Právě je 18 říj 2019 03:31

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Všechny časy jsou v UTC + 1 hodina


Pravidla fóra


Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.



Odeslat nové téma Odpovědět na téma  [ Příspěvků: 10 ] 
Autor Zpráva
 Předmět příspěvku: Modrá smrt
PříspěvekNapsal: 20 zář 2018 20:51 
Offline
Návštěvník
Návštěvník

Registrován: 29 zář 2014 22:07
Příspěvky: 168
Dobrý den,

objevila se mi na počítači modrá smrt. Prosím o kontrolu logu.

Děkuji.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Daniel at 2018-09-20 21:51:20
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 255 GB (55%) free of 464 GB
Total RAM: 4007 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:51:23, on 20.9.2018
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19130)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
C:\Program Files\trend micro\Daniel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Send to OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Global Startup: Avast Cleanup Premium.lnk = C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{9373A2C9-50E9-4FDE-B418-9B7C50FDAC6C}: NameServer = 77.234.40.79
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Cleanup Premium (CleanupPSvc) - AVAST Software - C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12064 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 27997088
\??\C:\Windows\system32\conhost.exe "-76706443912945862941481691279-1323033798-62143875-1186935196-1497200962561111131
atieclxx
"C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe"
C:\Windows\System32\spoolsv.exe
taskeng.exe {40BBA573-BF8E-471E-8004-6B8C4500BADC}
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\Windows\SysWOW64\SAsrv.exe
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\rundll32.exe "C:\Program Files\LENOVO\HOTKEY\hotkey.dll",InstallAudioHotkeyHook
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE /UEFI
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe"
AvastUI.exe /nogui
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe"
"C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe" /nogui
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 2816
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="4372.0.498184139\1297810321" -childID 1 -isForBrowser -prefsHandle 1536 -prefsLen 20514 -schedulerPrefs 0001,2 -parentBuildID 20180830143136 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" - 4372 "\\.\pipe\gecko-crash-server-pipe.4372" 1668 tab
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="4372.6.1874323025\678136135" -childID 2 -isForBrowser -prefsHandle 2396 -prefsLen 20510 -schedulerPrefs 0001,2 -parentBuildID 20180830143136 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" - 4372 "\\.\pipe\gecko-crash-server-pipe.4372" 2408 tab
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="4372.12.1476306609\198318524" -childID 3 -isForBrowser -prefsHandle 2632 -prefsLen 20510 -schedulerPrefs 0001,2 -parentBuildID 20180830143136 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" - 4372 "\\.\pipe\gecko-crash-server-pipe.4372" 2552 tab
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="4372.18.482297390\1990009616" -childID 4 -isForBrowser -prefsHandle 2920 -prefsLen 24856 -schedulerPrefs 0001,2 -parentBuildID 20180830143136 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" - 4372 "\\.\pipe\gecko-crash-server-pipe.4372" 1268 tab
C:\Windows\system32\sppsvc.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Daniel\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\SystemToolsDailyTest.job - C:\Program Files\PC-Doctor\pcdrcui.exe -silentenumeration -st SystemToolsDailyTest

