problém s about.blank, prosím o kontrolu logu
Napsal: 13 dub 2014 17:25
Zdravím, nejde mi nastavit domácí stránka, pořád mi tam skáče jenom about.blank. Někde jsem vyčetl že je to vir, tak přikládám log na kontrolu.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Wilson at 2014-04-13 18:15:08
Microsoft Windows 8.1 Pro
System drive C: has 3 GB (2%) free of 114 GB
Total RAM: 6135 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:15:15, on 13. 4. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files\trend micro\Wilson.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (file missing)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O2 - BHO: (no name) - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: (no name) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - (no file)
O3 - Toolbar: (no name) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - (no file)
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: (no name) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - (no file)
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKUS\S-1-5-21-1460209786-2656286751-2583658488-1004\..\Run: [BrowserChoice] "C:\Windows\BrowserChoice\browserchoice.exe" /run (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1460209786-2656286751-2583658488-1004\..\Run: [MicroUpdate] C:\Users\UpdatusUser\Documents\MSDCSC\msdcsc.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1460209786-2656286751-2583658488-1004\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun (User 'UpdatusUser')
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: DTSAudioService - DTS - C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iSafeService - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\iSafe\iSafeSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Surftastic - Unknown owner - C:\Program Files (x86)\Surftastic\updateSurftastic.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 9379 bytes
======Listing Processes======
wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files (x86)\iSafe\iSafeSvc.exe"
"C:\Program Files (x86)\iSafe\iSafeSvc2.exe"
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe"
"C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe"
dashost.exe {1c84baeb-bda4-46bc-90cbee6c3e779bf4}
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-16ae9d4a-fb04-47db-b5e2-37c79f67aefc -SystemEventPortName:HostProcess-6152b9db-e4d8-4210-86cc-96b79995bd1b -IoCancelEventPortName:HostProcess-405141e5-8f02-4934-9540-46b5dc18e681 -NonStateChangingEventPortName:HostProcess-b3086542-8a74-41d0-a6b3-a6a697638f7a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c25f65be-efb7-4335-831f-b7e074b659d3 -DeviceGroupId:WpdFsGroup
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
taskhostex.exe
C:\Windows\Explorer.EXE
ClassicStartMenu.exe -startup
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE" /logon
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORDTSUPTBT
"C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe"
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
"C:\Users\Wilson\AppData\Local\JDownloader v2.0\JDownloader2.exe"
"C:\Program Files (x86)\totalcmd\TOTALCMD.EXE"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:267521 /prefetch:2
"C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:4068635 /prefetch:2
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:922974 /prefetch:2
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:3282399 /prefetch:2
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "N:\==SERIÁLY==\MASH\215+Na+zdravi+Hawkeye.avi"
"C:\Windows\system32\SearchFilterHost.exe" 0 584 588 596 65536 592
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe51_ Global\UsGthrCtrlFltPipeMssGthrPipe51 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Users\Wilson\AppData\Local\Microsoft\Windows\INetCache\IE\WWSJTJ14\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C42510-9B41-42c1-9DCD-7282A2D07C61}C]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310}
{95B7759C-8C7F-4BF1-B163-73684A933233}
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2011-03-14 2779024]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-01-10 7202520]
"RtHDVBg_DTS"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-01-10 1321688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"TomTomHOME.exe"=C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [2013-08-27 248208]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-02-16 3767096]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
AVerQuick.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-04-13 18:12:38 ----D---- C:\rsit
