Kontrola logu
Napsal: 21 srp 2015 02:38
Poprosím o kontrolu logu, nemůžu se zbavit malwaru conduitu. Použil jsem adware cleaner, ale po resetu je v registru znovu. Děkuji.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2015-08-21 03:27:05
Microsoft Windows 10 Pro
System drive C: has 96 GB (42%) free of 228 GB
Total RAM: 3071 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:27:28, on 21.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\TC UP\TC UP.exe
C:\Program Files (x86)\TC UP\TOTALCMD.EXE
C:\Program Files (x86)\Webteh\BSplayerPro\bsplayer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O4 - HKLM\..\Run: [TC UP] "C:\Program Files (x86)\TC UP\TC UP.exe" /wnd=max
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Martin Rejn\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /AUTO
O4 - HKCU\..\Run: [ACDSeeCommanderUltimate8] C:\Program Files\ACD Systems\ACDSee Ultimate\8.0\ACDSeeCommanderUltimate8.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8AD29032B93C7CEDF313371CC9288ABE] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Linky na tuto stránku - C:\ProgramData\AVG\AWL2015\Web\gbacklinks.htm
O8 - Extra context menu item: &Podobné stránky - C:\ProgramData\AVG\AWL2015\Web\gsimilar.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Hledat pomocí &Google - C:\ProgramData\AVG\AWL2015\Web\gsearch.htm
O8 - Extra context menu item: Přeložit tuto stránku pomocí Google - C:\ProgramData\AVG\AWL2015\Web\gtranslate.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMSEmulator - MDL Forum, mod by Ratiborus - C:\Windows\KMS\bin\KMSSS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - @ByELDI - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11823 bytes
======Listing Processes======
C:\Windows\system32\lsass.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-80a6b3a3-d5b2-4254-993c-97fd85a09926 -SystemEventPortName:HostProcess-a43085bf-cafc-4ecd-8521-d2b5f6aa595a -IoCancelEventPortName:HostProcess-819e6887-5e99-407c-9c2c-e80f66a42ff3 -NonStateChangingEventPortName:HostProcess-a9edb4ba-0bc4-4cb5-81c6-6be17a890ab2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:465e8403-ed86-4d57-8e3e-55910d7abb58 -DeviceGroupId:WpdFsGroup
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe" /StartService
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\KMSpico\Service_KMS.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 7368c8b2-4f0d-4ea0-9e74-2bfa887493fb
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
dashost.exe {172aa3f7-433d-444f-b0710f9720dcc63f}
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\Windows\system32\conhost.exe 0x4
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2696
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" gpureading
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Martin Rejn\AppData\Local\Steam\htmlcache" -steampid 1076 -buildid 1440016726 -steamid "0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-direct-write
"C:\Program Files (x86)\TC UP\TC UP.exe" /wnd=max
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\TC UP\TOTALCMD.EXE" /i="C:\Program Files (x86)\TC UP\wincmd.ini" /wnd=max
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\Program Files (x86)\Webteh\BSplayerPro\bsplayer.exe" "C:\Mp3\Katapult - Best of\13 - Katapult - Hlupák váhá.mp3"
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\System32\svchost.exe -k smphost
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Internet downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin Rejn\AppData\Roaming\Mozilla\Firefox\Profiles\p1na36y7.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "chrome://speeddial/content/speeddial.xul"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.60.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.60.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL
C:\Users\Martin Rejn\AppData\Roaming\Mozilla\Firefox\Profiles\p1na36y7.default\extensions\
fastestsearch@mingyi.org
zigboom@hotmail.com
{0545b830-f0aa-4d7e-8820-50a4629a56fe}
{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2015-08-14 226984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-08-20 551520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2015-08-14 2167928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-20 212576]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2015-08-14 162888]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2015-08-14 1513592]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5595848]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-08-09 13885696]
"ACUW08EN"=C:\Program Files\ACD Systems\ACDSee Ultimate\8.0\acdIDInTouch2.exe [2015-02-03 1814800]
"Cm108Sound"=C:\Windows\syswow64\RunDll32.exe [2015-07-10 53760]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-08-07 2634896]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-08-07 1710568]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Martin Rejn\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-09 402632]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2015-08-19 2899136]
"CCleaner"=C:\Program Files (x86)\CCleaner\CCleaner64.exe [2015-07-17 8418584]
"ACDSeeCommanderUltimate8"=C:\Program Files\ACD Systems\ACDSee Ultimate\8.0\ACDSeeCommanderUltimate8.exe [2015-05-06 2054664]
"uTorrent"=C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe [2015-02-22 416168]
"DAEMON Tools Ultra Agent"=C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [2015-08-06 4526424]
"GoogleChromeAutoLaunch_8AD29032B93C7CEDF313371CC9288ABE"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-08-08 813896]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TC UP"=C:\Program Files (x86)\TC UP\TC UP.exe [2015-06-09 675328]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-08-04 597552]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
"NoDriveAutoRun"=67108851
"NoDrives"=0x00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acdseeultimate8.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amd overdrive.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccleaner.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccleaner64.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtagent.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtimgeditor.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtlauncher.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtpro.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lync.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoev.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msotd.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocpubmgr.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
"Debugger="C:\Program Files (x86)\AVG\AVG PC TuneUp\PMLauncher.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\visio.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winproj.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"vidc.x264"=x264vfw.dll
"msacm.ac3filter"=ac3filter.acm
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
======File associations======
.inf - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\Notepad++\notepad++.exe" "%1"
.inf - install -
.ini - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\Notepad++\notepad++.exe" "%1"
.js - edit -
.js - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\HateML\HateML.exe" "%1"
.txt - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\Notepad++\notepad++.exe" "%1"
======List of files/folders created in the last 1 month======
2015-08-21 03:27:05 ----D---- C:\rsit
2015-08-21 03:27:05 ----D---- C:\Program Files\trend micro
2015-08-20 23:45:20 ----D---- C:\AdwCleaner
2015-08-20 22:16:41 ----SHD---- C:\Config.Msi
2015-08-20 02:07:32 ----D---- C:\Users\Martin Rejn\AppData\Roaming\NVIDIA
2015-08-20 01:33:27 ----D---- C:\Program Files (x86)\AMD
2015-08-19 22:51:17 ----D---- C:\NVIDIA
2015-08-19 22:26:49 ----HD---- C:\Windows\Icons
2015-08-19 17:17:17 ----D---- C:\Windows\rescache
2015-08-19 08:48:10 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2015-08-19 08:48:10 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2015-08-19 08:48:10 ----A---- C:\Windows\system32\nvspcap64.dll
2015-08-19 08:48:10 ----A---- C:\Windows\system32\nvspbridge64.dll
2015-08-19 08:47:34 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-08-19 08:46:48 ----D---- C:\Windows\LastGood.Tmp
2015-08-19 06:00:23 ----D---- C:\Temp
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvvsvc.exe
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvsvcr.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvsvc64.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvshext.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvmctray.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvcpl.dll
2015-08-19 05:59:13 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2015-08-19 05:59:13 ----A---- C:\Windows\system32\OpenCL.dll
2015-08-19 05:55:03 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-08-19 05:55:03 ----A---- C:\Windows\system32\nvhdap64.dll