=========Mozilla firefox=========

ProfilePath - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\l7o2zrf1.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-03-03 207016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2018-03-03 1058480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-03-24 2731304]
"IntelWireless"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2010-12-17 1933584]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-04-28 307768]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-03-26 167960]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-03-26 391704]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-03-26 418840]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [2011-01-27 41320]
"ALCKRESI.EXE"=C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE [2010-12-17 281448]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2018-08-31 242392]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"RotateImage"=C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [2008-10-31 55808]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-02-05 336384]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Avast Cleanup Premium.lnk - C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Send to OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-03-26 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2010-12-08 135504]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adwcleaner_7.0.8.0.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bttray.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iwrap.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jrt.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenotem.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\panui.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcdlauncher.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pwmui.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windvd.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2018-09-20 21:45:03 ----A---- C:\Windows\ntbtlog.txt
2018-09-11 23:32:10 ----A---- C:\Windows\system32\drivers\ks.sys
2018-09-11 23:32:09 ----A---- C:\Windows\system32\mshtml.dll
2018-09-11 23:32:08 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2018-09-11 23:32:07 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2018-09-11 23:32:07 ----A---- C:\Windows\system32\jscript9.dll
2018-09-11 23:32:06 ----A---- C:\Windows\SYSWOW64\shell32.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\shell32.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\msxml6.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\msxml3.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\drivers\tcpip.sys
2018-09-11 23:32:05 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2018-09-11 23:32:05 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2018-09-11 23:32:05 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2018-09-11 23:32:05 ----A---- C:\Windows\system32\urlmon.dll
2018-09-11 23:32:04 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2018-09-11 23:32:04 ----A---- C:\Windows\SYSWOW64\msjet40.dll
2018-09-11 23:32:04 ----A---- C:\Windows\system32\ntoskrnl.exe
2018-09-11 23:32:04 ----A---- C:\Windows\system32\ntdll.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\msexcl40.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\WindowsCodecs.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\t2embed.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\schedsvc.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\iedkcs32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\gdi32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\netio.sys
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\bowser.sys
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\mf3216.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\jscript.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2018-09-11 23:32:02 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2018-09-11 23:32:02 ----A---- C:\Windows\system32\mf3216.dll
2018-09-11 23:32:02 ----A---- C:\Windows\system32\hal.dll
2018-09-11 23:32:02 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2018-09-11 23:32:02 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2018-09-11 23:32:02 ----A---- C:\Windows\system32\atmfd.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\certcli.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\winsrv.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\wdigest.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\schannel.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\rstrui.exe
2018-09-11 23:32:01 ----A---- C:\Windows\system32\rpcrt4.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\lsasrv.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\kernel32.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\kerberos.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\drivers\mpsdrv.sys
2018-09-11 23:32:01 ----A---- C:\Windows\system32\conhost.exe
2018-09-11 23:32:01 ----A---- C:\Windows\system32\certcli.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\advapi32.dll
2018-09-11 23:32:00 ----A---- C:\Windows\SYSWOW64\schannel.dll
2018-09-11 23:32:00 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2018-09-11 23:32:00 ----A---- C:\Windows\system32\TSpkg.dll
2018-09-11 23:32:00 ----A---- C:\Windows\system32\srcore.dll
2018-09-11 23:32:00 ----A---- C:\Windows\system32\smss.exe
2018-09-11 23:31:59 ----A---- C:\Windows\system32\KernelBase.dll
2018-09-11 23:31:58 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2018-09-11 23:31:58 ----A---- C:\Windows\system32\msv1_0.dll
2018-09-11 23:31:57 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2018-09-11 23:31:57 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2018-09-11 23:31:57 ----A---- C:\Windows\system32\rpchttp.dll
2018-09-11 23:31:57 ----A---- C:\Windows\system32\ncrypt.dll
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\processr.sys
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\intelppm.sys
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\amdppm.sys
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\amdk8.sys
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\wininet.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\ntvdm64.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\mshtmlmedia.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\ieframe.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\drivers\videoprt.sys
2018-09-11 23:31:55 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2018-09-11 23:31:55 ----A---- C:\Windows\system32\csrsrv.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\auditpol.exe
2018-09-11 23:31:55 ----A---- C:\Windows\system32\appidsvc.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\appidapi.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\wininet.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2018-09-11 23:31:53 ----A---- C:\Windows\system32\wow64win.dll
2018-09-11 23:31:53 ----A---- C:\Windows\system32\sspicli.dll
2018-09-11 23:31:53 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2018-09-11 23:31:53 ----A---- C:\Windows\system32\bcrypt.dll
2018-09-11 23:31:52 ----A---- C:\Windows\SYSWOW64\srclient.dll
2018-09-11 23:31:52 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2018-09-11 23:31:52 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\wow64cpu.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\wow64.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\vbscript.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\sspisrv.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\srclient.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\setbcdlocale.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\secur32.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\msfeeds.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\lsass.exe
2018-09-11 23:31:52 ----A---- C:\Windows\system32\jscript.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\iertutil.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\drivers\appid.sys
2018-09-11 23:31:52 ----A---- C:\Windows\system32\cryptbase.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\credssp.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\secur32.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\credssp.dll
2018-09-11 23:31:51 ----A---- C:\Windows\system32\ieui.dll
2018-09-11 23:31:51 ----A---- C:\Windows\system32\ieapfltr.dll
2018-09-11 23:31:50 ----A---- C:\Windows\system32\dxtrans.dll
2018-09-11 23:31:50 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2018-09-11 23:31:49 ----A---- C:\Windows\system32\dxtmsft.dll
2018-09-11 23:31:48 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2018-09-11 23:31:48 ----A---- C:\Windows\system32\webcheck.dll
2018-09-11 23:31:48 ----A---- C:\Windows\system32\mshtmled.dll
2018-09-11 23:31:48 ----A---- C:\Windows\system32\apisetschema.dll
2018-09-11 23:31:46 ----A---- C:\Windows\SYSWOW64\wow32.dll
2018-09-11 23:31:46 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2018-09-11 23:31:45 ----A---- C:\Windows\system32\msrating.dll
2018-09-11 23:31:45 ----A---- C:\Windows\system32\jscript9diag.dll
2018-09-11 23:31:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2018-09-11 23:31:44 ----A---- C:\Windows\system32\ExplorerFrame.dll
2018-09-11 23:31:43 ----A---- C:\Windows\system32\occache.dll
2018-09-11 23:31:42 ----A---- C:\Windows\system32\jsproxy.dll
2018-09-11 23:31:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2018-09-11 23:31:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-09-11 23:31:41 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2018-09-11 23:31:41 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2018-09-11 23:31:41 ----A---- C:\Windows\system32\MPSSVC.dll
2018-09-11 23:31:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2018-09-11 23:31:39 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2018-09-11 23:31:39 ----A---- C:\Windows\system32\ieUnatt.exe
2018-09-11 23:31:39 ----A---- C:\Windows\system32\FirewallAPI.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-09-11 23:31:38 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-09-11 23:31:36 ----A---- C:\Windows\SYSWOW64\occache.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-09-11 23:31:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2018-09-11 23:31:35 ----A---- C:\Windows\system32\inseng.dll
2018-09-11 23:31:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2018-09-11 23:31:34 ----A---- C:\Windows\SYSWOW64\instnm.exe
2018-09-11 23:31:33 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-09-11 23:31:33 ----A---- C:\Windows\system32\ieetwproxystub.dll
2018-09-11 23:31:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-09-11 23:31:32 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2018-09-11 23:31:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2018-09-11 23:31:32 ----A---- C:\Windows\system32\iesetup.dll
2018-09-11 23:31:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2018-09-11 23:31:31 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-09-11 23:31:31 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-09-11 23:31:30 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\inseng.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\FirewallAPI.dll
2018-09-11 23:31:30 ----A---- C:\Windows\system32\ie4uinit.exe
2018-09-11 23:31:29 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2018-09-11 23:31:29 ----A---- C:\Windows\system32\iernonce.dll
2018-09-11 23:31:29 ----A---- C:\Windows\system32\ieetwcollector.exe
2018-09-11 23:31:28 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2018-09-11 23:31:27 ----A---- C:\Windows\SYSWOW64\user.exe
2018-09-11 23:31:27 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2018-09-11 23:31:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2018-09-11 23:31:27 ----A---- C:\Windows\system32\icfupgd.dll
2018-09-11 23:31:26 ----A---- C:\Windows\system32\lpk.dll
2018-09-11 23:31:25 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2018-09-11 23:31:25 ----A---- C:\Windows\system32\fontsub.dll
2018-09-11 23:31:25 ----A---- C:\Windows\system32\dciman32.dll
2018-09-11 23:31:25 ----A---- C:\Windows\system32\adtschema.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\wfapigp.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\lpk.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2018-09-11 23:31:24 ----A---- C:\Windows\system32\wfapigp.dll
2018-09-11 23:31:24 ----A---- C:\Windows\system32\msimg32.dll
2018-09-11 23:31:23 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2018-09-11 23:31:23 ----A---- C:\Windows\SYSWOW64\msimg32.dll
2018-09-11 23:31:23 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2018-09-11 23:31:23 ----A---- C:\Windows\system32\msobjs.dll
2018-09-11 23:31:23 ----A---- C:\Windows\system32\msaudite.dll
2018-09-11 23:31:20 ----A---- C:\Windows\SYSWOW64\netevent.dll
2018-09-11 23:31:20 ----A---- C:\Windows\system32\netevent.dll
2018-09-11 23:31:20 ----A---- C:\Windows\system32\atmlib.dll
2018-09-11 23:31:19 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2018-09-11 23:31:13 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2018-09-11 23:31:12 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2018-09-11 23:31:12 ----A---- C:\Windows\system32\msxml3r.dll
2018-09-11 23:31:11 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2018-09-11 23:31:10 ----A---- C:\Windows\system32\msxml6r.dll
2018-09-02 10:43:07 ----A---- C:\Windows\system32\FNTCACHE.DAT
2018-08-31 20:16:21 ----A---- C:\Windows\system32\aswBoot.exe

