Stránka 1 z 2

Kontrola logu

Napsal: 30 srp 2014 13:29
od Thooty
Dobrý den,

chtěl bych vás požádat o kontrolu logu. Už několik týdnů mě trápí problém s náhodným "padáním" systému s hláškou driver_irql_not_less_or_equal (cm10864.sys). Jde nejspíše o hardwarový problém nebo problém s drivery, ale chtěl bych vyloučit i možnost viru.

Předem děkuji :-)

-----------------------

Logfile of random's system information tool 1.10 (written by random/random)
Run by Ultimate at 2014-08-30 14:14:51
Microsoft Windows 8.1 Pro
System drive C: has 10 GB (18%) free of 57 GB
Total RAM: 4044 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:14:52, on 30. 8. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe
C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
C:\Program Files\trend micro\Ultimate.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FastAccess Web Alert] D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe
O4 - HKLM\..\Run: [Live! Central 3] "D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe" /mode2
O4 - HKLM\..\Run: [AdobeCEPServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [reg_svr] "C:\Windows\SysWoW64\regsvr32.exe" /s "C:\Users\Ultimate\AppData\Roaming\gleam\nvm.dll"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_F35B4131FD575AA3DE87A46A5D1B0D6F] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Bloody2] "C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe" Minimum
O4 - HKCU\..\Run: [SandboxieControl] "D:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - Startup: Voicemeeter (VB-Audio).LNK = C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office15\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C104FC3-9622-4F11-A4F5-369B7C7CC98D}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECA9AD42-81CA-4A95-BEEA-5056853B8B19}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: prio32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Forge Client Service (ForgeClientService) - Unknown owner - D:\Program Files\Forge\ForgeClientService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - The OpenVPN Project - D:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Prio Service (prio_svc) - Unknown owner - D:\Program Files\Prio\prio_svc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - Sandboxie Holdings, LLC - D:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Service KMSELDI - Unknown owner - D:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StartMenu8 Service (StartMenuService) - IObit - C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10460 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"dwm.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"D:\Program Files\Sandboxie\SbieSvc.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskhostex.exe
C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe"
dashost.exe {9d076504-88af-4b33-bae6f40838b4b3cb}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"D:\Program Files\Forge\ForgeClientService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"D:\Program Files\Prio\prio_svc.exe"
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22d2b1e1-09d7-4fbd-874d-777c9fa10b9b 0
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe"
"C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe" /HotCorners
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Windows\SysWOW64\regsvr32.exe" /s "C:\Users\Ultimate\AppData\Roaming\gleam\nvm.dll"
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe" -Embedding
"C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe" Minimum

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2260.0.1466780663\947030019" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16,44 --gpu-vendor-id=0x10de --gpu-device-id=0x11c0 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.4052 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.1.1600419582\447643300" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.3.1322034057\1201979806" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.4.958771505\1333890582" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.5.1854489260\2021649501" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.6.265189981\1693401092" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.7.1684784961\250003740" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.8.15635396\257558433" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.9.1966743254\351151929" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.10.1848179308\1194151688" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/ControlHttps/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="2260.11.2010656010\703386681" /prefetch:673131151
"C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe"
"C:\Users\Ultimate\AppData\Roaming\uTorrent\uTorrent.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Ultimate\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf8a715b278e1a.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Ultimate\AppData\Roaming\Mozilla\Firefox\Profiles\3e97d50y.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=D:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-16 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-16 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-08-09 1283136]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-08-09 2403288]
"Cm108Sound"=C:\Windows\syswow64\RunDll32.exe [2013-08-22 49664]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-06-02 7575768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=D:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-08-01 3673696]
"reg_svr"=C:\Windows\SysWoW64\regsvr32.exe [2013-08-22 17408]
"GoogleChromeAutoLaunch_F35B4131FD575AA3DE87A46A5D1B0D6F"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-08-26 911176]
"Bloody2"=C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe [2014-08-14 13965312]
"SandboxieControl"=D:\Program Files\Sandboxie\SbieCtrl.exe [2014-05-29 784392]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=D:\Program Files\QuickTime\QTTask.exe [2013-05-01 421888]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"FastAccess Web Alert"=D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe [2011-07-11 2033648]
"Live! Central 3"=D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe [2013-08-15 461312]
"AdobeCEPServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [2013-03-13 1039248]

C:\Users\Ultimate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Voicemeeter (VB-Audio).LNK - C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="prio.dll"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"VIDC.FPS1"=frapsv64.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"vidc.pDAD"=prodad-codec.dll
"MSVideo8"=VfWWDM32.dll
"midi8"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"VIDC.LAGS"=lagarith.dll
"msacm.lameacm"=LameACM.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave8"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer8"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-08-30 14:14:51 ----D---- C:\rsit
2014-08-28 13:19:28 ----A---- C:\Windows\system32\win32k.sys
2014-08-24 23:15:53 ----RD---- C:\Sandbox
2014-08-24 23:11:05 ----A---- C:\Windows\Sandboxie.ini
2014-08-19 14:49:02 ----A---- C:\Windows\system32\RtNicProp64.dll
2014-08-19 14:49:02 ----A---- C:\Windows\system32\drivers\Rt630x64.sys
2014-08-16 23:07:35 ----A---- C:\Windows\unins000.exe
2014-08-13 23:56:38 ----D---- C:\Program Files\TAP-Windows
2014-08-13 12:54:58 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2014-08-13 12:54:57 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2014-08-13 12:54:57 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-13 12:54:57 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 12:54:56 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2014-08-13 12:54:56 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-08-13 12:54:56 ----A---- C:\Windows\system32\mstscax.dll
2014-08-13 12:54:55 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\twinui.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\SettingsHandlers.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\d3d10warp.dll
2014-08-13 12:54:54 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2014-08-13 12:54:54 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\wlansvc.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\mfcore.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\gpsvc.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-08-13 12:54:54 ----A---- C:\Windows\system32\authui.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\actxprxy.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\twinui.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\workfolderssvc.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-08-13 12:54:53 ----A---- C:\Windows\system32\Windows.Media.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\SRH.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\mfplat.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\localspl.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\drivers\srv.sys
2014-08-13 12:54:52 ----AC---- C:\Windows\system32\drivers\spaceport.sys
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\SRH.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\printui.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\mispace.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\XpsPrint.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\wuaueng.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\wlanmsm.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\srvsvc.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\printui.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\netcfgx.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\mispace.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\dxgi.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\netio.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\AppxPackaging.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\aclui.dll
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\volsnap.sys
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\USBHUB3.SYS
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\usbccgp.sys
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\SHCore.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\mftranscode.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\AppxPackaging.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\aclui.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wuapi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wsecedit.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\WSDMon.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wisp.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\winresume.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\winload.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\WebClnt.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\usbmon.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\uDWM.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\storagewmi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\spoolsv.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\SHCore.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\puiobj.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\mftranscode.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\mfreadwrite.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\lsasrv.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\defragsvc.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\comdlg32.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\clusapi.dll
2014-08-13 12:54:50 ----AC---- C:\Windows\system32\drivers\usbhub.sys
2014-08-13 12:54:50 ----AC---- C:\Windows\system32\drivers\hdaudbus.sys
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wsecedit.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wlanapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wisp.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\winmmbase.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\Display.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\clusapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\AppxSip.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\wucltux.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WSShared.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\wpdbusenum.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WorkFoldersGPExt.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\winmmbase.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\winmm.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\Windows.Networking.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\win32spl.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WiFiDisplay.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\VAN.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\user32.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\twinapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\SndVol.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\SettingSync.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\rdpcorets.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\profsvc.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\prnntfy.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\osk.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\mfps.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\httpprxm.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\GdiPlus.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\dwmcore.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\dwmapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\nwifi.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\NdisImPlatform.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\msgpioclx.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\bridge.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\Display.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\DafPrintProvider.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\conhost.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\bcryptprimitives.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\AppxSip.dll
2014-08-13 12:54:49 ----AC---- C:\Windows\system32\drivers\pci.sys
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\winmm.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\Windows.Networking.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\VAN.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\user32.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\SndVol.exe
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\SettingSync.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\rsaenh.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\puiapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\prnntfy.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\KBDRUM.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\iasnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\gpedit.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wwanconn.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wups2.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wups.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wuauclt.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wshbth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\WorkFoldersShell.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wlansvcpal.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wlanapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wcmcsp.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\stobject.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\schannel.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\SearchFolder.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\rsaenh.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\puiapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\PrintDialogs.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\ppcsnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\pmcsnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRUM.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\iasnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\gpedit.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\drivers\ks.sys
2014-08-13 12:54:49 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 12:54:49 ----A---- C:\Windows\system32\Defrag.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\dab.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\browser.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\AppxSysprep.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\adhsvc.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\ActionCenter.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\PrintDialogs.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDTT102.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wwanmm.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wudriver.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wlansec.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\SndVolSSO.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\rdpudd.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\KBDTT102.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\system32\compstui.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\certcli.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\BluetoothApis.dll
2014-08-13 12:54:38 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-13 12:54:38 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-08-13 12:54:34 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\msi.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\consent.exe
2014-08-13 12:54:34 ----A---- C:\Windows\system32\aepdu.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\aeinv.dll
2014-08-13 12:54:34 ----A---- C:\Windows\explorer.exe
2014-08-13 12:54:33 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\WpcWebSync.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\WpcMon.exe
2014-08-13 12:54:33 ----A---- C:\Windows\system32\Wpc.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\MrmCoreR.dll
2014-08-13 12:54:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-13 12:54:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-08-13 12:54:27 ----A---- C:\Windows\system32\MDMAgent.exe
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\iernonce.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\urlmon.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-13 12:54:24 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-08-13 12:54:24 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-13 12:54:24 ----A---- C:\Windows\system32\iesetup.dll
2014-08-13 12:54:24 ----A---- C:\Windows\system32\iertutil.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\jscript9.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-13 12:54:23 ----A---- C:\Windows\system32\ieframe.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\wininet.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\msrating.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\mshtml.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\vbscript.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-13 12:52:47 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-13 12:52:47 ----A---- C:\Windows\system32\gdi32.dll
2014-08-11 14:43:09 ----D---- C:\Users\Ultimate\AppData\Roaming\FileZilla
2014-08-11 01:32:32 ----D---- C:\ProgramData\shimgen
2014-08-11 01:29:00 ----D---- C:\Users\Ultimate\AppData\Roaming\NuGet
2014-08-11 01:28:07 ----D---- C:\Chocolatey
2014-08-10 22:05:25 ----D---- C:\Users\Ultimate\AppData\Roaming\Atom
2014-08-08 14:59:12 ----D---- C:\Users\Ultimate\AppData\Roaming\Opera Software
2014-08-07 13:58:21 ----D---- C:\Program Files\CyberGhost 5
2014-08-03 16:37:45 ----D---- C:\Users\Ultimate\AppData\Roaming\Publish Providers
2014-08-03 16:35:43 ----D---- C:\ProgramData\Sony
2014-08-03 16:35:43 ----D---- C:\Program Files\Sony
2014-08-03 16:35:43 ----D---- C:\Program Files (x86)\Sony
2014-08-03 16:34:51 ----D---- C:\Users\Ultimate\AppData\Roaming\Sony