2015-08-19 05:55:03 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2015-08-19 05:55:03 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvopencl.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvoglv64.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvinitx.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\NvIFR64.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\NvFBC64.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvdispgenco6435560.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvdispco6435560.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvcuvid.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvcuda.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvcompiler.dll
2015-08-19 05:54:59 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-08-19 05:54:59 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-08-19 05:54:59 ----A---- C:\Windows\system32\nvapi64.dll
2015-08-19 04:48:30 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Oracle
2015-08-19 04:46:47 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Sun
2015-08-19 00:39:51 ----D---- C:\Users\Martin Rejn\AppData\Roaming\XnView
2015-08-19 00:36:45 ----A---- C:\Windows\system32\drivers\dtultrausbbus.sys
2015-08-19 00:36:41 ----A---- C:\Windows\system32\drivers\dtultrascsibus.sys
2015-08-19 00:36:40 ----D---- C:\Users\Martin Rejn\AppData\Roaming\DAEMON Tools Ultra
2015-08-19 00:36:33 ----D---- C:\Program Files\DAEMON Tools Ultra
2015-08-19 00:35:46 ----D---- C:\ProgramData\DAEMON Tools Ultra
2015-08-18 23:55:46 ----A---- C:\Windows\system32\mshtml.dll
2015-08-18 23:55:45 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-18 23:55:44 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-18 23:55:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-18 23:55:41 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-18 23:55:40 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-18 23:55:38 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-18 23:55:38 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-18 23:55:38 ----A---- C:\Windows\system32\tquery.dll
2015-08-18 23:55:38 ----A---- C:\Windows\system32\mssrch.dll
2015-08-18 23:55:38 ----A---- C:\Windows\explorer.exe
2015-08-18 23:55:37 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-18 23:55:37 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-18 23:55:37 ----A---- C:\Windows\system32\Chakra.dll
2015-08-18 23:55:37 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-18 23:55:36 ----A---- C:\Windows\system32\wlidsvc.dll
2015-08-18 23:55:36 ----A---- C:\Windows\system32\iertutil.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\RDXService.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-18 23:55:35 ----A---- C:\Windows\system32\InputService.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\directmanipulation.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-18 23:55:34 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\mfplat.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\MbaeApiPublic.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\LocationPermissions.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\directmanipulation.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\UserMgrProxy.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\OneDriveSettingSyncProvider.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\MbaeApiPublic.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\AppXDeploymentClient.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\wuautoappupdate.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\UserMgrProxy.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\TextInputFramework.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\tetheringclient.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\sysmain.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\syncutil.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-08-18 23:55:33 ----A---- C:\Windows\system32\rdbui.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\OneDriveSettingSyncProvider.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-18 23:55:33 ----A---- C:\Windows\system32\mfcore.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\MbaeParserTask.exe
2015-08-18 23:55:33 ----A---- C:\Windows\system32\LocationGeofences.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\LocationFramework.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\enterprisecsps.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\drivers\storport.sys
2015-08-18 23:55:33 ----A---- C:\Windows\system32\drivers\stornvme.sys
2015-08-18 23:55:33 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\Windows.UI.Core.TextInput.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\tetheringclient.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-18 23:55:32 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-18 23:55:32 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-18 23:55:32 ----A---- C:\Windows\system32\LocationFrameworkInternalPS.dll
2015-08-18 23:55:32 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-18 23:09:55 ----D---- C:\Windows\Minidump
2015-08-18 22:57:11 ----A---- C:\Windows\system32\nvexpBar.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\nvcplUIR.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\nvcplUI.exe
2015-08-18 22:57:11 ----A---- C:\Windows\system32\msvcr71.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\msvcp71.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\MFC71.dll
2015-08-18 22:56:26 ----D---- C:\Program Files (x86)\NVIDIA nTune Performance Application
2015-08-18 22:33:12 ----N---- C:\Windows\Vmix108.dll
2015-08-18 22:33:12 ----N---- C:\Windows\SYSWOW64\cmpa108.dll
2015-08-18 22:33:12 ----N---- C:\Windows\SYSWOW64\CM108.dll
2015-08-18 22:33:12 ----N---- C:\Windows\system32\Cmeau108.exe
2015-08-18 22:33:00 ----A---- C:\Windows\system32\drivers\CM10864.sys
2015-08-18 22:32:58 ----RA---- C:\Windows\difxapi.dll
2015-08-18 22:32:58 ----N---- C:\Windows\system32\CmiInstallResAll64.dll
2015-08-18 22:32:58 ----N---- C:\Windows\cm108.ini
2015-08-18 22:18:18 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Convertilla
2015-08-18 22:18:10 ----AD---- C:\Program Files (x86)\Convertilla
2015-08-18 20:37:22 ----D---- C:\ProgramData\StartMenuReviver.exe
2015-08-18 20:37:05 ----D---- C:\Users\Martin Rejn\AppData\Roaming\MetroSidebar
2015-08-18 19:36:58 ----A---- C:\Windows\system32\drivers\i8042HDR.sys
2015-08-18 19:27:16 ----AD---- C:\Program Files\SmartTechnology
2015-08-17 18:21:50 ----D---- C:\Users\Martin Rejn\AppData\Roaming\PDM
2015-08-17 18:21:13 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-08-17 18:21:13 ----D---- C:\Program Files (x86)\Palm
2015-08-17 04:18:28 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Might & Magic Heroes VI
2015-08-17 04:18:28 ----D---- C:\ProgramData\Orbit
2015-08-17 04:16:40 ----D---- C:\Windows\SYSWOW64\directx
2015-08-17 03:58:11 ----D---- C:\Games Install
2015-08-17 03:50:57 ----D---- C:\Users\Martin Rejn\AppData\Roaming\DAEMON Tools iSCSI Target
2015-08-17 03:48:38 ----A---- C:\Windows\system32\drivers\dtproscsibus.sys
2015-08-17 03:43:10 ----A---- C:\Windows\system32\drivers\sptd2.sys
2015-08-17 00:59:26 ----A---- C:\Windows\SYSWOW64\NlsLexicons0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\SYSWOW64\NlsData0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\system32\prm0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\system32\NlsData0009.dll
2015-08-17 00:35:00 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2015-08-17 00:35:00 ----A---- C:\Windows\system32\TURegOpt.exe
2015-08-17 00:35:00 ----A---- C:\Windows\system32\authuitu.dll
2015-08-17 00:34:29 ----D---- C:\Users\Martin Rejn\AppData\Roaming\AVG
2015-08-17 00:34:16 ----D---- C:\Program Files (x86)\AVG
2015-08-17 00:14:44 ----D---- C:\GamesUpdate
2015-08-17 00:14:16 ----D---- C:\Users\Martin Rejn\AppData\Roaming\HateML
2015-08-17 00:02:10 ----D---- C:\ProgramData\Package Cache
2015-08-16 21:37:17 ----D---- C:\Users\Martin Rejn\AppData\Roaming\ACD Systems
2015-08-16 21:36:47 ----D---- C:\ProgramData\ACD Systems
2015-08-16 21:36:36 ----AD---- C:\Program Files\Common Files\ACD Systems
2015-08-16 21:36:36 ----AD---- C:\Program Files\ACD Systems
2015-08-16 21:28:37 ----D---- C:\Program Files\VideoLAN
2015-08-16 21:22:38 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Totusoft
2015-08-16 21:22:35 ----AD---- C:\Program Files (x86)\LAN Speed Test
2015-08-16 20:25:56 ----D---- C:\Users\Martin Rejn\AppData\Roaming\HEXelon
2015-08-16 20:22:38 ----RD---- C:\Program Files (x86)\TC UP
2015-08-16 20:07:23 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Internet Download Accelerator
2015-08-16 20:02:28 ----HD---- C:\ProgramData\Common Files
2015-08-16 20:02:25 ----D---- C:\ProgramData\AVG
2015-08-16 19:20:39 ----D---- C:\Mp3
2015-08-16 18:35:12 ----AD---- C:\Program Files (x86)\Windows Phone
2015-08-16 18:34:57 ----D---- C:\ProgramData\Applications
2015-08-16 18:14:21 ----AD---- C:\Program Files (x86)\CCleaner
2015-08-16 18:13:44 ----D---- C:\Users\Martin Rejn\AppData\Roaming\CCleaner
