 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-04-11 20:02:34 ----A---- C:\WINDOWS\system32\AccountsRt.dll
2017-04-11 20:02:33 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-04-11 20:02:23 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-04-11 20:02:23 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2017-04-11 20:02:23 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2017-04-11 20:02:22 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-04-11 20:02:22 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-11 20:02:22 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-04-11 20:02:22 ----A---- C:\WINDOWS\system32\rdpencom.dll
2017-04-11 20:02:22 ----A---- C:\WINDOWS\system32\localspl.dll
2017-04-11 20:02:20 ----A---- C:\WINDOWS\system32\wpninprc.dll
2017-04-11 20:02:20 ----A---- C:\WINDOWS\system32\RdpRelayTransport.dll
2017-04-11 20:02:20 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-04-11 20:02:20 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2017-04-11 20:02:20 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-04-11 20:02:19 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-04-11 20:02:16 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-04-11 20:02:15 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-04-11 20:02:14 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-04-11 20:02:13 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-04-11 20:02:12 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-04-11 20:02:11 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-04-11 20:02:10 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-04-11 20:02:10 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2017-04-11 20:02:10 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-04-11 20:02:08 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-04-11 20:02:08 ----A---- C:\WINDOWS\system32\quartz.dll
2017-04-11 20:02:08 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2017-04-11 20:02:08 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-04-11 20:02:07 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-04-11 20:02:07 ----A---- C:\WINDOWS\system32\ole32.dll
2017-04-11 20:02:07 ----A---- C:\WINDOWS\system32\kerberos.dll
2017-04-11 20:02:06 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-04-11 20:02:06 ----A---- C:\WINDOWS\system32\wininet.dll
2017-04-11 20:02:06 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-04-11 20:02:06 ----A---- C:\WINDOWS\HelpPane.exe
2017-04-11 20:02:05 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2017-04-11 20:02:05 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-04-11 20:02:05 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2017-04-11 20:02:05 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2017-04-11 20:02:05 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-04-11 20:02:04 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-04-11 20:02:04 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-04-11 20:02:03 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-04-11 20:02:02 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-04-11 20:02:02 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-04-11 20:02:01 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-04-11 20:02:01 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-04-11 20:02:01 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-04-11 20:02:00 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2017-04-11 20:01:59 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-04-11 20:01:59 ----A---- C:\WINDOWS\system32\d2d1.dll
2017-04-11 20:01:59 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-04-11 20:01:58 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2017-04-11 20:01:58 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2017-04-11 20:01:58 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2017-04-11 20:01:58 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-04-11 20:01:58 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2017-04-11 20:01:58 ----A---- C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-04-11 20:01:58 ----A---- C:\WINDOWS\system32\asycfilt.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\Windows.Devices.Lights.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-04-11 20:01:57 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-04-11 20:01:56 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-04-11 20:01:56 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2017-04-11 20:01:56 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-04-11 20:01:56 ----A---- C:\WINDOWS\system32\dafpos.dll
2017-04-11 20:01:55 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2017-04-11 20:01:55 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-04-11 20:01:55 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-04-11 20:01:55 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-04-11 20:01:55 ----A---- C:\WINDOWS\system32\Geolocation.dll
2017-04-11 20:01:55 ----A---- C:\WINDOWS\system32\FontProvider.dll
2017-04-11 20:01:54 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2017-04-11 20:01:54 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-04-11 20:01:54 ----A---- C:\WINDOWS\system32\mfmjpegdec.dll
2017-04-11 20:01:54 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-04-11 20:01:54 ----A---- C:\WINDOWS\system32\dxtrans.dll
2017-04-11 20:01:54 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-04-11 20:01:53 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2017-04-11 20:01:53 ----A---- C:\WINDOWS\system32\Windows.Devices.Printers.dll
2017-04-11 20:01:53 ----A---- C:\WINDOWS\system32\webcheck.dll
2017-04-11 20:01:53 ----A---- C:\WINDOWS\system32\mshtmled.dll
2017-04-11 20:01:52 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-04-11 20:01:52 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2017-04-11 20:01:52 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2017-04-11 20:01:52 ----A---- C:\WINDOWS\system32\DeviceDirectoryClient.dll
2017-04-11 20:01:51 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2017-04-11 20:01:51 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2017-04-11 20:01:51 ----A---- C:\WINDOWS\system32\dosvc.dll
