problemy win 8.1
Napsal: 04 říj 2014 17:39
Dobrý den, cca pred 14 dny se po jednom restartu zacal system chovat ponekud zvlastne. Napriklad se zastavila sluzba pro zvuk a od te doby tedy nejde zvuk a sluzba nelze nastartovat. Nedari se mi take dostat do nastaveni pres najeti mysi do leveho rohu se zobrazi klasicky panel ale po kliknuti na nastaveni se nestane nic. Do nastaveni se lze dostat pres vyhledavani v nabidce start. Zkousel jsem diagnosticke spusteni bez zbytecnych sluzeb a tam se alespon tato chyba s tlacitkem nastaveni neprojevovala. Prikladam log a predem dekuji za kontrolu.
Logfile of random's system information tool 1.08 (written by random/random)
Run by name at 2014-10-04 18:23:52
Microsoft Windows 8.1 Pro
System drive C: has 656 GB (92%) free of 714 GB
Total RAM: 3535 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:23:58, on 4. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\name.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [icq] C:\Users\name\AppData\Roaming\ICQM\icq.exe -CU
O4 - HKCU\..\Run: [MyDriveConnect.exe] "C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe"
O4 - Global Startup: LINKMAGIC.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\name\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\name\AppData\Roaming\ICQM\icq.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7802 bytes
======Listing Processes======
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=b04ed978-d962-4f0e-9a06-c97859e8a763 /coreSdkOptions=4382 /logConfFile="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\9cc76203-1ca1-4d06-a852-b669e5962170-174-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\" /logPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\log\"
wininit.exe
C:\WINDOWS\system32\lsass.exe
winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
atieclxx
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\AVG\AVG2014\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"
dashost.exe {8416b452-4af6-4991-9a00f9363b45e0dd}
taskhostex.exe
taskhost.exe
C:\Windows\system32\HPSIsvc.exe
taskeng.exe {920B8B99-F612-454F-AF03-A4D1CAD0ED8E}
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgemca.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe"
taskhost.exe SYSTEM
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0d0a746d-1022-4468-b79d-9560ae37434e -SystemEventPortName:HostProcess-61831ad2-264e-410f-a265-c7f106e13a10 -IoCancelEventPortName:HostProcess-44a4c516-b1b3-4d63-87fb-92bd76eb8868 -NonStateChangingEventPortName:HostProcess-e9bfdb31-271d-4a4b-9166-b90909680670 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2158ec06-0f07-45e4-b2d7-0e748c70338f -DeviceGroupId:WpdFsGroup
"C:\WINDOWS\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_ce3896fd6d3851995a9f6854e17907036b19973_00000000_0574d8cc"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3852.0.710406742\249735838" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17 --gpu-vendor-id=0x1002 --gpu-device-id=0x9991 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.9001.0 --ignored=" --type=renderer " /prefetch:822062411
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=a1dfad1c-c38d-4343-b474-4a6f4d9a494c /coreSdkOptions=4114 /logConfFile="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\e3344b78-6c29-4135-a765-3a54b2553631-b08-oopp.tmp" /loggerName=AVG.NS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_09/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3852.6.1974199982\2029483603" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_09/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3852.7.353209847\26451119" /prefetch:673131151
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\name\Downloads\RSITx64.exe"
C:\WINDOWS\System32\ThumbnailExtractionHost.exe -Embedding
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"icq"=C:\Users\name\AppData\Roaming\ICQM\icq.exe [2013-06-08 27598184]
"MyDriveConnect.exe"=C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [2013-11-29 473496]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
""= []
"HPUsageTrackingLEDM"=C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2014-08-25 5188112]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
LINKMAGIC.lnk - C:\Program Files (x86)\LINKMAGIC\LINKMAGIC.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-10-04 18:23:53 ----D---- C:\Program Files\trend micro
2014-10-04 18:23:52 ----D---- C:\rsit
2014-09-15 10:36:23 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 10:36:23 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 10:36:20 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 10:36:20 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 10:36:20 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 10:36:19 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 10:36:18 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 10:36:16 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 10:36:16 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 10:36:16 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 10:36:15 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 10:35:45 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 10:35:41 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 10:35:40 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 10:35:38 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 10:35:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 10:35:36 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 10:35:35 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 10:35:34 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 10:35:33 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 10:35:32 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 10:35:31 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 10:35:30 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 10:35:24 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 10:35:23 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 10:35:21 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 10:35:21 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 10:35:20 