2015-08-16 17:59:19 ----D---- C:\ProgramData\VS Revo Group
2015-08-16 17:59:18 ----A---- C:\Windows\system32\drivers\revoflt.sys
2015-08-16 17:59:15 ----D---- C:\Program Files\VS Revo Group
2015-08-16 16:50:57 ----D---- C:\Users\Martin Rejn\AppData\Roaming\TeamViewer
2015-08-16 16:50:47 ----AD---- C:\Program Files (x86)\TeamViewer
2015-08-16 01:15:39 ----D---- C:\Program Files (x86)\FinalWire
2015-08-16 00:29:37 ----D---- C:\ProgramData\IObit
2015-08-16 00:29:37 ----A---- C:\Windows\SYSWOW64\drivers\HWiNFO64A.SYS
2015-08-16 00:29:36 ----D---- C:\Users\Martin Rejn\AppData\Roaming\IObit
2015-08-16 00:28:27 ----D---- C:\Internet downloads
2015-08-15 23:37:16 ----RD---- C:\Users\Martin Rejn\AppData\Roaming\Brother
2015-08-15 20:16:25 ----D---- C:\Program Files\7-Zip
2015-08-15 18:36:53 ----D---- C:\Users\Martin Rejn\AppData\Roaming\java
2015-08-15 18:36:14 ----D---- C:\ProgramData\Sun
2015-08-15 18:36:09 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2015-08-15 18:34:33 ----D---- C:\ProgramData\Oracle
2015-08-15 18:34:31 ----D---- C:\Program Files\Java
2015-08-15 18:30:02 ----D---- C:\Users\Martin Rejn\AppData\Roaming\.minecraft
2015-08-15 18:20:27 ----D---- C:\Clips
2015-08-15 18:12:21 ----A---- C:\Windows\system32\VSFilter.dll.bak
2015-08-15 18:12:20 ----A---- C:\Windows\system32\WMPDMC.exe.bak
2015-08-15 18:12:11 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe.bak
2015-08-15 18:12:04 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll.bak
2015-08-15 18:12:03 ----A---- C:\Windows\SYSWOW64\mfds.dll.bak
2015-08-15 18:11:58 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2015-08-15 18:11:06 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Shark007
2015-08-15 18:11:06 ----D---- C:\ProgramData\Shark007
2015-08-15 18:10:52 ----A---- C:\Windows\system32\x264vfw.dll
2015-08-15 18:10:51 ----A---- C:\Windows\system32\VSFilter.dll
2015-08-15 18:10:51 ----A---- C:\Windows\system32\unrar64.dll
2015-08-15 18:10:51 ----A---- C:\Windows\system32\pthreadGC2.dll
2015-08-15 18:10:50 ----AD---- C:\Program Files\Shark007
2015-08-15 18:10:21 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Advanced
2015-08-15 18:10:10 ----D---- C:\Program Files (x86)\Shark007
2015-08-15 18:09:19 ----D---- C:\ProgramData\Advanced
2015-08-14 07:18:27 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-12 03:43:08 ----D---- C:\Filmy
2015-08-12 02:49:18 ----D---- C:\Users\Martin Rejn\AppData\Roaming\BSplayer PRO
2015-08-12 02:49:05 ----D---- C:\Program Files (x86)\Webteh
2015-08-12 01:08:50 ----D---- C:\Program Files (x86)\Google
2015-08-12 00:37:47 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Mozilla
2015-08-12 00:37:31 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-11 23:49:23 ----D---- C:\!!!
2015-08-11 23:37:12 ----D---- C:\Users\Martin Rejn\AppData\Roaming\IsolatedStorage
2015-08-11 23:37:12 ----D---- C:\ProgramData\IsolatedStorage
2015-08-11 23:36:56 ----D---- C:\Users\Martin Rejn\AppData\Roaming\DigitalVolcano
2015-08-11 23:36:13 ----D---- C:\Program Files (x86)\Duplicate Cleaner Pro
2015-08-11 21:11:06 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2015-08-11 21:03:59 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 21:03:58 ----D---- C:\Program Files\Microsoft Office 15
2015-08-11 20:38:40 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 20:38:16 ----D---- C:\ProgramData\Adobe
2015-08-11 19:59:03 ----D---- C:\Windows\system32\MRT
2015-08-11 19:58:59 ----A---- C:\Windows\system32\MRT.exe
2015-08-11 19:56:16 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-11 19:56:16 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-11 19:55:59 ----A---- C:\Windows\system32\shell32.dll
2015-08-11 19:55:58 ----A---- C:\Windows\system32\ieframe.dll
2015-08-11 19:55:57 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-11 19:55:55 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-11 19:55:54 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-11 19:55:48 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-11 19:55:48 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-11 19:55:47 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-11 19:55:47 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-11 19:55:47 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-11 19:55:47 ----A---- C:\Windows\system32\DWrite.dll
2015-08-11 19:55:46 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\schedsvc.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\mf.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\LogonController.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\FntCache.dll
2015-08-11 19:55:45 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-11 19:55:45 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-11 19:55:45 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-11 19:55:45 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-11 19:55:44 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-11 19:55:44 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-11 19:55:44 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-11 19:55:44 ----A---- C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\NetworkStatus.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-11 19:55:44 ----A---- C:\Windows\system32\facecredentialprovider.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2015-08-11 19:55:44 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2015-08-11 19:55:44 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-11 19:55:44 ----A---- C:\Windows\system32\atmfd.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\ActionCenter.dll
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\NotificationObjFactory.dll
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\msctfuimanager.dll
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\WinBioDataModel.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\VPNv2CSP.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\ntdll.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\NotificationObjFactory.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-11 19:55:43 ----A---- C:\Windows\system32\msctfuimanager.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\drivers\wof.sys
2015-08-11 19:55:43 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-11 19:55:43 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-11 19:55:43 ----A---- C:\Windows\system32\configmanager2.dll
2015-08-11 19:55:43 ----A---- C:\Windows\notepad.exe
2015-08-11 19:55:42 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-11 19:55:42 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-11 19:55:42 ----A---- C:\Windows\system32\coredpus.dll
2015-08-11 19:55:41 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-11 19:55:41 ----A---- C:\Windows\system32\drivers\wpcfltr.sys
2015-08-11 19:55:41 ----A---- C:\Windows\system32\drivers\msgpiowin32.sys
2015-08-11 19:55:39 ----A---- C:\Windows\system32\mfps.dll
2015-08-11 19:55:39 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-11 19:55:37 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-11 19:55:36 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-11 19:55:36 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-11 17:14:13 ----A---- C:\Windows\acpimof.dll
2015-08-11 17:14:05 ----D---- C:\Program Files (x86)\MSI
2015-08-11 16:42:00 ----A---- C:\Windows\SYSWOW64\drivers\DrvAgent64.SYS
2015-08-11 16:22:20 ----D---- C:\Program Files (x86)\Lavalys
2015-08-11 00:27:54 ----D---- C:\Program Files (x86)\Foxit Software
2015-08-10 23:15:17 ----D---- C:\Windows\system32\SleepStudy
2015-08-10 20:01:36 ----D---- C:\Windows\SYSWOW64\XPSViewer
2015-08-10 20:01:26 ----D---- C:\Program Files (x86)\Reference Assemblies
2015-08-10 20:01:26 ----D---- C:\Program Files (x86)\MSBuild
2015-08-10 20:01:25 ----D---- C:\Program Files\Reference Assemblies
2015-08-10 20:01:25 ----D---- C:\Program Files\MSBuild
2015-08-10 19:59:32 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2015-08-10 19:59:32 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2015-08-10 19:59:32 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 19:59:27 ----A---- C:\Windows\system32\TsWpfWrp.exe
2015-08-10 19:59:27 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2015-08-10 19:59:27 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 19:57:46 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2015-08-10 19:57:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2015-08-10 19:57:46 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2015-08-10 19:57:46 ----A---- C:\Windows\system32\XAudio2_7.dll
2015-08-10 19:57:46 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2015-08-10 19:57:46 ----A---- C:\Windows\system32\xactengine3_7.dll
2015-08-10 19:57:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2015-08-10 19:57:45 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2015-08-10 19:57:44 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2015-08-10 19:57:44 ----A---- C:\Windows\system32\d3dcsx_43.dll