======List of files/folders modified in the last 1 month======

2014-08-30 14:14:51 ----D---- C:\Program Files\trend micro
2014-08-30 14:14:46 ----D---- C:\Users\Ultimate\AppData\Roaming\uTorrent
2014-08-30 14:12:59 ----D---- C:\Windows\Temp
2014-08-30 14:12:19 ----D---- C:\Users\Ultimate\AppData\Roaming\vlc
2014-08-30 14:06:02 ----RD---- C:\Windows\System32
2014-08-30 14:06:02 ----D---- C:\Windows\Inf
2014-08-30 14:06:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-08-30 14:00:14 ----D---- C:\Windows
2014-08-30 14:00:10 ----D---- C:\Windows\system32\Tasks
2014-08-30 14:00:08 ----D---- C:\Windows\Minidump
2014-08-30 13:59:51 ----D---- C:\ProgramData\NVIDIA
2014-08-30 13:02:00 ----D---- C:\Windows\system32\sru
2014-08-29 21:38:15 ----D---- C:\Users\Ultimate\AppData\Roaming\Skype
2014-08-29 17:29:01 ----D---- C:\Windows\system32\logs
2014-08-29 13:42:04 ----D---- C:\Users\Ultimate\AppData\Roaming\Audacity
2014-08-29 12:35:35 ----D---- C:\Windows\AppReadiness
2014-08-29 12:34:33 ----HD---- C:\Program Files\WindowsApps
2014-08-29 11:14:00 ----SHD---- C:\System Volume Information
2014-08-29 11:12:59 ----D---- C:\Windows\Microsoft.NET
2014-08-29 11:12:57 ----D---- C:\Windows\debug
2014-08-29 11:06:19 ----D---- C:\Windows\system32\config
2014-08-29 11:02:56 ----D---- C:\Windows\WinSxS
2014-08-29 01:31:27 ----D---- C:\Windows\SoftwareDistribution
2014-08-29 01:11:20 ----D---- C:\Users\Ultimate\AppData\Roaming\Notepad++
2014-08-29 01:11:20 ----D---- C:\Users\Ultimate\AppData\Roaming\DAEMON Tools Lite
2014-08-29 01:11:18 ----D---- C:\Windows\Logs
2014-08-29 01:10:51 ----D---- C:\Program Files\CCleaner
2014-08-28 16:38:46 ----D---- C:\Windows\CbsTemp
2014-08-27 20:46:05 ----D---- C:\Users\Ultimate\AppData\Roaming\npm-cache
2014-08-25 13:19:17 ----D---- C:\Windows\system32\wdi
2014-08-24 23:10:28 ----SHD---- C:\Windows\Installer
2014-08-24 23:10:28 ----SHD---- C:\Config.Msi
2014-08-24 19:23:49 ----D---- C:\Program Files\NVIDIA Corporation
2014-08-24 01:33:29 ----D---- C:\Windows\system32\catroot2
2014-08-20 01:08:18 ----D---- C:\Windows\system32\NDF
2014-08-19 18:09:01 ----D---- C:\Windows\system32\DriverStore
2014-08-19 17:43:48 ----D---- C:\Program Files (x86)\Bloody5
2014-08-19 14:49:26 ----D---- C:\Windows\system32\drivers
2014-08-19 14:49:24 ----D---- C:\Windows\system32\catroot
2014-08-16 02:34:54 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-08-16 01:45:59 ----RSD---- C:\Windows\Fonts
2014-08-14 16:54:17 ----RSD---- C:\Windows\assembly
2014-08-13 23:56:38 ----RD---- C:\Program Files
2014-08-13 22:11:00 ----D---- C:\Windows\rescache
2014-08-13 13:18:58 ----SHD---- C:\Boot
2014-08-13 13:18:11 ----RD---- C:\Windows\ToastData
2014-08-13 13:18:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-13 13:18:11 ----D---- C:\Windows\SysWOW64
2014-08-13 13:18:11 ----D---- C:\Windows\system32\migration
2014-08-13 13:18:11 ----D---- C:\Windows\system32\cs-CZ
2014-08-13 13:18:11 ----D---- C:\Windows\PolicyDefinitions
2014-08-13 13:18:11 ----D---- C:\Program Files\Internet Explorer
2014-08-13 13:18:11 ----D---- C:\Program Files (x86)\Internet Explorer
2014-08-13 13:18:10 ----RD---- C:\Windows\ImmersiveControlPanel
2014-08-13 13:18:10 ----D---- C:\Windows\WinStore
2014-08-13 13:18:10 ----D---- C:\Windows\SYSWOW64\wbem
2014-08-13 13:18:10 ----D---- C:\Windows\SYSWOW64\setup
2014-08-13 13:18:10 ----D---- C:\Windows\system32\wbem
2014-08-13 13:18:10 ----D---- C:\Windows\system32\setup
2014-08-13 13:18:10 ----D---- C:\Windows\system32\oobe
2014-08-13 13:18:10 ----D---- C:\Windows\system32\drivers\cs-CZ
2014-08-13 13:18:10 ----D---- C:\Windows\system32\Boot
2014-08-13 13:18:10 ----D---- C:\Program Files\Windows Journal
2014-08-13 13:18:09 ----D---- C:\Windows\SYSWOW64\migration
2014-08-13 13:18:09 ----D---- C:\Windows\SYSWOW64\InputMethod
2014-08-13 13:18:09 ----D---- C:\Windows\apppatch
2014-08-13 13:02:18 ----D---- C:\Windows\system32\MRT
2014-08-13 13:01:10 ----A---- C:\Windows\system32\MRT.exe
2014-08-13 13:00:29 ----SD---- C:\Windows\system32\CompatTel
2014-08-12 13:52:37 ----HD---- C:\ProgramData
2014-08-11 22:33:42 ----SD---- C:\ProgramData\Microsoft
2014-08-11 22:33:39 ----D---- C:\Windows\ShellNew
2014-08-11 20:04:20 ----RD---- C:\Program Files (x86)
2014-08-09 14:33:01 ----D---- C:\Users\Ultimate\AppData\Roaming\gleam
2014-08-09 14:28:45 ----D---- C:\Users\Ultimate\AppData\Roaming\Identities
2014-08-09 02:22:16 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-08-09 02:22:16 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-08-09 02:22:05 ----A---- C:\Windows\system32\nvspcap64.dll
2014-08-09 02:22:05 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-08-07 18:54:18 ----D---- C:\ProgramData\Skype
2014-08-07 15:14:10 ----D---- C:\Program Files (x86)\Common Files
2014-08-06 23:45:17 ----D---- C:\Users\Ultimate\AppData\Roaming\Security_File
2014-08-05 18:02:19 ----D---- C:\Program Files (x86)\Adobe
2014-08-02 13:56:54 ----D---- C:\ProgramData\Origin
2014-08-02 02:17:43 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-07-31 16:34:31 ----D---- C:\Program Files\Adobe
2014-07-31 16:31:05 ----D---- C:\Program Files\Common Files\Adobe
2014-07-31 16:22:42 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2014-07-31 16:19:09 ----D---- C:\Users\Ultimate\AppData\Roaming\Adobe
2014-07-31 16:17:43 ----D---- C:\ProgramData\Package Cache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2013-09-17 239296]
R1 dtsoftbus01;@oem20.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2013-10-12 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R2 Dokan;Dokan; \??\C:\WINDOWS\system32\drivers\dokan.sys [2011-01-10 120408]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2013-08-22 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-06-02 3962840]
R3 MEIx64;@oem11.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\HECIx64.sys [2012-07-17 62784]
R3 NVHDA;@oem9.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-28 197408]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2014-07-02 12866008]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-08-09 20440]
R3 nvvad_WaveExtensible;@oem73.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 RTL8168;@oem91.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-08-19 873688]
R3 SbieDrv;SbieDrv; \??\D:\Program Files\Sandboxie\SbieDrv.sys [2014-05-29 185352]
R3 ScreamBAudioSvc;@oem21.inf,%sbee_audio.SvcDesc%;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys [2010-07-01 38992]
R3 tap0901;@oem86.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2014-04-08 27136]
R3 USBPNPA;@oem67.inf,%CM108.SvcDesc%;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM10864.sys [2014-03-13 4333568]
R3 VBAudioVACMME;@oem37.inf,%DeviceName% (WDM);VB-Audio Virtual Cable (WDM); C:\Windows\system32\DRIVERS\vbaudio_cable64_win7.sys [2013-07-11 41192]
R3 VBAudioVMVAIOMME;@oem74.inf,%DeviceName% (WDM);VB-Audio VoiceMeeter VAIO (WDM); C:\Windows\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [2014-05-15 41192]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\Windows\system32\DRIVERS\CtClsFlt.sys [2011-09-05 178176]
S3 dg_ssudbus;@oem42.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-08-20 103576]
S3 EuMusDesignVirtualAudioCableWdm;@oem36.inf,%DeviceName% (WDM);Virtual Audio Cable (WDM); C:\Windows\system32\DRIVERS\vrtaucbl.sys [2014-01-01 90624]
S3 LHidFilt;@oem31.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2013-05-23 76568]
S3 LMouFilt;@oem31.inf,%LMouFilt.SvcDesc%;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2013-05-23 59160]
S3 LUsbFilt;@oem27.inf,%FltDisplayName%;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2013-05-23 40728]
S3 ptun0901;@oem90.inf,%DeviceDescription%;TAP Adapter V9 for Private Tunnel; C:\Windows\system32\DRIVERS\ptun0901.sys [2014-04-24 27136]
S3 RTL8167;@oem2.inf,%rtl8167.Service.DispName%;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-04-10 849992]
S3 tap0901_openvpn_accl;@oem49.inf,%DeviceDescription%;TAP-Win32 Adapter V9 for OpenVPN Accelerator; C:\Windows\system32\DRIVERS\tap0901_openvpn_accl.sys [2012-08-21 37912]
S3 taphss6;@oem87.inf,%DeviceDescription%;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2014-05-17 42184]
S3 tapoas;@oem72.inf,%DeviceDescription%;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2012-07-15 30720]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 DokanMounter;DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [2011-01-10 14848]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 ForgeClientService;Forge Client Service; D:\Program Files\Forge\ForgeClientService.exe [2014-07-11 45320]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-08-09 1720792]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-08-09 18973144]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-07-02 935368]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-06-13 76888]
R2 prio_svc;Prio Service; D:\Program Files\Prio\prio_svc.exe [2012-11-08 12656]
R2 SbieSvc;Sandboxie Service; D:\Program Files\Sandboxie\SbieSvc.exe [2014-05-29 174088]
R2 StartMenuService;StartMenu8 Service; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [2014-06-06 72992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-11 116648]
S2 Service KMSELDI;Service KMSELDI; D:\Program Files\KMSpico\Service_KMS.exe [2013-11-11 685568]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-24 262320]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2013-10-13 49152]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-11 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-04-22 119408]
S3 OpenVPNService;OpenVPN Service; D:\Program Files\OpenVPN\bin\openvpnserv.exe [2014-08-07 37176]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]

