Prosím o kontrolu logu
Napsal: 24 zář 2014 09:42
Dobrý den,
prosím o kontrolu logu. Včera mi Avast! (free verze) hlásil útok "URL:mal" při návštěvě jakékoliv stránky přes Chrome (v IE se nic takového nedělo ani neděje).
Děkuji.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Martin at 2014-09-24 10:34:45
Microsoft Windows 8.1 Pro
System drive C: has 486 GB (80%) free of 610 GB
Total RAM: 4030 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:35:24, on 24. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files\AVAST\avastui.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST\AvastUI.exe" /nogui
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6117 bytes
======Listing Processes======
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {20fd1ce8-9ed5-46f4-83e5e1622ef56caa}
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
atieclxx
taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\AVAST\avastui.exe" /nogui
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Program Files\Internet Explorer\iexplore.exe" -ServerName:DefaultBrowserServer
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe43_ Global\UsGthrCtrlFltPipeMssGthrPipe43 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:8380 CREDAT:3610254 /prefetch:1
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:8380 CREDAT:3610299 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-4224452743-666463508-3901887323-100244_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-4224452743-666463508-3901887323-100244 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Users\Martin\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST\aswWebRepIE64.dll [2014-07-29 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2014-07-27 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST\aswWebRepIE.dll [2014-07-29 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-07-27 1730256]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-29 171992]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-29 399832]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-29 442328]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-07-05 766688]
"AvastUI.exe"=C:\Program Files\AVAST\AvastUI.exe [2014-08-02 4085896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-29 442880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-09-24 10:34:45 ----D---- C:\rsit
2014-09-24 10:34:45 ----D---- C:\Program Files\trend micro
2014-09-18 12:05:43 ----D---- C:\Program Files (x86)\InstallShield Installation Information
2014-09-18 12:05:22 ----D---- C:\Program Files (x86)\Hewlett-Packard
2014-09-18 12:05:21 ----D---- C:\Users\Martin\AppData\Roaming\hpqLog
2014-09-14 09:42:31 ----D---- C:\Program Files (x86)\The SIMS 4
2014-09-14 08:49:46 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-14 00:39:54 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-14 00:39:53 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-14 00:39:51 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-14 00:39:51 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-14 00:39:50 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-14 00:39:50 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-14 00:39:50 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-14 00:39:49 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-14 00:39:45 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-14 00:39:45 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-14 00:39:45 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-14 00:39:44 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-14 00:39:44 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-14 00:39:43 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-14 00:39:43 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-14 00:39:42 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-14 00:39:41 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-14 00:39:40 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-14 00:39:35 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-14 00:39:32 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-14 00:39:31 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-14 00:39:31 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-14 00:39:30 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-14 00:39:30 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-14 00:28:13 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-09-14 00:27:50 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-14 00:27:49 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-14 00:27:49 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-14 00:27:48 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-14 00:27:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-14 00:27:44 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-14 00:27:43 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-14 00:27:40 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-14 00:27:38 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-14 00:27:37 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-14 00:27:36 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-14 00:27:35 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-14 00:27:32 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-14 00:27:31 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-14 00:27:31 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-14 00:27:30 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-14 00:27:30 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-14 00:27:29 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-14 00:27:29 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-14 00:27:28 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-14 00:27:27 