poprosil by som o kontrolu logu
Napsal: 07 lis 2015 15:53
mam windows 7, 64-bit. problem sa tyka toho ze mi dnes po prihlaseni viac krat nenabehol system to znamena ze som mal ciernu obrazovku alebo nabehol ale bol neskutocne pomaly. ked mi system nabehol tak hoci bol pomaly nastastie sa mi podarilo spustit obnovenie systemu cize som zadal datum ktory bol v ponuke 3.11.
len pre zaujimavost niekolko dni dozadu som mal aj tzv. modru obrazovku, cize sa objavila modra obrazovka a system sa sam restartoval.
tu je log
Logfile of random's system information tool 1.10 (written by random/random)
Run by Peťo at 2015-11-07 15:32:01
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 877 GB (93%) free of 941 GB
Total RAM: 4024 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:36:17, on 7. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18057)
Boot mode: Normal
Running processes:
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Peťo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [HP File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: HP Trust Circles Service (CreoService) - CryptoMill Technologies Ltd. - C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe
O23 - Service: Absolute Software Agent Service (CtAgentService) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\windows\SysWOW64\flcdlock.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Device Access Manager Usage Service (HpDamServiceHost) - Hewlett-Packard Development Company - c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe
O23 - Service: HP File Sanitizer (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12240 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPSP
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPCardEngine.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe"
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c4acc489-0124-41db-bb31-13c1ecad0a25 -SystemEventPortName:HostProcess-c00f7656-51cd-4f5e-923f-fd212baa033f -IoCancelEventPortName:HostProcess-e4ef6838-0f12-4701-8f64-731b8804dcdf -NonStateChangingEventPortName:HostProcess-18a5306a-df8d-429a-899a-e4beca0de111 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:05418221-34d4-4c1d-8678-7c9e6c3a0763 -DeviceGroupId:WpdFsGroup
C:\windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe"
HydraDM64.exe -h:66084 "Maximize to full desktop" "Maximize to window corners" "Restore desktop"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4316.0.1917683359\1480359320" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6771 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.152.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group23 stable:pp1 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_3/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4316.1.1924626602\1799321690" --font-cache-shared-handle=1824 /prefetch:673131151
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\windows\system32\GWX\GWX.exe"
"c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5888 CREDAT:275457 /prefetch:2
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5888 CREDAT:3748900 /prefetch:2
C:\windows\system32\wbem\wmiprvse.exe
"C:\Users\Peťo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U18KFEB2\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k WerSvcGroup
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_cab_01e6c85d"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c86d"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_a1a9c040be80fb638654f34d19837ef1ba5e8b_cab_01e6c87c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_2152759308_fbba4499ee721a68a91dbf50df77d6fe6c94f742_cab_01e6c88c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c89c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c8ab"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c8bb"
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1cffeff3732ce5a.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1d040bee0413f91.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1cffeff37d4abed.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1d040bee0d766ae.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default
prefs.js - "browser.startup.homepage" - "google.com"
prefs.js - "keyword.URL" - "http://www.bing.com/search?FORM=U303DF&PC=U303&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\digitalpersona.com/ChromeDPAgent]
"Description"=
"Path"=c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default\extensions\
bingsearch.full@microsoft.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
HP File Sanitizer - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2014-02-05 129240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-06-11 165872]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-06-11 407536]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-06-11 444400]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-07-27 7194840]
""= []
"CryptoMill Refresh"=C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2013-08-31 389120]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-10-20 811848]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-04-26 292848]
"StartCCC"=c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-08-31 766208]
"CLMLServer_For_P2G8"=c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05 111576]
"CLVirtualDrive"=c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [2013-08-07 490760]
"HP File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2014-02-05 2213592]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2013-07-18 683656]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-06-03 441344]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-11-07 15:32:02 ----D---- C:\Program Files\trend micro
2015-11-07 15:32:01 ----D---- C:\rsit
2015-10-16 08:06:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-10-15 08:36:03 ----A---- C:\windows\system32\appraiser.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\invagent.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\generaltel.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\devinv.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\aeinv.dll