-----------------EOF-----------------

Re: Kontrola logu

Napsal: 30 srp 2014 17:07
od Rudy
Zdravím!
Otevřte adresář c:\windows\minidump, jeho obsah zabalte do raru a přiložte k vašemu příštímu postu.

Re: Kontrola logu

Napsal: 30 srp 2014 19:08
od Thooty
Tady je :-)

Re: Kontrola logu

Napsal: 30 srp 2014 20:02
od Rudy
Problém se týká zvukové karty. Zkuste přeinstalovat ovladač.

Re: Kontrola logu

Napsal: 01 zář 2014 22:13
od Thooty
Tak jsem přeinstaloval všechny ovladače zvuku, které byly potřeba a dnes nastal opět problém, ale tentokrát mi místo modré obrazovky s chybovou hláškou zamrzl obraz i počítač. Jediným řešením bylo restartovat počítač.
Nemůže se tedy jednat o problém hardwaru, pokud jste v logu nic co by nasvědčovalo viru nenašel?

Re: Kontrola logu

Napsal: 02 zář 2014 16:19
od Rudy
PC samozřejmě vyčistíme. Připouštím, že problém může být v hardwaru.
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Kontrola logu

Napsal: 03 zář 2014 12:07
od Thooty
# AdwCleaner v3.309 - Report created 03/09/2014 at 13:04:44
# Updated 02/09/2014 by Xplode
# Operating System : Windows 8.1 Pro (64 bits)
# Username : Ultimate - ULTIMATE-PC
# Running from : C:\Users\Ultimate\Desktop\adwcleaner_3.309.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Users\Ultimate\AppData\Roaming\Mozilla\Firefox\Profiles\3e97d50y.default\invalidprefs.js

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\anchorfree
Key Deleted : HKCU\Software\Orbit
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17239


-\\ Mozilla Firefox v29.0 (cs)

[ File : C:\Users\Ultimate\AppData\Roaming\Mozilla\Firefox\Profiles\3e97d50y.default\prefs.js ]


-\\ Google Chrome v38.0.2125.24

[ File : C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R2].txt - [1386 octets] - [07/07/2014 15:31:24]
AdwCleaner[R3].txt - [1459 octets] - [03/09/2014 13:02:31]
AdwCleaner[S1].txt - [1231 octets] - [03/09/2014 13:04:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1291 octets] ##########

Re: Kontrola logu

Napsal: 03 zář 2014 17:03
od Rudy
Dejte nový log RSIT.

Re: Kontrola logu

Napsal: 04 zář 2014 12:21
od Thooty
Logfile of random's system information tool 1.10 (written by random/random)
Run by Ultimate at 2014-09-04 13:11:56
Microsoft Windows 8.1 Pro
System drive C: has 10 GB (17%) free of 57 GB
Total RAM: 4044 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:11:57, on 4. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe
C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
C:\Program Files\trend micro\Ultimate.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FastAccess Web Alert] D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe
O4 - HKLM\..\Run: [Live! Central 3] "D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe" /mode2
O4 - HKLM\..\Run: [AdobeCEPServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [reg_svr] "C:\Windows\SysWoW64\regsvr32.exe" /s "C:\Users\Ultimate\AppData\Roaming\gleam\nvm.dll"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_F35B4131FD575AA3DE87A46A5D1B0D6F] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Bloody2] "C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe" Minimum
O4 - HKCU\..\Run: [SandboxieControl] "D:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - Startup: Voicemeeter (VB-Audio).LNK = C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office15\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C104FC3-9622-4F11-A4F5-369B7C7CC98D}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECA9AD42-81CA-4A95-BEEA-5056853B8B19}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: prio32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Forge Client Service (ForgeClientService) - Unknown owner - D:\Program Files\Forge\ForgeClientService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - The OpenVPN Project - D:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Prio Service (prio_svc) - Unknown owner - D:\Program Files\Prio\prio_svc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - Sandboxie Holdings, LLC - D:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Service KMSELDI - Unknown owner - D:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StartMenu8 Service (StartMenuService) - IObit - C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10402 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"dwm.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"D:\Program Files\Sandboxie\SbieSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskhostex.exe
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe"
dashost.exe {dfdc9e8b-5466-4676-8072c78e39279312}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
taskeng.exe {8CF81035-D11B-44F4-82C2-2EE83EC33BBB}
"D:\Program Files\Forge\ForgeClientService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"D:\Program Files\Prio\prio_svc.exe"
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe" Service
"C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe" /HotCorners
C:\Windows\system32\wbem\wmiprvse.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22d2b1e1-09d7-4fbd-874d-777c9fa10b9b 0
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
"C:\Windows\SysWOW64\regsvr32.exe" /s "C:\Users\Ultimate\AppData\Roaming\gleam\nvm.dll"
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe" -Embedding
"C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe" Minimum

C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}

"C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5480.0.1292342257\213814103" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16,44 --gpu-vendor-id=0x10de --gpu-device-id=0x11c0 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.4052 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.1.1894876001\1338699048" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.3.1594078818\290402350" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.4.37256854\316885148" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.5.300894232\532123303" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.6.84900630\1028877692" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.7.2084287127\1401179322" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.8.1867258495\1452101931" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.9.1902117306\1975546867" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.10.781156899\1843640338" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/BetaBookmarksIndexURLsControl_R2/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="5480.11.296715890\852625283" /prefetch:673131151
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe -Embedding
"C:\Users\Ultimate\Desktop\RSITx64.exe"
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf8a715b278e1a.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Ultimate\AppData\Roaming\Mozilla\Firefox\Profiles\3e97d50y.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=D:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


C:\Users\Ultimate\AppData\Roaming\Mozilla\Firefox\Profiles\3e97d50y.default\extensions\
staged

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-16 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-16 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-08-09 1283136]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-08-09 2403288]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-05-14 7575768]
"Cm108Sound"=C:\Windows\syswow64\RunDll32.exe [2013-08-22 49664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=D:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-08-01 3673696]
"reg_svr"=C:\Windows\SysWoW64\regsvr32.exe [2013-08-22 17408]
"GoogleChromeAutoLaunch_F35B4131FD575AA3DE87A46A5D1B0D6F"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-09-03 911176]
"Bloody2"=C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe [2014-08-14 13965312]
"SandboxieControl"=D:\Program Files\Sandboxie\SbieCtrl.exe [2014-05-29 784392]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=D:\Program Files\QuickTime\QTTask.exe [2013-05-01 421888]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"FastAccess Web Alert"=D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe [2011-07-11 2033648]
"Live! Central 3"=D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe [2013-08-15 461312]
"AdobeCEPServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [2013-03-13 1039248]

