Pomalé PC - Vytížení RAM - svchost.exe
Napsal: 14 kvě 2015 08:10
Zdravím, mám opět problém s dalším PC.
Po zapnutí je PC téměř nepoužitelné, neustále hrabe na disk. Zjištěno, že RAM (2GB) je využita stále na maximum, takže na disk stále ukládá stránkovací soubor (asi).
Problém je, že schvost.exe, který žere RAM (aktuálně 1,3 GB), je proces windows, takže se za ním může schovávat cokoli.
Třeba se vám podaří objevit něco, já zatím na nic nepřišel, co by to dělalo:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jana at 2015-05-14 09:01:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 16 GB (32%) free of 51 GB
Total RAM: 2047 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:01:32, on 14.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17801)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Jana.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1431586072
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: Hauppauge WinTV Extender - Hauppauge Computer Works, Inc - C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 6611 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
winlogon.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe"
"C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\WinTV\TVServer\CaptureGenPCI.exe" -Embedding
"C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe" -Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss e63c36eb-9be3-4f69-9682-97cab84a5ac3 1
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
\??\C:\Windows\system32\conhost.exe "67846070115270744341263554379-210719211976104840229500817551690842-422076988
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "203524602316467569671871550811614312802-1276388872-4496620572061804106-789600185
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1852 CREDAT:267521 /prefetch:2
"C:\Windows\System32\MsSpellCheckingFacility.exe" -Embedding
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1852 CREDAT:1053994 /prefetch:2
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Users\Jana\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Jana\AppData\Roaming\Mozilla\Firefox\Profiles\c1ro9vda.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-07-25 1283136]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Adobe Speed Launcher"=1431586072 []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-03 1021128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 2 months======
2015-05-14 09:01:20 ----D---- C:\Program Files\trend micro
2015-05-14 09:01:18 ----D---- C:\rsit
2015-05-13 20:30:27 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:30:27 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:18:23 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-13 20:18:23 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 20:18:23 ----A---- C:\Windows\system32\schannel.dll
2015-05-13 20:18:23 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-05-13 20:17:07 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-05-13 20:17:07 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-05-13 20:17:06 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-13 20:17:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-13 20:17:06 ----A---- C:\Windows\system32\iernonce.dll
2015-05-13 20:17:06 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-13 20:17:05 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 20:17:04 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-05-13 20:17:04 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\urlmon.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 20:17:03 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-13 20:17:02 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-13 20:17:02 ----A---- C:\Windows\system32\iesetup.dll
2015-05-13 20:17:01 ----A---- C:\Windows\system32\iertutil.dll
2015-05-13 20:17:01 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-13 20:17:00 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-13 20:17:00 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-05-13 20:17:00 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-13 20:17:00 ----A---- C:\Windows\system32\vbscript.dll
2015-05-13 20:17:00 ----A---- C:\Windows\system32\jsproxy.dll
2015-05-13 20:17:00 ----A---- C:\Windows\system32\ieUnatt.exe
2015-05-13 20:16:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-05-13 20:16:59 ----A---- C:\Windows\system32\ieui.dll
2015-05-13 20:16:59 ----A---- C:\Windows\system32\ieframe.dll
2015-05-13 20:16:59 ----A---- C:\Windows\system32\dxtmsft.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\jscript9diag.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\jscript9.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\jscript.dll
2015-05-13 20:16:57 ----A---- C:\Windows\system32\wininet.dll
2015-05-13 20:16:57 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-05-13 20:16:56 ----A---- C:\Windows\system32\msrating.dll
2015-05-13 20:16:56 ----A---- C:\Windows\system32\mshtml.dll
2015-05-13 20:15:35 ----A---- C:\Windows\system32\win32k.sys
2015-05-13 20:15:35 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 20:15:35 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 20:15:34 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 20:15:30 ----A---- C:\Windows\system32\services.exe