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-14 00:27:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-14 00:27:25 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-14 00:27:25 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-14 00:27:24 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-14 00:27:22 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-14 00:27:22 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-14 00:27:21 ----AC---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-14 00:27:21 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-14 00:27:20 ----AC---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-14 00:27:20 ----AC---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-14 00:27:18 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-14 00:27:17 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-14 00:27:17 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-14 00:27:17 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-14 00:27:16 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-14 00:27:15 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-14 00:27:15 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-14 00:27:15 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-14 00:27:14 ----AC---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-14 00:27:14 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-14 00:27:13 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-14 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-14 00:27:10 ----AC---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-14 00:27:10 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-14 00:27:09 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\ppcsnap.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-14 00:27:07 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-14 00:27:07 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-14 00:27:06 ----AC---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-14 00:27:06 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-14 00:27:01 ----A---- C:\WINDOWS\system32\pmcsnap.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-14 00:27:00 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-14 00:27:00 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-14 00:27:00 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-14 00:26:59 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-14 00:26:58 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-14 00:26:58 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-14 00:26:58 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-14 00:26:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-14 00:26:57 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-14 00:26:57 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-14 00:26:56 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-14 00:26:56 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-14 00:26:55 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-14 00:26:54 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-14 00:26:54 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-14 00:26:51 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-14 00:26:50 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-14 00:26:49 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-14 00:26:49 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-14 00:26:49 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-14 00:26:48 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-14 00:26:48 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-14 00:26:47 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-14 00:26:45 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-14 00:26:45 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-14 00:26:44 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-14 00:26:44 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-14 00:26:44 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-14 00:26:43 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-14 00:26:42 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-14 00:26:42 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-14 00:26:42 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-14 00:26:42 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-14 00:26:41 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-14 00:26:39 ----AC---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-14 00:26:39 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-14 00:26:39 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-14 00:26:38 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-14 00:26:38 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-14 00:26:38 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-14 00:26:37 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-14 00:26:35 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-14 00:26:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-14 00:26:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-14 00:26:33 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-14 00:26:33 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-14 00:26:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-14 00:26:31 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-14 00:24:48 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-14 00:24:47 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-14 00:24:47 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-14 00:24:47 ----A---- C:\WINDOWS\explorer.exe