2017-04-11 20:01:51 ----A---- C:\WINDOWS\system32\DdcWnsListener.dll
2017-04-11 20:01:51 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-04-11 20:01:51 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-04-11 20:01:50 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-04-11 20:01:50 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-04-11 20:01:50 ----A---- C:\WINDOWS\system32\NaturalLanguage6.dll
2017-04-11 20:01:50 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-04-11 20:01:50 ----A---- C:\WINDOWS\system32\CastLaunch.dll
2017-04-11 20:01:43 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-04-11 20:01:43 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-04-11 20:01:42 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2017-04-11 20:01:42 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-04-11 20:01:42 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-04-11 20:01:42 ----A---- C:\WINDOWS\system32\actxprxy.dll
2017-04-11 20:01:41 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-04-11 20:01:40 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-04-11 20:01:40 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2017-04-11 20:01:40 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-04-11 20:01:39 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-04-11 20:01:39 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-04-11 20:01:39 ----A---- C:\WINDOWS\system32\twinui.dll
2017-04-11 20:01:39 ----A---- C:\WINDOWS\system32\atmfd.dll
2017-04-11 20:01:38 ----A---- C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-04-11 20:01:38 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-04-11 20:01:37 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-04-11 20:01:37 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-04-11 20:01:37 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-04-11 20:01:36 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-04-11 20:01:36 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-04-11 20:01:36 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-04-11 20:01:36 ----A---- C:\WINDOWS\system32\qedit.dll
2017-04-11 20:01:36 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-04-11 20:01:36 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-04-11 20:01:36 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-04-11 20:01:35 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-04-11 20:01:35 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-04-11 20:01:35 ----A---- C:\WINDOWS\system32\sbe.dll
2017-04-11 20:01:35 ----A---- C:\WINDOWS\system32\dlnashext.dll
2017-04-11 20:01:35 ----A---- C:\WINDOWS\system32\CompPkgSup.dll
2017-04-11 20:01:35 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-04-11 20:01:34 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-04-11 20:01:34 ----A---- C:\WINDOWS\system32\wer.dll
2017-04-11 20:01:34 ----A---- C:\WINDOWS\system32\OneBackupHandler.dll
2017-04-11 20:01:34 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-04-11 20:01:34 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-04-11 20:01:34 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-04-11 20:01:33 ----A---- C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-04-11 20:01:33 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-04-11 20:01:33 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2017-04-11 20:01:33 ----A---- C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-04-11 20:01:33 ----A---- C:\WINDOWS\system32\AppContracts.dll
2017-04-11 20:01:32 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2017-04-11 20:01:32 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-04-11 20:01:32 ----A---- C:\WINDOWS\system32\invagent.dll
2017-04-11 20:01:32 ----A---- C:\WINDOWS\system32\devinv.dll
2017-04-11 20:01:32 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-04-11 20:01:32 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-04-11 20:01:31 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2017-04-11 20:01:31 ----A---- C:\WINDOWS\system32\Windows.Media.Devices.dll
2017-04-11 20:01:31 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-04-11 20:01:31 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-04-11 20:01:31 ----A---- C:\WINDOWS\system32\psmsrv.dll
2017-04-11 20:01:31 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-04-11 20:01:31 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-04-11 20:01:30 ----A---- C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2017-04-11 20:01:30 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-04-11 20:01:30 ----A---- C:\WINDOWS\system32\oleacc.dll
2017-04-11 20:01:30 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2017-04-11 20:01:30 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-04-11 20:01:30 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-04-11 20:01:30 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-04-11 20:01:29 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-04-11 20:01:29 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-04-11 20:01:29 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2017-04-11 20:01:29 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2017-04-11 20:01:28 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2017-04-11 20:01:27 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-04-11 20:01:27 ----A---- C:\WINDOWS\system32\vss_ps.dll
2017-04-11 20:01:27 ----A---- C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
2017-04-11 20:01:27 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2017-04-11 20:01:27 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2017-04-11 20:01:26 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2017-04-11 20:01:26 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2017-04-11 20:01:26 ----A---- C:\WINDOWS\system32\TokenBrokerUI.dll
2017-04-11 20:01:26 ----A---- C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\WSManMigrationPlugin.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\vaultcli.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\Family.Client.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2017-04-11 20:01:25 ----A---- C:\WINDOWS\system32\cdp.dll
2017-04-11 20:01:24 ----A---- C:\WINDOWS\system32\atmlib.dll
2017-04-07 11:23:21 ----SHD---- C:\found.000