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 10:35:19 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 10:35:18 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 10:35:16 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 10:35:15 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 10:35:14 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 10:35:13 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 10:35:13 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 10:35:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 10:35:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 10:35:12 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 10:35:11 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 10:35:10 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 10:35:09 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 10:35:09 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 10:35:08 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 10:35:08 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 10:35:07 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 10:35:06 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 10:35:06 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 10:35:05 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 10:35:05 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 10:35:04 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 10:35:03 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 10:35:03 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 10:35:03 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 10:35:02 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 10:35:02 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 10:35:01 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 10:35:01 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 10:35:01 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 10:35:00 ----AC---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 10:35:00 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 10:35:00 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 10:34:59 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 10:34:58 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 10:34:58 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 10:34:58 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 10:34:57 ----AC---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 10:34:57 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 10:34:56 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 10:34:56 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 10:34:55 ----AC---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 10:34:55 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 10:34:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 10:34:52 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 10:34:52 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 10:34:52 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 10:34:50 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 10:34:49 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 10:34:49 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 10:34:49 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 10:34:48 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 10:34:48 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 10:34:47 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 10:34:47 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 10:34:46 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 10:34:46 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 10:34:45 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 10:34:44 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 10:34:43 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 10:34:43 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 10:34:42 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 10:34:42 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 10:34:41 ----AC---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 10:34:41 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 10:34:41 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 10:34:41 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 10:34:40 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 10:34:39 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 10:34:38 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 10:34:38 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 10:34:38 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 10:34:37 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 10:34:37 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 10:34:37 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 10:34:35 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 10:34:35 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 10:34:35 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 10:34:35 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 10:34:34 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 10:34:34 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 10:34:34 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 10:34:33 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 10:34:33 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 10:34:33 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 10:34:32 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 10:34:32 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 10:34:32 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 10:34:31 ----AC---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 10:34:30 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 10:34:29 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 10:34:29 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 10:34:29 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 10:34:29 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 10:34:27 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 10:34:27 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 10:34:27 ----A---- C:\WINDOWS\system32\ppcsnap.dll