2015-08-10 19:57:42 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2015-08-10 19:57:42 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2015-08-10 19:57:42 ----A---- C:\Windows\system32\XAudio2_6.dll
2015-08-10 19:57:42 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2015-08-10 19:57:41 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2015-08-10 19:57:41 ----A---- C:\Windows\system32\xactengine3_6.dll
2015-08-10 19:57:40 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2015-08-10 19:57:40 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2015-08-10 19:57:40 ----A---- C:\Windows\system32\XAudio2_5.dll
2015-08-10 19:57:40 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2015-08-10 19:57:39 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2015-08-10 19:57:39 ----A---- C:\Windows\system32\xactengine3_5.dll
2015-08-10 19:57:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2015-08-10 19:57:38 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2015-08-10 19:57:37 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2015-08-10 19:57:37 ----A---- C:\Windows\system32\d3dcsx_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\system32\d3dx11_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\system32\d3dx10_42.dll
2015-08-10 19:57:35 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2015-08-10 19:57:35 ----A---- C:\Windows\system32\D3DX9_42.dll
2015-08-10 19:57:34 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2015-08-10 19:57:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2015-08-10 19:57:34 ----A---- C:\Windows\system32\d3dx10_41.dll
2015-08-10 19:57:34 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2015-08-10 19:57:33 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2015-08-10 19:57:33 ----A---- C:\Windows\system32\D3DX9_41.dll
2015-08-10 19:57:32 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2015-08-10 19:57:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2015-08-10 19:57:32 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2015-08-10 19:57:32 ----A---- C:\Windows\system32\XAudio2_4.dll
2015-08-10 19:57:32 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2015-08-10 19:57:32 ----A---- C:\Windows\system32\xactengine3_4.dll
2015-08-10 19:57:31 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2015-08-10 19:57:31 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2015-08-10 19:57:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2015-08-10 19:57:31 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2015-08-10 19:57:31 ----A---- C:\Windows\system32\d3dx10_40.dll
2015-08-10 19:57:31 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2015-08-10 19:57:29 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2015-08-10 19:57:29 ----A---- C:\Windows\system32\D3DX9_40.dll
2015-08-10 19:57:28 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2015-08-10 19:57:28 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2015-08-10 19:57:28 ----A---- C:\Windows\system32\XAudio2_3.dll
2015-08-10 19:57:28 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2015-08-10 19:57:27 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2015-08-10 19:57:27 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2015-08-10 19:57:27 ----A---- C:\Windows\system32\xactengine3_3.dll
2015-08-10 19:57:27 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2015-08-10 19:57:26 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2015-08-10 19:57:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2015-08-10 19:57:26 ----A---- C:\Windows\system32\XAudio2_2.dll
2015-08-10 19:57:26 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2015-08-10 19:57:25 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2015-08-10 19:57:25 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2015-08-10 19:57:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2015-08-10 19:57:25 ----A---- C:\Windows\system32\xactengine3_2.dll
2015-08-10 19:57:25 ----A---- C:\Windows\system32\d3dx10_39.dll
2015-08-10 19:57:25 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2015-08-10 19:57:23 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2015-08-10 19:57:23 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2015-08-10 19:57:23 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2015-08-10 19:57:23 ----A---- C:\Windows\system32\XAudio2_1.dll
2015-08-10 19:57:23 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2015-08-10 19:57:23 ----A---- C:\Windows\system32\D3DX9_39.dll
2015-08-10 19:57:22 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2015-08-10 19:57:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2015-08-10 19:57:22 ----A---- C:\Windows\system32\xactengine3_1.dll
2015-08-10 19:57:22 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2015-08-10 19:57:21 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2015-08-10 19:57:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2015-08-10 19:57:21 ----A---- C:\Windows\system32\d3dx10_38.dll
2015-08-10 19:57:21 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2015-08-10 19:57:20 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2015-08-10 19:57:20 ----A---- C:\Windows\system32\D3DX9_38.dll
2015-08-10 19:57:19 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2015-08-10 19:57:19 ----A---- C:\Windows\system32\XAudio2_0.dll
2015-08-10 19:57:18 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2015-08-10 19:57:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2015-08-10 19:57:18 ----A---- C:\Windows\system32\xactengine3_0.dll
2015-08-10 19:57:18 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2015-08-10 19:57:17 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2015-08-10 19:57:17 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2015-08-10 19:57:17 ----A---- C:\Windows\system32\d3dx10_37.dll
2015-08-10 19:57:17 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2015-08-10 19:57:15 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2015-08-10 19:57:15 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2015-08-10 19:57:15 ----A---- C:\Windows\system32\xactengine2_10.dll
2015-08-10 19:57:15 ----A---- C:\Windows\system32\D3DX9_37.dll
2015-08-10 19:57:13 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2015-08-10 19:57:13 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2015-08-10 19:57:13 ----A---- C:\Windows\system32\d3dx10_36.dll
2015-08-10 19:57:13 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2015-08-10 19:57:12 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2015-08-10 19:57:12 ----A---- C:\Windows\system32\d3dx9_36.dll
2015-08-10 19:57:11 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2015-08-10 19:57:11 ----A---- C:\Windows\system32\xactengine2_9.dll
2015-08-10 19:57:10 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2015-08-10 19:57:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2015-08-10 19:57:10 ----A---- C:\Windows\system32\d3dx10_35.dll
2015-08-10 19:57:10 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2015-08-10 19:57:08 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2015-08-10 19:57:08 ----A---- C:\Windows\system32\d3dx9_35.dll
2015-08-10 19:57:07 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2015-08-10 19:57:07 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2015-08-10 19:57:07 ----A---- C:\Windows\system32\xactengine2_8.dll
2015-08-10 19:57:07 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2015-08-10 19:57:06 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2015-08-10 19:57:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2015-08-10 19:57:06 ----A---- C:\Windows\system32\d3dx10_34.dll
2015-08-10 19:57:06 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2015-08-10 19:57:05 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2015-08-10 19:57:05 ----A---- C:\Windows\system32\d3dx9_34.dll
2015-08-10 19:57:04 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2015-08-10 19:57:04 ----A---- C:\Windows\system32\xinput1_3.dll
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2015-08-21 03:27:05
Microsoft Windows 10 Pro
System drive C: has 96 GB (42%) free of 228 GB
Total RAM: 3071 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:27:28, on 21.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\TC UP\TC UP.exe
C:\Program Files (x86)\TC UP\TOTALCMD.EXE
C:\Program Files (x86)\Webteh\BSplayerPro\bsplayer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O4 - HKLM\..\Run: [TC UP] "C:\Program Files (x86)\TC UP\TC UP.exe" /wnd=max
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Martin Rejn\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /AUTO
O4 - HKCU\..\Run: [ACDSeeCommanderUltimate8] C:\Program Files\ACD Systems\ACDSee Ultimate\8.0\ACDSeeCommanderUltimate8.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8AD29032B93C7CEDF313371CC9288ABE] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Linky na tuto stránku - C:\ProgramData\AVG\AWL2015\Web\gbacklinks.htm
O8 - Extra context menu item: &Podobné stránky - C:\ProgramData\AVG\AWL2015\Web\gsimilar.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Hledat pomocí &Google - C:\ProgramData\AVG\AWL2015\Web\gsearch.htm
