Havěť
Napsal: 24 srp 2015 18:51
Ahoj, stáhl jsem si do počítače nějaké kraviny, nejdou vypnout přes správce úloh, napíše to, že přístup byl odepřen, odinstalovat taktéž nejdou.
FRST Log mi vytvořit nejde.
ADWCleaner nic nenašel.
Screen věcí ve správci úloh : https://gyazo.com/bccc59b544acd6fdb9c1dc46689bc8e5
RSIT :
RSIT : Logfile of random's system information tool 1.10 (written by random/random)
Run by Petr at 2015-08-24 19:48:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 207 GB (45%) free of 461 GB
Total RAM: 3835 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:48:45, on 24.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Garena Plus\ggdllhost.exe
C:\Program Files (x86)\Gyazo\GyStation.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\ProgramData\Battle.net\Agent\Agent.4318\Agent.exe
C:\Program Files (x86)\Battle.net\Battle.net.6087\Battle.net.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Petr\AppData\Local\Temp\setup.exe
C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\core\PDApp.exe
C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\DECore\Setup.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMDeskTopGC.exe
C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCPatch.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\plugins\QMNetMon\QQPCNetFlow.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRealTimeSpeedup.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMAutoClean.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Petr.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: SohuBHO - {452ADB5B-00BE-469D-A65F-3046146B2ED5} - C:\Program Files (x86)\????\SoHuAutoDetector.dll (file missing)
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [setup.exe -start] C:\Users\Petr\AppData\Local\Temp\setup.exe -start
O4 - HKLM\..\Run: [SohuVA] "C:\Program Files (x86)\????\SHPlayer.exe" /auto
O4 - HKLM\..\Run: [RSDTRAY] "C:\Program Files (x86)\Rising\RSD\popwndexe.exe"
O4 - HKLM\..\Run: [ QQPCTray] "C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe" /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto (User 'Default user')
O4 - Startup: MEGAsync.lnk = C:\Users\Petr\AppData\Local\MEGAsync\MEGAsync.exe
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - (no file)
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - (no file)
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{F266592C-96FC-4C75-9FB1-044DA469F9AC}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\SysWow64\DreamScene.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QQPCMgr RTP Service (QQPCRTP) - Tencent - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRTP.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Rsd Service (RsMgrSvc) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe
O23 - Service: Rav Service (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RAV\ravmond.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TAOFrame - Tencent - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TAOFrame.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe
--
End of file - 12985 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
taskeng.exe {2BD92549-D2F6-47FF-9C9A-71456330D5D1}
"C:\Program Files (x86)\Garena Plus\ggdllhost.exe" "C:\Program Files (x86)\Garena Plus\ggspawn.dll",rundll_entry
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Gyazo\GyStation.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\system32\wbem\wmiprvse.exe
WLIDSvcM.exe 2608
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Petr\AppData\Local\Steam\htmlcache" -steampid 4652 -buildid 1440016726 -steamid "0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe" "<hpNotification><Toast><Title>HP Wireless Assistant</Title><Text>Combo: On</Text><IconPath>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WA_tray_32_on.ico</IconPath><ID>1843685420</ID><Path>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe</Path><Parameters></Parameters></Toast></hpNotification>"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --device-scale-factor=1 --font-cache-shared-mem-suffix=2008 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --disable-accelerated-video-decode --disable-gpu-compositing --channel="2008.0.593194497\600572336" /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe" Restart start ccc
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\ProgramData\Battle.net\Agent\Agent.4318\Agent.exe" --locale=enGB --session=350553187791997185
\??\C:\Windows\system32\conhost.exe "-334962074446107757156313936-2046207406-3542156462788453991736109038778788398
"C:\Program Files (x86)\Battle.net\Battle.net.6087\Battle.net.exe" "--gamepath=C:\Program Files (x86)\Hearthstone" --game=hs_beta
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="2192.2.499375426\1122871738" --font-cache-shared-handle=2776 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2192.8.896959894\1126773821" --use-gl=swiftshader --supports-dual-gpus=false --swiftshader-path="C:\Users\Petr\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159" --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.812.1.3000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.10.1028835618\1380316339" --font-cache-shared-handle=3468 /prefetch:673131151
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --device-scale-factor=1 --font-cache-shared-mem-suffix=2008 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --disable-accelerated-video-decode --disable-gpu-compositing --channel="2008.7.2058502497\1232248022" /prefetch:673131151
"taskhost.exe"
"C:\Program Files\Teamspeak\ts3client_win64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2192.146.662474096\407123378" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\Petr\AppData\Local\Temp\setup.exe" /VERYSILENT /SP-
"C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\core\PDApp.exe" --media="C:\Users\Petr\Documents\Photoshop" --appletID="DWA_UI" --appletVersion="2.0" --requiredSize=149175
"C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\DECore\Setup.exe" --deploymentFile="C:\Users\Petr\AppData\Local\Temp\{890585E7-0DB9-43B0-A8EE-0FCEB4D7DC48}\deploy.xml" --userASUPath="C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp" --DEVersion=8.0
"C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe"
"C:\Program Files (x86)\Rising\RAV\ravmond.exe"
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TAOFrame.exe"
"C:\Windows\system32\taskmgr.exe" /4
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRtp.exe" -r
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe" /elevated /regrun
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCPatch.exe"
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe" /slient /PLUGIN_管家蓝屏修复 /pcmgr
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMDeskTopGC.exe" /ShowUEFromInstall
"C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.171.794774908\735003121" --font-cache-shared-handle=5848 /prefetch:673131151
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCPatch.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.173.11003299\937529188" --font-cache-shared-handle=5836 /prefetch:673131151
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\plugins\QMNetMon\QQPCNetFlow.exe" /regrun /elevated
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRealTimeSpeedup.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe44_ Global\UsGthrCtrlFltPipeMssGthrPipe44 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.176.210237886\980951272" --font-cache-shared-handle=4596 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.177.1203048719\589887624" --font-cache-shared-handle=3336 /prefetch:673131151
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMAutoClean.exe" garbageLimit:300|taskId:5|tipsId:5|taskType:5|depthGarbageLimit:1024
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
taskeng.exe {687B8E75-C467-4D0A-AA62-BC8923560761}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.180.259077382\90457591" --font-cache-shared-handle=1588 /prefetch:673131151