2014-04-13 18:12:38 ----D---- C:\Program Files\trend micro
2014-04-10 06:11:51 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-04-10 06:11:51 ----A---- C:\Windows\system32\drivers\clfs.sys
2014-04-10 06:11:49 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-04-10 06:11:49 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-04-10 06:11:49 ----A---- C:\Windows\system32\KernelBase.dll
2014-04-10 06:11:49 ----A---- C:\Windows\system32\kernel32.dll
2014-04-10 06:11:47 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-04-10 06:11:47 ----A---- C:\Windows\system32\mshtml.dll
2014-04-08 21:26:26 ----D---- C:\Users\Wilson\AppData\Roaming\iSafe
2014-04-08 21:20:47 ----D---- C:\Windows\ERUNT
2014-04-08 20:41:51 ----D---- C:\Users\Wilson\AppData\Roaming\LavasoftStatistics
2014-04-08 20:13:07 ----D---- C:\ProgramData\Lavasoft
2014-04-08 19:28:01 ----A---- C:\Windows\system32\drivers\stflt.sys
2014-04-07 22:06:27 ----D---- C:\Users\Wilson\AppData\Roaming\vlc
2014-04-07 14:44:33 ----D---- C:\Program Files (x86)\AA Antimalware
2014-04-06 17:31:16 ----D---- C:\Users\Wilson\AppData\Roaming\Sony Network Entertainment International LLC
2014-04-02 23:38:32 ----D---- C:\Users\Wilson\AppData\Roaming\eCyber
2014-04-02 23:38:26 ----D---- C:\Windows\system32\log
2014-04-02 23:38:23 ----D---- C:\Program Files (x86)\iSafe
2014-04-02 23:31:08 ----D---- C:\ProgramData\Ashampoo
2014-04-02 19:27:01 ----D---- C:\Program Files (x86)\Seznam.cz
2014-04-02 19:26:38 ----D---- C:\Users\Wilson\AppData\Roaming\Seznam.cz
2014-03-25 18:10:28 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2014-03-25 18:10:28 ----A---- C:\Windows\system32\poqexec.exe
2014-03-17 23:50:34 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2014-03-17 23:50:33 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2014-03-17 23:50:33 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-03-17 23:50:33 ----A---- C:\Windows\system32\SettingSyncHost.exe
2014-03-17 23:50:32 ----A---- C:\Windows\system32\SettingSyncCore.dll
2014-03-17 23:50:31 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-03-17 23:50:31 ----A---- C:\Windows\system32\shell32.dll
2014-03-17 23:50:30 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2014-03-17 23:50:29 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2014-03-17 23:50:27 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2014-03-17 23:50:27 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2014-03-17 23:50:27 ----A---- C:\Windows\system32\schedsvc.dll
2014-03-17 23:50:27 ----A---- C:\Windows\system32\MFMediaEngine.dll
2014-03-17 23:50:27 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-03-17 23:50:26 ----A---- C:\Windows\SYSWOW64\WSClient.dll
2014-03-17 23:50:26 ----A---- C:\Windows\SYSWOW64\OEMLicense.dll
2014-03-17 23:50:26 ----A---- C:\Windows\system32\WSClient.dll
2014-03-17 23:50:26 ----A---- C:\Windows\system32\OEMLicense.dll
2014-03-17 23:50:26 ----A---- C:\Windows\system32\mfsvr.dll
2014-03-17 23:50:25 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2014-03-17 23:50:25 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2014-03-17 23:50:25 ----A---- C:\Windows\system32\ReAgent.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\pnrpsvc.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\MsSpellCheckingFacility.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\hal.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-03-17 23:50:23 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-03-17 23:50:23 ----A---- C:\Windows\SYSWOW64\MsSpellCheckingFacility.dll
2014-03-17 23:50:23 ----A---- C:\Windows\system32\reseteng.dll
2014-03-17 23:50:23 ----A---- C:\Windows\system32\ntdll.dll
2014-03-17 23:50:23 ----A---- C:\Windows\system32\easinvoker.exe
2014-03-17 23:50:23 ----A---- C:\Windows\system32\drivers\rdbss.sys
2014-03-17 23:50:22 ----AC---- C:\Windows\system32\drivers\USBXHCI.SYS
2014-03-17 23:50:22 ----A---- C:\Windows\SYSWOW64\sti.dll
2014-03-17 23:50:22 ----A---- C:\Windows\SYSWOW64\easwrt.dll
2014-03-17 23:50:22 ----A---- C:\Windows\system32\sti.dll
2014-03-17 23:50:22 ----A---- C:\Windows\system32\easwrt.dll
2014-03-17 17:13:23 ----D---- C:\ProgramData\EPSON
2014-03-15 17:34:04 ----D---- C:\ProgramData\CODEX