O8 - Extra context menu item: Přeložit tuto stránku pomocí Google - C:\ProgramData\AVG\AWL2015\Web\gtranslate.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMSEmulator - MDL Forum, mod by Ratiborus - C:\Windows\KMS\bin\KMSSS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - @ByELDI - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11823 bytes
======Listing Processes======
C:\Windows\system32\lsass.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-80a6b3a3-d5b2-4254-993c-97fd85a09926 -SystemEventPortName:HostProcess-a43085bf-cafc-4ecd-8521-d2b5f6aa595a -IoCancelEventPortName:HostProcess-819e6887-5e99-407c-9c2c-e80f66a42ff3 -NonStateChangingEventPortName:HostProcess-a9edb4ba-0bc4-4cb5-81c6-6be17a890ab2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:465e8403-ed86-4d57-8e3e-55910d7abb58 -DeviceGroupId:WpdFsGroup
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe" /StartService
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\KMSpico\Service_KMS.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 7368c8b2-4f0d-4ea0-9e74-2bfa887493fb
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
dashost.exe {172aa3f7-433d-444f-b0710f9720dcc63f}
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\Windows\system32\conhost.exe 0x4
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2696
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" gpureading
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Martin Rejn\AppData\Local\Steam\htmlcache" -steampid 1076 -buildid 1440016726 -steamid "0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-direct-write
"C:\Program Files (x86)\TC UP\TC UP.exe" /wnd=max
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\TC UP\TOTALCMD.EXE" /i="C:\Program Files (x86)\TC UP\wincmd.ini" /wnd=max
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\Program Files (x86)\Webteh\BSplayerPro\bsplayer.exe" "C:\Mp3\Katapult - Best of\13 - Katapult - Hlupák váhá.mp3"
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\System32\svchost.exe -k smphost
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Internet downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin Rejn\AppData\Roaming\Mozilla\Firefox\Profiles\p1na36y7.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "chrome://speeddial/content/speeddial.xul"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.60.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.60.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL
C:\Users\Martin Rejn\AppData\Roaming\Mozilla\Firefox\Profiles\p1na36y7.default\extensions\
fastestsearch@mingyi.org
zigboom@hotmail.com
{0545b830-f0aa-4d7e-8820-50a4629a56fe}
{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2015-08-14 226984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-08-20 551520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2015-08-14 2167928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-20 212576]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2015-08-14 162888]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2015-08-14 1513592]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5595848]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-08-09 13885696]
"ACUW08EN"=C:\Program Files\ACD Systems\ACDSee Ultimate\8.0\acdIDInTouch2.exe [2015-02-03 1814800]
"Cm108Sound"=C:\Windows\syswow64\RunDll32.exe [2015-07-10 53760]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-08-07 2634896]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-08-07 1710568]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Martin Rejn\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-08-09 402632]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2015-08-19 2899136]
"CCleaner"=C:\Program Files (x86)\CCleaner\CCleaner64.exe [2015-07-17 8418584]
"ACDSeeCommanderUltimate8"=C:\Program Files\ACD Systems\ACDSee Ultimate\8.0\ACDSeeCommanderUltimate8.exe [2015-05-06 2054664]
"uTorrent"=C:\Users\Martin Rejn\AppData\Roaming\uTorrent\utorrent.exe [2015-02-22 416168]
"DAEMON Tools Ultra Agent"=C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [2015-08-06 4526424]
"GoogleChromeAutoLaunch_8AD29032B93C7CEDF313371CC9288ABE"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-08-08 813896]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TC UP"=C:\Program Files (x86)\TC UP\TC UP.exe [2015-06-09 675328]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-08-04 597552]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
"NoDriveAutoRun"=67108851
"NoDrives"=0x00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acdseeultimate8.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amd overdrive.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appvlp.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccleaner.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccleaner64.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtagent.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtimgeditor.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtlauncher.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dtpro.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\groove.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lync.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoev.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msotd.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ocpubmgr.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setlang.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
"Debugger="C:\Program Files (x86)\AVG\AVG PC TuneUp\PMLauncher.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\visio.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winproj.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"vidc.x264"=x264vfw.dll
"msacm.ac3filter"=ac3filter.acm
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
======File associations======
.inf - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\Notepad++\notepad++.exe" "%1"
.inf - install -
.ini - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\Notepad++\notepad++.exe" "%1"
.js - edit -
.js - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\HateML\HateML.exe" "%1"
.txt - open - "C:\Program Files (x86)\TC UP\PLUGINS\Media\Notepad++\notepad++.exe" "%1"
======List of files/folders created in the last 1 month======
2015-08-21 03:27:05 ----D---- C:\rsit
2015-08-21 03:27:05 ----D---- C:\Program Files\trend micro
2015-08-20 23:45:20 ----D---- C:\AdwCleaner
2015-08-20 22:16:41 ----SHD---- C:\Config.Msi
2015-08-20 02:07:32 ----D---- C:\Users\Martin Rejn\AppData\Roaming\NVIDIA
2015-08-20 01:33:27 ----D---- C:\Program Files (x86)\AMD
2015-08-19 22:51:17 ----D---- C:\NVIDIA
2015-08-19 22:26:49 ----HD---- C:\Windows\Icons
2015-08-19 17:17:17 ----D---- C:\Windows\rescache
2015-08-19 08:48:10 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2015-08-19 08:48:10 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2015-08-19 08:48:10 ----A---- C:\Windows\system32\nvspcap64.dll
2015-08-19 08:48:10 ----A---- C:\Windows\system32\nvspbridge64.dll
2015-08-19 08:47:34 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-08-19 08:46:48 ----D---- C:\Windows\LastGood.Tmp
2015-08-19 06:00:23 ----D---- C:\Temp
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvvsvc.exe
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvsvcr.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvsvc64.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvshext.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvmctray.dll
2015-08-19 05:59:37 ----A---- C:\Windows\system32\nvcpl.dll
2015-08-19 05:59:13 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2015-08-19 05:59:13 ----A---- C:\Windows\system32\OpenCL.dll
2015-08-19 05:55:03 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-08-19 05:55:03 ----A---- C:\Windows\system32\nvhdap64.dll
2015-08-19 05:55:03 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2015-08-19 05:55:03 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-08-19 05:55:02 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvopencl.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvoglv64.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\nvinitx.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\NvIFR64.dll
2015-08-19 05:55:02 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-08-19 05:55:01 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\NvFBC64.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvdispgenco6435560.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvdispco6435560.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvcuvid.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvcuda.dll
2015-08-19 05:55:01 ----A---- C:\Windows\system32\nvcompiler.dll
2015-08-19 05:54:59 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-08-19 05:54:59 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-08-19 05:54:59 ----A---- C:\Windows\system32\nvapi64.dll
2015-08-19 04:48:30 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Oracle