"C:\Program Files\CCleaner\CCleaner.exe" /uac
"C:\Program Files\CCleaner\CCleaner.exe" /uac
"C:\Users\Petr\Desktop\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\HPCeeScheduleForPetr.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPetr (null)
=========Mozilla firefox=========
ProfilePath - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\faqsxm5w.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1218158.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/QQPCMgr]
"Description"=QQPCMgr Detector
"Path"=C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\npQMExtensionsMozilla.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@rising.com.cn/nprising]
"Description"=
"Path"=C:\Program Files (x86)\Rising\RAV\nprising.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@sohu.com/npifox]
"Description"=ifox-plugin
"Path"=C:\Program Files (x86)\搜狐影音\npifox.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@t.garena.com/garenatalk]
"Description"=Garena Talk Plugin
"Path"=C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}]
电脑管家网页防火墙 - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TSWebMon64.dat [2015-08-24 414560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{452ADB5B-00BE-469D-A65F-3046146B2ED5}]
CSohuDetector Object - C:\Program Files (x86)\搜狐影音\SoHuAutoDetector.dll [2015-08-24 213432]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2011-01-12 6602856]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-14 2837288]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-04-13 627360]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-04-13 379552]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2010-07-21 8192]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-01-28 5595848]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
"Gyazo"=C:\Program Files (x86)\Gyazo\GyStation.exe [2015-08-19 3098424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 8]
C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe /Auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2014-10-08 843480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
C:\Program Files (x86)\Origin\Origin.exe [2014-12-16 3618648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarenaPlus]
C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [2014-10-27 9974576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe /autostart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
C:\Users\Petr\AppData\Roaming\Spotify\spotify.exe [2015-01-10 6737976]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\Petr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2015-01-10 1676344]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-04 336384]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2012-03-05 578944]
"HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [2011-08-19 379960]
"setup.exe -start"=C:\Users\Petr\AppData\Local\Temp\setup.exe [2015-08-24 122880]
"SohuVA"=C:\Program Files (x86)\????\SHPlayer.exe /auto []
"RSDTRAY"=C:\Program Files (x86)\Rising\RSD\popwndexe.exe [2012-09-25 126808]
" QQPCTray"=C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe [2015-08-24 355296]
C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Petr\AppData\Local\MEGAsync\MEGAsync.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2015-02-17 275360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll
"vidc.tsc2"=C:\Windows\SysWOW64\tsc2_codec64.dll
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-24 19:45:00 ----D---- C:\Program Files (x86)\Adobe
2015-08-24 19:42:48 ----D---- C:\ProgramData\TXQMPC
2015-08-24 19:41:50 ----A---- C:\Windows\system32\drivers\TAOAccelerator64.sys
2015-08-24 19:41:07 ----D---- C:\Program Files\Common Files\Tencent
2015-08-24 19:40:05 ----A---- C:\Windows\system32\drivers\TSSKX64.sys
2015-08-24 19:39:38 ----A---- C:\Windows\system32\drivers\TAOKernel64.sys
2015-08-24 19:38:52 ----A---- C:\Windows\system32\drivers\TFsFltX64.sys
2015-08-24 19:36:43 ----RSH---- C:\rising.ini
2015-08-24 19:35:02 ----N---- C:\Windows\system32\drivers\sysmon.sys
2015-08-24 19:35:02 ----N---- C:\Windows\system32\drivers\rsutils.sys
2015-08-24 19:35:02 ----N---- C:\Windows\system32\drivers\rsndisp.sys
2015-08-24 19:34:31 ----D---- C:\Users\Petr\AppData\Roaming\Tencent
2015-08-24 19:34:31 ----D---- C:\Program Files (x86)\Tencent
2015-08-24 19:34:05 ----D---- C:\Program Files (x86)\Rising
2015-08-24 19:34:04 ----D---- C:\ProgramData\Rising
2015-08-24 19:33:53 ----D---- C:\ProgramData\Tencent
2015-08-24 19:24:56 ----D---- C:\ProgramData\Adobe
2015-08-24 19:22:24 ----D---- C:\AdwCleaner
2015-08-24 19:13:31 ----HD---- C:\sohucache
2015-08-24 19:13:20 ----D---- C:\SHDownload
2015-08-24 19:12:39 ----D---- C:\Program Files (x86)\搜狐影音
2015-08-18 21:22:33 ----D---- C:\Users\Petr\AppData\Roaming\HearthstoneDeckTracker
2015-08-18 11:49:38 ----D---- C:\Users\Petr\AppData\Roaming\TS3Client
2015-08-18 11:48:59 ----D---- C:\Program Files\Teamspeak
2015-08-17 21:05:20 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 21:05:20 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 20:28:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-17 20:28:40 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-17 20:28:40 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-17 20:28:40 ----A---- C:\Windows\system32\iertutil.dll
2015-08-17 20:28:40 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-17 20:28:40 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-17 20:28:39 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-17 20:28:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-17 20:28:39 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-17 20:28:39 ----A---- C:\Windows\system32\iernonce.dll
2015-08-17 20:28:39 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-17 20:28:38 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-17 20:28:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-17 20:28:35 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-17 20:28:35 ----A---- C:\Windows\system32\urlmon.dll
2015-08-17 20:28:35 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-17 20:28:34 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-17 20:28:34 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-17 20:28:33 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-17 20:28:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-17 20:28:33 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-17 20:28:33 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-17 20:28:33 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-17 20:28:32 ----A---- C:\Windows\system32\iesetup.dll
2015-08-17 20:28:32 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-17 20:28:29 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-17 20:28:29 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-17 20:28:29 ----A---- C:\Windows\system32\vbscript.dll
2015-08-17 20:28:28 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-17 20:28:28 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-17 20:28:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-17 20:28:28 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-17 20:28:28 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-17 20:28:27 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-17 20:28:26 ----A---- C:\Windows\system32\ieui.dll
2015-08-17 20:28:26 ----A---- C:\Windows\system32\ieframe.dll
2015-08-17 20:28:25 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-17 20:28:25 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-17 20:28:24 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-17 20:28:24 ----A---- C:\Windows\system32\jscript.dll
2015-08-17 20:28:23 ----A---- C:\Windows\system32\jscript9.dll
2015-08-17 20:28:22 ----A---- C:\Windows\system32\wininet.dll
2015-08-17 20:28:21 ----A---- C:\Windows\system32\msrating.dll