C:\Users\Ultimate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Voicemeeter (VB-Audio).LNK - C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="prio.dll"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"VIDC.FPS1"=frapsv64.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"vidc.pDAD"=prodad-codec.dll
"MSVideo8"=VfWWDM32.dll
"midi8"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"VIDC.LAGS"=lagarith.dll
"msacm.lameacm"=LameACM.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave8"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"midi9"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-04 13:11:56 ----D---- C:\rsit
2014-09-01 01:50:56 ----A---- C:\Users\Ultimate\AppData\Roaming\Recorder.ini
2014-08-31 00:15:43 ----D---- C:\Windows\LastGood.Tmp
2014-08-31 00:15:40 ----A---- C:\Windows\system32\drivers\vbaudio_vmvaio64_win7.sys
2014-08-31 00:14:31 ----N---- C:\Windows\Vmix108.dll
2014-08-31 00:14:31 ----N---- C:\Windows\SYSWOW64\cmpa108.dll
2014-08-31 00:14:31 ----N---- C:\Windows\SYSWOW64\CM108.dll
2014-08-31 00:13:19 ----D---- C:\Windows\SYSWOW64\RTCOM
2014-08-31 00:13:19 ----D---- C:\Program Files\Realtek
2014-08-31 00:13:04 ----A---- C:\Windows\system32\YamahaAE.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\WavesGUILib64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tossaeapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\toseaeapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tosasfapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tosade.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tepeqapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tadefxapo264.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tadefxapo.dll
2014-08-31 00:13:03 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SStudio.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSWOW64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSTSX64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSTSH64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSHP64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\sltech64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\slprp64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\slcnt64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\sl3apo64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFSS_APO.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFNHK64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFCOM64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFAPO64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtPgEx64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtkCfg64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtkApi64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEEP64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEEL64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEEG64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEED64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtDataProc64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTCOM64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2014-08-31 00:13:01 ----A---- C:\Windows\system32\RP3DHT64.dll
2014-08-31 00:13:01 ----A---- C:\Windows\system32\RP3DAA64.dll
2014-08-31 00:13:01 ----A---- C:\Windows\system32\RltkAPO64.dll
2014-08-31 00:13:01 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2014-08-31 00:13:00 ----A---- C:\Windows\system32\RCoRes64.dat
2014-08-31 00:13:00 ----A---- C:\Windows\system32\RCoInstII64.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEP64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEL64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEG64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EED64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEA64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\NAHIMICAPOSettingsIPC.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\MISS_APO.dll
2014-08-31 00:12:58 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2014-08-31 00:12:58 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2014-08-31 00:12:58 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2014-08-31 00:12:57 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2014-08-31 00:12:57 ----A---- C:\Windows\system32\MaxxAudioVnN64.dll
2014-08-31 00:12:57 ----A---- C:\Windows\system32\MaxxAudioVnA64.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-08-31 00:12:55 ----A---- C:\Windows\SYSWOW64\MaxxAudioAPOShell.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\KAAPORT64.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2014-08-31 00:12:54 ----A---- C:\Windows\system32\FMAPO64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPP64A.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPO64A.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPD64A.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPA64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\audioLibVc.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\AERTAR64.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\AERTAC64.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2014-08-31 00:10:07 ----A---- C:\Windows\system32\drivers\CM10864.sys
2014-08-30 20:01:07 ----D---- C:\ProgramData\Windows App Certification Kit
2014-08-30 20:00:58 ----D---- C:\Program Files (x86)\Microsoft SDKs
2014-08-30 20:00:55 ----D---- C:\Program Files\Application Verifier
2014-08-30 20:00:55 ----D---- C:\Program Files (x86)\Application Verifier
2014-08-28 13:19:28 ----A---- C:\Windows\system32\win32k.sys
2014-08-24 23:15:53 ----RD---- C:\Sandbox
2014-08-24 23:11:05 ----A---- C:\Windows\Sandboxie.ini
2014-08-19 14:49:02 ----A---- C:\Windows\system32\RtNicProp64.dll
2014-08-19 14:49:02 ----A---- C:\Windows\system32\drivers\Rt630x64.sys
2014-08-16 23:07:35 ----A---- C:\Windows\unins000.exe
2014-08-13 23:56:38 ----D---- C:\Program Files\TAP-Windows
2014-08-13 12:54:58 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2014-08-13 12:54:57 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2014-08-13 12:54:57 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-13 12:54:57 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 12:54:56 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2014-08-13 12:54:56 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-08-13 12:54:56 ----A---- C:\Windows\system32\mstscax.dll
2014-08-13 12:54:55 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\twinui.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\SettingsHandlers.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\d3d10warp.dll
2014-08-13 12:54:54 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2014-08-13 12:54:54 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\wlansvc.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\mfcore.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\gpsvc.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-08-13 12:54:54 ----A---- C:\Windows\system32\authui.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\actxprxy.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\twinui.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\workfolderssvc.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-08-13 12:54:53 ----A---- C:\Windows\system32\Windows.Media.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\SRH.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\mfplat.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\localspl.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\drivers\srv.sys
2014-08-13 12:54:52 ----AC---- C:\Windows\system32\drivers\spaceport.sys
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\SRH.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\printui.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\mispace.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\XpsPrint.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\wuaueng.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\wlanmsm.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\srvsvc.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\printui.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\netcfgx.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\mispace.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\dxgi.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\netio.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\AppxPackaging.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\aclui.dll
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\volsnap.sys
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\USBHUB3.SYS
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\usbccgp.sys
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\SHCore.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\mftranscode.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\AppxPackaging.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\aclui.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wuapi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wsecedit.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\WSDMon.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wisp.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\winresume.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\winload.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\WebClnt.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\usbmon.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\uDWM.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\storagewmi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\spoolsv.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\SHCore.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\puiobj.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\mftranscode.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\mfreadwrite.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\lsasrv.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\defragsvc.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\comdlg32.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\clusapi.dll
2014-08-13 12:54:50 ----AC---- C:\Windows\system32\drivers\usbhub.sys
2014-08-13 12:54:50 ----AC---- C:\Windows\system32\drivers\hdaudbus.sys
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wsecedit.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wlanapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wisp.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\winmmbase.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\Display.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\clusapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\AppxSip.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\wucltux.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WSShared.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\wpdbusenum.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WorkFoldersGPExt.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\winmmbase.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\winmm.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\Windows.Networking.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\win32spl.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WiFiDisplay.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\VAN.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\user32.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\twinapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\SndVol.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\SettingSync.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\rdpcorets.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\profsvc.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\prnntfy.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\osk.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\mfps.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\httpprxm.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\GdiPlus.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\dwmcore.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\dwmapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\nwifi.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\NdisImPlatform.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\msgpioclx.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\bridge.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\Display.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\DafPrintProvider.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\conhost.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\bcryptprimitives.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\AppxSip.dll
2014-08-13 12:54:49 ----AC---- C:\Windows\system32\drivers\pci.sys
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\winmm.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\Windows.Networking.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\VAN.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\user32.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\SndVol.exe
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\SettingSync.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\rsaenh.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\puiapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\prnntfy.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\KBDRUM.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\iasnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\gpedit.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wwanconn.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wups2.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wups.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wuauclt.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wshbth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\WorkFoldersShell.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wlansvcpal.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wlanapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wcmcsp.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\stobject.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\schannel.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\SearchFolder.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\rsaenh.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\puiapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\PrintDialogs.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\ppcsnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\pmcsnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRUM.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\iasnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\gpedit.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\drivers\ks.sys
2014-08-13 12:54:49 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 12:54:49 ----A---- C:\Windows\system32\Defrag.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\dab.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\browser.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\AppxSysprep.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\adhsvc.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\ActionCenter.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\PrintDialogs.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDTT102.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wwanmm.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wudriver.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wlansec.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\SndVolSSO.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\rdpudd.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\KBDTT102.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\system32\compstui.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\certcli.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\BluetoothApis.dll
2014-08-13 12:54:38 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-13 12:54:38 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-08-13 12:54:34 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\msi.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\consent.exe
2014-08-13 12:54:34 ----A---- C:\Windows\system32\aepdu.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\aeinv.dll
2014-08-13 12:54:34 ----A---- C:\Windows\explorer.exe
2014-08-13 12:54:33 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\WpcWebSync.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\WpcMon.exe
2014-08-13 12:54:33 ----A---- C:\Windows\system32\Wpc.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\MrmCoreR.dll
2014-08-13 12:54:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-13 12:54:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-08-13 12:54:27 ----A---- C:\Windows\system32\MDMAgent.exe
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\iernonce.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\urlmon.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-13 12:54:24 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-08-13 12:54:24 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-13 12:54:24 ----A---- C:\Windows\system32\iesetup.dll
2014-08-13 12:54:24 ----A---- C:\Windows\system32\iertutil.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\jscript9.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-13 12:54:23 ----A---- C:\Windows\system32\ieframe.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\wininet.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\msrating.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\mshtml.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\vbscript.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-13 12:52:47 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-13 12:52:47 ----A---- C:\Windows\system32\gdi32.dll
2014-08-11 14:43:09 ----D---- C:\Users\Ultimate\AppData\Roaming\FileZilla
2014-08-11 01:32:32 ----D---- C:\ProgramData\shimgen
2014-08-11 01:29:00 ----D---- C:\Users\Ultimate\AppData\Roaming\NuGet
2014-08-11 01:28:07 ----D---- C:\Chocolatey
2014-08-10 22:05:25 ----D---- C:\Users\Ultimate\AppData\Roaming\Atom
2014-08-08 14:59:12 ----D---- C:\Users\Ultimate\AppData\Roaming\Opera Software
2014-08-07 13:58:21 ----D---- C:\Program Files\CyberGhost 5