2015-05-13 20:15:22 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 20:15:22 ----A---- C:\Windows\system32\InkEd.dll
2015-05-12 22:04:20 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-05-11 16:56:50 ----A---- C:\Windows\system32\UtcResources.dll
2015-05-11 16:56:50 ----A---- C:\Windows\system32\diagtrack.dll
2015-05-11 16:56:49 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-05-11 16:56:49 ----A---- C:\Windows\system32\ntdll.dll
2015-05-11 16:56:48 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-05-11 16:56:48 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-05-11 16:56:48 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-05-11 16:56:48 ----A---- C:\Windows\system32\tdh.dll
2015-05-11 16:56:48 ----A---- C:\Windows\system32\advapi32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\wow64.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\tracerpt.exe
2015-05-11 16:56:46 ----A---- C:\Windows\system32\srcore.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\sechost.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\msv1_0.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\logman.exe
2015-05-11 16:56:46 ----A---- C:\Windows\system32\KernelBase.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\kernel32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-05-11 16:56:46 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-05-11 16:56:45 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-11 16:56:45 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-11 16:56:45 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\wow64win.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\wow64cpu.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\winsrv.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\wdigest.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\typeperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\TSpkg.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\sspisrv.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\sspicli.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\srclient.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\smss.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\secur32.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\rstrui.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\relog.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\ntvdm64.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\ncrypt.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\lsass.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\kerberos.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\diskperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\csrsrv.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\credssp.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\conhost.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\auditpol.exe
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\user.exe
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\msobjs.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\msaudite.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\apisetschema.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\adtschema.dll
2015-05-11 16:56:31 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-11 16:56:31 ----A---- C:\Windows\system32\poqexec.exe
2015-05-11 16:56:30 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-05-11 16:56:30 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-05-11 16:56:30 ----A---- C:\Windows\system32\dwmcore.dll
2015-05-11 16:56:30 ----A---- C:\Windows\system32\dwmapi.dll
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\shimeng.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\sdbinst.exe
2015-05-11 16:56:28 ----A---- C:\Windows\system32\apphelp.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-06 20:41:12 ----D---- C:\Program Files\ImageJ
2015-04-29 19:48:07 ----D---- C:\ImageJ
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wups2.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wups.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wudriver.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wucltux.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuapp.exe
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuapi.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-15 14:15:54 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-15 14:15:54 ----A---- C:\Windows\system32\gdi32.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\invagent.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\generaltel.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\devinv.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\appraiser.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\aepic.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\aepdu.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\aeinv.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\acmigration.dll