2015-08-17 20:28:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-17 20:28:20 ----A---- C:\Windows\system32\mshtml.dll
2015-08-17 20:28:16 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-08-17 20:28:16 ----A---- C:\Windows\system32\ole32.dll
2015-08-17 20:28:15 ----A---- C:\Windows\system32\wksprt.exe
2015-08-17 20:28:15 ----A---- C:\Windows\system32\mstscax.dll
2015-08-17 20:28:13 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-17 20:28:11 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-17 20:28:11 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2015-08-17 20:28:11 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-17 20:28:11 ----A---- C:\Windows\system32\rdvidcrl.dll
2015-08-17 20:28:03 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-17 20:28:03 ----A---- C:\Windows\system32\msi.dll
2015-08-17 20:28:03 ----A---- C:\Windows\system32\authui.dll
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-08-17 20:28:02 ----A---- C:\Windows\system32\msimsg.dll
2015-08-17 20:28:02 ----A---- C:\Windows\system32\msihnd.dll
2015-08-17 20:28:02 ----A---- C:\Windows\system32\msiexec.exe
2015-08-17 20:28:02 ----A---- C:\Windows\system32\consent.exe
2015-08-17 20:28:02 ----A---- C:\Windows\system32\appinfo.dll
2015-08-17 20:27:51 ----A---- C:\Windows\system32\gdi32.dll
2015-08-17 20:27:50 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-17 20:27:49 ----A---- C:\Windows\system32\msxml3.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-17 20:27:48 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-17 20:27:48 ----A---- C:\Windows\system32\msxml6.dll
2015-08-17 20:27:48 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-17 20:27:34 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-17 20:27:34 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-17 20:27:34 ----A---- C:\Windows\system32\kerberos.dll
2015-08-17 20:27:33 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-17 20:27:33 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-17 20:27:33 ----A---- C:\Windows\system32\schannel.dll
2015-08-17 20:27:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-17 20:27:33 ----A---- C:\Windows\system32\ntdll.dll
2015-08-17 20:27:33 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-17 20:27:32 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-17 20:27:32 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-17 20:27:32 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-17 20:27:32 ----A---- C:\Windows\system32\kernel32.dll
2015-08-17 20:27:32 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-17 20:27:32 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-17 20:27:31 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-17 20:27:31 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-17 20:27:31 ----A---- C:\Windows\system32\sysmain.dll
2015-08-17 20:27:31 ----A---- C:\Windows\system32\adtschema.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\wdigest.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-17 20:27:29 ----A---- C:\Windows\system32\wow64.dll
2015-08-17 20:27:29 ----A---- C:\Windows\system32\rstrui.exe
2015-08-17 20:27:29 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-17 20:27:28 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\winsrv.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\srcore.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\conhost.exe
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-17 20:27:27 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\sspicli.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\srclient.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\smss.exe
2015-08-17 20:27:27 ----A---- C:\Windows\system32\secur32.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\msaudite.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\lsass.exe
2015-08-17 20:27:27 ----A---- C:\Windows\system32\credssp.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\auditpol.exe
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-17 20:27:26 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-17 20:27:26 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-17 20:27:26 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-17 20:27:26 ----A---- C:\Windows\system32\wow64win.dll
2015-08-17 20:27:26 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-17 20:27:26 ----A---- C:\Windows\system32\msobjs.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-17 20:27:25 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-17 20:27:25 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-17 20:27:25 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-17 20:27:25 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-17 20:26:42 ----A---- C:\Windows\system32\basesrv.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\invagent.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\generaltel.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\devinv.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\appraiser.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\aeinv.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\acmigration.dll
2015-08-17 20:26:16 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-17 20:26:16 ----A---- C:\Windows\system32\aepdu.dll
2015-08-17 20:25:47 ----A---- C:\Windows\system32\FntCache.dll
2015-08-17 20:25:46 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-17 20:25:46 ----A---- C:\Windows\system32\win32k.sys
2015-08-17 20:25:46 ----A---- C:\Windows\system32\DWrite.dll
2015-08-17 20:25:46 ----A---- C:\Windows\system32\atmfd.dll
2015-08-17 20:25:45 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-17 20:25:42 ----A---- C:\Windows\system32\lpk.dll
2015-08-17 20:25:41 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-17 20:25:41 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-17 20:25:41 ----A---- C:\Windows\system32\atmlib.dll
2015-08-17 20:25:40 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-17 20:25:39 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-17 20:25:39 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-17 20:25:39 ----A---- C:\Windows\system32\fontsub.dll
2015-08-17 20:25:39 ----A---- C:\Windows\system32\dciman32.dll
2015-08-17 20:25:38 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-17 20:25:35 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-08-17 20:25:35 ----A---- C:\Windows\system32\cewmdm.dll
2015-08-17 20:25:25 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-08-17 20:25:25 ----A---- C:\Windows\system32\rdpcorets.dll
2015-08-17 20:25:18 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-08-17 20:25:18 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-08-17 20:25:18 ----A---- C:\Windows\system32\cryptsvc.dll
2015-08-17 20:25:17 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-17 20:25:17 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-08-17 20:25:17 ----A---- C:\Windows\system32\wintrust.dll
2015-08-17 20:25:17 ----A---- C:\Windows\system32\cryptnet.dll
2015-08-17 20:25:17 ----A---- C:\Windows\system32\crypt32.dll
2015-08-17 20:25:08 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-17 20:25:08 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-17 20:25:08 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-17 20:25:08 ----A---- C:\Windows\system32\davclnt.dll
2015-08-17 20:24:11 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-17 20:24:11 ----A---- C:\Windows\system32\notepad.exe
2015-08-17 20:24:11 ----A---- C:\Windows\notepad.exe
2015-08-17 20:10:26 ----A---- C:\Windows\system32\shell32.dll
2015-08-17 20:10:23 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wucltux.dll
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wuapp.exe
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wuapi.dll