2014-09-15 10:34:26 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 10:34:26 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 10:34:25 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 10:34:25 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 10:34:25 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 10:34:25 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 10:34:24 ----AC---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 10:34:24 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 10:34:24 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 10:34:23 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 10:34:22 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 10:34:21 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 10:34:21 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 10:34:20 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 10:34:20 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 10:34:20 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 10:34:20 ----A---- C:\WINDOWS\system32\pmcsnap.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 10:34:18 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 10:34:18 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 10:34:18 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 10:34:18 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 10:34:17 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 10:34:17 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 10:34:17 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 10:34:15 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 10:34:14 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 10:34:14 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 10:34:13 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 10:34:13 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 10:34:13 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 10:34:12 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 10:34:12 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 10:34:11 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 10:34:11 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 10:34:10 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 10:34:04 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 10:34:04 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 10:34:03 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 10:34:02 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 10:34:02 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 10:34:02 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 10:34:00 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 10:34:00 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 10:27:50 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 19:42:40 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-14 19:42:40 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-14 19:42:38 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-14 19:42:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-14 19:42:31 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-14 19:42:31 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-14 19:42:31 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-14 19:42:31 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-14 19:42:30 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-14 19:42:28 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-14 19:42:28 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-14 19:42:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-14 19:42:26 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-14 19:42:25 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-14 19:42:25 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-14 19:42:25 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-11 10:00:44 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-09-11 09:58:23 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-11 09:58:22 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
======List of files/folders modified in the last 1 months======
2014-10-04 18:23:55 ----D---- C:\WINDOWS\Prefetch
2014-10-04 18:23:53 ----RD---- C:\Program Files
2014-10-04 18:21:48 ----D---- C:\WINDOWS\Temp
2014-10-04 18:11:19 ----D---- C:\WINDOWS\AppReadiness
2014-10-04 18:11:13 ----D---- C:\WINDOWS\system32\config
2014-10-04 18:02:43 ----D---- C:\WINDOWS\system32\sru
2014-10-04 17:15:25 ----D---- C:\ProgramData\MFAData
2014-10-04 16:20:08 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-03 20:01:59 ----D---- C:\ProgramData\firebird
2014-10-03 10:57:40 ----D---- C:\UCTO2014
2014-10-02 17:57:16 ----D---- C:\UCTO2013
2014-10-02 15:46:07 ----SHD---- C:\WINDOWS\Installer
2014-10-01 20:24:26 ----D---- C:\WINDOWS\Inf
2014-09-30 11:26:42 ----SHD---- C:\System Volume Information
2014-09-27 19:23:23 ----D---- C:\WINDOWS\System32
2014-09-27 19:23:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-27 19:16:15 ----D---- C:\WINDOWS\system32\wbem
2014-09-27 19:16:15 ----D---- C:\Windows
2014-09-27 19:11:22 ----D---- C:\Program Files\Internet Explorer
2014-09-27 19:11:22 ----D---- C:\Program Files\Common Files\microsoft shared
2014-09-27 19:11:22 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-27 19:11:21 ----D---- C:\Program Files\Windows Journal
2014-09-27 19:11:19 ----D---- C:\Users\name\AppData\Roaming\IrfanView
2014-09-27 19:11:18 ----D---- C:\WINDOWS\apppatch
2014-09-27 19:11:14 ----RSD---- C:\WINDOWS\Fonts
2014-09-27 19:11:14 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-27 19:11:10 ----RSD---- C:\WINDOWS\Media
2014-09-27 19:11:09 ----D---- C:\WINDOWS\schemas
2014-09-27 19:11:09 ----D---- C:\WINDOWS\rescache
2014-09-27 19:11:09 ----D---- C:\WINDOWS\PolicyDefinitions
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\migration
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\Macromed
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\drivers
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\CodeIntegrity
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\catroot2