2014-09-14 00:24:45 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-14 00:24:16 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-14 00:24:16 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-14 00:24:15 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 00:18:09 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-14 00:18:09 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-13 23:29:50 ----D---- C:\WINDOWS\Minidump
2014-09-13 23:25:47 ----D---- C:\Program Files\ATI
2014-08-28 22:09:35 ----A---- C:\WINDOWS\system32\win32k.sys
======List of files/folders modified in the last 1 months======
2014-09-24 10:34:45 ----D---- C:\Program Files
2014-09-24 10:34:42 ----D---- C:\WINDOWS\Prefetch
2014-09-24 10:18:06 ----D---- C:\WINDOWS\system32\config
2014-09-24 10:05:14 ----D---- C:\WINDOWS\system32\Tasks
2014-09-24 10:05:09 ----D---- C:\WINDOWS\Temp
2014-09-24 10:03:14 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-24 10:03:10 ----D---- C:\Windows
2014-09-24 10:03:07 ----D---- C:\WINDOWS\system32\sru
2014-09-24 00:43:54 ----D---- C:\WINDOWS\Inf
2014-09-24 00:43:53 ----D---- C:\WINDOWS\debug
2014-09-24 00:21:16 ----D---- C:\ProgramData\Origin
2014-09-23 23:32:54 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-23 22:00:51 ----SHD---- C:\System Volume Information
2014-09-23 21:20:50 ----D---- C:\Program Files (x86)\Origin Games
2014-09-23 21:17:54 ----HD---- C:\_acestream_cache_
2014-09-23 21:17:43 ----D---- C:\Users\Martin\AppData\Roaming\.ACEStream
2014-09-23 21:16:52 ----D---- C:\Program Files (x86)\Origin
2014-09-23 16:37:07 ----RD---- C:\WINDOWS\System32
2014-09-23 16:37:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-22 23:34:27 ----D---- C:\Program Files\AVAST
2014-09-21 13:33:52 ----D---- C:\WINDOWS\AppReadiness
2014-09-20 13:22:21 ----HD---- C:\Program Files\WindowsApps
2014-09-18 12:36:07 ----RSD---- C:\WINDOWS\assembly
2014-09-18 12:06:08 ----D---- C:\ProgramData\Hewlett-Packard
2014-09-18 12:05:43 ----SHD---- C:\WINDOWS\Installer
2014-09-18 12:05:43 ----RD---- C:\Program Files (x86)
2014-09-18 12:04:59 ----D---- C:\SwSetup
2014-09-17 20:18:21 ----HD---- C:\ProgramData
2014-09-17 14:46:46 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-17 10:23:57 ----D---- C:\WINDOWS\WinSxS
2014-09-17 10:13:40 ----D---- C:\WINDOWS\rescache
2014-09-15 23:08:30 ----D---- C:\Program Files\CCleaner
2014-09-15 18:29:37 ----HD---- C:\Users\Martin\AppData\Roaming\Origin
2014-09-15 10:46:49 ----D---- C:\WINDOWS\CbsTemp
2014-09-14 11:01:41 ----D---- C:\Games
2014-09-14 10:18:02 ----D---- C:\WINDOWS\SysWOW64
2014-09-14 10:18:00 ----D---- C:\ProgramData\Package Cache
2014-09-14 08:49:46 ----SHD---- C:\Boot
2014-09-14 08:46:46 ----RD---- C:\WINDOWS\ToastData
2014-09-14 08:46:40 ----D---- C:\WINDOWS\WinStore
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\en-US
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-14 08:46:40 ----D---- C:\Program Files\Windows Journal
2014-09-14 08:46:39 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\wbem
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\setup
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\oobe
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\en-US
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\drivers\en-US
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\drivers
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\Boot
2014-09-14 08:46:39 ----D---- C:\WINDOWS\PolicyDefinitions
2014-09-14 08:46:38 ----RSD---- C:\WINDOWS\Fonts
2014-09-14 08:46:37 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-14 08:46:37 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-14 08:46:37 ----D---- C:\WINDOWS\system32\migration
2014-09-14 08:46:37 ----D---- C:\WINDOWS\apppatch
2014-09-14 08:46:36 ----D---- C:\Program Files\Internet Explorer
2014-09-14 08:46:36 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-14 00:45:35 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 00:40:26 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-14 00:40:25 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-14 00:40:14 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-14 00:40:14 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-14 00:40:14 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-14 00:40:13 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-14 00:40:13 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-14 00:40:12 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-14 00:40:11 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-14 00:40:11 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-14 00:40:11 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-14 00:40:11 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-14 00:40:08 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-14 00:40:04 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-14 00:31:48 ----D---- C:\WINDOWS\system32\MRT
2014-09-14 00:31:42 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-14 00:23:20 ----D---- C:\WINDOWS\system32\catroot2
2014-09-13 23:57:06 ----D---- C:\WINDOWS\system32\wdi
2014-09-13 23:54:19 ----RSD---- C:\WINDOWS\Media
2014-09-13 23:54:18 ----D---- C:\WINDOWS\Tasks
2014-09-13 23:54:11 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2014-09-13 23:54:11 ----D---- C:\WINDOWS\system32\Sysprep
2014-09-13 23:54:11 ----D---- C:\WINDOWS\system32\Macromed
2014-09-13 23:54:10 ----D---- C:\WINDOWS\system32\CodeIntegrity
2014-09-13 23:54:02 ----D---- C:\ProgramData\Protexis
2014-09-13 23:54:01 ----D---- C:\Program Files\Common Files\microsoft shared
2014-09-13 23:48:16 ----D---- C:\WINDOWS\registration
2014-09-13 23:47:43 ----D---- C:\WINDOWS\system32\catroot
2014-09-13 23:45:15 ----D---- C:\Program Files\Microsoft Office
2014-09-13 23:36:38 ----D---- C:\WINDOWS\Logs
prosím o kontrolu logu. Včera mi Avast! (free verze) hlásil útok "URL:mal" při návštěvě jakékoliv stránky přes Chrome (v IE se nic takového nedělo ani neděje).