======List of files/folders modified in the last 1 month======

2018-09-20 21:51:23 ----D---- C:\Windows\Prefetch
2018-09-20 21:51:22 ----D---- C:\Program Files\trend micro
2018-09-20 21:47:31 ----D---- C:\Windows\Temp
2018-09-20 21:45:03 ----D---- C:\Windows
2018-09-20 21:10:12 ----D---- C:\Windows\system32\config
2018-09-19 21:04:21 ----D---- C:\Windows\System32
2018-09-19 21:04:21 ----D---- C:\Windows\inf
2018-09-19 21:04:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2018-09-17 20:07:50 ----D---- C:\Windows\system32\Tasks
2018-09-16 20:24:43 ----SHD---- C:\System Volume Information
2018-09-13 19:43:22 ----SHD---- C:\Windows\Installer
2018-09-13 19:43:22 ----SHD---- C:\Config.Msi
2018-09-13 19:43:10 ----D---- C:\Windows\SysWOW64
2018-09-13 19:43:10 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2018-09-12 20:00:40 ----D---- C:\Windows\rescache
2018-09-12 19:17:59 ----D---- C:\Windows\Microsoft.NET
2018-09-12 19:15:18 ----RSD---- C:\Windows\assembly
2018-09-12 19:13:19 ----D---- C:\Windows\system32\drivers
2018-09-12 19:05:57 ----D---- C:\Windows\winsxs
2018-09-12 19:05:16 ----D---- C:\Windows\system32\catroot2
2018-09-12 19:01:53 ----D---- C:\Program Files\Internet Explorer
2018-09-12 19:01:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2018-09-12 19:01:50 ----D---- C:\Program Files (x86)\Internet Explorer
2018-09-12 19:01:49 ----D---- C:\Windows\SYSWOW64\en-US
2018-09-12 19:01:40 ----D---- C:\Windows\system32\en-US
2018-09-12 19:01:40 ----D---- C:\Windows\system32\cs-CZ
2018-09-12 19:01:03 ----D---- C:\Windows\AppPatch
2018-09-12 19:00:58 ----D---- C:\Windows\system32\Boot
2018-09-12 19:00:53 ----D---- C:\Windows\system32\DriverStore
2018-09-12 00:06:26 ----D---- C:\ProgramData\Microsoft Help
2018-09-12 00:05:54 ----D---- C:\Windows\system32\MRT
2018-09-12 00:02:09 ----D---- C:\Windows\debug
2018-09-12 00:01:54 ----AC---- C:\Windows\system32\MRT.exe
2018-09-09 12:26:29 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-09-09 12:26:29 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-08-25 23:23:13 ----D---- C:\Users\Daniel\AppData\Roaming\vlc
2018-08-23 22:18:28 ----D---- C:\Users\Daniel\AppData\Roaming\HpUpdate