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\Bthprops
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\Boot
2014-09-27 19:11:08 ----D---- C:\WINDOWS\ShellNew
2014-09-27 19:11:08 ----D---- C:\WINDOWS\servicing
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\Tasks
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\Sysprep
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\setup
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\oobe
2014-09-27 19:11:06 ----D---- C:\WINDOWS\SysWOW64
2014-09-27 19:11:05 ----RD---- C:\WINDOWS\ToastData
2014-09-27 19:11:05 ----D---- C:\WINDOWS\Tasks
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\config
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\Bthprops
2014-09-27 19:11:04 ----D---- C:\WINDOWS\WinSxS
2014-09-27 19:11:04 ----D---- C:\WINDOWS\WinStore
2014-09-27 19:01:26 ----D---- C:\WINDOWS\registration
2014-09-27 17:58:24 ----D---- C:\WINDOWS\Logs
2014-09-21 12:58:09 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-18 12:42:01 ----HD---- C:\Program Files\WindowsApps
2014-09-17 14:52:24 ----D---- C:\WINDOWS\CbsTemp
2014-09-17 13:15:11 ----D---- C:\ProgramData\AVG2014
2014-09-15 11:39:14 ----RSD---- C:\WINDOWS\assembly
2014-09-14 19:45:08 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 19:43:13 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-14 19:43:12 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-14 19:43:00 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-14 19:42:59 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-14 19:42:58 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-14 19:42:58 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-14 19:42:57 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-14 19:42:57 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-14 19:42:55 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-14 19:42:52 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-14 19:42:23 ----D---- C:\WINDOWS\system32\MRT
2014-09-14 19:38:55 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
Logfile of random's system information tool 1.08 (written by random/random)
Run by name at 2014-10-04 18:23:52
Microsoft Windows 8.1 Pro
System drive C: has 656 GB (92%) free of 714 GB
Total RAM: 3535 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:23:58, on 4. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\name.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [icq] C:\Users\name\AppData\Roaming\ICQM\icq.exe -CU
O4 - HKCU\..\Run: [MyDriveConnect.exe] "C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe"
O4 - Global Startup: LINKMAGIC.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\name\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\name\AppData\Roaming\ICQM\icq.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7802 bytes
======Listing Processes======
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=b04ed978-d962-4f0e-9a06-c97859e8a763 /coreSdkOptions=4382 /logConfFile="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\9cc76203-1ca1-4d06-a852-b669e5962170-174-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\" /logPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\log\"
wininit.exe
C:\WINDOWS\system32\lsass.exe
winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
atieclxx
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\AVG\AVG2014\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"
dashost.exe {8416b452-4af6-4991-9a00f9363b45e0dd}
taskhostex.exe
taskhost.exe
C:\Windows\system32\HPSIsvc.exe
taskeng.exe {920B8B99-F612-454F-AF03-A4D1CAD0ED8E}
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgemca.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe"
taskhost.exe SYSTEM
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0d0a746d-1022-4468-b79d-9560ae37434e -SystemEventPortName:HostProcess-61831ad2-264e-410f-a265-c7f106e13a10 -IoCancelEventPortName:HostProcess-44a4c516-b1b3-4d63-87fb-92bd76eb8868 -NonStateChangingEventPortName:HostProcess-e9bfdb31-271d-4a4b-9166-b90909680670 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2158ec06-0f07-45e4-b2d7-0e748c70338f -DeviceGroupId:WpdFsGroup
"C:\WINDOWS\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_ce3896fd6d3851995a9f6854e17907036b19973_00000000_0574d8cc"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3852.0.710406742\249735838" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17 --gpu-vendor-id=0x1002 --gpu-device-id=0x9991 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.9001.0 --ignored=" --type=renderer " /prefetch:822062411
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=a1dfad1c-c38d-4343-b474-4a6f4d9a494c /coreSdkOptions=4114 /logConfFile="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\e3344b78-6c29-4135-a765-3a54b2553631-b08-oopp.tmp" /loggerName=AVG.NS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_09/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3852.6.1974199982\2029483603" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-1-Percent/group_09/UMA-Uniformity-Trial-10-Percent/group_03/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3852.7.353209847\26451119" /prefetch:673131151
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\name\Downloads\RSITx64.exe"
C:\WINDOWS\System32\ThumbnailExtractionHost.exe -Embedding
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"icq"=C:\Users\name\AppData\Roaming\ICQM\icq.exe [2013-06-08 27598184]
"MyDriveConnect.exe"=C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [2013-11-29 473496]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
""= []
"HPUsageTrackingLEDM"=C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [2009-10-15 30264]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2014-08-25 5188112]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
LINKMAGIC.lnk - C:\Program Files (x86)\LINKMAGIC\LINKMAGIC.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2014-10-04 18:23:53 ----D---- C:\Program Files\trend micro
2014-10-04 18:23:52 ----D---- C:\rsit
2014-09-15 10:36:23 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-09-15 10:36:23 ----A---- C:\WINDOWS\system32\tcpmon.dll