======List of files/folders modified in the last 1 month======

2014-09-04 13:11:57 ----D---- C:\Program Files\trend micro
2014-09-04 13:11:34 ----D---- C:\Windows\Temp
2014-09-04 13:10:20 ----D---- C:\Windows\system32\Tasks
2014-09-04 13:10:11 ----RD---- C:\Windows\System32
2014-09-04 13:10:04 ----D---- C:\ProgramData\NVIDIA
2014-09-04 02:31:48 ----D---- C:\Users\Ultimate\AppData\Roaming\vlc
2014-09-04 02:00:00 ----D---- C:\Windows\system32\sru
2014-09-03 22:59:01 ----D---- C:\Windows\system32\logs
2014-09-03 22:29:24 ----D---- C:\Users\Ultimate\AppData\Roaming\uTorrent
2014-09-03 20:30:11 ----D---- C:\Windows\Inf
2014-09-03 19:59:23 ----SHD---- C:\System Volume Information
2014-09-03 19:56:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-03 18:59:18 ----D---- C:\Windows\Microsoft.NET
2014-09-03 13:04:53 ----D---- C:\AdwCleaner
2014-08-31 23:35:48 ----D---- C:\Users\Ultimate\AppData\Roaming\Skype
2014-08-31 19:58:26 ----D---- C:\Users\Ultimate\AppData\Roaming\Audacity
2014-08-31 19:45:21 ----D---- C:\Windows\AppReadiness
2014-08-31 00:19:56 ----D---- C:\Program Files\VB
2014-08-31 00:19:55 ----D---- C:\Program Files (x86)\VB
2014-08-31 00:16:04 ----D---- C:\Windows
2014-08-31 00:15:43 ----D---- C:\Windows\system32\DriverStore
2014-08-31 00:15:43 ----D---- C:\Windows\system32\drivers
2014-08-31 00:14:33 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-08-31 00:14:31 ----D---- C:\Windows\SysWOW64
2014-08-31 00:14:30 ----D---- C:\Windows\System
2014-08-31 00:13:29 ----HD---- C:\Program Files (x86)\Temp
2014-08-31 00:13:19 ----RD---- C:\Program Files
2014-08-30 20:06:53 ----D---- C:\Windows\Minidump
2014-08-30 20:01:12 ----SHD---- C:\Windows\Installer
2014-08-30 20:01:12 ----SHD---- C:\Config.Msi
2014-08-30 20:01:07 ----HD---- C:\ProgramData
2014-08-30 20:00:58 ----RD---- C:\Program Files (x86)
2014-08-30 20:00:04 ----D---- C:\Program Files (x86)\Common Files
2014-08-30 19:59:57 ----D---- C:\ProgramData\Package Cache
2014-08-30 15:39:34 ----HD---- C:\Program Files\WindowsApps
2014-08-30 14:25:49 ----D---- C:\Users\Ultimate\AppData\Roaming\Notepad++
2014-08-29 11:12:57 ----D---- C:\Windows\debug
2014-08-29 11:06:19 ----D---- C:\Windows\system32\config
2014-08-29 11:02:56 ----D---- C:\Windows\WinSxS
2014-08-29 01:31:27 ----D---- C:\Windows\SoftwareDistribution
2014-08-29 01:11:20 ----D---- C:\Users\Ultimate\AppData\Roaming\DAEMON Tools Lite
2014-08-29 01:11:18 ----D---- C:\Windows\Logs
2014-08-29 01:10:51 ----D---- C:\Program Files\CCleaner
2014-08-28 16:38:46 ----D---- C:\Windows\CbsTemp
2014-08-27 20:46:05 ----D---- C:\Users\Ultimate\AppData\Roaming\npm-cache
2014-08-25 13:19:17 ----D---- C:\Windows\system32\wdi
2014-08-24 19:23:49 ----D---- C:\Program Files\NVIDIA Corporation
2014-08-24 01:33:29 ----D---- C:\Windows\system32\catroot2
2014-08-20 01:08:18 ----D---- C:\Windows\system32\NDF
2014-08-19 17:43:48 ----D---- C:\Program Files (x86)\Bloody5
2014-08-19 14:49:24 ----D---- C:\Windows\system32\catroot
2014-08-16 01:45:59 ----RSD---- C:\Windows\Fonts
2014-08-14 16:54:17 ----RSD---- C:\Windows\assembly
2014-08-13 22:11:00 ----D---- C:\Windows\rescache
2014-08-13 13:18:58 ----SHD---- C:\Boot
2014-08-13 13:18:11 ----RD---- C:\Windows\ToastData
2014-08-13 13:18:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-13 13:18:11 ----D---- C:\Windows\system32\migration
2014-08-13 13:18:11 ----D---- C:\Windows\system32\cs-CZ
2014-08-13 13:18:11 ----D---- C:\Windows\PolicyDefinitions
2014-08-13 13:18:11 ----D---- C:\Program Files\Internet Explorer
2014-08-13 13:18:11 ----D---- C:\Program Files (x86)\Internet Explorer
2014-08-13 13:18:10 ----RD---- C:\Windows\ImmersiveControlPanel
2014-08-13 13:18:10 ----D---- C:\Windows\WinStore
2014-08-13 13:18:10 ----D---- C:\Windows\SYSWOW64\wbem
2014-08-13 13:18:10 ----D---- C:\Windows\SYSWOW64\setup
2014-08-13 13:18:10 ----D---- C:\Windows\system32\wbem
2014-08-13 13:18:10 ----D---- C:\Windows\system32\setup
2014-08-13 13:18:10 ----D---- C:\Windows\system32\oobe
2014-08-13 13:18:10 ----D---- C:\Windows\system32\drivers\cs-CZ
2014-08-13 13:18:10 ----D---- C:\Windows\system32\Boot
2014-08-13 13:18:10 ----D---- C:\Program Files\Windows Journal
2014-08-13 13:18:09 ----D---- C:\Windows\SYSWOW64\migration
2014-08-13 13:18:09 ----D---- C:\Windows\SYSWOW64\InputMethod
2014-08-13 13:18:09 ----D---- C:\Windows\apppatch
2014-08-13 13:02:18 ----D---- C:\Windows\system32\MRT
2014-08-13 13:01:10 ----A---- C:\Windows\system32\MRT.exe
2014-08-13 13:00:29 ----SD---- C:\Windows\system32\CompatTel
2014-08-11 22:33:42 ----SD---- C:\ProgramData\Microsoft
2014-08-11 22:33:39 ----D---- C:\Windows\ShellNew
2014-08-09 14:33:01 ----D---- C:\Users\Ultimate\AppData\Roaming\gleam
2014-08-09 14:28:45 ----D---- C:\Users\Ultimate\AppData\Roaming\Identities
2014-08-09 02:22:16 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-08-09 02:22:16 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-08-09 02:22:05 ----A---- C:\Windows\system32\nvspcap64.dll
2014-08-09 02:22:05 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-08-07 18:54:18 ----D---- C:\ProgramData\Skype
2014-08-06 23:45:17 ----D---- C:\Users\Ultimate\AppData\Roaming\Security_File
2014-08-05 18:02:19 ----D---- C:\Program Files (x86)\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2013-09-17 239296]
R1 dtsoftbus01;@oem20.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2013-10-12 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R2 Dokan;Dokan; \??\C:\WINDOWS\system32\drivers\dokan.sys [2011-01-10 120408]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2013-08-22 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-05-14 3962840]
R3 MEIx64;@oem11.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\HECIx64.sys [2012-07-17 62784]
R3 NVHDA;@oem9.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-28 197408]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2014-07-02 12866008]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-08-09 20440]
R3 nvvad_WaveExtensible;@oem73.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 RTL8168;@oem91.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-08-19 873688]
R3 SbieDrv;SbieDrv; \??\D:\Program Files\Sandboxie\SbieDrv.sys [2014-05-29 185352]
R3 ScreamBAudioSvc;@oem21.inf,%sbee_audio.SvcDesc%;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys [2010-07-01 38992]
R3 tap0901;@oem86.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2014-04-08 27136]
R3 USBPNPA;@oem54.inf,%CM108.SvcDesc%;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM10864.sys [2014-03-13 4333568]
R3 VBAudioVACMME;@oem37.inf,%DeviceName% (WDM);VB-Audio Virtual Cable (WDM); C:\Windows\system32\DRIVERS\vbaudio_cable64_win7.sys [2013-07-11 41192]
R3 VBAudioVMVAIOMME;@oem67.inf,%DeviceName% (WDM);VB-Audio VoiceMeeter VAIO (WDM); C:\Windows\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [2014-08-31 41192]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\Windows\system32\DRIVERS\CtClsFlt.sys [2011-09-05 178176]
S3 dg_ssudbus;@oem42.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-08-20 103576]
S3 EuMusDesignVirtualAudioCableWdm;@oem36.inf,%DeviceName% (WDM);Virtual Audio Cable (WDM); C:\Windows\system32\DRIVERS\vrtaucbl.sys [2014-01-01 90624]
S3 LHidFilt;@oem31.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2013-05-23 76568]
S3 LMouFilt;@oem31.inf,%LMouFilt.SvcDesc%;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2013-05-23 59160]
S3 LUsbFilt;@oem27.inf,%FltDisplayName%;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2013-05-23 40728]
S3 ptun0901;@oem90.inf,%DeviceDescription%;TAP Adapter V9 for Private Tunnel; C:\Windows\system32\DRIVERS\ptun0901.sys [2014-04-24 27136]
S3 RTL8167;@oem2.inf,%rtl8167.Service.DispName%;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-04-10 849992]
S3 tap0901_openvpn_accl;@oem49.inf,%DeviceDescription%;TAP-Win32 Adapter V9 for OpenVPN Accelerator; C:\Windows\system32\DRIVERS\tap0901_openvpn_accl.sys [2012-08-21 37912]
S3 taphss6;@oem87.inf,%DeviceDescription%;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2014-05-17 42184]
S3 tapoas;@oem72.inf,%DeviceDescription%;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2012-07-15 30720]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 DokanMounter;DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [2011-01-10 14848]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 ForgeClientService;Forge Client Service; D:\Program Files\Forge\ForgeClientService.exe [2014-07-11 45320]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-08-09 1720792]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-08-09 18973144]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-07-02 935368]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-06-13 76888]
R2 prio_svc;Prio Service; D:\Program Files\Prio\prio_svc.exe [2012-11-08 12656]
R2 SbieSvc;Sandboxie Service; D:\Program Files\Sandboxie\SbieSvc.exe [2014-05-29 174088]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
R2 StartMenuService;StartMenu8 Service; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [2014-06-06 72992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-11 116648]
S2 Service KMSELDI;Service KMSELDI; D:\Program Files\KMSpico\Service_KMS.exe [2013-11-11 685568]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-24 262320]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2013-10-13 49152]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; D:\Program Files\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-02-20 142336]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-11 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-04-22 119408]
S3 OpenVPNService;OpenVPN Service; D:\Program Files\OpenVPN\bin\openvpnserv.exe [2014-08-07 37176]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S3 Te.Service;Te.Service; D:\Program Files\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]