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2018-08-31 201320]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2018-08-31 346664]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2018-08-31 59568]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2018-08-31 87904]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2018-08-31 381560]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-05 438808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R0 Shockprf;Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [2011-01-13 139888]
R0 TPDIGIMN;TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [2011-01-13 23664]
R1 aswArPot;aswArPot; C:\Windows\system32\drivers\aswArPot.sys [2018-08-31 199712]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2018-08-31 229384]
R1 aswHdsKe;aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [2018-08-31 249016]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2018-08-31 111864]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2018-08-31 1027720]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2018-09-04 467320]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472]
R1 PHCORE;PHCORE; \??\C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [2010-12-03 31592]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2011-02-03 14960]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2018-09-11 163392]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2018-09-12 215920]
R2 risdxc;risdxc; C:\Windows\system32\DRIVERS\risdxc64.sys [2010-12-15 98816]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
R3 5U877;USB Video Device; C:\Windows\system32\DRIVERS\5U877.sys [2011-03-05 166016]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-02-05 8283136]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-02-05 295424]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-11-23 1567360]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2010-11-12 39024]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2011-03-26 12262336]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2010-12-21 8505856]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2009-07-02 40512]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-12-07 412776]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-03-24 1423408]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 wdkmd;Intel WiDi KMD; C:\Windows\system32\DRIVERS\WDKMD.sys [2011-04-09 42392]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2018-08-31 46968]
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2017-05-06 53904]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\drivers\bthpan.sys [2017-07-06 119296]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2010-12-18 425000]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-12-18 145960]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-12-18 162344]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-12-18 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-12-18 21416]
S3 MBAMSwissArmy;MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [2018-05-26 253880]
S3 PCDSRVC{127174DC-C366ED8B-06020101}_0;PCDSRVC{127174DC-C366ED8B-06020101}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [2010-12-10 25072]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2016-02-05 147904]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUSB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-02-05 203776]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2018-08-31 322464]
R2 CleanupPSvc;Avast Cleanup Premium; C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe [2018-07-24 8730648]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2010-11-12 45928]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2010-11-24 45496]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2010-04-07 93032]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2010-12-03 114024]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2010-12-02 64440]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2018-08-31 7994520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2018-03-26 107592]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2018-03-26 128584]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-21 153168]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-21 153168]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2018-08-24 116224]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-09-07 196048]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2018-03-12 211632]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2017-04-17 5132888]
S3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2011-02-03 79208]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG64.exe [2011-01-13 47728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2017-05-05 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2018-03-26 52832]
S4 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [2010-12-19 962848]
S4 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2018-03-13 7962288]
S4 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2010-12-17 1515792]
S4 HyperW7Svc;HyperW7 Service; C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2010-12-03 116072]
S4 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
S4 LENOVO.CAMMUTE;Lenovo Camera Mute; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [2011-01-27 40808]
S4 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-01-27 59240]
S4 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
S4 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-11-01 6234056]
S4 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2018-03-26 136288]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2018-03-26 136288]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2018-03-26 136288]
S4 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
S4 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2010-12-17 836880]
S4 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2010-11-25 28672]
S4 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

-----------------EOF-----------------


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 20 zář 2018 20:54 
Offline
Site Admin
Site Admin
Uživatelský avatar

Registrován: 30 říj 2003 13:42
Příspěvky: 109644
Bydliště: Plzeň
Zdravím!
Otevřte adresář C:\Windows\minidump, jeho obsah zabalte do raru a přiložte k vašemu příštímu postu. Zároveň přesouvám váš příspěvek do správné sekce.

_________________
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 21 zář 2018 20:16 
Offline
Návštěvník
Návštěvník

Registrován: 29 zář 2014 22:07
Příspěvky: 168
Zdravím. Otevřel jsem ten adresář, ale nic v něm není. Píše to složka je prázdná. Nešel firefox, musel jsem ho přeinstalovat. Nešly by pro jistotu zkontrolovat i ty logy?


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 21 zář 2018 21:01 
Offline
Site Admin
Site Admin
Uživatelský avatar

Registrován: 30 říj 2003 13:42
Příspěvky: 109644
Bydliště: Plzeň
Logy zkontrolovat můžu, ovšem nepřijdu s jejich pomocí na příčinu BSOD. Pokud je složka prázdná, budete muset počkat na další BSOD a poud se minidump zapíše, budeme ho analyzovat. Pomocí tohoto logu lze pouze PC vyčistit od malware a zbytečností. Spusťte tuto utilitu:

Citace:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

_________________
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 22 zář 2018 21:20 
Offline
Návštěvník
Návštěvník

Registrován: 29 zář 2014 22:07
Příspěvky: 168
OK. U té složky je takovej jako zámeček. Když se to objeví znova, tak to zkusim hned otevřít.

Tady je log ADW.

# -------------------------------
# Malwarebytes AdwCleaner 7.2.3.1
# -------------------------------
# Build: 09-03-2018
# Database: (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 09-22-2018
# Duration: 00:00:18
# OS: Windows 7 Home Premium
# Scanned: 41930
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 23 zář 2018 13:45 
Offline
Site Admin
Site Admin
Uživatelský avatar

Registrován: 30 říj 2003 13:42
Příspěvky: 109644
Bydliště: Plzeň
Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:

Citace:
:commands
[Purity]
[Emptytemp]
[Emptyflash]


a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

_________________
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 23 zář 2018 21:47 
Offline
Návštěvník
Návštěvník

Registrován: 29 zář 2014 22:07
Příspěvky: 168
Vypadá to, že se tam něco smazalo.