2014-09-15 10:36:20 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-09-15 10:36:20 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-09-15 10:36:20 ----A---- C:\WINDOWS\explorer.exe
2014-09-15 10:36:19 ----A---- C:\WINDOWS\system32\twinui.dll
2014-09-15 10:36:18 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-09-15 10:36:16 ----A---- C:\WINDOWS\SYSWOW64\UXInit.dll
2014-09-15 10:36:16 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-09-15 10:36:16 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-09-15 10:36:15 ----A---- C:\WINDOWS\system32\UXInit.dll
2014-09-15 10:35:45 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-09-15 10:35:41 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-09-15 10:35:40 ----A---- C:\WINDOWS\system32\authui.dll
2014-09-15 10:35:38 ----A---- C:\WINDOWS\system32\shell32.dll
2014-09-15 10:35:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-09-15 10:35:36 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-09-15 10:35:35 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-09-15 10:35:34 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-15 10:35:33 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-09-15 10:35:32 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-09-15 10:35:31 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-09-15 10:35:30 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-09-15 10:35:24 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-09-15 10:35:23 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-09-15 10:35:21 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-09-15 10:35:21 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-09-15 10:35:20 ----A---- C:\WINDOWS\system32\gpsvc.dll
2014-09-15 10:35:19 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-09-15 10:35:18 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2014-09-15 10:35:16 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-09-15 10:35:15 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-09-15 10:35:14 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-09-15 10:35:13 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-09-15 10:35:13 ----A---- C:\WINDOWS\system32\localspl.dll
2014-09-15 10:35:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-09-15 10:35:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-09-15 10:35:12 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2014-09-15 10:35:11 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2014-09-15 10:35:10 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2014-09-15 10:35:09 ----A---- C:\WINDOWS\system32\SRH.dll
2014-09-15 10:35:09 ----A---- C:\WINDOWS\system32\mfplat.dll
2014-09-15 10:35:08 ----A---- C:\WINDOWS\system32\printui.dll
2014-09-15 10:35:08 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-09-15 10:35:07 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-09-15 10:35:06 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2014-09-15 10:35:06 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-09-15 10:35:05 ----A---- C:\WINDOWS\system32\mispace.dll
2014-09-15 10:35:05 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-09-15 10:35:04 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2014-09-15 10:35:03 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2014-09-15 10:35:03 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-09-15 10:35:03 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2014-09-15 10:35:02 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-09-15 10:35:02 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-09-15 10:35:01 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2014-09-15 10:35:01 ----A---- C:\WINDOWS\SYSWOW64\printui.dll
2014-09-15 10:35:01 ----A---- C:\WINDOWS\system32\aclui.dll
2014-09-15 10:35:00 ----AC---- C:\WINDOWS\system32\drivers\spaceport.sys
2014-09-15 10:35:00 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-09-15 10:35:00 ----A---- C:\WINDOWS\system32\srvsvc.dll
2014-09-15 10:34:59 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-09-15 10:34:58 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-09-15 10:34:58 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-09-15 10:34:58 ----A---- C:\WINDOWS\system32\spoolsv.exe
2014-09-15 10:34:57 ----AC---- C:\WINDOWS\system32\drivers\usbccgp.sys
2014-09-15 10:34:57 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2014-09-15 10:34:56 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-09-15 10:34:56 ----A---- C:\WINDOWS\system32\SHCore.dll
2014-09-15 10:34:55 ----AC---- C:\WINDOWS\system32\drivers\volsnap.sys
2014-09-15 10:34:55 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-09-15 10:34:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2014-09-15 10:34:52 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2014-09-15 10:34:52 ----A---- C:\WINDOWS\system32\storagewmi.dll
2014-09-15 10:34:52 ----A---- C:\WINDOWS\system32\mftranscode.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\system32\comdlg32.dll
2014-09-15 10:34:51 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-09-15 10:34:50 ----A---- C:\WINDOWS\system32\usbmon.dll
2014-09-15 10:34:49 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-09-15 10:34:49 ----A---- C:\WINDOWS\system32\winload.exe
2014-09-15 10:34:49 ----A---- C:\WINDOWS\system32\WebClnt.dll
2014-09-15 10:34:48 ----A---- C:\WINDOWS\system32\wisp.dll
2014-09-15 10:34:48 ----A---- C:\WINDOWS\system32\defragsvc.dll
2014-09-15 10:34:47 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2014-09-15 10:34:47 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-09-15 10:34:46 ----A---- C:\WINDOWS\system32\wsecedit.dll
2014-09-15 10:34:46 ----A---- C:\WINDOWS\system32\winresume.exe
2014-09-15 10:34:45 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-09-15 10:34:44 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2014-09-15 10:34:43 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-09-15 10:34:43 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-09-15 10:34:42 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-09-15 10:34:42 ----A---- C:\WINDOWS\system32\user32.dll