-----------------EOF-----------------

Re: Kontrola logu

Napsal: 04 zář 2014 17:12
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf8a715b278e1a.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]

a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: Kontrola logu

Napsal: 08 zář 2014 13:09
od Thooty
Logfile of random's system information tool 1.10 (written by random/random)
Run by Ultimate at 2014-09-08 13:59:38
Microsoft Windows 8.1 Pro
System drive C: has 11 GB (18%) free of 57 GB
Total RAM: 4044 MB (48% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:59:39, on 8. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe
C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
C:\Program Files\trend micro\Ultimate.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FastAccess Web Alert] D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe
O4 - HKLM\..\Run: [Live! Central 3] "D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe" /mode2
O4 - HKLM\..\Run: [AdobeCEPServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [reg_svr] "C:\Windows\SysWoW64\regsvr32.exe" /s "C:\Users\Ultimate\AppData\Roaming\gleam\nvm.dll"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_F35B4131FD575AA3DE87A46A5D1B0D6F] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Bloody2] "C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe" Minimum
O4 - HKCU\..\Run: [SandboxieControl] "D:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - Startup: Voicemeeter (VB-Audio).LNK = C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office15\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C104FC3-9622-4F11-A4F5-369B7C7CC98D}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECA9AD42-81CA-4A95-BEEA-5056853B8B19}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: prio32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Forge Client Service (ForgeClientService) - Unknown owner - D:\Program Files\Forge\ForgeClientService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - The OpenVPN Project - D:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Prio Service (prio_svc) - Unknown owner - D:\Program Files\Prio\prio_svc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - Sandboxie Holdings, LLC - D:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Service KMSELDI - Unknown owner - D:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StartMenu8 Service (StartMenuService) - IObit - C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10402 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"dwm.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"D:\Program Files\Sandboxie\SbieSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
taskhostex.exe
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe"
dashost.exe {83943b53-33ee-4578-994daa48a273d3d4}
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
taskeng.exe {B1D9BBAF-CEA0-421B-AC33-56FDC940F7D6}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"D:\Program Files\Forge\ForgeClientService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"D:\Program Files\Prio\prio_svc.exe"
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22d2b1e1-09d7-4fbd-874d-777c9fa10b9b 0
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe"
"C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe" /HotCorners
"C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
"C:\Windows\SysWOW64\regsvr32.exe" /s "C:\Users\Ultimate\AppData\Roaming\gleam\nvm.dll"
"C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe" Minimum
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe" -Embedding

"C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3416.0.1652305758\191536247" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16,44 --gpu-vendor-id=0x10de --gpu-device-id=0x11c0 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.4052 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.1.1003831373\85498359" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.3.406791877\699179035" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.4.1376571903\330368472" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.5.1099006379\1821712183" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.6.1518070142\1102013493" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.7.1883744793\374314570" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.8.6190588\2038492470" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.9.1138001344\12001540" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.10.263839587\1672776866" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/ML Kodachrome beta/EmbeddedSearch/Group3 dev:r1 prefetch_results:1 reuse_instant_search_base_page:1 prerender_instant_url_on_omnibox_focus:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/beta=3a:LocalPredictor=Enabled:SkipHTTPS=Enabled:SideEffectFreeWhitelist=Enabled:MaxConcurrentPrerenders=3:PrerenderPriorityHalfLifeTimeSeconds=30:PrerenderQueryPrerenderService=Enabled:PrerenderServiceFetchTimeoutMs=5000:SkipPrerenderLocalCandidates=Enabled:PrerenderAlwaysControl=Enabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledHttpOnly/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_88/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --channel="3416.11.2126026462\1318025262" /prefetch:673131151

"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Ultimate\Desktop\RSITx64.exe"

C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe -Embedding

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Ultimate\AppData\Roaming\Mozilla\Firefox\Profiles\3e97d50y.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=D:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.179 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-16 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-16 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-08-09 1283136]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-08-09 2403288]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-05-14 7575768]
"Cm108Sound"=C:\Windows\syswow64\RunDll32.exe [2013-08-22 49664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=D:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-08-01 3673696]
"reg_svr"=C:\Windows\SysWoW64\regsvr32.exe [2013-08-22 17408]
"GoogleChromeAutoLaunch_F35B4131FD575AA3DE87A46A5D1B0D6F"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-09-03 911176]
"Bloody2"=C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe [2014-08-14 13965312]
"SandboxieControl"=D:\Program Files\Sandboxie\SbieCtrl.exe [2014-05-29 784392]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=D:\Program Files\QuickTime\QTTask.exe [2013-05-01 421888]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"FastAccess Web Alert"=D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FATRY.exe [2011-07-11 2033648]
"Live! Central 3"=D:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe [2013-08-15 461312]
"AdobeCEPServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [2013-03-13 1039248]