======List of files/folders modified in the last 1 month======

2017-04-26 12:20:46 ----RD---- C:\Program Files
2017-04-26 12:19:31 ----D---- C:\WINDOWS\Prefetch
2017-04-26 12:17:07 ----D---- C:\WINDOWS\Temp
2017-04-26 12:09:58 ----D---- C:\Users\Hynek\AppData\Roaming\Skype
2017-04-26 12:08:35 ----D---- C:\WINDOWS\System32
2017-04-26 12:08:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-04-26 12:08:29 ----A---- C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-04-26 12:04:05 ----D---- C:\WINDOWS\system32\SleepStudy
2017-04-26 12:01:52 ----D---- C:\WINDOWS\system32\sru
2017-04-25 14:56:05 ----SHD---- C:\System Volume Information
2017-04-25 14:54:22 ----RD---- C:\WINDOWS\Microsoft.NET
2017-04-25 04:11:11 ----D---- C:\WINDOWS\system32\config
2017-04-23 12:44:14 ----D---- C:\WINDOWS\system32\appraiser
2017-04-23 12:44:06 ----D---- C:\WINDOWS\system32\catroot2
2017-04-23 12:39:18 ----D---- C:\Windows
2017-04-23 12:39:17 ----D---- C:\WINDOWS\WinSxS
2017-04-23 12:39:16 ----D---- C:\WINDOWS\CbsTemp
2017-04-23 12:35:29 ----D---- C:\WINDOWS\INF
2017-04-23 12:35:28 ----D---- C:\WINDOWS\system32\DriverStore
2017-04-23 12:35:28 ----D---- C:\WINDOWS\system32\CatRoot
2017-04-20 09:18:43 ----D---- C:\WINDOWS\system32\WDI
2017-04-18 10:19:10 ----RD---- C:\WINDOWS\assembly
2017-04-15 15:14:59 ----D---- C:\WINDOWS\system32\Tasks
2017-04-15 15:14:59 ----AD---- C:\Program Files (x86)\TeamViewer
2017-04-13 14:37:04 ----D---- C:\WINDOWS\system32\NDF
2017-04-13 13:54:48 ----D---- C:\WINDOWS\rescache
2017-04-13 09:07:35 ----D---- C:\WINDOWS\system32\drivers
2017-04-12 20:09:46 ----SD---- C:\WINDOWS\SYSWOW64\F12
2017-04-12 20:09:46 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-CS
2017-04-12 20:09:46 ----D---- C:\WINDOWS\SYSWOW64\setup
2017-04-12 20:09:45 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2017-04-12 20:09:45 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-04-12 20:09:45 ----D---- C:\WINDOWS\SysWOW64
2017-04-12 20:09:43 ----SD---- C:\WINDOWS\system32\F12
2017-04-12 20:09:43 ----D---- C:\WINDOWS\system32\wbem
2017-04-12 20:09:43 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-04-12 20:09:43 ----D---- C:\WINDOWS\system32\setup
2017-04-12 20:09:43 ----D---- C:\WINDOWS\system32\migration
2017-04-12 20:09:43 ----D---- C:\WINDOWS\system32\en-GB
2017-04-12 20:09:43 ----D---- C:\WINDOWS\system32\Dism
2017-04-12 20:09:43 ----D---- C:\WINDOWS\system32\cs-CZ
2017-04-12 20:09:37 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-04-12 20:09:37 ----RD---- C:\Program Files\Windows Defender
2017-04-12 20:09:37 ----D---- C:\WINDOWS\ShellExperiences
2017-04-12 20:09:37 ----D---- C:\WINDOWS\Provisioning
2017-04-12 20:09:37 ----D---- C:\Program Files\Windows Photo Viewer
2017-04-12 20:09:37 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-04-12 20:09:37 ----D---- C:\Program Files (x86)\Windows Defender
2017-04-12 12:43:17 ----D---- C:\WINDOWS\system32\MRT
2017-04-12 12:40:49 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-04-12 09:11:44 ----SHD---- C:\WINDOWS\Installer
2017-04-12 09:11:44 ----SHD---- C:\Config.Msi
2017-04-12 09:06:45 ----RD---- C:\Program Files (x86)
2017-04-10 08:55:29 ----D---- C:\ProgramData\McAfee
2017-04-10 08:55:29 ----D---- C:\Program Files\Common Files
2017-04-10 08:55:29 ----D---- C:\Program Files (x86)\McAfee
2017-04-10 08:55:15 ----HD---- C:\ProgramData
2017-04-08 17:04:15 ----SD---- C:\Users\Hynek\AppData\Roaming\Microsoft
2017-04-08 16:57:46 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2017-04-07 08:13:33 ----HD---- C:\Program Files\WindowsApps
2017-04-07 08:13:33 ----D---- C:\WINDOWS\AppReadiness
2017-04-06 09:03:27 ----AD---- C:\Program Files (x86)\Microsoft Office
2017-04-05 08:59:30 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2017-04-05 08:58:39 ----D---- C:\Program Files (x86)\Common Files
2017-04-01 20:52:38 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-03-28 08:20:43 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2015-06-23 1455552]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992]
R1 CLVirtualDrive;CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-07-16 88576]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-07-16 8192]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2016-07-16 48128]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2016-07-16 78336]
R3 bcbtums;@oem43.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-10-01 208176]
R3 BCM43XX;@oem42.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2016-04-28 7551240]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2016-08-20 114176]
R3 BthLEEnum;@BthLEEnum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-09-15 249856]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2016-10-05 128512]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\drivers\BTHUSB.sys [2016-08-20 84992]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2016-09-10 7886304]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2016-01-15 4695288]