2015-04-15 14:15:51 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-15 14:15:51 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-15 14:15:51 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-15 14:15:51 ----A---- C:\Windows\system32\msxml3.dll
2015-04-15 14:13:36 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-15 14:13:06 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-15 14:13:06 ----A---- C:\Windows\system32\clfs.sys
2015-04-15 14:13:05 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-14 03:38:52 ----A---- C:\Windows\SYSWOW64\FM20.DLL
2015-04-06 22:52:43 ----SD---- C:\Windows\SYSWOW64\GWX
2015-04-06 22:52:42 ----SD---- C:\Windows\system32\GWX
======List of files/folders modified in the last 2 months======
2015-05-14 09:01:32 ----D---- C:\Windows\Prefetch
2015-05-14 09:01:25 ----D---- C:\Windows\Temp
2015-05-14 09:01:20 ----RD---- C:\Program Files
2015-05-14 08:51:14 ----D---- C:\Windows\system32\config
2015-05-14 08:48:32 ----D---- C:\Windows\Tasks
2015-05-14 08:47:28 ----D---- C:\ProgramData\NVIDIA
2015-05-13 22:15:23 ----D---- C:\Windows\Microsoft.NET
2015-05-13 22:13:13 ----RSD---- C:\Windows\assembly
2015-05-13 21:26:53 ----D---- C:\Windows\winsxs
2015-05-13 21:25:40 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-13 21:25:39 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2015-05-13 21:24:28 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-05-13 21:24:28 ----D---- C:\Windows\SysWOW64
2015-05-13 21:24:28 ----D---- C:\Windows\system32\cs-CZ
2015-05-13 21:24:28 ----D---- C:\Windows\System32
2015-05-13 21:24:28 ----D---- C:\Program Files\Internet Explorer
2015-05-13 21:24:27 ----D---- C:\Windows\system32\en-US
2015-05-13 21:24:27 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-13 20:45:51 ----SHD---- C:\Windows\Installer
2015-05-13 20:45:49 ----D---- C:\ProgramData\Microsoft Help
2015-05-13 20:44:18 ----D---- C:\Windows\system32\MRT
2015-05-13 20:39:25 ----A---- C:\Windows\system32\MRT.exe
2015-05-13 20:27:09 ----SHD---- C:\System Volume Information
2015-05-13 20:07:38 ----D---- C:\Windows\system32\catroot2
2015-05-13 19:24:18 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-12 22:04:40 ----RD---- C:\Program Files (x86)
2015-05-11 22:47:49 ----D---- C:\Users\Jana\AppData\Roaming\Skype
2015-05-11 18:47:07 ----D---- C:\Windows\inf
2015-05-11 18:47:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-05-11 18:45:27 ----D---- C:\Windows\rescache
2015-05-11 17:02:48 ----D---- C:\Windows\AppPatch
2015-05-11 17:02:47 ----D---- C:\Windows\system32\drivers
2015-05-11 17:02:47 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-11 17:02:42 ----D---- C:\Windows\system32\DriverStore
2015-05-11 16:27:02 ----D---- C:\Windows
2015-04-15 22:56:52 ----D---- C:\Windows\AppCompat
2015-04-15 14:35:21 ----SD---- C:\Windows\system32\CompatTel
2015-04-15 14:35:21 ----D---- C:\Windows\system32\appraiser
2015-04-15 14:35:21 ----D---- C:\Windows\PolicyDefinitions
2015-04-15 14:31:39 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 22:52:51 ----D---- C:\Windows\Logs
2015-03-26 08:51:52 ----D---- C:\Windows\system32\wbem
2015-03-15 10:52:29 ----D---- C:\Windows\system32\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-11-29 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture; C:\Windows\system32\drivers\hcw88aud.sys [2012-11-20 16128]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod; C:\Windows\system32\drivers\hcw88bda.sys [2012-11-20 259456]
R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder; C:\Windows\System32\Drivers\hcw88rc5.sys [2012-11-20 15872]
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture; C:\Windows\system32\drivers\hcw88tse.sys [2012-11-20 339968]
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner; C:\Windows\system32\drivers\hcw88tun.sys [2012-11-20 111232]
R3 hcw88vid;Hauppauge WinTV 88x Video; C:\Windows\system32\drivers\hcw88vid.sys [2012-11-20 440576]
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar; C:\Windows\system32\drivers\HCW88BAR.sys [2012-11-20 21632]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-07-25 20256]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
S1 Uim_IM;Universal Image Mounter Plugin; C:\Windows\System32\Drivers\Uim_IMx64.sys [2012-11-22 633680]
S1 UimBus;Universal Image Mounter Controller; C:\Windows\system32\DRIVERS\uimx64.sys [2012-11-22 90960]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 Hauppauge WinTV Extender;Hauppauge WinTV Extender; C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe [2013-08-07 59392]
R2 HauppaugeTVServer;HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [2013-08-31 582144]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-07-25 1720608]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-07-25 18956064]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-07-02 935368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-21 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-12 148080]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------
Po zapnutí je PC téměř nepoužitelné, neustále hrabe na disk. Zjištěno, že RAM (2GB) je využita stále na maximum, takže na disk stále ukládá stránkovací soubor (asi).
Problém je, že schvost.exe, který žere RAM (aktuálně 1,3 GB), je proces windows, takže se za ním může schovávat cokoli.