Děkuji.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Martin at 2014-09-24 10:34:45
Microsoft Windows 8.1 Pro
System drive C: has 486 GB (80%) free of 610 GB
Total RAM: 4030 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:35:24, on 24. 9. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files\AVAST\avastui.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST\AvastUI.exe" /nogui
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6117 bytes
======Listing Processes======
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {20fd1ce8-9ed5-46f4-83e5e1622ef56caa}
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
atieclxx
taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\AVAST\avastui.exe" /nogui
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe" -ServerName:Microsoft.Reader.AppXtszmc7avrx02s7n8gch63tzwg517wd9k.mca
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
"C:\Program Files\Internet Explorer\iexplore.exe" -ServerName:DefaultBrowserServer
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe43_ Global\UsGthrCtrlFltPipeMssGthrPipe43 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:8380 CREDAT:3610254 /prefetch:1
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:8380 CREDAT:3610299 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-4224452743-666463508-3901887323-100244_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-4224452743-666463508-3901887323-100244 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Users\Martin\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST\aswWebRepIE64.dll [2014-07-29 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2014-07-27 2335960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST\aswWebRepIE.dll [2014-07-29 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-07-27 1730256]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-29 171992]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-29 399832]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-29 442328]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-10-30 2804976]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-07-05 766688]
"AvastUI.exe"=C:\Program Files\AVAST\AvastUI.exe [2014-08-02 4085896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-29 442880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-09-24 10:34:45 ----D---- C:\rsit
2014-09-24 10:34:45 ----D---- C:\Program Files\trend micro
2014-09-18 12:05:43 ----D---- C:\Program Files (x86)\InstallShield Installation Information
2014-09-18 12:05:22 ----D---- C:\Program Files (x86)\Hewlett-Packard
2014-09-18 12:05:21 ----D---- C:\Users\Martin\AppData\Roaming\hpqLog
2014-09-14 09:42:31 ----D---- C:\Program Files (x86)\The SIMS 4
2014-09-14 08:49:46 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-14 00:39:54 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-14 00:39:53 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-14 00:39:51 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-14 00:39:51 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-14 00:39:50 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-14 00:39:50 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-14 00:39:50 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-14 00:39:49 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-14 00:39:46 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-14 00:39:45 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-14 00:39:45 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-14 00:39:45 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-14 00:39:44 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-14 00:39:44 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-14 00:39:43 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-14 00:39:43 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-14 00:39:42 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-14 00:39:41 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-14 00:39:40 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-14 00:39:35 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-14 00:39:34 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-14 00:39:32 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-14 00:39:31 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-14 00:39:31 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-14 00:39:30 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-14 00:39:30 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-14 00:28:13 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-09-14 00:27:50 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-14 00:27:49 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-14 00:27:49 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-14 00:27:48 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-14 00:27:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-14 00:27:44 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-14 00:27:43 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-14 00:27:40 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-14 00:27:38 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-14 00:27:37 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-14 00:27:36 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-14 00:27:35 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-14 00:27:32 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-14 00:27:31 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-14 00:27:31 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-14 00:27:30 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-14 00:27:30 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-14 00:27:29 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-14 00:27:29 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-14 00:27:28 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-14 00:27:27 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-14 00:27:26 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-14 00:27:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-14 00:27:25 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-14 00:27:25 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-14 