R3 IntcDAud;@oem76.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-12-08 481032]
R3 MEIx64;@oem67.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [2015-07-07 184608]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2016-07-16 183808]
R3 RSP2STOR;@oem39.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2015-06-05 310528]
R3 rt640x64;@oem48.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2016-02-17 896768]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-07-16 105824]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-07-16 101216]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 64352]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2016-07-16 58720]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2016-07-16 61792]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2016-07-16 32096]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2016-07-16 9728]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\drivers\BTHport.sys [2016-11-11 967168]
S3 btwampfl;@oem43.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-10-01 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-07-16 38912]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-09-10 118272]
S3 dg_ssudbus;@oem78.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2016-09-05 131712]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-07-16 20480]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-07-16 50016]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-08-06 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2016-07-16 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-07-16 176384]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2016-07-16 526176]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-07-16 842584]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2016-07-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2016-07-16 928608]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S3 ssudmdm;@oem79.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2016-09-05 165504]
S3 ssudserd;@oem1.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys [2016-09-05 165504]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2016-07-16 95744]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [2016-07-16 108544]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2016-07-16 50688]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2016-07-16 45568]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2016-07-16 263008]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2016-07-16 96608]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-07-16 137056]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 BcmBtRSupport;@oem43.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-10-01 2286848]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 CDPUserSvc_393b33;CDPUserSvc_393b33; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2017-03-26 3737792]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R2 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2014-08-25 255040]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [2016-02-18 26680]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2016-09-10 373728]
R2 isaHelperSvc;Intel(R) Security Assist Helper; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [2015-05-19 7680]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-07-10 223520]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2015-07-10 415520]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2014-09-27 94720]
R2 OneSyncSvc_393b33;Sync Host_393b33; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2014-04-14 389896]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2016-01-15 316152]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2017-04-06 7757040]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
R3 PimIndexMaintenanceSvc_393b33;Contact Data_393b33; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-15 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2016-09-10 301536]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-07-16 93184]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2014-04-24 203344]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-15 144200]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2015-04-28 1102472]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2015-05-22 881152]
S3 Intel(R) Security Assist;Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [2015-05-19 335872]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService_393b33;MessagingService_393b33; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-03-25 198192]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2017-03-04 1312768]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2016-07-16 287744]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]