Třeba se vám podaří objevit něco, já zatím na nic nepřišel, co by to dělalo:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jana at 2015-05-14 09:01:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 16 GB (32%) free of 51 GB
Total RAM: 2047 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:01:32, on 14.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17801)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Jana.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1431586072
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: Hauppauge WinTV Extender - Hauppauge Computer Works, Inc - C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 6611 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
winlogon.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe"
"C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\WinTV\TVServer\CaptureGenPCI.exe" -Embedding
"C:\Program Files (x86)\WinTV\TVServer\CaptureDLNA.exe" -Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss e63c36eb-9be3-4f69-9682-97cab84a5ac3 1
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
\??\C:\Windows\system32\conhost.exe "67846070115270744341263554379-210719211976104840229500817551690842-422076988
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "203524602316467569671871550811614312802-1276388872-4496620572061804106-789600185
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1852 CREDAT:267521 /prefetch:2
"C:\Windows\System32\MsSpellCheckingFacility.exe" -Embedding
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1852 CREDAT:1053994 /prefetch:2
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Users\Jana\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Jana\AppData\Roaming\Mozilla\Firefox\Profiles\c1ro9vda.default
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.305 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-09-12 5618456]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-07-25 1283136]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Adobe Speed Launcher"=1431586072 []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-03 1021128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 2 months======
2015-05-14 09:01:20 ----D---- C:\Program Files\trend micro
2015-05-14 09:01:18 ----D---- C:\rsit
2015-05-13 20:30:27 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:30:27 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 20:18:23 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-13 20:18:23 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 20:18:23 ----A---- C:\Windows\system32\schannel.dll
2015-05-13 20:18:23 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-05-13 20:17:07 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-05-13 20:17:07 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-05-13 20:17:07 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-05-13 20:17:06 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-13 20:17:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-13 20:17:06 ----A---- C:\Windows\system32\iernonce.dll
2015-05-13 20:17:06 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-05-13 20:17:05 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-13 20:17:05 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 20:17:04 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-05-13 20:17:04 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-13 20:17:03 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\urlmon.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 20:17:03 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-13 20:17:03 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-13 20:17:02 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-13 20:17:02 ----A---- C:\Windows\system32\iesetup.dll
2015-05-13 20:17:01 ----A---- C:\Windows\system32\iertutil.dll
2015-05-13 20:17:01 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-13 20:17:00 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-13 20:17:00 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-05-13 20:17:00 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-13 20:17:00 ----A---- C:\Windows\system32\vbscript.dll
2015-05-13 20:17:00 ----A---- C:\Windows\system32\jsproxy.dll
2015-05-13 20:17:00 ----A---- C:\Windows\system32\ieUnatt.exe
2015-05-13 20:16:59 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-05-13 20:16:59 ----A---- C:\Windows\system32\ieui.dll
2015-05-13 20:16:59 ----A---- C:\Windows\system32\ieframe.dll
2015-05-13 20:16:59 ----A---- C:\Windows\system32\dxtmsft.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\jscript9diag.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\jscript9.dll
2015-05-13 20:16:58 ----A---- C:\Windows\system32\jscript.dll
2015-05-13 20:16:57 ----A---- C:\Windows\system32\wininet.dll
2015-05-13 20:16:57 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-05-13 20:16:56 ----A---- C:\Windows\system32\msrating.dll
2015-05-13 20:16:56 ----A---- C:\Windows\system32\mshtml.dll
2015-05-13 20:15:35 ----A---- C:\Windows\system32\win32k.sys
2015-05-13 20:15:35 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 20:15:35 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 20:15:34 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 20:15:30 ----A---- C:\Windows\system32\services.exe
2015-05-13 20:15:22 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 20:15:22 ----A---- C:\Windows\system32\InkEd.dll