00:27:24 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-14 00:27:24 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-14 00:27:23 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-14 00:27:22 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2014-09-14 00:27:22 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-14 00:27:22 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-14 00:27:21 ----AC---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-14 00:27:21 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-14 00:27:21 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-14 00:27:20 ----AC---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-14 00:27:20 ----AC---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-14 00:27:20 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-14 00:27:19 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-14 00:27:18 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-14 00:27:18 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-14 00:27:17 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-14 00:27:17 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-14 00:27:17 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-14 00:27:16 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-14 00:27:15 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-14 00:27:15 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-14 00:27:15 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-14 00:27:14 ----AC---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-14 00:27:14 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-14 00:27:14 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-14 00:27:13 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-14 00:27:13 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-14 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-14 00:27:12 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-14 00:27:11 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-14 00:27:10 ----AC---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-14 00:27:10 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-14 00:27:10 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-14 00:27:09 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-14 00:27:09 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\ppcsnap.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-14 00:27:08 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-14 00:27:07 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-14 00:27:07 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-14 00:27:06 ----AC---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-14 00:27:06 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-14 00:27:05 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-14 00:27:04 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-14 00:27:01 ----A---- C:\WINDOWS\system32\pmcsnap.dll
2014-09-14 00:27:01 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-14 00:27:00 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-14 00:27:00 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-14 00:27:00 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-14 00:26:59 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-14 00:26:58 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-14 00:26:58 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-14 00:26:58 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-14 00:26:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-14 00:26:57 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-14 00:26:57 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-14 00:26:56 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-14 00:26:56 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-14 00:26:55 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-14 00:26:54 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-14 00:26:54 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-14 00:26:51 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-14 00:26:50 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-14 00:26:49 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-14 00:26:49 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-14 00:26:49 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-14 00:26:48 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-14 00:26:48 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-14 00:26:47 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-14 00:26:45 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-14 00:26:45 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-14 00:26:44 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-14 00:26:44 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-14 00:26:44 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-14 00:26:43 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-14 00:26:42 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-14 00:26:42 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-14 00:26:42 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-14 00:26:42 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-14 00:26:41 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-14 00:26:39 ----AC---- C:\WINDOWS\system32\drivers\bthpan.sys
2014-09-14 00:26:39 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-14 00:26:39 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-14 00:26:39 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-14 00:26:38 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-14 00:26:38 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-14 00:26:38 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-14 00:26:37 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-14 00:26:35 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-14 00:26:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-14 00:26:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-14 00:26:33 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-14 00:26:33 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-14 00:26:31 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-14 00:26:31 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-14 00:24:48 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-14 00:24:47 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-14 00:24:47 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-14 00:24:47 ----A---- C:\WINDOWS\explorer.exe