2015-08-17 20:09:20 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wups2.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wups.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wudriver.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-17 19:55:18 ----D---- C:\ProgramData\Gyazo
======List of files/folders modified in the last 1 month======
2015-08-24 19:48:39 ----D---- C:\Windows\Temp
2015-08-24 19:48:35 ----D---- C:\Program Files\trend micro
2015-08-24 19:48:17 ----D---- C:\Users\Petr\AppData\Roaming\Adobe
2015-08-24 19:45:00 ----RD---- C:\Program Files (x86)
2015-08-24 19:42:48 ----HD---- C:\ProgramData
2015-08-24 19:41:50 ----D---- C:\Windows\system32\drivers
2015-08-24 19:41:07 ----D---- C:\Program Files\Common Files
2015-08-24 19:39:54 ----RSD---- C:\Windows\Fonts
2015-08-24 19:38:49 ----D---- C:\Program Files (x86)\Common Files
2015-08-24 19:32:37 ----SHD---- C:\Windows\Installer
2015-08-24 19:32:36 ----SHD---- C:\Config.Msi
2015-08-24 19:32:35 ----D---- C:\Windows\SysWOW64
2015-08-24 19:32:09 ----SHD---- C:\System Volume Information
2015-08-24 19:32:09 ----D---- C:\ProgramData\Package Cache
2015-08-24 14:51:33 ----D---- C:\Program Files (x86)\Steam
2015-08-24 10:52:22 ----D---- C:\ProgramData\PDFC
2015-08-24 10:02:28 ----D---- C:\Windows\system32\config
2015-08-24 09:51:31 ----D---- C:\Windows\system32\Tasks
2015-08-20 20:02:37 ----D---- C:\Program Files (x86)\Gyazo
2015-08-19 21:33:15 ----D---- C:\Program Files (x86)\Opera
2015-08-19 20:22:27 ----D---- C:\Windows\Microsoft.NET
2015-08-19 12:26:21 ----RSD---- C:\Windows\assembly
2015-08-18 20:17:18 ----D---- C:\Program Files (x86)\Hearthstone
2015-08-18 19:47:34 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-18 11:49:05 ----RD---- C:\Program Files
2015-08-18 11:47:32 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2015-08-18 07:17:33 ----D---- C:\Windows\winsxs
2015-08-18 07:14:51 ----D---- C:\Program Files (x86)\Battle.net
2015-08-17 21:14:30 ----SD---- C:\Windows\system32\CompatTel
2015-08-17 21:14:24 ----D---- C:\Windows\system32\wbem
2015-08-17 21:14:24 ----D---- C:\Windows\system32\appraiser
2015-08-17 21:14:24 ----D---- C:\Windows\System32
2015-08-17 21:14:22 ----D---- C:\Windows\AppPatch
2015-08-17 21:14:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-17 21:14:07 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-17 21:14:07 ----D---- C:\Windows\system32\cs-CZ
2015-08-17 21:13:59 ----SD---- C:\Windows\SYSWOW64\GWX
2015-08-17 21:13:59 ----SD---- C:\Windows\system32\GWX
2015-08-17 21:13:42 ----D---- C:\Program Files\Internet Explorer
2015-08-17 21:13:40 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-17 21:13:37 ----D---- C:\Windows\system32\en-US
2015-08-17 21:13:33 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-17 21:13:05 ----D---- C:\Windows
2015-08-17 21:10:30 ----D---- C:\FRST
2015-08-17 21:10:29 ----D---- C:\Windows\Tasks
2015-08-17 21:03:00 ----D---- C:\Program Files\Microsoft Silverlight
2015-08-17 21:03:00 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-08-17 21:02:34 ----D---- C:\Windows\Prefetch
2015-08-17 20:48:29 ----D---- C:\Windows\system32\MRT
2015-08-17 20:23:33 ----D---- C:\Windows\system32\catroot2
2015-07-28 10:59:08 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2010-11-12 77952]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2010-11-12 37504]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-06-17 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sysmon;sysmon; C:\Windows\system32\DRIVERS\sysmon.sys [2014-09-10 119344]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-03-10 246000]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-03-10 169792]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2015-02-28 26528]
R1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMUdisk64.sys [2015-08-24 62264]
R1 rsutils;rsutils; C:\Windows\system32\DRIVERS\rsutils.sys [2014-08-15 69336]
R1 TSDefenseBt;TSDefenseBt; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TSDefenseBT64.sys [2015-08-24 28472]
R1 TSSysKit;TSSysKit; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TSSysKit64.sys [2015-08-24 87352]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2014-10-08 122072]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-03-10 159480]
R2 QQSysMonX64;QQSysMonX64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQSysMonX64.sys [2015-08-24 138040]
R2 TAOAccelerator;Tencent TAOAccelerator driver.; \??\C:\Windows\system32\Drivers\TAOAccelerator64.sys [2015-08-24 74040]
R2 TAOKernelDriver;Tencent TAO kernel driver.; \??\C:\Windows\system32\Drivers\TAOKernel64.sys [2015-08-24 274232]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-03-05 8283136]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-03-04 295424]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2011-04-13 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2011-04-13 298656]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2011-04-13 29344]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2011-04-13 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2011-04-13 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2011-04-13 154272]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2011-04-13 281760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-01-12 2709224]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-02-15 335464]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-10-14 396848]
R3 TFsFlt;TFsFlt; C:\Windows\system32\Drivers\TFsFltX64.sys [2015-08-24 87864]
R3 TSSKX64;TSSKX64; C:\Windows\System32\drivers\tsskx64.sys [2015-08-24 38200]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-11-29 44672]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-06-10 1311232]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2015-01-19 19456]
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 31800]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2012-11-28 1866080]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2015-01-19 30208]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-03-04 203776]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-04 354304]
R2 AMD Reservation Manager;AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-04-13 146592]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-04-13 77984]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2014-10-08 388824]
R2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [2014-10-08 782040]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-01-28 1349576]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-12-15 9216]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-07-21 103992]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-03-05 35200]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2010-12-28 1817088]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2015-02-03 76888]
R2 QQPCRTP;QQPCMgr RTP Service; C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRTP.exe [2015-08-24 301728]
R2 RsMgrSvc;Rsd Service; C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe [2014-09-02 179992]
R2 RsRavMon;Rav Service; C:\Program Files (x86)\Rising\RAV\ravmond.exe [2014-05-15 277552]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-04-17 5448976]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-09-01 991288]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-08-19 838336]
R3 TAOFrame;TAOFrame; C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TAOFrame.exe [2015-08-24 293856]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2014-10-08 409304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-05 107848]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-18 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-05 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-03 148080]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-10-27 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-16 1900400]
S4 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-02-18 315488]
-----------------EOF-----------------
FRST Log mi vytvořit nejde.
ADWCleaner nic nenašel.