2015-05-12 22:04:20 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-05-11 16:56:50 ----A---- C:\Windows\system32\UtcResources.dll
2015-05-11 16:56:50 ----A---- C:\Windows\system32\diagtrack.dll
2015-05-11 16:56:49 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-05-11 16:56:49 ----A---- C:\Windows\system32\ntdll.dll
2015-05-11 16:56:48 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-05-11 16:56:48 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-05-11 16:56:48 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-05-11 16:56:48 ----A---- C:\Windows\system32\tdh.dll
2015-05-11 16:56:48 ----A---- C:\Windows\system32\advapi32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\wow64.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\tracerpt.exe
2015-05-11 16:56:46 ----A---- C:\Windows\system32\srcore.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\sechost.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\msv1_0.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\logman.exe
2015-05-11 16:56:46 ----A---- C:\Windows\system32\KernelBase.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\kernel32.dll
2015-05-11 16:56:46 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-05-11 16:56:46 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-05-11 16:56:45 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-11 16:56:45 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-11 16:56:45 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-05-11 16:56:45 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\wow64win.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\wow64cpu.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\winsrv.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\wdigest.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\typeperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\TSpkg.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\sspisrv.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\sspicli.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\srclient.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\smss.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\secur32.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\rstrui.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\relog.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\ntvdm64.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\ncrypt.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\lsass.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\kerberos.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\diskperf.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\csrsrv.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\credssp.dll
2015-05-11 16:56:45 ----A---- C:\Windows\system32\conhost.exe
2015-05-11 16:56:45 ----A---- C:\Windows\system32\auditpol.exe
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-11 16:56:44 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\user.exe
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-05-11 16:56:44 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\msobjs.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\msaudite.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\apisetschema.dll
2015-05-11 16:56:44 ----A---- C:\Windows\system32\adtschema.dll
2015-05-11 16:56:31 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-11 16:56:31 ----A---- C:\Windows\system32\poqexec.exe
2015-05-11 16:56:30 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-05-11 16:56:30 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-05-11 16:56:30 ----A---- C:\Windows\system32\dwmcore.dll
2015-05-11 16:56:30 ----A---- C:\Windows\system32\dwmapi.dll
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-11 16:56:28 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\shimeng.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\sdbinst.exe
2015-05-11 16:56:28 ----A---- C:\Windows\system32\apphelp.dll
2015-05-11 16:56:28 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-06 20:41:12 ----D---- C:\Program Files\ImageJ
2015-04-29 19:48:07 ----D---- C:\ImageJ
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-04-15 14:16:27 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuwebv.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wups2.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wups.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wudriver.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wucltux.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuaueng.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuauclt.exe
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuapp.exe
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wuapi.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 14:16:27 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-04-15 14:15:54 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-04-15 14:15:54 ----A---- C:\Windows\system32\gdi32.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\invagent.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\generaltel.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\devinv.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\appraiser.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\aepic.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\aepdu.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\aeinv.dll