C:\Users\Ultimate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Voicemeeter (VB-Audio).LNK - C:\Program Files (x86)\VB\Voicemeeter\voicemeeter.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="prio.dll"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"VIDC.FPS1"=frapsv64.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"vidc.pDAD"=prodad-codec.dll
"MSVideo8"=VfWWDM32.dll
"midi8"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"VIDC.LAGS"=lagarith.dll
"msacm.lameacm"=LameACM.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave8"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"midi9"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-08 13:59:38 ----D---- C:\rsit
2014-09-08 13:55:24 ----D---- C:\_OTM
2014-09-01 01:50:56 ----A---- C:\Users\Ultimate\AppData\Roaming\Recorder.ini
2014-08-31 00:15:40 ----A---- C:\Windows\system32\drivers\vbaudio_vmvaio64_win7.sys
2014-08-31 00:14:31 ----N---- C:\Windows\Vmix108.dll
2014-08-31 00:14:31 ----N---- C:\Windows\SYSWOW64\cmpa108.dll
2014-08-31 00:14:31 ----N---- C:\Windows\SYSWOW64\CM108.dll
2014-08-31 00:13:19 ----D---- C:\Windows\SYSWOW64\RTCOM
2014-08-31 00:13:19 ----D---- C:\Program Files\Realtek
2014-08-31 00:13:04 ----A---- C:\Windows\system32\YamahaAE.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\WavesGUILib64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tossaeapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\toseaeapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tosasfapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tosade.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tepeqapo64.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tadefxapo264.dll
2014-08-31 00:13:04 ----A---- C:\Windows\system32\tadefxapo.dll
2014-08-31 00:13:03 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SStudio.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSWOW64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSTSX64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSTSH64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SRSHP64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\sltech64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\slprp64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\slcnt64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\sl3apo64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFSS_APO.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFNHK64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFCOM64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\SFAPO64.dll
2014-08-31 00:13:03 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtPgEx64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtkCfg64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtkApi64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEEP64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEEL64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEEG64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTEED64A.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RtDataProc64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\RTCOM64.dll
2014-08-31 00:13:02 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2014-08-31 00:13:01 ----A---- C:\Windows\system32\RP3DHT64.dll
2014-08-31 00:13:01 ----A---- C:\Windows\system32\RP3DAA64.dll
2014-08-31 00:13:01 ----A---- C:\Windows\system32\RltkAPO64.dll
2014-08-31 00:13:01 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2014-08-31 00:13:00 ----A---- C:\Windows\system32\RCoRes64.dat
2014-08-31 00:13:00 ----A---- C:\Windows\system32\RCoInstII64.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEP64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEL64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEG64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EED64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\R4EEA64A.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\NAHIMICAPOSettingsIPC.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2014-08-31 00:12:59 ----A---- C:\Windows\system32\MISS_APO.dll
2014-08-31 00:12:58 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2014-08-31 00:12:58 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2014-08-31 00:12:58 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2014-08-31 00:12:57 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2014-08-31 00:12:57 ----A---- C:\Windows\system32\MaxxAudioVnN64.dll
2014-08-31 00:12:57 ----A---- C:\Windows\system32\MaxxAudioVnA64.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioRealtek264.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2014-08-31 00:12:56 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-08-31 00:12:55 ----A---- C:\Windows\SYSWOW64\MaxxAudioAPOShell.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\KAAPORT64.dll
2014-08-31 00:12:55 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2014-08-31 00:12:54 ----A---- C:\Windows\system32\FMAPO64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPP64A.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPO64A.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPD64A.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\DDPA64.dll
2014-08-31 00:12:53 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\audioLibVc.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\AERTAR64.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\AERTAC64.dll
2014-08-31 00:12:52 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2014-08-31 00:10:07 ----A---- C:\Windows\system32\drivers\CM10864.sys
2014-08-30 20:01:07 ----D---- C:\ProgramData\Windows App Certification Kit
2014-08-30 20:00:58 ----D---- C:\Program Files (x86)\Microsoft SDKs
2014-08-30 20:00:55 ----D---- C:\Program Files\Application Verifier
2014-08-30 20:00:55 ----D---- C:\Program Files (x86)\Application Verifier
2014-08-28 13:19:28 ----A---- C:\Windows\system32\win32k.sys
2014-08-24 23:15:53 ----RD---- C:\Sandbox
2014-08-24 23:11:05 ----A---- C:\Windows\Sandboxie.ini
2014-08-19 14:49:02 ----A---- C:\Windows\system32\RtNicProp64.dll
2014-08-19 14:49:02 ----A---- C:\Windows\system32\drivers\Rt630x64.sys
2014-08-16 23:07:35 ----A---- C:\Windows\unins000.exe
2014-08-13 23:56:38 ----D---- C:\Program Files\TAP-Windows
2014-08-13 12:54:58 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2014-08-13 12:54:57 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2014-08-13 12:54:57 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-13 12:54:57 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 12:54:56 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2014-08-13 12:54:56 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-08-13 12:54:56 ----A---- C:\Windows\system32\mstscax.dll
2014-08-13 12:54:55 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\twinui.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\SettingsHandlers.dll
2014-08-13 12:54:55 ----A---- C:\Windows\system32\d3d10warp.dll
2014-08-13 12:54:54 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2014-08-13 12:54:54 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\wlansvc.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\mfcore.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\gpsvc.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-08-13 12:54:54 ----A---- C:\Windows\system32\authui.dll
2014-08-13 12:54:54 ----A---- C:\Windows\system32\actxprxy.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\twinui.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2014-08-13 12:54:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\workfolderssvc.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-08-13 12:54:53 ----A---- C:\Windows\system32\Windows.Media.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\SRH.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\mfplat.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\localspl.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-08-13 12:54:53 ----A---- C:\Windows\system32\drivers\srv.sys
2014-08-13 12:54:52 ----AC---- C:\Windows\system32\drivers\spaceport.sys
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\SRH.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\printui.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\netcfgx.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\mispace.dll
2014-08-13 12:54:52 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\XpsPrint.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\wuaueng.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\wlanmsm.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\srvsvc.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\printui.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\netcfgx.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\mispace.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\dxgi.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\drivers\netio.sys
2014-08-13 12:54:52 ----A---- C:\Windows\system32\AppxPackaging.dll
2014-08-13 12:54:52 ----A---- C:\Windows\system32\aclui.dll
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\volsnap.sys
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\USBHUB3.SYS
2014-08-13 12:54:51 ----AC---- C:\Windows\system32\drivers\usbccgp.sys
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\SHCore.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\mftranscode.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\AppxPackaging.dll
2014-08-13 12:54:51 ----A---- C:\Windows\SYSWOW64\aclui.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wuapi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wsecedit.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\WSDMon.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\wisp.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\winresume.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\winload.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\WebClnt.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\usbmon.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\uDWM.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\storagewmi.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\spoolsv.exe
2014-08-13 12:54:51 ----A---- C:\Windows\system32\SHCore.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\puiobj.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\mftranscode.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\mfreadwrite.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\lsasrv.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\defragsvc.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\comdlg32.dll
2014-08-13 12:54:51 ----A---- C:\Windows\system32\clusapi.dll
2014-08-13 12:54:50 ----AC---- C:\Windows\system32\drivers\usbhub.sys
2014-08-13 12:54:50 ----AC---- C:\Windows\system32\drivers\hdaudbus.sys
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wsecedit.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wlanapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\wisp.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\winmmbase.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\storagewmi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\Display.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\clusapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2014-08-13 12:54:50 ----A---- C:\Windows\SYSWOW64\AppxSip.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\wucltux.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WSShared.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\wpdbusenum.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WorkFoldersGPExt.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\winmmbase.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\winmm.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\Windows.Networking.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\win32spl.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\WiFiDisplay.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\VAN.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\user32.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\twinapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\SndVol.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\SettingSync.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\rdvidcrl.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\rdpcorets.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\profsvc.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\prnntfy.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\osk.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\mfps.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\httpprxm.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\GdiPlus.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\dwmcore.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\dwmapi.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\nwifi.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\NdisImPlatform.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\ndis.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\msgpioclx.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\drivers\bridge.sys
2014-08-13 12:54:50 ----A---- C:\Windows\system32\Display.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\DafPrintProvider.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\conhost.exe
2014-08-13 12:54:50 ----A---- C:\Windows\system32\bcryptprimitives.dll
2014-08-13 12:54:50 ----A---- C:\Windows\system32\AppxSip.dll
2014-08-13 12:54:49 ----AC---- C:\Windows\system32\drivers\pci.sys
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\winmm.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\Windows.Networking.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\VAN.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\user32.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\stobject.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\SndVol.exe
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\SettingSync.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\rsaenh.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\puiapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\prnntfy.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\KBDRUM.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\iasnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\gpedit.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2014-08-13 12:54:49 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wwanconn.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wups2.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wups.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wuauclt.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wshbth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\WorkFoldersShell.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wlansvcpal.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wlanapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\wcmcsp.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\stobject.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\schannel.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\SearchFolder.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\rsaenh.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\puiapi.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\PrintDialogs.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\ppcsnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\pmcsnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRUM.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-13 12:54:49 ----A---- C:\Windows\system32\iasnap.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\gpedit.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\drivers\ks.sys
2014-08-13 12:54:49 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 12:54:49 ----A---- C:\Windows\system32\Defrag.exe
2014-08-13 12:54:49 ----A---- C:\Windows\system32\dab.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\browser.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\AppxSysprep.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\adhsvc.dll
2014-08-13 12:54:49 ----A---- C:\Windows\system32\ActionCenter.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\PrintDialogs.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDTT102.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-08-13 12:54:48 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wwanmm.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wudriver.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\wlansec.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\SndVolSSO.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\rdpudd.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\KBDTT102.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 12:54:48 ----A---- C:\Windows\system32\compstui.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\certcli.dll
2014-08-13 12:54:48 ----A---- C:\Windows\system32\BluetoothApis.dll
2014-08-13 12:54:38 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-13 12:54:38 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-13 12:54:34 ----A---- C:\Windows\SYSWOW64\explorer.exe
2014-08-13 12:54:34 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\msi.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\consent.exe
2014-08-13 12:54:34 ----A---- C:\Windows\system32\aepdu.dll
2014-08-13 12:54:34 ----A---- C:\Windows\system32\aeinv.dll
2014-08-13 12:54:34 ----A---- C:\Windows\explorer.exe
2014-08-13 12:54:33 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\WpcWebSync.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\WpcMon.exe
2014-08-13 12:54:33 ----A---- C:\Windows\system32\Wpc.dll
2014-08-13 12:54:33 ----A---- C:\Windows\system32\MrmCoreR.dll
2014-08-13 12:54:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-13 12:54:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-08-13 12:54:27 ----A---- C:\Windows\system32\MDMAgent.exe
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-13 12:54:26 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\iernonce.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 12:54:26 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-08-13 12:54:25 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\urlmon.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-13 12:54:25 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-13 12:54:24 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-08-13 12:54:24 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-13 12:54:24 ----A---- C:\Windows\system32\iesetup.dll
2014-08-13 12:54:24 ----A---- C:\Windows\system32\iertutil.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-08-13 12:54:23 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\jscript9.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-13 12:54:23 ----A---- C:\Windows\system32\ieframe.dll
2014-08-13 12:54:23 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\wininet.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\msrating.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\mshtml.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-13 12:54:22 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-13 12:54:21 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\vbscript.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 12:54:21 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-13 12:52:47 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-13 12:52:47 ----A---- C:\Windows\system32\gdi32.dll
2014-08-11 14:43:09 ----D---- C:\Users\Ultimate\AppData\Roaming\FileZilla
2014-08-11 01:32:32 ----D---- C:\ProgramData\shimgen
2014-08-11 01:29:00 ----D---- C:\Users\Ultimate\AppData\Roaming\NuGet
2014-08-11 01:28:07 ----D---- C:\Chocolatey
2014-08-10 22:05:25 ----D---- C:\Users\Ultimate\AppData\Roaming\Atom