-----------------EOF-----------------

Kodlz
Přítel fóra
Přítel fóra
Příspěvky: 780
Registrován: 30 kvě 2008 12:11

Re: prosím o kontrolu

#2 Příspěvek od Kodlz »

Ahoj
Poprosim o vlozeni logu FRST.txt a Addition.txt z aplikace FRST (Farbar Recovery Scan Tool). Navod naleznes zde: http://forum.viry.cz/viewtopic.php?f=13&t=133100

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#3 Příspěvek od HINEGB »

logy jsou v zipu
Přílohy
logy.zip
(23.42 KiB) Staženo 116 x

Kodlz
Přítel fóra
Přítel fóra
Příspěvky: 780
Registrován: 30 kvě 2008 12:11

Re: prosím o kontrolu

#4 Příspěvek od Kodlz »

Jedna se o soukromy nebo sluzebni pc?
6. Fórum viry.cz se nezabývá odvirováním firemních PC - na toto jsou ve firmách placení (a někdy až hodně nadstandardně) IT technici, případně si je firma může najmout. My jsme tu zdarma a ve svém volném čase, nehodláme dělat práci za někoho jiného, kdo si pak jen slízne smetánku a plat. Taktéž ani neposkytujeme poradenství v oblasti zabezpečení firemních sítí či nastavení firemních sítí. Zkrátka a jednoduše, naše fórum poskytuje podporu pouze domácím uživatelům.
V tom pripade by sem Vas musel odkazat na www.neslape.cz

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#5 Příspěvek od HINEGB »

Dobrý den, omlouvám se, že reaguji tak pozdě. Jsem v jednom kole.

Je to můj vlastní PC. Mám tento PC a noťas, oba mám doma, ale je pravda, že je občas používám i k pracovním věcem.

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#6 Příspěvek od HINEGB »

Dobrý večer, mám šanci na pomoc?

Kodlz
Přítel fóra
Přítel fóra
Příspěvky: 780
Registrován: 30 kvě 2008 12:11

Re: prosím o kontrolu

#7 Příspěvek od Kodlz »

Stáhni AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Ulož na plochu
Ukonči všechny programy
Klikni nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vlož.


MBAM

nasledne tento tool MBAM: http://forum.viry.cz/viewtopic.php?f=29&t=144868
-Nainstaluj,dej úplný sken

-Log zkopíruj sem.

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#8 Příspěvek od HINEGB »

Dobrý den, mám problém. Test trvá poměrně dlouho a i přes veškerou snahu se mi zatím nepodařilo "odchytit" jeho konec. Počítač pak usne a už se nemůžu přihlásit - další závada, kterou PC vykazuje. PC je nutné restartovat. Žádný log, který by se uložil automaticky jsem nenašel. :(
Poraďte mi prosím co dál...

Kodlz
Přítel fóra
Přítel fóra
Příspěvky: 780
Registrován: 30 kvě 2008 12:11

Re: prosím o kontrolu

#9 Příspěvek od Kodlz »

ktery test mas ted na mysli? AdwCleaner nebo MBAM?