Tady je log z RSIT:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Daniel at 2018-09-23 22:46:46
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 249 GB (54%) free of 464 GB
Total RAM: 4007 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:46:48, on 23.9.2018
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19130)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe
C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Daniel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Send to OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Global Startup: Avast Cleanup Premium.lnk = C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{9373A2C9-50E9-4FDE-B418-9B7C50FDAC6C}: NameServer = 77.234.40.79
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Cleanup Premium (CleanupPSvc) - AVAST Software - C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12064 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 39998720
\??\C:\Windows\system32\conhost.exe "121914757313543738061664971804-1606918677-1436407239487524414-1037791023-901692338
atieclxx
"C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe"
C:\Windows\System32\spoolsv.exe
taskeng.exe {46A2A4B4-9FF5-444F-8C49-A59C6D1EE964}
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
C:\Windows\SysWOW64\SAsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2604
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
"taskhost.exe"
C:\Windows\system32\rundll32.exe "C:\Program Files\LENOVO\HOTKEY\hotkey.dll",InstallAudioHotkeyHook
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE /UEFI
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\09232018_223946.log
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
C:\Windows\system32\sppsvc.exe
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe"
"C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe" /nogui
"C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
AvastUI.exe /nogui
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1352.0.360698419\232384333" -childID 1 -isForBrowser -prefsHandle 1572 -prefsLen 7851 -schedulerPrefs 0001,2 -parentBuildID 20180920131237 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1352 "\\.\pipe\gecko-crash-server-pipe.1352" 1468 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1352.6.581181548\979651491" -childID 2 -isForBrowser -prefsHandle 2052 -prefsLen 7851 -schedulerPrefs 0001,2 -parentBuildID 20180920131237 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1352 "\\.\pipe\gecko-crash-server-pipe.1352" 1456 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1352.12.880433576\265256547" -childID 3 -isForBrowser -prefsHandle 2608 -prefsLen 11610 -schedulerPrefs 0001,2 -parentBuildID 20180920131237 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1352 "\\.\pipe\gecko-crash-server-pipe.1352" 3256 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1352.18.1205786695\2009067191" -childID 4 -isForBrowser -prefsHandle 3436 -prefsLen 12249 -schedulerPrefs 0001,2 -parentBuildID 20180920131237 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1352 "\\.\pipe\gecko-crash-server-pipe.1352" 3472 tab
wmiadap.exe /F /T /R
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Daniel\Desktop\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\SystemToolsDailyTest.job - C:\Program Files\PC-Doctor\pcdrcui.exe -silentenumeration -st SystemToolsDailyTest

=========Mozilla firefox=========

ProfilePath - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\w2jidik6.default-1537557771445

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-03-03 207016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2018-03-03 1058480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-03-24 2731304]
"IntelWireless"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2010-12-17 1933584]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-04-28 307768]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-03-26 167960]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-03-26 391704]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-03-26 418840]
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [2011-01-27 41320]
"ALCKRESI.EXE"=C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE [2010-12-17 281448]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2018-08-31 242392]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"RotateImage"=C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [2008-10-31 55808]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-02-05 336384]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Avast Cleanup Premium.lnk - C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe

C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Send to OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-03-26 385024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll [2010-12-08 135504]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adwcleaner_7.0.8.0.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bttray.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iwrap.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jrt.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenotem.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\panui.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcdlauncher.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pwmui.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\unins000.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windvd.exe]
"Debugger=""C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2018-09-23 22:34:44 ----D---- C:\Windows\SYSWOW64\18092304_stream
2018-09-21 21:17:25 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-09-20 21:45:03 ----A---- C:\Windows\ntbtlog.txt
2018-09-11 23:32:10 ----A---- C:\Windows\system32\drivers\ks.sys
2018-09-11 23:32:09 ----A---- C:\Windows\system32\mshtml.dll
2018-09-11 23:32:08 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2018-09-11 23:32:07 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2018-09-11 23:32:07 ----A---- C:\Windows\system32\jscript9.dll
2018-09-11 23:32:06 ----A---- C:\Windows\SYSWOW64\shell32.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\shell32.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\msxml6.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\msxml3.dll
2018-09-11 23:32:06 ----A---- C:\Windows\system32\drivers\tcpip.sys
2018-09-11 23:32:05 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2018-09-11 23:32:05 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2018-09-11 23:32:05 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2018-09-11 23:32:05 ----A---- C:\Windows\system32\urlmon.dll
2018-09-11 23:32:04 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2018-09-11 23:32:04 ----A---- C:\Windows\SYSWOW64\msjet40.dll
2018-09-11 23:32:04 ----A---- C:\Windows\system32\ntoskrnl.exe
2018-09-11 23:32:04 ----A---- C:\Windows\system32\ntdll.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\msexcl40.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\WindowsCodecs.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\t2embed.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\schedsvc.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\iedkcs32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\gdi32.dll
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\netio.sys
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2018-09-11 23:32:03 ----A---- C:\Windows\system32\drivers\bowser.sys
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\mf3216.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\jscript.dll
2018-09-11 23:32:02 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2018-09-11 23:32:02 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2018-09-11 23:32:02 ----A---- C:\Windows\system32\mf3216.dll
2018-09-11 23:32:02 ----A---- C:\Windows\system32\hal.dll
2018-09-11 23:32:02 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2018-09-11 23:32:02 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2018-09-11 23:32:02 ----A---- C:\Windows\system32\atmfd.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\certcli.dll
2018-09-11 23:32:01 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\winsrv.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\wdigest.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\schannel.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\rstrui.exe
2018-09-11 23:32:01 ----A---- C:\Windows\system32\rpcrt4.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\lsasrv.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\kernel32.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\kerberos.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\drivers\mpsdrv.sys
2018-09-11 23:32:01 ----A---- C:\Windows\system32\conhost.exe
2018-09-11 23:32:01 ----A---- C:\Windows\system32\certcli.dll
2018-09-11 23:32:01 ----A---- C:\Windows\system32\advapi32.dll
2018-09-11 23:32:00 ----A---- C:\Windows\SYSWOW64\schannel.dll
2018-09-11 23:32:00 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2018-09-11 23:32:00 ----A---- C:\Windows\system32\TSpkg.dll
2018-09-11 23:32:00 ----A---- C:\Windows\system32\srcore.dll
2018-09-11 23:32:00 ----A---- C:\Windows\system32\smss.exe
2018-09-11 23:31:59 ----A---- C:\Windows\system32\KernelBase.dll
2018-09-11 23:31:58 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2018-09-11 23:31:58 ----A---- C:\Windows\system32\msv1_0.dll
2018-09-11 23:31:57 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2018-09-11 23:31:57 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2018-09-11 23:31:57 ----A---- C:\Windows\system32\rpchttp.dll
2018-09-11 23:31:57 ----A---- C:\Windows\system32\ncrypt.dll
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\processr.sys
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\intelppm.sys
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\amdppm.sys
2018-09-11 23:31:56 ----A---- C:\Windows\system32\drivers\amdk8.sys
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2018-09-11 23:31:55 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\wininet.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\ntvdm64.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\mshtmlmedia.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\ieframe.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\drivers\videoprt.sys
2018-09-11 23:31:55 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2018-09-11 23:31:55 ----A---- C:\Windows\system32\csrsrv.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\auditpol.exe
2018-09-11 23:31:55 ----A---- C:\Windows\system32\appidsvc.dll
2018-09-11 23:31:55 ----A---- C:\Windows\system32\appidapi.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\wininet.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\setup16.exe
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2018-09-11 23:31:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2018-09-11 23:31:53 ----A---- C:\Windows\system32\wow64win.dll
2018-09-11 23:31:53 ----A---- C:\Windows\system32\sspicli.dll
2018-09-11 23:31:53 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2018-09-11 23:31:53 ----A---- C:\Windows\system32\bcrypt.dll
2018-09-11 23:31:52 ----A---- C:\Windows\SYSWOW64\srclient.dll
2018-09-11 23:31:52 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2018-09-11 23:31:52 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\wow64cpu.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\wow64.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\vbscript.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\sspisrv.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\srclient.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\setbcdlocale.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\secur32.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\msfeeds.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\lsass.exe
2018-09-11 23:31:52 ----A---- C:\Windows\system32\jscript.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\iertutil.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\drivers\appid.sys
2018-09-11 23:31:52 ----A---- C:\Windows\system32\cryptbase.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\credssp.dll
2018-09-11 23:31:52 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\secur32.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2018-09-11 23:31:51 ----A---- C:\Windows\SYSWOW64\credssp.dll
2018-09-11 23:31:51 ----A---- C:\Windows\system32\ieui.dll
2018-09-11 23:31:51 ----A---- C:\Windows\system32\ieapfltr.dll
2018-09-11 23:31:50 ----A---- C:\Windows\system32\dxtrans.dll
2018-09-11 23:31:50 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2018-09-11 23:31:49 ----A---- C:\Windows\system32\dxtmsft.dll
2018-09-11 23:31:48 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2018-09-11 23:31:48 ----A---- C:\Windows\system32\webcheck.dll
2018-09-11 23:31:48 ----A---- C:\Windows\system32\mshtmled.dll
2018-09-11 23:31:48 ----A---- C:\Windows\system32\apisetschema.dll
2018-09-11 23:31:46 ----A---- C:\Windows\SYSWOW64\wow32.dll
2018-09-11 23:31:46 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2018-09-11 23:31:45 ----A---- C:\Windows\system32\msrating.dll
2018-09-11 23:31:45 ----A---- C:\Windows\system32\jscript9diag.dll
2018-09-11 23:31:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2018-09-11 23:31:44 ----A---- C:\Windows\system32\ExplorerFrame.dll
2018-09-11 23:31:43 ----A---- C:\Windows\system32\occache.dll
2018-09-11 23:31:42 ----A---- C:\Windows\system32\jsproxy.dll
2018-09-11 23:31:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2018-09-11 23:31:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-09-11 23:31:41 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2018-09-11 23:31:41 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2018-09-11 23:31:41 ----A---- C:\Windows\system32\MPSSVC.dll
2018-09-11 23:31:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2018-09-11 23:31:39 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2018-09-11 23:31:39 ----A---- C:\Windows\system32\ieUnatt.exe
2018-09-11 23:31:39 ----A---- C:\Windows\system32\FirewallAPI.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-09-11 23:31:38 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-09-11 23:31:38 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-09-11 23:31:37 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-09-11 23:31:36 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-09-11 23:31:36 ----A---- C:\Windows\SYSWOW64\occache.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-09-11 23:31:35 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-09-11 23:31:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2018-09-11 23:31:35 ----A---- C:\Windows\system32\inseng.dll
2018-09-11 23:31:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2018-09-11 23:31:34 ----A---- C:\Windows\SYSWOW64\instnm.exe
2018-09-11 23:31:33 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-09-11 23:31:33 ----A---- C:\Windows\system32\ieetwproxystub.dll
2018-09-11 23:31:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-09-11 23:31:32 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2018-09-11 23:31:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2018-09-11 23:31:32 ----A---- C:\Windows\system32\iesetup.dll
2018-09-11 23:31:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2018-09-11 23:31:31 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-09-11 23:31:31 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-09-11 23:31:30 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\inseng.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2018-09-11 23:31:30 ----A---- C:\Windows\SYSWOW64\FirewallAPI.dll
2018-09-11 23:31:30 ----A---- C:\Windows\system32\ie4uinit.exe
2018-09-11 23:31:29 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2018-09-11 23:31:29 ----A---- C:\Windows\system32\iernonce.dll
2018-09-11 23:31:29 ----A---- C:\Windows\system32\ieetwcollector.exe
2018-09-11 23:31:28 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2018-09-11 23:31:27 ----A---- C:\Windows\SYSWOW64\user.exe
2018-09-11 23:31:27 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2018-09-11 23:31:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2018-09-11 23:31:27 ----A---- C:\Windows\system32\icfupgd.dll
2018-09-11 23:31:26 ----A---- C:\Windows\system32\lpk.dll
2018-09-11 23:31:25 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2018-09-11 23:31:25 ----A---- C:\Windows\system32\fontsub.dll
2018-09-11 23:31:25 ----A---- C:\Windows\system32\dciman32.dll
2018-09-11 23:31:25 ----A---- C:\Windows\system32\adtschema.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\wfapigp.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\lpk.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2018-09-11 23:31:24 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2018-09-11 23:31:24 ----A---- C:\Windows\system32\wfapigp.dll
2018-09-11 23:31:24 ----A---- C:\Windows\system32\msimg32.dll
2018-09-11 23:31:23 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2018-09-11 23:31:23 ----A---- C:\Windows\SYSWOW64\msimg32.dll
2018-09-11 23:31:23 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2018-09-11 23:31:23 ----A---- C:\Windows\system32\msobjs.dll
2018-09-11 23:31:23 ----A---- C:\Windows\system32\msaudite.dll
2018-09-11 23:31:20 ----A---- C:\Windows\SYSWOW64\netevent.dll
2018-09-11 23:31:20 ----A---- C:\Windows\system32\netevent.dll
2018-09-11 23:31:20 ----A---- C:\Windows\system32\atmlib.dll
2018-09-11 23:31:19 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2018-09-11 23:31:13 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2018-09-11 23:31:12 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2018-09-11 23:31:12 ----A---- C:\Windows\system32\msxml3r.dll
2018-09-11 23:31:11 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2018-09-11 23:31:10 ----A---- C:\Windows\system32\msxml6r.dll
2018-09-02 10:43:07 ----A---- C:\Windows\system32\FNTCACHE.DAT
2018-08-31 20:16:21 ----A---- C:\Windows\system32\aswBoot.exe