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\xactengine3_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\d3dcsx_43.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\xactengine3_6.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\xinput1_3.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\d3dx10.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xinput1_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xinput1_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-03-15 17:33:09 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-03-15 17:33:09 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-03-15 17:33:09 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-03-15 17:33:09 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-03-15 17:33:09 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-03-15 17:33:09 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-03-15 17:33:08 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-03-15 17:33:08 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-03-15 17:33:08 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-03-15 17:33:08 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-03-15 17:30:43 ----D---- C:\Program Files (x86)\The Walking Dead Season 2 EP 2
======List of files/folders modified in the last 1 month======
2014-04-13 18:14:21 ----D---- C:\Windows\Prefetch
2014-04-13 18:12:38 ----D---- C:\Program Files
2014-04-13 18:00:00 ----D---- C:\Windows\system32\sru
2014-04-13 17:23:18 ----D---- C:\Windows\Temp
2014-04-13 17:04:23 ----D---- C:\Windows\AppReadiness
2014-04-13 08:54:52 ----D---- C:\Users\Wilson\AppData\Roaming\ClassicShell
2014-04-13 08:53:01 ----D---- C:\Windows\Microsoft.NET
2014-04-13 08:47:48 ----RD---- C:\Windows\System32
2014-04-13 08:47:48 ----D---- C:\Windows\Inf
2014-04-13 08:47:48 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-04-12 09:51:40 ----SHD---- C:\System Volume Information
2014-04-12 08:25:45 ----D---- C:\Windows\system32\config
2014-04-12 08:19:42 ----HD---- C:\Program Files\WindowsApps
2014-04-11 06:40:37 ----D---- C:\Windows\WinSxS
2014-04-11 06:22:12 ----D---- C:\ProgramData\NVIDIA
2014-04-11 00:33:56 ----D---- C:\Windows\SysWOW64
2014-04-11 00:33:56 ----D---- C:\Windows\system32\drivers
2014-04-10 19:21:38 ----SHD---- C:\Windows\Installer
2014-04-10 19:21:37 ----D---- C:\ProgramData\Microsoft Help
2014-04-10 19:21:31 ----D---- C:\Windows\CbsTemp
2014-04-10 19:21:30 ----D---- C:\Windows\system32\MRT
2014-04-10 19:20:59 ----A---- C:\Windows\system32\MRT.exe
2014-04-08 21:29:48 ----D---- C:\Program Files (x86)\totalcmd
2014-04-08 21:22:14 ----RD---- C:\Program Files (x86)
2014-04-08 21:22:10 ----HD---- C:\ProgramData
2014-04-08 21:20:47 ----D---- C:\Windows
2014-04-08 21:18:41 ----D---- C:\Program Files\Common Files
2014-04-07 22:05:34 ----D---- C:\Program Files (x86)\VideoLAN
2014-04-07 15:02:05 ----D---- C:\Windows\SYSWOW64\drivers
2014-04-07 15:01:24 ----D---- C:\Program Files (x86)\Common Files
2014-04-07 00:59:11 ----D---- C:\Users\Wilson\AppData\Roaming\uTorrent
2014-04-03 00:01:16 ----D---- C:\Program Files (x86)\Need For Speed Rivals
2014-04-02 23:46:00 ----D---- C:\Program Files\Classic Shell
2014-04-02 21:08:52 ----D---- C:\Windows\debug
2014-04-02 20:58:44 ----D---- C:\Windows\SoftwareDistribution
2014-04-02 20:41:23 ----D---- C:\Windows\system32\Tasks
2014-04-02 19:02:23 ----D---- C:\ProgramData\CanonIJPLM
2014-03-31 23:23:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-03-27 17:58:57 ----D---- C:\Windows\system32\DriverStore
2014-03-19 17:24:28 ----D---- C:\Windows\rescache
2014-03-18 11:12:13 ----D---- C:\Windows\system32\catroot
2014-03-18 11:12:09 ----RD---- C:\Windows\ToastData
2014-03-18 11:12:09 ----D---- C:\Windows\SYSWOW64\en-US
2014-03-18 11:12:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-03-18 11:12:09 ----D---- C:\Windows\system32\en-US
2014-03-18 11:12:09 ----D---- C:\Windows\system32\cs-CZ
2014-03-18 11:12:08 ----D---- C:\Windows\system32\drivers\UMDF
2014-03-17 23:48:20 ----D---- C:\Windows\system32\catroot2
2014-03-17 17:09:55 ----D---- C:\Users\Wilson\AppData\Roaming\DAEMON Tools Lite
2014-03-17 17:09:53 ----D---- C:\Windows\Logs
2014-03-15 17:33:12 ----RSD---- C:\Windows\assembly
2014-03-15 17:28:57 ----D---- C:\ProgramData\DAEMON Tools Lite
Logfile of random's system information tool 1.09 (written by random/random)
Run by Wilson at 2014-04-13 18:15:08
Microsoft Windows 8.1 Pro
System drive C: has 3 GB (2%) free of 114 GB
Total RAM: 6135 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:15:15, on 13. 4. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files\trend micro\Wilson.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (file missing)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O2 - BHO: (no name) - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - (no file)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O2 - BHO: (no name) - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - (no file)