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#10 Příspěvek od HINEGB »

MBAM

AdwCleaner:

# AdwCleaner v6.046 - Logfile created 04/05/2017 at 11:22:10
# Updated on 24/04/2017 by Malwarebytes
# Database : 2017-05-03.1 [Server]
# Operating System : Windows 10 Home (X64)
# Username : Hynek - PAVILION_REC2
# Running from : C:\Users\Hynek\Desktop\adwcleaner_6.046.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****



***** [ Folders ] *****

[-] Folder deleted: C:\Program Files\Reimage
[#] Folder deleted on reboot: C:\Program Files\reimage
[-] Folder deleted: C:\rei
[-] Folder deleted: C:\ProgramData\Reimage Protector


***** [ Files ] *****

[-] File deleted: C:\Users\Hynek\AppData\Local\Temp\reimage.log
[-] File deleted: C:\Users\ca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_zstatenice.rajce.idnes.cz_0.localstorage
[-] File deleted: C:\Users\ca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_zstatenice.rajce.idnes.cz_0.localstorage-journal


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****

[-] Data restored: HKU\S-1-5-21-3082648221-2456842191-3673000228-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]


***** [ Web browsers ] *****



*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1577 Bytes] - [04/05/2017 11:22:10]
C:\AdwCleaner\AdwCleaner[S0].txt - [2188 Bytes] - [04/05/2017 11:21:48]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1723 Bytes] ##########

Kodlz
Přítel fóra
Přítel fóra
Příspěvky: 780
Registrován: 30 kvě 2008 12:11

Re: prosím o kontrolu

#11 Příspěvek od Kodlz »

Poprosim Te znovu o vlozeni cerstveho logu FRST.txt a Addition.txt z aplikace FRST (Farbar Recovery Scan Tool).

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#12 Příspěvek od HINEGB »

v příloze
Přílohy
Logy2.zip
(23.09 KiB) Staženo 105 x

Kodlz
Přítel fóra
Přítel fóra
Příspěvky: 780
Registrován: 30 kvě 2008 12:11

Re: prosím o kontrolu

#13 Příspěvek od Kodlz »

Na plose, tam kde mas umisteny FRST vytvor TXT soubor, ktery pojmenujes fixlist.txt a do nej vloz nasledujici text:

( Spusť znovu FRST a klikni na >Fix<. Po skončení akce se objeví log, který sem zkopíruj).
start
CreateRestorePoint:

CloseProcesses:

Hosts:

EmptyTemp:

2017-05-09 17:00 - 2016-09-12 18:07 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-05 09:12 - 2016-09-12 18:27 - 00003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-05 09:12 - 2016-09-12 18:27 - 00003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
Task: {02F31D6C-0CD0-49DF-8063-E0E8F9836D20} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {1F3FAF41-0A30-4199-BB31-813B057EBB0E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {2B027D83-E54C-4F22-9305-65044B2F8362} - \McAfee\McAfee Idle Detection Task -> No File <==== ATTENTION
Task: {36D57492-2E16-428F-90AD-FD8E0501F939} - \WPD\SqmUpload_S-1-5-21-3082648221-2456842191-3673000228-1001 -> No File <==== ATTENTION
Task: {3770B81D-938E-4937-ADD7-0AD783F8184F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {6977A7D3-4BD6-4483-BD8C-C327BFB16855} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7377FC27-FA68-4B0A-ABF2-F3C831AC0CD3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {821AE634-072E-4712-A474-E99868A58964} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {847652B6-ABDD-406B-8D8E-8F37BD9BE91A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {854439C3-34A1-4355-A106-0D49F6CEE2AD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {AEDC12E4-D27E-448A-BF81-41C57F3E2977} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {B145A8E9-5243-4BC6-862D-FCC0AC81DD5C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {D9978181-BD85-4D2C-BFA9-B889346015CF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION

end

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#14 Příspěvek od HINEGB »

Fix result of Farbar Recovery Scan Tool (x64) Version: 08-05-2017
Ran by Hynek (10-05-2017 11:39:07) Run:1
Running from C:\Users\Hynek\Desktop
Loaded Profiles: Hynek (Available Profiles: Hynek & ca)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:

CloseProcesses:

Hosts:

EmptyTemp:

2017-05-09 17:00 - 2016-09-12 18:07 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-05 09:12 - 2016-09-12 18:27 - 00003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-05 09:12 - 2016-09-12 18:27 - 00003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
Task: {02F31D6C-0CD0-49DF-8063-E0E8F9836D20} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {1F3FAF41-0A30-4199-BB31-813B057EBB0E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {2B027D83-E54C-4F22-9305-65044B2F8362} - \McAfee\McAfee Idle Detection Task -> No File <==== ATTENTION
Task: {36D57492-2E16-428F-90AD-FD8E0501F939} - \WPD\SqmUpload_S-1-5-21-3082648221-2456842191-3673000228-1001 -> No File <==== ATTENTION
Task: {3770B81D-938E-4937-ADD7-0AD783F8184F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {6977A7D3-4BD6-4483-BD8C-C327BFB16855} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7377FC27-FA68-4B0A-ABF2-F3C831AC0CD3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {821AE634-072E-4712-A474-E99868A58964} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {847652B6-ABDD-406B-8D8E-8F37BD9BE91A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {854439C3-34A1-4355-A106-0D49F6CEE2AD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {AEDC12E4-D27E-448A-BF81-41C57F3E2977} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {B145A8E9-5243-4BC6-862D-FCC0AC81DD5C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {D9978181-BD85-4D2C-BFA9-B889346015CF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION

end
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02F31D6C-0CD0-49DF-8063-E0E8F9836D20} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02F31D6C-0CD0-49DF-8063-E0E8F9836D20} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1F3FAF41-0A30-4199-BB31-813B057EBB0E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F3FAF41-0A30-4199-BB31-813B057EBB0E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2B027D83-E54C-4F22-9305-65044B2F8362} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B027D83-E54C-4F22-9305-65044B2F8362} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee\McAfee Idle Detection Task => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36D57492-2E16-428F-90AD-FD8E0501F939} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36D57492-2E16-428F-90AD-FD8E0501F939} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-3082648221-2456842191-3673000228-1001 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3770B81D-938E-4937-ADD7-0AD783F8184F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3770B81D-938E-4937-ADD7-0AD783F8184F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6977A7D3-4BD6-4483-BD8C-C327BFB16855} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6977A7D3-4BD6-4483-BD8C-C327BFB16855} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7377FC27-FA68-4B0A-ABF2-F3C831AC0CD3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7377FC27-FA68-4B0A-ABF2-F3C831AC0CD3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{821AE634-072E-4712-A474-E99868A58964} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{821AE634-072E-4712-A474-E99868A58964} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{847652B6-ABDD-406B-8D8E-8F37BD9BE91A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{847652B6-ABDD-406B-8D8E-8F37BD9BE91A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{854439C3-34A1-4355-A106-0D49F6CEE2AD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{854439C3-34A1-4355-A106-0D49F6CEE2AD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEDC12E4-D27E-448A-BF81-41C57F3E2977} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEDC12E4-D27E-448A-BF81-41C57F3E2977} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B145A8E9-5243-4BC6-862D-FCC0AC81DD5C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B145A8E9-5243-4BC6-862D-FCC0AC81DD5C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D9978181-BD85-4D2C-BFA9-B889346015CF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9978181-BD85-4D2C-BFA9-B889346015CF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11732910 B
Java, Flash, Steam htmlcache => 1267 B
Windows/system/drivers => 806485349 B
Edge => 1965952 B
Chrome => 334247276 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 5365 B
systemprofile32 => 128 B
LocalService => 157462 B
NetworkService => 28584 B
Hynek => 129203653 B
ca => 544461698 B

RecycleBin => 230728651 B
EmptyTemp: => 1.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 11:42:43 ====

HINEGB
Návštěvník
Návštěvník
Příspěvky: 90
Registrován: 22 led 2009 09:34

Re: prosím o kontrolu

#15 Příspěvek od HINEGB »