2014-09-15 10:34:41 ----AC---- C:\WINDOWS\system32\drivers\usbhub.sys
2014-09-15 10:34:41 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2014-09-15 10:34:41 ----A---- C:\WINDOWS\system32\winmmbase.dll
2014-09-15 10:34:41 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2014-09-15 10:34:40 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-09-15 10:34:39 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-09-15 10:34:38 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-09-15 10:34:38 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-09-15 10:34:38 ----A---- C:\WINDOWS\system32\conhost.exe
2014-09-15 10:34:37 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-09-15 10:34:37 ----A---- C:\WINDOWS\system32\VAN.dll
2014-09-15 10:34:37 ----A---- C:\WINDOWS\system32\SettingSync.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\system32\Display.dll
2014-09-15 10:34:36 ----A---- C:\WINDOWS\system32\AppxSip.dll
2014-09-15 10:34:35 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2014-09-15 10:34:35 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-09-15 10:34:35 ----A---- C:\WINDOWS\system32\SndVol.exe
2014-09-15 10:34:35 ----A---- C:\WINDOWS\system32\osk.exe
2014-09-15 10:34:34 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-09-15 10:34:34 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2014-09-15 10:34:34 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-09-15 10:34:33 ----A---- C:\WINDOWS\system32\mfps.dll
2014-09-15 10:34:33 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2014-09-15 10:34:33 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2014-09-15 10:34:32 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2014-09-15 10:34:32 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-09-15 10:34:32 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-09-15 10:34:31 ----AC---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\winmm.dll
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\drivers\NdisImPlatform.sys
2014-09-15 10:34:31 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2014-09-15 10:34:30 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\twinapi.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\dwmapi.dll
2014-09-15 10:34:30 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2014-09-15 10:34:29 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2014-09-15 10:34:29 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-09-15 10:34:29 ----A---- C:\WINDOWS\system32\prnntfy.dll
2014-09-15 10:34:29 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2014-09-15 10:34:28 ----A---- C:\WINDOWS\system32\gpedit.dll
2014-09-15 10:34:27 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2014-09-15 10:34:27 ----A---- C:\WINDOWS\system32\puiapi.dll
2014-09-15 10:34:27 ----A---- C:\WINDOWS\system32\ppcsnap.dll
2014-09-15 10:34:26 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2014-09-15 10:34:26 ----A---- C:\WINDOWS\system32\iasnap.dll
2014-09-15 10:34:25 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2014-09-15 10:34:25 ----A---- C:\WINDOWS\SYSWOW64\SndVol.exe
2014-09-15 10:34:25 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2014-09-15 10:34:25 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-09-15 10:34:24 ----AC---- C:\WINDOWS\system32\drivers\pci.sys
2014-09-15 10:34:24 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-09-15 10:34:24 ----A---- C:\WINDOWS\system32\wups.dll
2014-09-15 10:34:23 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2014-09-15 10:34:22 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\stobject.dll
2014-09-15 10:34:22 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2014-09-15 10:34:21 ----A---- C:\WINDOWS\system32\wwanconn.dll
2014-09-15 10:34:21 ----A---- C:\WINDOWS\system32\dab.dll
2014-09-15 10:34:20 ----A---- C:\WINDOWS\SYSWOW64\iasnap.dll
2014-09-15 10:34:20 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2014-09-15 10:34:20 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-09-15 10:34:20 ----A---- C:\WINDOWS\system32\pmcsnap.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\system32\rsaenh.dll
2014-09-15 10:34:19 ----A---- C:\WINDOWS\system32\ActionCenter.dll
2014-09-15 10:34:18 ----A---- C:\WINDOWS\SYSWOW64\osk.exe
2014-09-15 10:34:18 ----A---- C:\WINDOWS\system32\wups2.dll
2014-09-15 10:34:18 ----A---- C:\WINDOWS\system32\wshbth.dll
2014-09-15 10:34:18 ----A---- C:\WINDOWS\system32\schannel.dll
2014-09-15 10:34:17 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2014-09-15 10:34:17 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2014-09-15 10:34:17 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-09-15 10:34:16 ----A---- C:\WINDOWS\system32\browser.dll
2014-09-15 10:34:15 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2014-09-15 10:34:14 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2014-09-15 10:34:14 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2014-09-15 10:34:13 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2014-09-15 10:34:13 ----A---- C:\WINDOWS\SYSWOW64\ActionCenter.dll
2014-09-15 10:34:13 ----A---- C:\WINDOWS\system32\Defrag.exe
2014-09-15 10:34:12 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-09-15 10:34:12 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2014-09-15 10:34:11 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-09-15 10:34:11 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-09-15 10:34:10 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2014-09-15 10:34:10 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2014-09-15 10:34:09 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2014-09-15 10:34:04 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2014-09-15 10:34:04 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\wwanmm.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\compstui.dll
2014-09-15 10:34:04 ----A---- C:\WINDOWS\system32\certcli.dll
2014-09-15 10:34:03 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2014-09-15 10:34:02 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-09-15 10:34:02 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-09-15 10:34:02 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-09-15 10:34:01 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-15 10:34:00 ----A---- C:\WINDOWS\SYSWOW64\KBDTT102.DLL