2014-09-14 00:24:45 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-14 00:24:43 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-14 00:24:16 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-14 00:24:16 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-14 00:24:15 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 00:18:09 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-14 00:18:09 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-13 23:29:50 ----D---- C:\WINDOWS\Minidump
2014-09-13 23:25:47 ----D---- C:\Program Files\ATI
2014-08-28 22:09:35 ----A---- C:\WINDOWS\system32\win32k.sys
======List of files/folders modified in the last 1 months======
2014-09-24 10:34:45 ----D---- C:\Program Files
2014-09-24 10:34:42 ----D---- C:\WINDOWS\Prefetch
2014-09-24 10:18:06 ----D---- C:\WINDOWS\system32\config
2014-09-24 10:05:14 ----D---- C:\WINDOWS\system32\Tasks
2014-09-24 10:05:09 ----D---- C:\WINDOWS\Temp
2014-09-24 10:03:14 ----D---- C:\WINDOWS\SoftwareDistribution
2014-09-24 10:03:10 ----D---- C:\Windows
2014-09-24 10:03:07 ----D---- C:\WINDOWS\system32\sru
2014-09-24 00:43:54 ----D---- C:\WINDOWS\Inf
2014-09-24 00:43:53 ----D---- C:\WINDOWS\debug
2014-09-24 00:21:16 ----D---- C:\ProgramData\Origin
2014-09-23 23:32:54 ----D---- C:\WINDOWS\Microsoft.NET
2014-09-23 22:00:51 ----SHD---- C:\System Volume Information
2014-09-23 21:20:50 ----D---- C:\Program Files (x86)\Origin Games
2014-09-23 21:17:54 ----HD---- C:\_acestream_cache_
2014-09-23 21:17:43 ----D---- C:\Users\Martin\AppData\Roaming\.ACEStream
2014-09-23 21:16:52 ----D---- C:\Program Files (x86)\Origin
2014-09-23 16:37:07 ----RD---- C:\WINDOWS\System32
2014-09-23 16:37:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-22 23:34:27 ----D---- C:\Program Files\AVAST
2014-09-21 13:33:52 ----D---- C:\WINDOWS\AppReadiness
2014-09-20 13:22:21 ----HD---- C:\Program Files\WindowsApps
2014-09-18 12:36:07 ----RSD---- C:\WINDOWS\assembly
2014-09-18 12:06:08 ----D---- C:\ProgramData\Hewlett-Packard
2014-09-18 12:05:43 ----SHD---- C:\WINDOWS\Installer
2014-09-18 12:05:43 ----RD---- C:\Program Files (x86)
2014-09-18 12:04:59 ----D---- C:\SwSetup
2014-09-17 20:18:21 ----HD---- C:\ProgramData
2014-09-17 14:46:46 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-17 10:23:57 ----D---- C:\WINDOWS\WinSxS
2014-09-17 10:13:40 ----D---- C:\WINDOWS\rescache
2014-09-15 23:08:30 ----D---- C:\Program Files\CCleaner
2014-09-15 18:29:37 ----HD---- C:\Users\Martin\AppData\Roaming\Origin
2014-09-15 10:46:49 ----D---- C:\WINDOWS\CbsTemp
2014-09-14 11:01:41 ----D---- C:\Games
2014-09-14 10:18:02 ----D---- C:\WINDOWS\SysWOW64
2014-09-14 10:18:00 ----D---- C:\ProgramData\Package Cache
2014-09-14 08:49:46 ----SHD---- C:\Boot
2014-09-14 08:46:46 ----RD---- C:\WINDOWS\ToastData
2014-09-14 08:46:40 ----D---- C:\WINDOWS\WinStore
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\en-US
2014-09-14 08:46:40 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-14 08:46:40 ----D---- C:\Program Files\Windows Journal
2014-09-14 08:46:39 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\wbem
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\setup
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\oobe
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\en-US
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\drivers\en-US
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\drivers
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-14 08:46:39 ----D---- C:\WINDOWS\system32\Boot
2014-09-14 08:46:39 ----D---- C:\WINDOWS\PolicyDefinitions
2014-09-14 08:46:38 ----RSD---- C:\WINDOWS\Fonts
2014-09-14 08:46:37 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-14 08:46:37 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-14 08:46:37 ----D---- C:\WINDOWS\system32\migration
2014-09-14 08:46:37 ----D---- C:\WINDOWS\apppatch
2014-09-14 08:46:36 ----D---- C:\Program Files\Internet Explorer
2014-09-14 08:46:36 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-14 00:45:35 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 00:40:26 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-14 00:40:25 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-14 00:40:14 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-14 00:40:14 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-14 00:40:14 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-14 00:40:13 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-14 00:40:13 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-14 00:40:12 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-14 00:40:11 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-14 00:40:11 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-14 00:40:11 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-14 00:40:11 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-14 00:40:08 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-14 00:40:04 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-14 00:31:48 ----D---- C:\WINDOWS\system32\MRT
2014-09-14 00:31:42 ----A---- C:\WINDOWS\system32\MRT.exe
2014-09-14 00:23:20 ----D---- C:\WINDOWS\system32\catroot2
2014-09-13 23:57:06 ----D---- C:\WINDOWS\system32\wdi
2014-09-13 23:54:19 ----RSD---- C:\WINDOWS\Media
2014-09-13 23:54:18 ----D---- C:\WINDOWS\Tasks
2014-09-13 23:54:11 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2014-09-13 23:54:11 ----D---- C:\WINDOWS\system32\Sysprep
2014-09-13 23:54:11 ----D---- C:\WINDOWS\system32\Macromed
2014-09-13 23:54:10 ----D---- C:\WINDOWS\system32\CodeIntegrity
2014-09-13 23:54:02 ----D---- C:\ProgramData\Protexis
2014-09-13 23:54:01 ----D---- C:\Program Files\Common Files\microsoft shared
2014-09-13 23:48:16 ----D---- C:\WINDOWS\registration
2014-09-13 23:47:43 ----D---- C:\WINDOWS\system32\catroot
2014-09-13 23:45:15 ----D---- C:\Program Files\Microsoft Office
2014-09-13 23:36:38 ----D---- C:\WINDOWS\Logs