Screen věcí ve správci úloh : https://gyazo.com/bccc59b544acd6fdb9c1dc46689bc8e5
RSIT :
RSIT : Logfile of random's system information tool 1.10 (written by random/random)
Run by Petr at 2015-08-24 19:48:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 207 GB (45%) free of 461 GB
Total RAM: 3835 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:48:45, on 24.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17937)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Garena Plus\ggdllhost.exe
C:\Program Files (x86)\Gyazo\GyStation.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\ProgramData\Battle.net\Agent\Agent.4318\Agent.exe
C:\Program Files (x86)\Battle.net\Battle.net.6087\Battle.net.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Petr\AppData\Local\Temp\setup.exe
C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\core\PDApp.exe
C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\DECore\Setup.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMDeskTopGC.exe
C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCPatch.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\plugins\QMNetMon\QQPCNetFlow.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRealTimeSpeedup.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMAutoClean.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Petr.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: SohuBHO - {452ADB5B-00BE-469D-A65F-3046146B2ED5} - C:\Program Files (x86)\????\SoHuAutoDetector.dll (file missing)
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [setup.exe -start] C:\Users\Petr\AppData\Local\Temp\setup.exe -start
O4 - HKLM\..\Run: [SohuVA] "C:\Program Files (x86)\????\SHPlayer.exe" /auto
O4 - HKLM\..\Run: [RSDTRAY] "C:\Program Files (x86)\Rising\RSD\popwndexe.exe"
O4 - HKLM\..\Run: [ QQPCTray] "C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe" /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto (User 'Default user')
O4 - Startup: MEGAsync.lnk = C:\Users\Petr\AppData\Local\MEGAsync\MEGAsync.exe
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - (no file)
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - (no file)
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{F266592C-96FC-4C75-9FB1-044DA469F9AC}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\SysWow64\DreamScene.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QQPCMgr RTP Service (QQPCRTP) - Tencent - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRTP.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Rsd Service (RsMgrSvc) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe
O23 - Service: Rav Service (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RAV\ravmond.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TAOFrame - Tencent - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TAOFrame.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe
--
End of file - 12985 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
taskeng.exe {2BD92549-D2F6-47FF-9C9A-71456330D5D1}
"C:\Program Files (x86)\Garena Plus\ggdllhost.exe" "C:\Program Files (x86)\Garena Plus\ggspawn.dll",rundll_entry
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Gyazo\GyStation.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\system32\wbem\wmiprvse.exe
WLIDSvcM.exe 2608
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Users\Petr\AppData\Local\Steam\htmlcache" -steampid 4652 -buildid 1440016726 -steamid "0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe" "<hpNotification><Toast><Title>HP Wireless Assistant</Title><Text>Combo: On</Text><IconPath>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WA_tray_32_on.ico</IconPath><ID>1843685420</ID><Path>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe</Path><Parameters></Parameters></Toast></hpNotification>"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --device-scale-factor=1 --font-cache-shared-mem-suffix=2008 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --disable-accelerated-video-decode --disable-gpu-compositing --channel="2008.0.593194497\600572336" /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe" Restart start ccc
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\ProgramData\Battle.net\Agent\Agent.4318\Agent.exe" --locale=enGB --session=350553187791997185
\??\C:\Windows\system32\conhost.exe "-334962074446107757156313936-2046207406-3542156462788453991736109038778788398
"C:\Program Files (x86)\Battle.net\Battle.net.6087\Battle.net.exe" "--gamepath=C:\Program Files (x86)\Hearthstone" --game=hs_beta
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="2192.2.499375426\1122871738" --font-cache-shared-handle=2776 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2192.8.896959894\1126773821" --use-gl=swiftshader --supports-dual-gpus=false --swiftshader-path="C:\Users\Petr\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159" --gpu-driver-bug-workarounds=2,22,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.812.1.3000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.10.1028835618\1380316339" --font-cache-shared-handle=3468 /prefetch:673131151
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --device-scale-factor=1 --font-cache-shared-mem-suffix=2008 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --disable-accelerated-video-decode --disable-gpu-compositing --channel="2008.7.2058502497\1232248022" /prefetch:673131151
"taskhost.exe"
"C:\Program Files\Teamspeak\ts3client_win64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2192.146.662474096\407123378" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\Petr\AppData\Local\Temp\setup.exe" /VERYSILENT /SP-
"C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\core\PDApp.exe" --media="C:\Users\Petr\Documents\Photoshop" --appletID="DWA_UI" --appletVersion="2.0" --requiredSize=149175
"C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp\DECore\Setup.exe" --deploymentFile="C:\Users\Petr\AppData\Local\Temp\{890585E7-0DB9-43B0-A8EE-0FCEB4D7DC48}\deploy.xml" --userASUPath="C:\Users\Petr\AppData\Local\Adobe\OOBE\PDApp" --DEVersion=8.0
"C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe"
"C:\Program Files (x86)\Rising\RAV\ravmond.exe"
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TAOFrame.exe"
"C:\Windows\system32\taskmgr.exe" /4
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRtp.exe" -r
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe" /elevated /regrun
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCPatch.exe"
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe" /slient /PLUGIN_管家蓝屏修复 /pcmgr
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMDeskTopGC.exe" /ShowUEFromInstall
"C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.171.794774908\735003121" --font-cache-shared-handle=5848 /prefetch:673131151
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCPatch.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.173.11003299\937529188" --font-cache-shared-handle=5836 /prefetch:673131151
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\plugins\QMNetMon\QQPCNetFlow.exe" /regrun /elevated
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRealTimeSpeedup.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe44_ Global\UsGthrCtrlFltPipeMssGthrPipe44 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.176.210237886\980951272" --font-cache-shared-handle=4596 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.177.1203048719\589887624" --font-cache-shared-handle=3336 /prefetch:673131151
"C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMAutoClean.exe" garbageLimit:300|taskId:5|tipsId:5|taskType:5|depthGarbageLimit:1024
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
taskeng.exe {687B8E75-C467-4D0A-AA62-BC8923560761}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/*AutofillEnabled/Default/*AutofillFieldMetadata/Enabled/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/ReportCertificateErrorsOverHttp/UploadReportsOverHttp/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_91/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --use-image-texture-target=3553 --disable-gpu-compositing --channel="2192.180.259077382\90457591" --font-cache-shared-handle=1588 /prefetch:673131151
"C:\Program Files\CCleaner\CCleaner.exe" /uac
"C:\Program Files\CCleaner\CCleaner.exe" /uac