2015-08-19 04:46:47 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Sun
2015-08-19 00:39:51 ----D---- C:\Users\Martin Rejn\AppData\Roaming\XnView
2015-08-19 00:36:45 ----A---- C:\Windows\system32\drivers\dtultrausbbus.sys
2015-08-19 00:36:41 ----A---- C:\Windows\system32\drivers\dtultrascsibus.sys
2015-08-19 00:36:40 ----D---- C:\Users\Martin Rejn\AppData\Roaming\DAEMON Tools Ultra
2015-08-19 00:36:33 ----D---- C:\Program Files\DAEMON Tools Ultra
2015-08-19 00:35:46 ----D---- C:\ProgramData\DAEMON Tools Ultra
2015-08-18 23:55:46 ----A---- C:\Windows\system32\mshtml.dll
2015-08-18 23:55:45 ----A---- C:\Windows\system32\edgehtml.dll
2015-08-18 23:55:44 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-18 23:55:42 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-18 23:55:41 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2015-08-18 23:55:40 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2015-08-18 23:55:38 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2015-08-18 23:55:38 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2015-08-18 23:55:38 ----A---- C:\Windows\system32\tquery.dll
2015-08-18 23:55:38 ----A---- C:\Windows\system32\mssrch.dll
2015-08-18 23:55:38 ----A---- C:\Windows\explorer.exe
2015-08-18 23:55:37 ----A---- C:\Windows\system32\NetworkMobileSettings.dll
2015-08-18 23:55:37 ----A---- C:\Windows\system32\MFMediaEngine.dll
2015-08-18 23:55:37 ----A---- C:\Windows\system32\Chakra.dll
2015-08-18 23:55:37 ----A---- C:\Windows\system32\diagtrack.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-18 23:55:36 ----A---- C:\Windows\SYSWOW64\explorer.exe
2015-08-18 23:55:36 ----A---- C:\Windows\system32\wlidsvc.dll
2015-08-18 23:55:36 ----A---- C:\Windows\system32\iertutil.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2015-08-18 23:55:35 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\wwansvc.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\RDXService.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\LockAppHost.exe
2015-08-18 23:55:35 ----A---- C:\Windows\system32\InputService.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\dwmcore.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2015-08-18 23:55:35 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\InputService.dll
2015-08-18 23:55:34 ----A---- C:\Windows\SYSWOW64\directmanipulation.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\win32kfull.sys
2015-08-18 23:55:34 ----A---- C:\Windows\system32\wcmsvc.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\ReAgent.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\mfplat.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\MbaeApiPublic.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\MbaeApi.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\LocationPermissions.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\directmanipulation.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\diagtrack_wininternal.dll
2015-08-18 23:55:34 ----A---- C:\Windows\system32\diagtrack_win.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\UserMgrProxy.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\OneDriveSettingSyncProvider.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\MbaeApiPublic.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\MbaeApi.dll
2015-08-18 23:55:33 ----A---- C:\Windows\SYSWOW64\AppXDeploymentClient.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\wuautoappupdate.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\UserMgrProxy.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\TextInputFramework.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\tetheringservice.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\tetheringclient.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\sysmain.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\syncutil.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-08-18 23:55:33 ----A---- C:\Windows\system32\rdbui.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\OneDriveSettingSyncProvider.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-18 23:55:33 ----A---- C:\Windows\system32\mfcore.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\MbaeParserTask.exe
2015-08-18 23:55:33 ----A---- C:\Windows\system32\LocationGeofences.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\LocationFramework.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\enterprisecsps.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\drivers\storport.sys
2015-08-18 23:55:33 ----A---- C:\Windows\system32\drivers\stornvme.sys
2015-08-18 23:55:33 ----A---- C:\Windows\system32\cloudAP.dll
2015-08-18 23:55:33 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\Windows.UI.Core.TextInput.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\tetheringclient.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\ReInfo.dll
2015-08-18 23:55:32 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2015-08-18 23:55:32 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-18 23:55:32 ----A---- C:\Windows\system32\mssprxy.dll
2015-08-18 23:55:32 ----A---- C:\Windows\system32\LocationFrameworkInternalPS.dll
2015-08-18 23:55:32 ----A---- C:\Windows\system32\GamePanel.exe
2015-08-18 23:09:55 ----D---- C:\Windows\Minidump
2015-08-18 22:57:11 ----A---- C:\Windows\system32\nvexpBar.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\nvcplUIR.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\nvcplUI.exe
2015-08-18 22:57:11 ----A---- C:\Windows\system32\msvcr71.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\msvcp71.dll
2015-08-18 22:57:11 ----A---- C:\Windows\system32\MFC71.dll
2015-08-18 22:56:26 ----D---- C:\Program Files (x86)\NVIDIA nTune Performance Application
2015-08-18 22:33:12 ----N---- C:\Windows\Vmix108.dll
2015-08-18 22:33:12 ----N---- C:\Windows\SYSWOW64\cmpa108.dll
2015-08-18 22:33:12 ----N---- C:\Windows\SYSWOW64\CM108.dll
2015-08-18 22:33:12 ----N---- C:\Windows\system32\Cmeau108.exe
2015-08-18 22:33:00 ----A---- C:\Windows\system32\drivers\CM10864.sys
2015-08-18 22:32:58 ----RA---- C:\Windows\difxapi.dll
2015-08-18 22:32:58 ----N---- C:\Windows\system32\CmiInstallResAll64.dll
2015-08-18 22:32:58 ----N---- C:\Windows\cm108.ini
2015-08-18 22:18:18 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Convertilla
2015-08-18 22:18:10 ----AD---- C:\Program Files (x86)\Convertilla
2015-08-18 20:37:22 ----D---- C:\ProgramData\StartMenuReviver.exe
2015-08-18 20:37:05 ----D---- C:\Users\Martin Rejn\AppData\Roaming\MetroSidebar
2015-08-18 19:36:58 ----A---- C:\Windows\system32\drivers\i8042HDR.sys
2015-08-18 19:27:16 ----AD---- C:\Program Files\SmartTechnology
2015-08-17 18:21:50 ----D---- C:\Users\Martin Rejn\AppData\Roaming\PDM
2015-08-17 18:21:13 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-08-17 18:21:13 ----D---- C:\Program Files (x86)\Palm
2015-08-17 04:18:28 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Might & Magic Heroes VI
2015-08-17 04:18:28 ----D---- C:\ProgramData\Orbit
2015-08-17 04:16:40 ----D---- C:\Windows\SYSWOW64\directx
2015-08-17 03:58:11 ----D---- C:\Games Install
2015-08-17 03:50:57 ----D---- C:\Users\Martin Rejn\AppData\Roaming\DAEMON Tools iSCSI Target
2015-08-17 03:48:38 ----A---- C:\Windows\system32\drivers\dtproscsibus.sys
2015-08-17 03:43:10 ----A---- C:\Windows\system32\drivers\sptd2.sys
2015-08-17 00:59:26 ----A---- C:\Windows\SYSWOW64\NlsLexicons0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\SYSWOW64\NlsData0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\system32\prm0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2015-08-17 00:59:26 ----A---- C:\Windows\system32\NlsData0009.dll
2015-08-17 00:35:00 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2015-08-17 00:35:00 ----A---- C:\Windows\system32\TURegOpt.exe
2015-08-17 00:35:00 ----A---- C:\Windows\system32\authuitu.dll
2015-08-17 00:34:29 ----D---- C:\Users\Martin Rejn\AppData\Roaming\AVG
2015-08-17 00:34:16 ----D---- C:\Program Files (x86)\AVG
2015-08-17 00:14:44 ----D---- C:\GamesUpdate
2015-08-17 00:14:16 ----D---- C:\Users\Martin Rejn\AppData\Roaming\HateML
2015-08-17 00:02:10 ----D---- C:\ProgramData\Package Cache
2015-08-16 21:37:17 ----D---- C:\Users\Martin Rejn\AppData\Roaming\ACD Systems
2015-08-16 21:36:47 ----D---- C:\ProgramData\ACD Systems
2015-08-16 21:36:36 ----AD---- C:\Program Files\Common Files\ACD Systems
2015-08-16 21:36:36 ----AD---- C:\Program Files\ACD Systems
2015-08-16 21:28:37 ----D---- C:\Program Files\VideoLAN
2015-08-16 21:22:38 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Totusoft
2015-08-16 21:22:35 ----AD---- C:\Program Files (x86)\LAN Speed Test
2015-08-16 20:25:56 ----D---- C:\Users\Martin Rejn\AppData\Roaming\HEXelon
2015-08-16 20:22:38 ----RD---- C:\Program Files (x86)\TC UP
2015-08-16 20:07:23 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Internet Download Accelerator
2015-08-16 20:02:28 ----HD---- C:\ProgramData\Common Files
2015-08-16 20:02:25 ----D---- C:\ProgramData\AVG
2015-08-16 19:20:39 ----D---- C:\Mp3