O3 - Toolbar: (no name) - {553891B7-A0D5-4526-BE18-D3CE461D6310} - (no file)
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O3 - Toolbar: (no name) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - (no file)
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKUS\S-1-5-21-1460209786-2656286751-2583658488-1004\..\Run: [BrowserChoice] "C:\Windows\BrowserChoice\browserchoice.exe" /run (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1460209786-2656286751-2583658488-1004\..\Run: [MicroUpdate] C:\Users\UpdatusUser\Documents\MSDCSC\msdcsc.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1460209786-2656286751-2583658488-1004\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun (User 'UpdatusUser')
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: DTSAudioService - DTS - C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iSafeService - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\iSafe\iSafeSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Surftastic - Unknown owner - C:\Program Files (x86)\Surftastic\updateSurftastic.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 9379 bytes
======Listing Processes======
wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files (x86)\iSafe\iSafeSvc.exe"
"C:\Program Files (x86)\iSafe\iSafeSvc2.exe"
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe"
"C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe"
dashost.exe {1c84baeb-bda4-46bc-90cbee6c3e779bf4}
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-16ae9d4a-fb04-47db-b5e2-37c79f67aefc -SystemEventPortName:HostProcess-6152b9db-e4d8-4210-86cc-96b79995bd1b -IoCancelEventPortName:HostProcess-405141e5-8f02-4934-9540-46b5dc18e681 -NonStateChangingEventPortName:HostProcess-b3086542-8a74-41d0-a6b3-a6a697638f7a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c25f65be-efb7-4335-831f-b7e074b659d3 -DeviceGroupId:WpdFsGroup
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
taskhostex.exe
C:\Windows\Explorer.EXE
ClassicStartMenu.exe -startup
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE" /logon
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORDTSUPTBT
"C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe"
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
"C:\Users\Wilson\AppData\Local\JDownloader v2.0\JDownloader2.exe"
"C:\Program Files (x86)\totalcmd\TOTALCMD.EXE"
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:267521 /prefetch:2
"C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:4068635 /prefetch:2
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:922974 /prefetch:2
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6728 CREDAT:3282399 /prefetch:2
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "N:\==SERIÁLY==\MASH\215+Na+zdravi+Hawkeye.avi"
"C:\Windows\system32\SearchFilterHost.exe" 0 584 588 596 65536 592
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe51_ Global\UsGthrCtrlFltPipeMssGthrPipe51 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Users\Wilson\AppData\Local\Microsoft\Windows\INetCache\IE\WWSJTJ14\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C42510-9B41-42c1-9DCD-7282A2D07C61}C]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310}
{95B7759C-8C7F-4BF1-B163-73684A933233}
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2011-03-14 2779024]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-01-10 7202520]
"RtHDVBg_DTS"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-01-10 1321688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"TomTomHOME.exe"=C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [2013-08-27 248208]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-02-16 3767096]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
AVerQuick.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-04-13 18:12:38 ----D---- C:\rsit
2014-04-13 18:12:38 ----D---- C:\Program Files\trend micro
2014-04-10 06:11:51 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-04-10 06:11:51 ----A---- C:\Windows\system32\drivers\clfs.sys
2014-04-10 06:11:49 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-04-10 06:11:49 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-04-10 06:11:49 ----A---- C:\Windows\system32\KernelBase.dll
2014-04-10 06:11:49 ----A---- C:\Windows\system32\kernel32.dll
2014-04-10 06:11:47 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-04-10 06:11:47 ----A---- C:\Windows\system32\mshtml.dll
2014-04-08 21:26:26 ----D---- C:\Users\Wilson\AppData\Roaming\iSafe
2014-04-08 21:20:47 ----D---- C:\Windows\ERUNT