======List of files/folders modified in the last 1 month======

2018-09-23 22:46:48 ----D---- C:\Windows\Prefetch
2018-09-23 22:46:47 ----D---- C:\Program Files\trend micro
2018-09-23 22:42:52 ----D---- C:\Windows\Temp
2018-09-23 22:42:27 ----D---- C:\Windows\system32\config
2018-09-23 22:41:30 ----D---- C:\Program Files\Mozilla Firefox
2018-09-23 22:39:19 ----D---- C:\Windows\System32
2018-09-23 22:39:19 ----D---- C:\Windows\inf
2018-09-23 22:39:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2018-09-23 22:34:44 ----D---- C:\Windows\SysWOW64
2018-09-22 22:09:41 ----D---- C:\AdwCleaner
2018-09-21 21:17:25 ----RD---- C:\Program Files (x86)
2018-09-21 21:12:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-09-20 21:45:03 ----D---- C:\Windows
2018-09-17 20:07:50 ----D---- C:\Windows\system32\Tasks
2018-09-16 20:24:43 ----SHD---- C:\System Volume Information
2018-09-13 19:43:22 ----SHD---- C:\Windows\Installer
2018-09-13 19:43:22 ----SHD---- C:\Config.Msi
2018-09-13 19:43:10 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2018-09-12 20:00:40 ----D---- C:\Windows\rescache
2018-09-12 19:17:59 ----D---- C:\Windows\Microsoft.NET
2018-09-12 19:15:18 ----RSD---- C:\Windows\assembly
2018-09-12 19:13:19 ----D---- C:\Windows\system32\drivers
2018-09-12 19:05:57 ----D---- C:\Windows\winsxs
2018-09-12 19:05:16 ----D---- C:\Windows\system32\catroot2
2018-09-12 19:01:53 ----D---- C:\Program Files\Internet Explorer
2018-09-12 19:01:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2018-09-12 19:01:50 ----D---- C:\Program Files (x86)\Internet Explorer
2018-09-12 19:01:49 ----D---- C:\Windows\SYSWOW64\en-US
2018-09-12 19:01:40 ----D---- C:\Windows\system32\en-US
2018-09-12 19:01:40 ----D---- C:\Windows\system32\cs-CZ
2018-09-12 19:01:03 ----D---- C:\Windows\AppPatch
2018-09-12 19:00:58 ----D---- C:\Windows\system32\Boot
2018-09-12 19:00:53 ----D---- C:\Windows\system32\DriverStore
2018-09-12 00:06:26 ----D---- C:\ProgramData\Microsoft Help
2018-09-12 00:05:54 ----D---- C:\Windows\system32\MRT
2018-09-12 00:02:09 ----D---- C:\Windows\debug
2018-09-12 00:01:54 ----AC---- C:\Windows\system32\MRT.exe
2018-08-25 23:23:13 ----D---- C:\Users\Daniel\AppData\Roaming\vlc