2015-08-16 18:35:12 ----AD---- C:\Program Files (x86)\Windows Phone
2015-08-16 18:34:57 ----D---- C:\ProgramData\Applications
2015-08-16 18:14:21 ----AD---- C:\Program Files (x86)\CCleaner
2015-08-16 18:13:44 ----D---- C:\Users\Martin Rejn\AppData\Roaming\CCleaner
2015-08-16 17:59:19 ----D---- C:\ProgramData\VS Revo Group
2015-08-16 17:59:18 ----A---- C:\Windows\system32\drivers\revoflt.sys
2015-08-16 17:59:15 ----D---- C:\Program Files\VS Revo Group
2015-08-16 16:50:57 ----D---- C:\Users\Martin Rejn\AppData\Roaming\TeamViewer
2015-08-16 16:50:47 ----AD---- C:\Program Files (x86)\TeamViewer
2015-08-16 01:15:39 ----D---- C:\Program Files (x86)\FinalWire
2015-08-16 00:29:37 ----D---- C:\ProgramData\IObit
2015-08-16 00:29:37 ----A---- C:\Windows\SYSWOW64\drivers\HWiNFO64A.SYS
2015-08-16 00:29:36 ----D---- C:\Users\Martin Rejn\AppData\Roaming\IObit
2015-08-16 00:28:27 ----D---- C:\Internet downloads
2015-08-15 23:37:16 ----RD---- C:\Users\Martin Rejn\AppData\Roaming\Brother
2015-08-15 20:16:25 ----D---- C:\Program Files\7-Zip
2015-08-15 18:36:53 ----D---- C:\Users\Martin Rejn\AppData\Roaming\java
2015-08-15 18:36:14 ----D---- C:\ProgramData\Sun
2015-08-15 18:36:09 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2015-08-15 18:34:33 ----D---- C:\ProgramData\Oracle
2015-08-15 18:34:31 ----D---- C:\Program Files\Java
2015-08-15 18:30:02 ----D---- C:\Users\Martin Rejn\AppData\Roaming\.minecraft
2015-08-15 18:20:27 ----D---- C:\Clips
2015-08-15 18:12:21 ----A---- C:\Windows\system32\VSFilter.dll.bak
2015-08-15 18:12:20 ----A---- C:\Windows\system32\WMPDMC.exe.bak
2015-08-15 18:12:11 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe.bak
2015-08-15 18:12:04 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll.bak
2015-08-15 18:12:03 ----A---- C:\Windows\SYSWOW64\mfds.dll.bak
2015-08-15 18:11:58 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2015-08-15 18:11:06 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Shark007
2015-08-15 18:11:06 ----D---- C:\ProgramData\Shark007
2015-08-15 18:10:52 ----A---- C:\Windows\system32\x264vfw.dll
2015-08-15 18:10:51 ----A---- C:\Windows\system32\VSFilter.dll
2015-08-15 18:10:51 ----A---- C:\Windows\system32\unrar64.dll
2015-08-15 18:10:51 ----A---- C:\Windows\system32\pthreadGC2.dll
2015-08-15 18:10:50 ----AD---- C:\Program Files\Shark007
2015-08-15 18:10:21 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Advanced
2015-08-15 18:10:10 ----D---- C:\Program Files (x86)\Shark007
2015-08-15 18:09:19 ----D---- C:\ProgramData\Advanced
2015-08-14 07:18:27 ----AD---- C:\Program Files\Common Files\DESIGNER
2015-08-12 03:43:08 ----D---- C:\Filmy
2015-08-12 02:49:18 ----D---- C:\Users\Martin Rejn\AppData\Roaming\BSplayer PRO
2015-08-12 02:49:05 ----D---- C:\Program Files (x86)\Webteh
2015-08-12 01:08:50 ----D---- C:\Program Files (x86)\Google
2015-08-12 00:37:47 ----D---- C:\Users\Martin Rejn\AppData\Roaming\Mozilla
2015-08-12 00:37:31 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-11 23:49:23 ----D---- C:\!!!
2015-08-11 23:37:12 ----D---- C:\Users\Martin Rejn\AppData\Roaming\IsolatedStorage
2015-08-11 23:37:12 ----D---- C:\ProgramData\IsolatedStorage
2015-08-11 23:36:56 ----D---- C:\Users\Martin Rejn\AppData\Roaming\DigitalVolcano
2015-08-11 23:36:13 ----D---- C:\Program Files (x86)\Duplicate Cleaner Pro
2015-08-11 21:11:06 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2015-08-11 21:03:59 ----AD---- C:\Program Files\Microsoft Office
2015-08-11 21:03:58 ----D---- C:\Program Files\Microsoft Office 15
2015-08-11 20:38:40 ----D---- C:\Program Files (x86)\Adobe
2015-08-11 20:38:16 ----D---- C:\ProgramData\Adobe
2015-08-11 19:59:03 ----D---- C:\Windows\system32\MRT
2015-08-11 19:58:59 ----A---- C:\Windows\system32\MRT.exe
2015-08-11 19:56:16 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-11 19:56:16 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-11 19:55:59 ----A---- C:\Windows\system32\shell32.dll
2015-08-11 19:55:58 ----A---- C:\Windows\system32\ieframe.dll
2015-08-11 19:55:57 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-11 19:55:55 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-11 19:55:54 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-11 19:55:48 ----A---- C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-11 19:55:48 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2015-08-11 19:55:47 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2015-08-11 19:55:47 ----A---- C:\Windows\SYSWOW64\RemoteNaturalLanguage.dll
2015-08-11 19:55:47 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2015-08-11 19:55:47 ----A---- C:\Windows\system32\DWrite.dll
2015-08-11 19:55:46 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\schedsvc.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\mf.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\LogonController.dll
2015-08-11 19:55:46 ----A---- C:\Windows\system32\FntCache.dll
2015-08-11 19:55:45 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2015-08-11 19:55:45 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2015-08-11 19:55:45 ----A---- C:\Windows\system32\win32kbase.sys
2015-08-11 19:55:45 ----A---- C:\Windows\system32\mfsvr.dll
2015-08-11 19:55:44 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2015-08-11 19:55:44 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-11 19:55:44 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\WWAHost.exe
2015-08-11 19:55:44 ----A---- C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\SubscriptionMgr.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\NetworkStatus.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\fontdrvhost.exe
2015-08-11 19:55:44 ----A---- C:\Windows\system32\facecredentialprovider.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2015-08-11 19:55:44 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2015-08-11 19:55:44 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2015-08-11 19:55:44 ----A---- C:\Windows\system32\atmfd.dll
2015-08-11 19:55:44 ----A---- C:\Windows\system32\ActionCenter.dll
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\NotificationObjFactory.dll
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\msctfuimanager.dll
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2015-08-11 19:55:43 ----A---- C:\Windows\SYSWOW64\ActionCenter.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\WinBioDataModel.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\wifinetworkmanager.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\VPNv2CSP.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\ntdll.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\NotificationObjFactory.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\notepad.exe
2015-08-11 19:55:43 ----A---- C:\Windows\system32\msctfuimanager.dll
2015-08-11 19:55:43 ----A---- C:\Windows\system32\drivers\wof.sys
2015-08-11 19:55:43 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2015-08-11 19:55:43 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-11 19:55:43 ----A---- C:\Windows\system32\configmanager2.dll
2015-08-11 19:55:43 ----A---- C:\Windows\notepad.exe
2015-08-11 19:55:42 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-11 19:55:42 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-11 19:55:42 ----A---- C:\Windows\system32\coredpus.dll
2015-08-11 19:55:41 ----A---- C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-11 19:55:41 ----A---- C:\Windows\system32\drivers\wpcfltr.sys
2015-08-11 19:55:41 ----A---- C:\Windows\system32\drivers\msgpiowin32.sys
2015-08-11 19:55:39 ----A---- C:\Windows\system32\mfps.dll
2015-08-11 19:55:39 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2015-08-11 19:55:37 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\Windows.UI.Shell.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\SharedStartModelShim.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\SharedStartModel.dll
2015-08-11 19:55:37 ----A---- C:\Windows\system32\LockAppBroker.dll
2015-08-11 19:55:36 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2015-08-11 19:55:36 ----A---- C:\Windows\SYSWOW64\VEDataLayerHelpers.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\tileobjserver.dll
2015-08-11 19:55:36 ----A---- C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-11 17:14:13 ----A---- C:\Windows\acpimof.dll
2015-08-11 17:14:05 ----D---- C:\Program Files (x86)\MSI
2015-08-11 16:42:00 ----A---- C:\Windows\SYSWOW64\drivers\DrvAgent64.SYS
2015-08-11 16:22:20 ----D---- C:\Program Files (x86)\Lavalys
2015-08-11 00:27:54 ----D---- C:\Program Files (x86)\Foxit Software
2015-08-10 23:15:17 ----D---- C:\Windows\system32\SleepStudy
2015-08-10 20:01:36 ----D---- C:\Windows\SYSWOW64\XPSViewer
2015-08-10 20:01:26 ----D---- C:\Program Files (x86)\Reference Assemblies
2015-08-10 20:01:26 ----D---- C:\Program Files (x86)\MSBuild
2015-08-10 20:01:25 ----D---- C:\Program Files\Reference Assemblies
2015-08-10 20:01:25 ----D---- C:\Program Files\MSBuild