2014-04-08 20:41:51 ----D---- C:\Users\Wilson\AppData\Roaming\LavasoftStatistics
2014-04-08 20:13:07 ----D---- C:\ProgramData\Lavasoft
2014-04-08 19:28:01 ----A---- C:\Windows\system32\drivers\stflt.sys
2014-04-07 22:06:27 ----D---- C:\Users\Wilson\AppData\Roaming\vlc
2014-04-07 14:44:33 ----D---- C:\Program Files (x86)\AA Antimalware
2014-04-06 17:31:16 ----D---- C:\Users\Wilson\AppData\Roaming\Sony Network Entertainment International LLC
2014-04-02 23:38:32 ----D---- C:\Users\Wilson\AppData\Roaming\eCyber
2014-04-02 23:38:26 ----D---- C:\Windows\system32\log
2014-04-02 23:38:23 ----D---- C:\Program Files (x86)\iSafe
2014-04-02 23:31:08 ----D---- C:\ProgramData\Ashampoo
2014-04-02 19:27:01 ----D---- C:\Program Files (x86)\Seznam.cz
2014-04-02 19:26:38 ----D---- C:\Users\Wilson\AppData\Roaming\Seznam.cz
2014-03-25 18:10:28 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2014-03-25 18:10:28 ----A---- C:\Windows\system32\poqexec.exe
2014-03-17 23:50:34 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2014-03-17 23:50:33 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2014-03-17 23:50:33 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-03-17 23:50:33 ----A---- C:\Windows\system32\SettingSyncHost.exe
2014-03-17 23:50:32 ----A---- C:\Windows\system32\SettingSyncCore.dll
2014-03-17 23:50:31 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-03-17 23:50:31 ----A---- C:\Windows\system32\shell32.dll
2014-03-17 23:50:30 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2014-03-17 23:50:29 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2014-03-17 23:50:27 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2014-03-17 23:50:27 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2014-03-17 23:50:27 ----A---- C:\Windows\system32\schedsvc.dll
2014-03-17 23:50:27 ----A---- C:\Windows\system32\MFMediaEngine.dll
2014-03-17 23:50:27 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-03-17 23:50:26 ----A---- C:\Windows\SYSWOW64\WSClient.dll
2014-03-17 23:50:26 ----A---- C:\Windows\SYSWOW64\OEMLicense.dll
2014-03-17 23:50:26 ----A---- C:\Windows\system32\WSClient.dll
2014-03-17 23:50:26 ----A---- C:\Windows\system32\OEMLicense.dll
2014-03-17 23:50:26 ----A---- C:\Windows\system32\mfsvr.dll
2014-03-17 23:50:25 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2014-03-17 23:50:25 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2014-03-17 23:50:25 ----A---- C:\Windows\system32\ReAgent.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\pnrpsvc.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\MsSpellCheckingFacility.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\hal.dll
2014-03-17 23:50:24 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-03-17 23:50:23 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-03-17 23:50:23 ----A---- C:\Windows\SYSWOW64\MsSpellCheckingFacility.dll
2014-03-17 23:50:23 ----A---- C:\Windows\system32\reseteng.dll
2014-03-17 23:50:23 ----A---- C:\Windows\system32\ntdll.dll
2014-03-17 23:50:23 ----A---- C:\Windows\system32\easinvoker.exe
2014-03-17 23:50:23 ----A---- C:\Windows\system32\drivers\rdbss.sys
2014-03-17 23:50:22 ----AC---- C:\Windows\system32\drivers\USBXHCI.SYS
2014-03-17 23:50:22 ----A---- C:\Windows\SYSWOW64\sti.dll
2014-03-17 23:50:22 ----A---- C:\Windows\SYSWOW64\easwrt.dll
2014-03-17 23:50:22 ----A---- C:\Windows\system32\sti.dll
2014-03-17 23:50:22 ----A---- C:\Windows\system32\easwrt.dll
2014-03-17 17:13:23 ----D---- C:\ProgramData\EPSON
2014-03-15 17:34:04 ----D---- C:\ProgramData\CODEX
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\xactengine3_7.dll
2014-03-15 17:33:26 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-03-15 17:33:25 ----A---- C:\Windows\system32\d3dcsx_43.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2014-03-15 17:33:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\xactengine3_6.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-03-15 17:33:24 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-03-15 17:33:23 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-03-15 17:33:22 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-03-15 17:33:21 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-03-15 17:33:20 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-03-15 17:33:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-03-15 17:33:19 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-03-15 17:33:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-03-15 17:33:18 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-03-15 17:33:17 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-03-15 17:33:16 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\xinput1_3.