"C:\Users\Petr\Desktop\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\HPCeeScheduleForPetr.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPetr (null)
=========Mozilla firefox=========
ProfilePath - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\faqsxm5w.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1218158.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/QQPCMgr]
"Description"=QQPCMgr Detector
"Path"=C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\npQMExtensionsMozilla.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@rising.com.cn/nprising]
"Description"=
"Path"=C:\Program Files (x86)\Rising\RAV\nprising.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@sohu.com/npifox]
"Description"=ifox-plugin
"Path"=C:\Program Files (x86)\搜狐影音\npifox.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@t.garena.com/garenatalk]
"Description"=Garena Talk Plugin
"Path"=C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}]
电脑管家网页防火墙 - C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TSWebMon64.dat [2015-08-24 414560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{452ADB5B-00BE-469D-A65F-3046146B2ED5}]
CSohuDetector Object - C:\Program Files (x86)\搜狐影音\SoHuAutoDetector.dll [2015-08-24 213432]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2011-01-12 6602856]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-14 2837288]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-04-13 627360]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-04-13 379552]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2010-07-21 8192]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-01-28 5595848]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
"Gyazo"=C:\Program Files (x86)\Gyazo\GyStation.exe [2015-08-19 3098424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 8]
C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe /Auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2014-10-08 843480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
C:\Program Files (x86)\Origin\Origin.exe [2014-12-16 3618648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarenaPlus]
C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [2014-10-27 9974576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe /autostart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
C:\Users\Petr\AppData\Roaming\Spotify\spotify.exe [2015-01-10 6737976]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\Petr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2015-01-10 1676344]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-03-04 336384]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2012-03-05 578944]
"HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [2011-08-19 379960]
"setup.exe -start"=C:\Users\Petr\AppData\Local\Temp\setup.exe [2015-08-24 122880]
"SohuVA"=C:\Program Files (x86)\????\SHPlayer.exe /auto []
"RSDTRAY"=C:\Program Files (x86)\Rising\RSD\popwndexe.exe [2012-09-25 126808]
" QQPCTray"=C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCTray.exe [2015-08-24 355296]
C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Petr\AppData\Local\MEGAsync\MEGAsync.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2015-02-17 275360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll
"vidc.tsc2"=C:\Windows\SysWOW64\tsc2_codec64.dll
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-24 19:45:00 ----D---- C:\Program Files (x86)\Adobe
2015-08-24 19:42:48 ----D---- C:\ProgramData\TXQMPC
2015-08-24 19:41:50 ----A---- C:\Windows\system32\drivers\TAOAccelerator64.sys
2015-08-24 19:41:07 ----D---- C:\Program Files\Common Files\Tencent
2015-08-24 19:40:05 ----A---- C:\Windows\system32\drivers\TSSKX64.sys
2015-08-24 19:39:38 ----A---- C:\Windows\system32\drivers\TAOKernel64.sys
2015-08-24 19:38:52 ----A---- C:\Windows\system32\drivers\TFsFltX64.sys
2015-08-24 19:36:43 ----RSH---- C:\rising.ini
2015-08-24 19:35:02 ----N---- C:\Windows\system32\drivers\sysmon.sys
2015-08-24 19:35:02 ----N---- C:\Windows\system32\drivers\rsutils.sys
2015-08-24 19:35:02 ----N---- C:\Windows\system32\drivers\rsndisp.sys
2015-08-24 19:34:31 ----D---- C:\Users\Petr\AppData\Roaming\Tencent
2015-08-24 19:34:31 ----D---- C:\Program Files (x86)\Tencent
2015-08-24 19:34:05 ----D---- C:\Program Files (x86)\Rising
2015-08-24 19:34:04 ----D---- C:\ProgramData\Rising
2015-08-24 19:33:53 ----D---- C:\ProgramData\Tencent
2015-08-24 19:24:56 ----D---- C:\ProgramData\Adobe
2015-08-24 19:22:24 ----D---- C:\AdwCleaner
2015-08-24 19:13:31 ----HD---- C:\sohucache
2015-08-24 19:13:20 ----D---- C:\SHDownload
2015-08-24 19:12:39 ----D---- C:\Program Files (x86)\搜狐影音
2015-08-18 21:22:33 ----D---- C:\Users\Petr\AppData\Roaming\HearthstoneDeckTracker
2015-08-18 11:49:38 ----D---- C:\Users\Petr\AppData\Roaming\TS3Client
2015-08-18 11:48:59 ----D---- C:\Program Files\Teamspeak
2015-08-17 21:05:20 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 21:05:20 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 20:28:40 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-08-17 20:28:40 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-08-17 20:28:40 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-08-17 20:28:40 ----A---- C:\Windows\system32\iertutil.dll
2015-08-17 20:28:40 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-17 20:28:40 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-17 20:28:39 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-08-17 20:28:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-08-17 20:28:39 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-08-17 20:28:39 ----A---- C:\Windows\system32\iernonce.dll
2015-08-17 20:28:39 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-08-17 20:28:38 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-08-17 20:28:38 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-17 20:28:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-08-17 20:28:35 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-08-17 20:28:35 ----A---- C:\Windows\system32\urlmon.dll
2015-08-17 20:28:35 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-08-17 20:28:34 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-08-17 20:28:34 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-17 20:28:34 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-17 20:28:33 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-08-17 20:28:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-08-17 20:28:33 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-08-17 20:28:33 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-17 20:28:33 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-17 20:28:32 ----A---- C:\Windows\system32\iesetup.dll
2015-08-17 20:28:32 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-17 20:28:29 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-08-17 20:28:29 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-08-17 20:28:29 ----A---- C:\Windows\system32\vbscript.dll
2015-08-17 20:28:28 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-08-17 20:28:28 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-08-17 20:28:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-08-17 20:28:28 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-17 20:28:28 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-17 20:28:27 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-17 20:28:26 ----A---- C:\Windows\system32\ieui.dll
2015-08-17 20:28:26 ----A---- C:\Windows\system32\ieframe.dll
2015-08-17 20:28:25 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-17 20:28:25 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-17 20:28:24 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-17 20:28:24 ----A---- C:\Windows\system32\jscript.dll
2015-08-17 20:28:23 ----A---- C:\Windows\system32\jscript9.dll
2015-08-17 20:28:22 ----A---- C:\Windows\system32\wininet.dll
2015-08-17 20:28:21 ----A---- C:\Windows\system32\msrating.dll
2015-08-17 20:28:21 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-17 20:28:20 ----A---- C:\Windows\system32\mshtml.dll
2015-08-17 20:28:16 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-08-17 20:28:16 ----A---- C:\Windows\system32\ole32.dll
2015-08-17 20:28:15 ----A---- C:\Windows\system32\wksprt.exe
2015-08-17 20:28:15 ----A---- C:\Windows\system32\mstscax.dll