Fix result of Farbar Recovery Scan Tool (x64) Version: 08-05-2017
Ran by Hynek (10-05-2017 11:39:07) Run:1
Running from C:\Users\Hynek\Desktop
Loaded Profiles: Hynek (Available Profiles: Hynek & ca)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:

CloseProcesses:

Hosts:

EmptyTemp:

2017-05-09 17:00 - 2016-09-12 18:07 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-05 09:12 - 2016-09-12 18:27 - 00003470 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-05-05 09:12 - 2016-09-12 18:27 - 00003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
Task: {02F31D6C-0CD0-49DF-8063-E0E8F9836D20} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {1F3FAF41-0A30-4199-BB31-813B057EBB0E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {2B027D83-E54C-4F22-9305-65044B2F8362} - \McAfee\McAfee Idle Detection Task -> No File <==== ATTENTION
Task: {36D57492-2E16-428F-90AD-FD8E0501F939} - \WPD\SqmUpload_S-1-5-21-3082648221-2456842191-3673000228-1001 -> No File <==== ATTENTION
Task: {3770B81D-938E-4937-ADD7-0AD783F8184F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {6977A7D3-4BD6-4483-BD8C-C327BFB16855} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7377FC27-FA68-4B0A-ABF2-F3C831AC0CD3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {821AE634-072E-4712-A474-E99868A58964} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {847652B6-ABDD-406B-8D8E-8F37BD9BE91A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {854439C3-34A1-4355-A106-0D49F6CEE2AD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {AEDC12E4-D27E-448A-BF81-41C57F3E2977} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {B145A8E9-5243-4BC6-862D-FCC0AC81DD5C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {D9978181-BD85-4D2C-BFA9-B889346015CF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION

end
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02F31D6C-0CD0-49DF-8063-E0E8F9836D20} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02F31D6C-0CD0-49DF-8063-E0E8F9836D20} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1F3FAF41-0A30-4199-BB31-813B057EBB0E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F3FAF41-0A30-4199-BB31-813B057EBB0E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2B027D83-E54C-4F22-9305-65044B2F8362} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B027D83-E54C-4F22-9305-65044B2F8362} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee\McAfee Idle Detection Task => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36D57492-2E16-428F-90AD-FD8E0501F939} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36D57492-2E16-428F-90AD-FD8E0501F939} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-3082648221-2456842191-3673000228-1001 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3770B81D-938E-4937-ADD7-0AD783F8184F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3770B81D-938E-4937-ADD7-0AD783F8184F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6977A7D3-4BD6-4483-BD8C-C327BFB16855} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6977A7D3-4BD6-4483-BD8C-C327BFB16855} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7377FC27-FA68-4B0A-ABF2-F3C831AC0CD3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7377FC27-FA68-4B0A-ABF2-F3C831AC0CD3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{821AE634-072E-4712-A474-E99868A58964} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{821AE634-072E-4712-A474-E99868A58964} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{847652B6-ABDD-406B-8D8E-8F37BD9BE91A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{847652B6-ABDD-406B-8D8E-8F37BD9BE91A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{854439C3-34A1-4355-A106-0D49F6CEE2AD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{854439C3-34A1-4355-A106-0D49F6CEE2AD} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AEDC12E4-D27E-448A-BF81-41C57F3E2977} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEDC12E4-D27E-448A-BF81-41C57F3E2977} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B145A8E9-5243-4BC6-862D-FCC0AC81DD5C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B145A8E9-5243-4BC6-862D-FCC0AC81DD5C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D9978181-BD85-4D2C-BFA9-B889346015CF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9978181-BD85-4D2C-BFA9-B889346015CF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11732910 B
Java, Flash, Steam htmlcache => 1267 B
Windows/system/drivers => 806485349 B
Edge => 1965952 B
Chrome => 334247276 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 5365 B
systemprofile32 => 128 B
LocalService => 157462 B
NetworkService => 28584 B
Hynek => 129203653 B
ca => 544461698 B

RecycleBin => 230728651 B
EmptyTemp: => 1.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 11:42:43 ====

Zamčeno