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-03-15 17:33:15 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-03-15 17:33:14 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-03-15 17:33:13 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-03-15 17:33:13 ----A---- C:\Windows\system32\d3dx10.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xinput1_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xinput1_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-03-15 17:33:12 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-03-15 17:33:10 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-03-15 17:33:10 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-03-15 17:33:09 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-03-15 17:33:09 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-03-15 17:33:09 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-03-15 17:33:09 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-03-15 17:33:09 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-03-15 17:33:09 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-03-15 17:33:08 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-03-15 17:33:08 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-03-15 17:33:08 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-03-15 17:33:08 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-03-15 17:30:43 ----D---- C:\Program Files (x86)\The Walking Dead Season 2 EP 2
======List of files/folders modified in the last 1 month======
2014-04-13 18:14:21 ----D---- C:\Windows\Prefetch
2014-04-13 18:12:38 ----D---- C:\Program Files
2014-04-13 18:00:00 ----D---- C:\Windows\system32\sru
2014-04-13 17:23:18 ----D---- C:\Windows\Temp
2014-04-13 17:04:23 ----D---- C:\Windows\AppReadiness
2014-04-13 08:54:52 ----D---- C:\Users\Wilson\AppData\Roaming\ClassicShell
2014-04-13 08:53:01 ----D---- C:\Windows\Microsoft.NET
2014-04-13 08:47:48 ----RD---- C:\Windows\System32
2014-04-13 08:47:48 ----D---- C:\Windows\Inf
2014-04-13 08:47:48 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-04-12 09:51:40 ----SHD---- C:\System Volume Information
2014-04-12 08:25:45 ----D---- C:\Windows\system32\config
2014-04-12 08:19:42 ----HD---- C:\Program Files\WindowsApps
2014-04-11 06:40:37 ----D---- C:\Windows\WinSxS
2014-04-11 06:22:12 ----D---- C:\ProgramData\NVIDIA
2014-04-11 00:33:56 ----D---- C:\Windows\SysWOW64
2014-04-11 00:33:56 ----D---- C:\Windows\system32\drivers
2014-04-10 19:21:38 ----SHD---- C:\Windows\Installer
2014-04-10 19:21:37 ----D---- C:\ProgramData\Microsoft Help
2014-04-10 19:21:31 ----D---- C:\Windows\CbsTemp
2014-04-10 19:21:30 ----D---- C:\Windows\system32\MRT
2014-04-10 19:20:59 ----A---- C:\Windows\system32\MRT.exe
2014-04-08 21:29:48 ----D---- C:\Program Files (x86)\totalcmd
2014-04-08 21:22:14 ----RD---- C:\Program Files (x86)
2014-04-08 21:22:10 ----HD---- C:\ProgramData
2014-04-08 21:20:47 ----D---- C:\Windows
2014-04-08 21:18:41 ----D---- C:\Program Files\Common Files
2014-04-07 22:05:34 ----D---- C:\Program Files (x86)\VideoLAN
2014-04-07 15:02:05 ----D---- C:\Windows\SYSWOW64\drivers
2014-04-07 15:01:24 ----D---- C:\Program Files (x86)\Common Files
2014-04-07 00:59:11 ----D---- C:\Users\Wilson\AppData\Roaming\uTorrent
2014-04-03 00:01:16 ----D---- C:\Program Files (x86)\Need For Speed Rivals
2014-04-02 23:46:00 ----D---- C:\Program Files\Classic Shell
2014-04-02 21:08:52 ----D---- C:\Windows\debug
2014-04-02 20:58:44 ----D---- C:\Windows\SoftwareDistribution
2014-04-02 20:41:23 ----D---- C:\Windows\system32\Tasks
2014-04-02 19:02:23 ----D---- C:\ProgramData\CanonIJPLM
2014-03-31 23:23:52 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-03-27 17:58:57 ----D---- C:\Windows\system32\DriverStore
2014-03-19 17:24:28 ----D---- C:\Windows\rescache
2014-03-18 11:12:13 ----D---- C:\Windows\system32\catroot
2014-03-18 11:12:09 ----RD---- C:\Windows\ToastData
2014-03-18 11:12:09 ----D---- C:\Windows\SYSWOW64\en-US
2014-03-18 11:12:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-03-18 11:12:09 ----D---- C:\Windows\system32\en-US
2014-03-18 11:12:09 ----D---- C:\Windows\system32\cs-CZ
2014-03-18 11:12:08 ----D---- C:\Windows\system32\drivers\UMDF
2014-03-17 23:48:20 ----D---- C:\Windows\system32\catroot2
2014-03-17 17:09:55 ----D---- C:\Users\Wilson\AppData\Roaming\DAEMON Tools Lite
2014-03-17 17:09:53 ----D---- C:\Windows\Logs
2014-03-15 17:33:12 ----RSD---- C:\Windows\assembly
2014-03-15 17:28:57 ----D---- C:\ProgramData\DAEMON Tools Lite