2015-08-17 20:28:13 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-08-17 20:28:11 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-08-17 20:28:11 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2015-08-17 20:28:11 ----A---- C:\Windows\system32\tsgqec.dll
2015-08-17 20:28:11 ----A---- C:\Windows\system32\rdvidcrl.dll
2015-08-17 20:28:03 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-08-17 20:28:03 ----A---- C:\Windows\system32\msi.dll
2015-08-17 20:28:03 ----A---- C:\Windows\system32\authui.dll
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-08-17 20:28:02 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-08-17 20:28:02 ----A---- C:\Windows\system32\msimsg.dll
2015-08-17 20:28:02 ----A---- C:\Windows\system32\msihnd.dll
2015-08-17 20:28:02 ----A---- C:\Windows\system32\msiexec.exe
2015-08-17 20:28:02 ----A---- C:\Windows\system32\consent.exe
2015-08-17 20:28:02 ----A---- C:\Windows\system32\appinfo.dll
2015-08-17 20:27:51 ----A---- C:\Windows\system32\gdi32.dll
2015-08-17 20:27:50 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-08-17 20:27:49 ----A---- C:\Windows\system32\msxml3.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-08-17 20:27:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-08-17 20:27:48 ----A---- C:\Windows\system32\msxml6r.dll
2015-08-17 20:27:48 ----A---- C:\Windows\system32\msxml6.dll
2015-08-17 20:27:48 ----A---- C:\Windows\system32\msxml3r.dll
2015-08-17 20:27:34 ----A---- C:\Windows\system32\rpcrt4.dll
2015-08-17 20:27:34 ----A---- C:\Windows\system32\lsasrv.dll
2015-08-17 20:27:34 ----A---- C:\Windows\system32\kerberos.dll
2015-08-17 20:27:33 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-08-17 20:27:33 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-08-17 20:27:33 ----A---- C:\Windows\system32\schannel.dll
2015-08-17 20:27:33 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-08-17 20:27:33 ----A---- C:\Windows\system32\ntdll.dll
2015-08-17 20:27:33 ----A---- C:\Windows\system32\msv1_0.dll
2015-08-17 20:27:32 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-08-17 20:27:32 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-08-17 20:27:32 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-08-17 20:27:32 ----A---- C:\Windows\system32\kernel32.dll
2015-08-17 20:27:32 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-08-17 20:27:32 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-08-17 20:27:31 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-08-17 20:27:31 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-08-17 20:27:31 ----A---- C:\Windows\system32\sysmain.dll
2015-08-17 20:27:31 ----A---- C:\Windows\system32\adtschema.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-08-17 20:27:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\wdigest.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\TSpkg.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\ncrypt.dll
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-08-17 20:27:30 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-08-17 20:27:29 ----A---- C:\Windows\system32\wow64.dll
2015-08-17 20:27:29 ----A---- C:\Windows\system32\rstrui.exe
2015-08-17 20:27:29 ----A---- C:\Windows\system32\KernelBase.dll
2015-08-17 20:27:28 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\winsrv.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\srcore.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\csrsrv.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\cryptbase.dll
2015-08-17 20:27:28 ----A---- C:\Windows\system32\conhost.exe
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-08-17 20:27:27 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-08-17 20:27:27 ----A---- C:\Windows\system32\sspisrv.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\sspicli.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\srclient.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\smss.exe
2015-08-17 20:27:27 ----A---- C:\Windows\system32\secur32.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\ntvdm64.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\msmmsp.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\msaudite.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\lsass.exe
2015-08-17 20:27:27 ----A---- C:\Windows\system32\credssp.dll
2015-08-17 20:27:27 ----A---- C:\Windows\system32\auditpol.exe
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-17 20:27:26 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-17 20:27:26 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-08-17 20:27:26 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-08-17 20:27:26 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-08-17 20:27:26 ----A---- C:\Windows\system32\wow64win.dll
2015-08-17 20:27:26 ----A---- C:\Windows\system32\wow64cpu.dll
2015-08-17 20:27:26 ----A---- C:\Windows\system32\msobjs.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-17 20:27:25 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-17 20:27:25 ----A---- C:\Windows\SYSWOW64\user.exe
2015-08-17 20:27:25 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-08-17 20:27:25 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-08-17 20:27:25 ----A---- C:\Windows\system32\apisetschema.dll
2015-08-17 20:26:42 ----A---- C:\Windows\system32\basesrv.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\invagent.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\generaltel.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\devinv.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\appraiser.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\aeinv.dll
2015-08-17 20:26:17 ----A---- C:\Windows\system32\acmigration.dll
2015-08-17 20:26:16 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-08-17 20:26:16 ----A---- C:\Windows\system32\aepdu.dll
2015-08-17 20:25:47 ----A---- C:\Windows\system32\FntCache.dll
2015-08-17 20:25:46 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-08-17 20:25:46 ----A---- C:\Windows\system32\win32k.sys
2015-08-17 20:25:46 ----A---- C:\Windows\system32\DWrite.dll
2015-08-17 20:25:46 ----A---- C:\Windows\system32\atmfd.dll
2015-08-17 20:25:45 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-08-17 20:25:42 ----A---- C:\Windows\system32\lpk.dll
2015-08-17 20:25:41 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-08-17 20:25:41 ----A---- C:\Windows\system32\d3d10warp.dll
2015-08-17 20:25:41 ----A---- C:\Windows\system32\atmlib.dll
2015-08-17 20:25:40 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-08-17 20:25:39 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-08-17 20:25:39 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-08-17 20:25:39 ----A---- C:\Windows\system32\fontsub.dll
2015-08-17 20:25:39 ----A---- C:\Windows\system32\dciman32.dll
2015-08-17 20:25:38 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-08-17 20:25:35 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-08-17 20:25:35 ----A---- C:\Windows\system32\cewmdm.dll
2015-08-17 20:25:25 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-08-17 20:25:25 ----A---- C:\Windows\system32\rdpcorets.dll
2015-08-17 20:25:18 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-08-17 20:25:18 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-08-17 20:25:18 ----A---- C:\Windows\system32\cryptsvc.dll
2015-08-17 20:25:17 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-08-17 20:25:17 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-08-17 20:25:17 ----A---- C:\Windows\system32\wintrust.dll
2015-08-17 20:25:17 ----A---- C:\Windows\system32\cryptnet.dll
2015-08-17 20:25:17 ----A---- C:\Windows\system32\crypt32.dll
2015-08-17 20:25:08 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-08-17 20:25:08 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-08-17 20:25:08 ----A---- C:\Windows\system32\WebClnt.dll
2015-08-17 20:25:08 ----A---- C:\Windows\system32\davclnt.dll
2015-08-17 20:24:11 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-08-17 20:24:11 ----A---- C:\Windows\system32\notepad.exe
2015-08-17 20:24:11 ----A---- C:\Windows\notepad.exe
2015-08-17 20:10:26 ----A---- C:\Windows\system32\shell32.dll
2015-08-17 20:10:23 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-08-17 20:09:20 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wucltux.dll
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wuauclt.exe
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wuapp.exe