2014-09-15 10:34:00 ----A---- C:\WINDOWS\system32\KBDTT102.DLL
2014-09-15 10:27:50 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2014-09-14 19:42:40 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-09-14 19:42:40 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-09-14 19:42:38 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-09-14 19:42:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-09-14 19:42:37 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-09-14 19:42:33 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-09-14 19:42:32 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-09-14 19:42:31 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-09-14 19:42:31 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-14 19:42:31 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-09-14 19:42:31 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-09-14 19:42:30 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-09-14 19:42:28 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-09-14 19:42:28 ----A---- C:\WINDOWS\system32\wininet.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-09-14 19:42:27 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-09-14 19:42:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-09-14 19:42:26 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-09-14 19:42:25 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-09-14 19:42:25 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-09-14 19:42:25 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-09-11 10:00:44 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-09-11 09:58:23 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2014-09-11 09:58:22 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
======List of files/folders modified in the last 1 months======
2014-10-04 18:23:55 ----D---- C:\WINDOWS\Prefetch
2014-10-04 18:23:53 ----RD---- C:\Program Files
2014-10-04 18:21:48 ----D---- C:\WINDOWS\Temp
2014-10-04 18:11:19 ----D---- C:\WINDOWS\AppReadiness
2014-10-04 18:11:13 ----D---- C:\WINDOWS\system32\config
2014-10-04 18:02:43 ----D---- C:\WINDOWS\system32\sru
2014-10-04 17:15:25 ----D---- C:\ProgramData\MFAData
2014-10-04 16:20:08 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-03 20:01:59 ----D---- C:\ProgramData\firebird
2014-10-03 10:57:40 ----D---- C:\UCTO2014
2014-10-02 17:57:16 ----D---- C:\UCTO2013
2014-10-02 15:46:07 ----SHD---- C:\WINDOWS\Installer
2014-10-01 20:24:26 ----D---- C:\WINDOWS\Inf
2014-09-30 11:26:42 ----SHD---- C:\System Volume Information
2014-09-27 19:23:23 ----D---- C:\WINDOWS\System32
2014-09-27 19:23:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-27 19:16:15 ----D---- C:\WINDOWS\system32\wbem
2014-09-27 19:16:15 ----D---- C:\Windows
2014-09-27 19:11:22 ----D---- C:\Program Files\Internet Explorer
2014-09-27 19:11:22 ----D---- C:\Program Files\Common Files\microsoft shared
2014-09-27 19:11:22 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-27 19:11:21 ----D---- C:\Program Files\Windows Journal
2014-09-27 19:11:19 ----D---- C:\Users\name\AppData\Roaming\IrfanView
2014-09-27 19:11:18 ----D---- C:\WINDOWS\apppatch
2014-09-27 19:11:14 ----RSD---- C:\WINDOWS\Fonts
2014-09-27 19:11:14 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-27 19:11:10 ----RSD---- C:\WINDOWS\Media
2014-09-27 19:11:09 ----D---- C:\WINDOWS\schemas
2014-09-27 19:11:09 ----D---- C:\WINDOWS\rescache
2014-09-27 19:11:09 ----D---- C:\WINDOWS\PolicyDefinitions
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\migration
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\Macromed
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\drivers
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\cs-CZ
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\CodeIntegrity
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\catroot2
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\Bthprops
2014-09-27 19:11:08 ----D---- C:\WINDOWS\system32\Boot
2014-09-27 19:11:08 ----D---- C:\WINDOWS\ShellNew
2014-09-27 19:11:08 ----D---- C:\WINDOWS\servicing
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\Tasks
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\Sysprep
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\setup
2014-09-27 19:11:07 ----D---- C:\WINDOWS\system32\oobe
2014-09-27 19:11:06 ----D---- C:\WINDOWS\SysWOW64
2014-09-27 19:11:05 ----RD---- C:\WINDOWS\ToastData
2014-09-27 19:11:05 ----D---- C:\WINDOWS\Tasks
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\config
2014-09-27 19:11:05 ----D---- C:\WINDOWS\SYSWOW64\Bthprops
2014-09-27 19:11:04 ----D---- C:\WINDOWS\WinSxS
2014-09-27 19:11:04 ----D---- C:\WINDOWS\WinStore
2014-09-27 19:01:26 ----D---- C:\WINDOWS\registration
2014-09-27 17:58:24 ----D---- C:\WINDOWS\Logs
2014-09-21 12:58:09 ----D---- C:\WINDOWS\system32\DriverStore
2014-09-18 12:42:01 ----HD---- C:\Program Files\WindowsApps
2014-09-17 14:52:24 ----D---- C:\WINDOWS\CbsTemp
2014-09-17 13:15:11 ----D---- C:\ProgramData\AVG2014
2014-09-15 11:39:14 ----RSD---- C:\WINDOWS\assembly
2014-09-14 19:45:08 ----D---- C:\ProgramData\Microsoft Help
2014-09-14 19:43:13 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-09-14 19:43:12 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-14 19:43:01 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-09-14 19:43:00 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-09-14 19:42:59 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-09-14 19:42:58 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-09-14 19:42:58 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-09-14 19:42:57 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-09-14 19:42:57 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-09-14 19:42:55 ----A---- C:\WINDOWS\system32\msrating.dll
2014-09-14 19:42:52 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-09-14 19:42:23 ----D---- C:\WINDOWS\system32\MRT
2014-09-14 19:38:55 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======