======List of files/folders modified in the last 1 month======

2014-09-08 13:59:39 ----D---- C:\Program Files\trend micro
2014-09-08 13:59:17 ----D---- C:\Windows\Temp
2014-09-08 13:57:09 ----D---- C:\Windows\system32\Tasks
2014-09-08 13:57:06 ----RD---- C:\Windows\System32
2014-09-08 13:57:01 ----D---- C:\ProgramData\NVIDIA
2014-09-08 13:56:42 ----D---- C:\Windows
2014-09-08 13:55:24 ----D---- C:\Windows\Tasks
2014-09-08 13:04:30 ----D---- C:\Windows\Inf
2014-09-08 13:04:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-08 02:02:00 ----D---- C:\Windows\system32\sru
2014-09-08 00:25:58 ----D---- C:\Users\Ultimate\AppData\Roaming\Skype
2014-09-07 19:44:53 ----D---- C:\Windows\AppReadiness
2014-09-07 19:15:24 ----D---- C:\Users\Ultimate\AppData\Roaming\vlc
2014-09-07 17:29:01 ----D---- C:\Windows\system32\logs
2014-09-07 15:50:24 ----D---- C:\Windows\Microsoft.NET
2014-09-05 02:27:05 ----D---- C:\Users\Ultimate\AppData\Roaming\uTorrent
2014-09-04 18:31:43 ----SHD---- C:\System Volume Information
2014-09-03 13:04:53 ----D---- C:\AdwCleaner
2014-08-31 19:58:26 ----D---- C:\Users\Ultimate\AppData\Roaming\Audacity
2014-08-31 00:19:56 ----D---- C:\Program Files\VB
2014-08-31 00:19:55 ----D---- C:\Program Files (x86)\VB
2014-08-31 00:15:43 ----D---- C:\Windows\system32\DriverStore
2014-08-31 00:15:43 ----D---- C:\Windows\system32\drivers
2014-08-31 00:14:33 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-08-31 00:14:31 ----D---- C:\Windows\SysWOW64
2014-08-31 00:14:30 ----D---- C:\Windows\System
2014-08-31 00:13:29 ----HD---- C:\Program Files (x86)\Temp
2014-08-31 00:13:19 ----RD---- C:\Program Files
2014-08-30 20:06:53 ----D---- C:\Windows\Minidump
2014-08-30 20:01:12 ----SHD---- C:\Windows\Installer
2014-08-30 20:01:12 ----SHD---- C:\Config.Msi
2014-08-30 20:01:07 ----HD---- C:\ProgramData
2014-08-30 20:00:58 ----RD---- C:\Program Files (x86)
2014-08-30 20:00:04 ----D---- C:\Program Files (x86)\Common Files
2014-08-30 19:59:57 ----D---- C:\ProgramData\Package Cache
2014-08-30 15:39:34 ----HD---- C:\Program Files\WindowsApps
2014-08-30 14:25:49 ----D---- C:\Users\Ultimate\AppData\Roaming\Notepad++
2014-08-29 11:12:57 ----D---- C:\Windows\debug
2014-08-29 11:06:19 ----D---- C:\Windows\system32\config
2014-08-29 11:02:56 ----D---- C:\Windows\WinSxS
2014-08-29 01:31:27 ----D---- C:\Windows\SoftwareDistribution
2014-08-29 01:11:20 ----D---- C:\Users\Ultimate\AppData\Roaming\DAEMON Tools Lite
2014-08-29 01:11:18 ----D---- C:\Windows\Logs
2014-08-29 01:10:51 ----D---- C:\Program Files\CCleaner
2014-08-28 16:38:46 ----D---- C:\Windows\CbsTemp
2014-08-27 20:46:05 ----D---- C:\Users\Ultimate\AppData\Roaming\npm-cache
2014-08-25 13:19:17 ----D---- C:\Windows\system32\wdi
2014-08-24 19:23:49 ----D---- C:\Program Files\NVIDIA Corporation
2014-08-24 01:33:29 ----D---- C:\Windows\system32\catroot2
2014-08-20 01:08:18 ----D---- C:\Windows\system32\NDF
2014-08-19 17:43:48 ----D---- C:\Program Files (x86)\Bloody5
2014-08-19 14:49:24 ----D---- C:\Windows\system32\catroot
2014-08-16 01:45:59 ----RSD---- C:\Windows\Fonts
2014-08-14 16:54:17 ----RSD---- C:\Windows\assembly
2014-08-13 22:11:00 ----D---- C:\Windows\rescache
2014-08-13 13:18:58 ----SHD---- C:\Boot
2014-08-13 13:18:11 ----RD---- C:\Windows\ToastData
2014-08-13 13:18:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-13 13:18:11 ----D---- C:\Windows\system32\migration
2014-08-13 13:18:11 ----D---- C:\Windows\system32\cs-CZ
2014-08-13 13:18:11 ----D---- C:\Windows\PolicyDefinitions
2014-08-13 13:18:11 ----D---- C:\Program Files\Internet Explorer
2014-08-13 13:18:11 ----D---- C:\Program Files (x86)\Internet Explorer
2014-08-13 13:18:10 ----RD---- C:\Windows\ImmersiveControlPanel
2014-08-13 13:18:10 ----D---- C:\Windows\WinStore
2014-08-13 13:18:10 ----D---- C:\Windows\SYSWOW64\wbem
2014-08-13 13:18:10 ----D---- C:\Windows\SYSWOW64\setup
2014-08-13 13:18:10 ----D---- C:\Windows\system32\wbem
2014-08-13 13:18:10 ----D---- C:\Windows\system32\setup
2014-08-13 13:18:10 ----D---- C:\Windows\system32\oobe
2014-08-13 13:18:10 ----D---- C:\Windows\system32\drivers\cs-CZ
2014-08-13 13:18:10 ----D---- C:\Windows\system32\Boot
2014-08-13 13:18:10 ----D---- C:\Program Files\Windows Journal
2014-08-13 13:18:09 ----D---- C:\Windows\SYSWOW64\migration
2014-08-13 13:18:09 ----D---- C:\Windows\SYSWOW64\InputMethod
2014-08-13 13:18:09 ----D---- C:\Windows\apppatch
2014-08-13 13:02:18 ----D---- C:\Windows\system32\MRT
2014-08-13 13:01:10 ----A---- C:\Windows\system32\MRT.exe
2014-08-13 13:00:29 ----SD---- C:\Windows\system32\CompatTel
2014-08-11 22:33:42 ----SD---- C:\ProgramData\Microsoft
2014-08-11 22:33:39 ----D---- C:\Windows\ShellNew
2014-08-11 19:51:32 ----D---- C:\Program Files\CyberGhost 5
2014-08-09 14:33:01 ----D---- C:\Users\Ultimate\AppData\Roaming\gleam
2014-08-09 14:28:45 ----D---- C:\Users\Ultimate\AppData\Roaming\Identities
2014-08-09 02:22:16 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-08-09 02:22:16 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-08-09 02:22:05 ----A---- C:\Windows\system32\nvspcap64.dll
2014-08-09 02:22:05 ----A---- C:\Windows\system32\nvspbridge64.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2013-09-17 239296]
R1 dtsoftbus01;@oem20.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2013-10-12 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R2 Dokan;Dokan; \??\C:\WINDOWS\system32\drivers\dokan.sys [2011-01-10 120408]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2013-08-22 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-05-14 3962840]
R3 MEIx64;@oem11.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\HECIx64.sys [2012-07-17 62784]
R3 NVHDA;@oem9.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-28 197408]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2014-07-02 12866008]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-08-09 20440]
R3 nvvad_WaveExtensible;@oem73.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 RTL8168;@oem91.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-08-19 873688]
R3 SbieDrv;SbieDrv; \??\D:\Program Files\Sandboxie\SbieDrv.sys [2014-05-29 185352]
R3 ScreamBAudioSvc;@oem21.inf,%sbee_audio.SvcDesc%;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys [2010-07-01 38992]
R3 tap0901;@oem86.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2014-04-08 27136]
R3 USBPNPA;@oem54.inf,%CM108.SvcDesc%;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM10864.sys [2014-03-13 4333568]
R3 VBAudioVACMME;@oem37.inf,%DeviceName% (WDM);VB-Audio Virtual Cable (WDM); C:\Windows\system32\DRIVERS\vbaudio_cable64_win7.sys [2013-07-11 41192]
R3 VBAudioVMVAIOMME;@oem67.inf,%DeviceName% (WDM);VB-Audio VoiceMeeter VAIO (WDM); C:\Windows\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [2014-08-31 41192]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\Windows\system32\DRIVERS\CtClsFlt.sys [2011-09-05 178176]
S3 dg_ssudbus;@oem42.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-08-20 103576]
S3 EuMusDesignVirtualAudioCableWdm;@oem36.inf,%DeviceName% (WDM);Virtual Audio Cable (WDM); C:\Windows\system32\DRIVERS\vrtaucbl.sys [2014-01-01 90624]
S3 LHidFilt;@oem31.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2013-05-23 76568]
S3 LMouFilt;@oem31.inf,%LMouFilt.SvcDesc%;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2013-05-23 59160]
S3 LUsbFilt;@oem27.inf,%FltDisplayName%;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2013-05-23 40728]
S3 ptun0901;@oem90.inf,%DeviceDescription%;TAP Adapter V9 for Private Tunnel; C:\Windows\system32\DRIVERS\ptun0901.sys [2014-04-24 27136]
S3 RTL8167;@oem2.inf,%rtl8167.Service.DispName%;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-04-10 849992]
S3 tap0901_openvpn_accl;@oem49.inf,%DeviceDescription%;TAP-Win32 Adapter V9 for OpenVPN Accelerator; C:\Windows\system32\DRIVERS\tap0901_openvpn_accl.sys [2012-08-21 37912]
S3 taphss6;@oem87.inf,%DeviceDescription%;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [2014-05-17 42184]
S3 tapoas;@oem72.inf,%DeviceDescription%;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2012-07-15 30720]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-08-22 212224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 DokanMounter;DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [2011-01-10 14848]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 ForgeClientService;Forge Client Service; D:\Program Files\Forge\ForgeClientService.exe [2014-07-11 45320]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-08-09 1720792]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-08-09 18973144]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-07-02 935368]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-06-13 76888]
R2 prio_svc;Prio Service; D:\Program Files\Prio\prio_svc.exe [2012-11-08 12656]
R2 SbieSvc;Sandboxie Service; D:\Program Files\Sandboxie\SbieSvc.exe [2014-05-29 174088]
R2 StartMenuService;StartMenu8 Service; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [2014-06-06 72992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-11 116648]
S2 Service KMSELDI;Service KMSELDI; D:\Program Files\KMSpico\Service_KMS.exe [2013-11-11 685568]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-24 262320]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2013-10-13 49152]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; D:\Program Files\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-02-20 142336]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-11 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-04-22 119408]
S3 OpenVPNService;OpenVPN Service; D:\Program Files\OpenVPN\bin\openvpnserv.exe [2014-08-07 37176]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S3 Te.Service;Te.Service; D:\Program Files\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]

-----------------EOF-----------------

Re: Kontrola logu

Napsal: 08 zář 2014 16:17
od Rudy
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?

Re: Kontrola logu

Napsal: 09 zář 2014 00:06
od Thooty
Provedl jsem >CleanUp!< a zatím se nic s PC nestalo, tedy pokud se ptáte ohledně toho zamrznutí PC. Každopádně asi 2 hodiny po té, co jsem zde napsal poslední příspěvek PC zamrzl. A zamrzl při normální činnosti se spuštěným prohlížečem a sledováním videí na YouTube. Prostě PC zamrzne kdy se mu zachce a nezáleží vůbec na tom, jestli je zatížený nebo ne... Takže se zřejmě bude jednat o chybu hardwaru... 2 dny PC jede v pohodě a pak najednou zamrzne.. někdy i 3x za den a pak se zase pár dní nic neděje a jede v pohodě..

No ale to bych měl řešit asi na jiném fóru a ne tady, takže ještě jednou děkuji za pomoc s pročištěním PC a vyloučením možnosti viru :-)

Re: Kontrola logu

Napsal: 09 zář 2014 17:39
od Rudy
Neprovedli jsme ještě hloubkový sken. Před tím ale se ještě pokuste o obnovu systému k datu, kdy korektně fungoval.

Re: Kontrola logu

Napsal: 11 zář 2014 19:19
od Thooty
Žádný bod obnovení, do kterého bych mohl systém obnovit bohužel nemám. Navíc, ten problém mám už delší dobu a stejně bych i s bodem obnovení neuměl určit, kdy správně fungoval.. to už bych mohl rovnou přeinstalovat celý OS... Prostě pár dní, někdy třeba i týden to jede v pohodě a pak to začne zamrzávat z ničeho nic.. no a tentokrát jsem se to rozhodl řešit, protože to bylo častější (měl jsem napsat hned, bohužel čas zpátky nevrátím).

Co se dá docílit tím "hloubkovým skenem"?