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2018-08-31 201320]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2018-08-31 346664]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2018-08-31 59568]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2018-08-31 87904]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2018-08-31 381560]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-11-05 438808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R0 Shockprf;Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [2011-01-13 139888]
R0 TPDIGIMN;TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [2011-01-13 23664]
R1 aswArPot;aswArPot; C:\Windows\system32\drivers\aswArPot.sys [2018-08-31 199712]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2018-08-31 229384]
R1 aswHdsKe;aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [2018-08-31 249016]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2018-08-31 111864]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2018-08-31 1027720]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2018-09-04 467320]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472]
R1 PHCORE;PHCORE; \??\C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [2010-12-03 31592]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2011-02-03 14960]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2018-09-11 163392]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2018-09-12 215920]
R2 risdxc;risdxc; C:\Windows\system32\DRIVERS\risdxc64.sys [2010-12-15 98816]
R2 smihlp;SMI Helper Driver (smihlp); \??\C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2009-03-13 13840]
R3 5U877;USB Video Device; C:\Windows\system32\DRIVERS\5U877.sys [2011-03-05 166016]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-02-05 8283136]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-02-05 295424]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-11-23 1567360]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2010-11-12 39024]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2011-03-26 12262336]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2010-12-21 8505856]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2009-07-02 40512]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-12-07 412776]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-03-24 1423408]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 wdkmd;Intel WiDi KMD; C:\Windows\system32\DRIVERS\WDKMD.sys [2011-04-09 42392]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2018-08-31 46968]
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2017-05-06 53904]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\drivers\bthpan.sys [2017-07-06 119296]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2010-12-18 425000]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-12-18 145960]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-12-18 162344]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-12-18 39464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-12-18 21416]
S3 MBAMSwissArmy;MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [2018-05-26 253880]
S3 PCDSRVC{127174DC-C366ED8B-06020101}_0;PCDSRVC{127174DC-C366ED8B-06020101}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [2010-12-10 25072]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2016-02-05 147904]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUSB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-02-05 203776]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2018-08-31 322464]
R2 CleanupPSvc;Avast Cleanup Premium; C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe [2018-07-24 8730648]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2010-11-12 45928]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2010-11-24 45496]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2010-04-07 93032]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2010-12-03 114024]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2010-12-02 64440]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2018-08-31 7994520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2018-03-26 107592]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2018-03-26 128584]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-21 153168]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-07-21 153168]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2018-08-24 116224]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-09-23 196048]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2018-03-12 211632]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2017-04-17 5132888]
S3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2011-02-03 79208]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG64.exe [2011-01-13 47728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2017-05-05 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2018-03-26 52832]
S4 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [2010-12-19 962848]
S4 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2018-03-13 7962288]
S4 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2010-12-17 1515792]
S4 HyperW7Svc;HyperW7 Service; C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2010-12-03 116072]
S4 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
S4 LENOVO.CAMMUTE;Lenovo Camera Mute; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [2011-01-27 40808]
S4 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-01-27 59240]
S4 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
S4 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-11-01 6234056]
S4 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2018-03-26 136288]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2018-03-26 136288]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2018-03-26 136288]
S4 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
S4 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2010-12-17 836880]
S4 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2010-11-25 28672]
S4 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

-----------------EOF-----------------


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 24 zář 2018 09:25 
Offline
Site Admin
Site Admin
Uživatelský avatar

Registrován: 30 říj 2003 13:42
Příspěvky: 109644
Bydliště: Plzeň
Smazáno, log je již OK.

_________________
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 24 zář 2018 19:50 
Offline
Návštěvník
Návštěvník

Registrován: 29 zář 2014 22:07
Příspěvky: 168
Díky !


Nahoru
 Profil  
Odpovědět s citací  
 Předmět příspěvku: Re: Modrá smrt
PříspěvekNapsal: 24 zář 2018 20:05 
Offline
Site Admin
Site Admin
Uživatelský avatar

Registrován: 30 říj 2003 13:42
Příspěvky: 109644
Bydliště: Plzeň
Nemáte zač. Pokud se BSOD znovu objeví, koukněte do c:\windows\minidump a pokud tam nějaký soubor bude, zabalte do raru a upněte sem. :)

_________________
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.


Nahoru
 Profil  
Odpovědět s citací  
Zobrazit příspěvky za předchozí:  Seřadit podle  
Odeslat nové téma Odpovědět na téma  [ Příspěvků: 10 ] 

Všechny časy jsou v UTC + 1 hodina


Kdo je online

Uživatelé procházející toto fórum: Žádní registrovaní uživatelé


Nemůžete zakládat nová témata v tomto fóru
Nemůžete odpovídat v tomto fóru
Nemůžete upravovat své příspěvky v tomto fóru
Nemůžete mazat své příspěvky v tomto fóru
Nemůžete přikládat soubory v tomto fóru

Hledat:
Přejít na:  
cron
Založeno na phpBB® Forum Software © phpBB Group
Český překlad – phpBB.cz
Přispějete na provoz fóra?