2015-08-10 19:59:32 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2015-08-10 19:59:32 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2015-08-10 19:59:32 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 19:59:27 ----A---- C:\Windows\system32\TsWpfWrp.exe
2015-08-10 19:59:27 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2015-08-10 19:59:27 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-10 19:57:46 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2015-08-10 19:57:46 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2015-08-10 19:57:46 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2015-08-10 19:57:46 ----A---- C:\Windows\system32\XAudio2_7.dll
2015-08-10 19:57:46 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2015-08-10 19:57:46 ----A---- C:\Windows\system32\xactengine3_7.dll
2015-08-10 19:57:45 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2015-08-10 19:57:45 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2015-08-10 19:57:44 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2015-08-10 19:57:44 ----A---- C:\Windows\system32\d3dcsx_43.dll
2015-08-10 19:57:42 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2015-08-10 19:57:42 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2015-08-10 19:57:42 ----A---- C:\Windows\system32\XAudio2_6.dll
2015-08-10 19:57:42 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2015-08-10 19:57:41 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2015-08-10 19:57:41 ----A---- C:\Windows\system32\xactengine3_6.dll
2015-08-10 19:57:40 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2015-08-10 19:57:40 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2015-08-10 19:57:40 ----A---- C:\Windows\system32\XAudio2_5.dll
2015-08-10 19:57:40 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2015-08-10 19:57:39 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2015-08-10 19:57:39 ----A---- C:\Windows\system32\xactengine3_5.dll
2015-08-10 19:57:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2015-08-10 19:57:38 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2015-08-10 19:57:37 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2015-08-10 19:57:37 ----A---- C:\Windows\system32\d3dcsx_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\system32\d3dx11_42.dll
2015-08-10 19:57:36 ----A---- C:\Windows\system32\d3dx10_42.dll
2015-08-10 19:57:35 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2015-08-10 19:57:35 ----A---- C:\Windows\system32\D3DX9_42.dll
2015-08-10 19:57:34 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2015-08-10 19:57:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2015-08-10 19:57:34 ----A---- C:\Windows\system32\d3dx10_41.dll
2015-08-10 19:57:34 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2015-08-10 19:57:33 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2015-08-10 19:57:33 ----A---- C:\Windows\system32\D3DX9_41.dll
2015-08-10 19:57:32 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2015-08-10 19:57:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2015-08-10 19:57:32 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2015-08-10 19:57:32 ----A---- C:\Windows\system32\XAudio2_4.dll
2015-08-10 19:57:32 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2015-08-10 19:57:32 ----A---- C:\Windows\system32\xactengine3_4.dll
2015-08-10 19:57:31 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2015-08-10 19:57:31 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2015-08-10 19:57:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2015-08-10 19:57:31 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2015-08-10 19:57:31 ----A---- C:\Windows\system32\d3dx10_40.dll
2015-08-10 19:57:31 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2015-08-10 19:57:29 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2015-08-10 19:57:29 ----A---- C:\Windows\system32\D3DX9_40.dll
2015-08-10 19:57:28 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2015-08-10 19:57:28 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2015-08-10 19:57:28 ----A---- C:\Windows\system32\XAudio2_3.dll
2015-08-10 19:57:28 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2015-08-10 19:57:27 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2015-08-10 19:57:27 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2015-08-10 19:57:27 ----A---- C:\Windows\system32\xactengine3_3.dll
2015-08-10 19:57:27 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2015-08-10 19:57:26 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2015-08-10 19:57:26 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2015-08-10 19:57:26 ----A---- C:\Windows\system32\XAudio2_2.dll
2015-08-10 19:57:26 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2015-08-10 19:57:25 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2015-08-10 19:57:25 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2015-08-10 19:57:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2015-08-10 19:57:25 ----A---- C:\Windows\system32\xactengine3_2.dll
2015-08-10 19:57:25 ----A---- C:\Windows\system32\d3dx10_39.dll
2015-08-10 19:57:25 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2015-08-10 19:57:23 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2015-08-10 19:57:23 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2015-08-10 19:57:23 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2015-08-10 19:57:23 ----A---- C:\Windows\system32\XAudio2_1.dll
2015-08-10 19:57:23 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2015-08-10 19:57:23 ----A---- C:\Windows\system32\D3DX9_39.dll
2015-08-10 19:57:22 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2015-08-10 19:57:22 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2015-08-10 19:57:22 ----A---- C:\Windows\system32\xactengine3_1.dll
2015-08-10 19:57:22 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2015-08-10 19:57:21 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2015-08-10 19:57:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2015-08-10 19:57:21 ----A---- C:\Windows\system32\d3dx10_38.dll
2015-08-10 19:57:21 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2015-08-10 19:57:20 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2015-08-10 19:57:20 ----A---- C:\Windows\system32\D3DX9_38.dll
2015-08-10 19:57:19 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2015-08-10 19:57:19 ----A---- C:\Windows\system32\XAudio2_0.dll
2015-08-10 19:57:18 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2015-08-10 19:57:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2015-08-10 19:57:18 ----A---- C:\Windows\system32\xactengine3_0.dll
2015-08-10 19:57:18 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2015-08-10 19:57:17 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2015-08-10 19:57:17 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2015-08-10 19:57:17 ----A---- C:\Windows\system32\d3dx10_37.dll
2015-08-10 19:57:17 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2015-08-10 19:57:15 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2015-08-10 19:57:15 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2015-08-10 19:57:15 ----A---- C:\Windows\system32\xactengine2_10.dll
2015-08-10 19:57:15 ----A---- C:\Windows\system32\D3DX9_37.dll
2015-08-10 19:57:13 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2015-08-10 19:57:13 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2015-08-10 19:57:13 ----A---- C:\Windows\system32\d3dx10_36.dll
2015-08-10 19:57:13 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2015-08-10 19:57:12 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2015-08-10 19:57:12 ----A---- C:\Windows\system32\d3dx9_36.dll
2015-08-10 19:57:11 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2015-08-10 19:57:11 ----A---- C:\Windows\system32\xactengine2_9.dll
2015-08-10 19:57:10 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2015-08-10 19:57:10 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2015-08-10 19:57:10 ----A---- C:\Windows\system32\d3dx10_35.dll
2015-08-10 19:57:10 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2015-08-10 19:57:08 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2015-08-10 19:57:08 ----A---- C:\Windows\system32\d3dx9_35.dll
2015-08-10 19:57:07 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2015-08-10 19:57:07 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2015-08-10 19:57:07 ----A---- C:\Windows\system32\xactengine2_8.dll
2015-08-10 19:57:07 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2015-08-10 19:57:06 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2015-08-10 19:57:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2015-08-10 19:57:06 ----A---- C:\Windows\system32\d3dx10_34.dll
2015-08-10 19:57:06 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2015-08-10 19:57:05 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2015-08-10 19:57:05 ----A---- C:\Windows\system32\d3dx9_34.dll
2015-08-10 19:57:04 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2015-08-10 19:57:04 ----A---- C:\Windows\system32\xinput1_3.dll
-----------------EOF-----------------