2015-04-15 14:15:52 ----A---- C:\Windows\system32\acmigration.dll
2015-04-15 14:15:51 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-04-15 14:15:51 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-04-15 14:15:51 ----A---- C:\Windows\system32\msxml3r.dll
2015-04-15 14:15:51 ----A---- C:\Windows\system32\msxml3.dll
2015-04-15 14:13:36 ----A---- C:\Windows\system32\drivers\http.sys
2015-04-15 14:13:06 ----A---- C:\Windows\system32\clfsw32.dll
2015-04-15 14:13:06 ----A---- C:\Windows\system32\clfs.sys
2015-04-15 14:13:05 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-04-14 03:38:52 ----A---- C:\Windows\SYSWOW64\FM20.DLL
2015-04-06 22:52:43 ----SD---- C:\Windows\SYSWOW64\GWX
2015-04-06 22:52:42 ----SD---- C:\Windows\system32\GWX
======List of files/folders modified in the last 2 months======
2015-05-14 09:01:32 ----D---- C:\Windows\Prefetch
2015-05-14 09:01:25 ----D---- C:\Windows\Temp
2015-05-14 09:01:20 ----RD---- C:\Program Files
2015-05-14 08:51:14 ----D---- C:\Windows\system32\config
2015-05-14 08:48:32 ----D---- C:\Windows\Tasks
2015-05-14 08:47:28 ----D---- C:\ProgramData\NVIDIA
2015-05-13 22:15:23 ----D---- C:\Windows\Microsoft.NET
2015-05-13 22:13:13 ----RSD---- C:\Windows\assembly
2015-05-13 21:26:53 ----D---- C:\Windows\winsxs
2015-05-13 21:25:40 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-13 21:25:39 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-13 21:24:28 ----D---- C:\Windows\SYSWOW64\en-US
2015-05-13 21:24:28 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-05-13 21:24:28 ----D---- C:\Windows\SysWOW64
2015-05-13 21:24:28 ----D---- C:\Windows\system32\cs-CZ
2015-05-13 21:24:28 ----D---- C:\Windows\System32
2015-05-13 21:24:28 ----D---- C:\Program Files\Internet Explorer
2015-05-13 21:24:27 ----D---- C:\Windows\system32\en-US
2015-05-13 21:24:27 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-13 20:45:51 ----SHD---- C:\Windows\Installer
2015-05-13 20:45:49 ----D---- C:\ProgramData\Microsoft Help
2015-05-13 20:44:18 ----D---- C:\Windows\system32\MRT
2015-05-13 20:39:25 ----A---- C:\Windows\system32\MRT.exe
2015-05-13 20:27:09 ----SHD---- C:\System Volume Information
2015-05-13 20:07:38 ----D---- C:\Windows\system32\catroot2
2015-05-13 19:24:18 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-12 22:04:40 ----RD---- C:\Program Files (x86)
2015-05-11 22:47:49 ----D---- C:\Users\Jana\AppData\Roaming\Skype
2015-05-11 18:47:07 ----D---- C:\Windows\inf
2015-05-11 18:47:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-05-11 18:45:27 ----D---- C:\Windows\rescache
2015-05-11 17:02:48 ----D---- C:\Windows\AppPatch
2015-05-11 17:02:47 ----D---- C:\Windows\system32\drivers
2015-05-11 17:02:47 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-11 17:02:42 ----D---- C:\Windows\system32\DriverStore
2015-05-11 16:27:02 ----D---- C:\Windows
2015-04-15 22:56:52 ----D---- C:\Windows\AppCompat
2015-04-15 14:35:21 ----SD---- C:\Windows\system32\CompatTel
2015-04-15 14:35:21 ----D---- C:\Windows\system32\appraiser
2015-04-15 14:35:21 ----D---- C:\Windows\PolicyDefinitions
2015-04-15 14:31:39 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-04-06 22:52:51 ----D---- C:\Windows\Logs
2015-03-26 08:51:52 ----D---- C:\Windows\system32\wbem
2015-03-15 10:52:29 ----D---- C:\Windows\system32\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-11-29 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 239320]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 168256]
R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture; C:\Windows\system32\drivers\hcw88aud.sys [2012-11-20 16128]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 157432]
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod; C:\Windows\system32\drivers\hcw88bda.sys [2012-11-20 259456]
R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder; C:\Windows\System32\Drivers\hcw88rc5.sys [2012-11-20 15872]
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture; C:\Windows\system32\drivers\hcw88tse.sys [2012-11-20 339968]
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner; C:\Windows\system32\drivers\hcw88tun.sys [2012-11-20 111232]
R3 hcw88vid;Hauppauge WinTV 88x Video; C:\Windows\system32\drivers\hcw88vid.sys [2012-11-20 440576]
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar; C:\Windows\system32\drivers\HCW88BAR.sys [2012-11-20 21632]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-07-25 20256]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
S1 Uim_IM;Universal Image Mounter Plugin; C:\Windows\System32\Drivers\Uim_IMx64.sys [2012-11-22 633680]
S1 UimBus;Universal Image Mounter Controller; C:\Windows\system32\DRIVERS\uimx64.sys [2012-11-22 90960]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2013-09-12 1337752]
R2 Hauppauge WinTV Extender;Hauppauge WinTV Extender; C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe [2013-08-07 59392]
R2 HauppaugeTVServer;HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [2013-08-31 582144]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-07-25 1720608]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-07-25 18956064]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-07-02 935368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-21 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-12 148080]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-29 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------