2015-08-17 20:09:20 ----A---- C:\Windows\system32\wuapi.dll
2015-08-17 20:09:20 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wuwebv.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wups2.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wups.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wudriver.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wuaueng.dll
2015-08-17 20:09:19 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-08-17 19:55:18 ----D---- C:\ProgramData\Gyazo
======List of files/folders modified in the last 1 month======
2015-08-24 19:48:39 ----D---- C:\Windows\Temp
2015-08-24 19:48:35 ----D---- C:\Program Files\trend micro
2015-08-24 19:48:17 ----D---- C:\Users\Petr\AppData\Roaming\Adobe
2015-08-24 19:45:00 ----RD---- C:\Program Files (x86)
2015-08-24 19:42:48 ----HD---- C:\ProgramData
2015-08-24 19:41:50 ----D---- C:\Windows\system32\drivers
2015-08-24 19:41:07 ----D---- C:\Program Files\Common Files
2015-08-24 19:39:54 ----RSD---- C:\Windows\Fonts
2015-08-24 19:38:49 ----D---- C:\Program Files (x86)\Common Files
2015-08-24 19:32:37 ----SHD---- C:\Windows\Installer
2015-08-24 19:32:36 ----SHD---- C:\Config.Msi
2015-08-24 19:32:35 ----D---- C:\Windows\SysWOW64
2015-08-24 19:32:09 ----SHD---- C:\System Volume Information
2015-08-24 19:32:09 ----D---- C:\ProgramData\Package Cache
2015-08-24 14:51:33 ----D---- C:\Program Files (x86)\Steam
2015-08-24 10:52:22 ----D---- C:\ProgramData\PDFC
2015-08-24 10:02:28 ----D---- C:\Windows\system32\config
2015-08-24 09:51:31 ----D---- C:\Windows\system32\Tasks
2015-08-20 20:02:37 ----D---- C:\Program Files (x86)\Gyazo
2015-08-19 21:33:15 ----D---- C:\Program Files (x86)\Opera
2015-08-19 20:22:27 ----D---- C:\Windows\Microsoft.NET
2015-08-19 12:26:21 ----RSD---- C:\Windows\assembly
2015-08-18 20:17:18 ----D---- C:\Program Files (x86)\Hearthstone
2015-08-18 19:47:34 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-08-18 11:49:05 ----RD---- C:\Program Files
2015-08-18 11:47:32 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2015-08-18 07:17:33 ----D---- C:\Windows\winsxs
2015-08-18 07:14:51 ----D---- C:\Program Files (x86)\Battle.net
2015-08-17 21:14:30 ----SD---- C:\Windows\system32\CompatTel
2015-08-17 21:14:24 ----D---- C:\Windows\system32\wbem
2015-08-17 21:14:24 ----D---- C:\Windows\system32\appraiser
2015-08-17 21:14:24 ----D---- C:\Windows\System32
2015-08-17 21:14:22 ----D---- C:\Windows\AppPatch
2015-08-17 21:14:11 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-08-17 21:14:07 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-08-17 21:14:07 ----D---- C:\Windows\system32\cs-CZ
2015-08-17 21:13:59 ----SD---- C:\Windows\SYSWOW64\GWX
2015-08-17 21:13:59 ----SD---- C:\Windows\system32\GWX
2015-08-17 21:13:42 ----D---- C:\Program Files\Internet Explorer
2015-08-17 21:13:40 ----D---- C:\Windows\SYSWOW64\en-US
2015-08-17 21:13:37 ----D---- C:\Windows\system32\en-US
2015-08-17 21:13:33 ----D---- C:\Program Files (x86)\Internet Explorer
2015-08-17 21:13:05 ----D---- C:\Windows
2015-08-17 21:10:30 ----D---- C:\FRST
2015-08-17 21:10:29 ----D---- C:\Windows\Tasks
2015-08-17 21:03:00 ----D---- C:\Program Files\Microsoft Silverlight
2015-08-17 21:03:00 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-08-17 21:02:34 ----D---- C:\Windows\Prefetch
2015-08-17 20:48:29 ----D---- C:\Windows\system32\MRT
2015-08-17 20:23:33 ----D---- C:\Windows\system32\catroot2
2015-07-28 10:59:08 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2010-11-12 77952]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2010-11-12 37504]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-06-17 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sysmon;sysmon; C:\Windows\system32\DRIVERS\sysmon.sys [2014-09-10 119344]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-03-10 246000]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-03-10 169792]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2015-02-28 26528]
R1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QMUdisk64.sys [2015-08-24 62264]
R1 rsutils;rsutils; C:\Windows\system32\DRIVERS\rsutils.sys [2014-08-15 69336]
R1 TSDefenseBt;TSDefenseBt; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TSDefenseBT64.sys [2015-08-24 28472]
R1 TSSysKit;TSSysKit; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TSSysKit64.sys [2015-08-24 87352]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2014-10-08 122072]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-03-10 159480]
R2 QQSysMonX64;QQSysMonX64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQSysMonX64.sys [2015-08-24 138040]
R2 TAOAccelerator;Tencent TAOAccelerator driver.; \??\C:\Windows\system32\Drivers\TAOAccelerator64.sys [2015-08-24 74040]
R2 TAOKernelDriver;Tencent TAO kernel driver.; \??\C:\Windows\system32\Drivers\TAOKernel64.sys [2015-08-24 274232]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-03-05 8283136]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-03-04 295424]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2011-04-13 36000]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-20 3678720]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2011-04-13 298656]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2011-04-13 29344]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2011-04-13 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2011-04-13 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2011-04-13 154272]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2011-04-13 281760]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-01-12 2709224]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-02-15 335464]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-10-14 396848]
R3 TFsFlt;TFsFlt; C:\Windows\system32\Drivers\TFsFltX64.sys [2015-08-24 87864]
R3 TSSKX64;TSSKX64; C:\Windows\System32\drivers\tsskx64.sys [2015-08-24 38200]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-11-29 44672]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-06-10 1311232]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2015-01-19 19456]
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 31800]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2012-11-28 1866080]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2015-01-19 30208]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-03-04 203776]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-03-04 354304]
R2 AMD Reservation Manager;AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-04-13 146592]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-04-13 77984]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2014-10-08 388824]
R2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [2014-10-08 782040]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-01-28 1349576]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-12-15 9216]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-07-21 103992]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-03-05 35200]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2010-12-28 1817088]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2015-02-03 76888]
R2 QQPCRTP;QQPCMgr RTP Service; C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\QQPCRTP.exe [2015-08-24 301728]
R2 RsMgrSvc;Rsd Service; C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe [2014-09-02 179992]
R2 RsRavMon;Rav Service; C:\Program Files (x86)\Rising\RAV\ravmond.exe [2014-05-15 277552]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-04-17 5448976]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-09-01 991288]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-08-19 838336]
R3 TAOFrame;TAOFrame; C:\Program Files (x86)\Tencent\QQPCMgr\10.11.16575.227\TAOFrame.exe [2015-08-24 293856]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2014-10-08 409304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-05 107848]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-18 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-05 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-07-16 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-03 148080]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-10-27 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-16 1900400]
S4 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-02-18 315488]
-----------------EOF-----------------