2015-10-15 08:36:01 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-10-15 08:36:01 ----A---- C:\windows\system32\acmigration.dll
2015-10-14 05:33:58 ----A---- C:\windows\system32\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2015-10-14 05:33:57 ----A---- C:\windows\system32\ExplorerFrame.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwcollector.exe
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\occache.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\iernonce.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\ie4uinit.exe
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\occache.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\iedkcs32.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\urlmon.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-10-14 05:33:50 ----A---- C:\windows\system32\msfeeds.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\dxtrans.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iesetup.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iertutil.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\ieapfltr.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-10-14 05:33:48 ----A---- C:\windows\system32\vbscript.dll
2015-10-14 05:33:48 ----A---- C:\windows\system32\jsproxy.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieui.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieframe.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\dxtmsft.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\webcheck.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmled.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9diag.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\ieUnatt.exe
2015-10-14 05:33:45 ----A---- C:\windows\system32\wininet.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\msrating.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\MshtmlDac.dll
2015-10-14 05:33:44 ----A---- C:\windows\system32\mshtml.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wucltux.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuaueng.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuapi.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups2.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuauclt.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\WinSetupUI.dll
2015-10-14 05:33:14 ----A---- C:\windows\SYSWOW64\wups.dll
2015-10-14 05:33:14 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2015-10-14 05:33:07 ----A---- C:\windows\system32\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-10-14 05:33:06 ----A---- C:\windows\system32\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\SYSWOW64\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\ntdll.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\lsasrv.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\wow64.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\winsrv.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\srcore.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\rstrui.exe
2015-10-14 05:33:04 ----A---- C:\windows\system32\rpcrt4.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\KernelBase.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\conhost.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\sspicli.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\smss.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\ntvdm64.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\msv1_0.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\lsass.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\csrsrv.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\cryptbase.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\auditpol.exe
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64win.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64cpu.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\sspisrv.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\credssp.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\user.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\adtschema.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msaudite.dll
2015-10-14 05:32:46 ----A---- C:\windows\SYSWOW64\appidapi.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\setbcdlocale.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidsvc.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidpolicyconverter.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidcertstorecheck.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidapi.dll
2015-10-14 05:32:45 ----A---- C:\windows\system32\drivers\appid.sys
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\ucrtbase.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
======List of files/folders modified in the last 1 month======
2015-11-07 15:32:02 ----RD---- C:\Program Files
2015-11-07 15:31:59 ----D---- C:\windows\Temp
2015-11-07 15:19:07 ----SHD---- C:\System Volume Information
2015-11-07 15:12:28 ----D---- C:\windows\System32
2015-11-07 15:12:28 ----D---- C:\windows\inf
2015-11-07 15:12:28 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-11-07 15:08:49 ----D---- C:\windows\system32\config
2015-11-07 15:07:43 ----D---- C:\ProgramData\PDFC
2015-11-07 15:07:20 ----D---- C:\Windows
2015-11-07 15:07:12 ----D---- C:\windows\Tasks
2015-11-07 15:07:12 ----D---- C:\windows\system32\wfp
2015-11-07 15:07:11 ----D---- C:\windows\system32\wbem
2015-11-07 15:06:35 ----D---- C:\windows\system32\DriverStore
2015-11-07 15:06:35 ----D---- C:\windows\system32\catroot2
2015-11-07 15:06:33 ----D---- C:\windows\system32\Tasks
2015-11-07 15:06:32 ----SD---- C:\windows\system32\GWX
2015-11-07 15:06:32 ----D---- C:\Users\Peťo\AppData\Roaming\MusicBee
2015-11-07 15:06:31 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-07 15:06:29 ----D---- C:\windows\registration
2015-11-07 15:06:19 ----RD---- C:\Program Files (x86)
2015-11-07 14:54:19 ----D---- C:\windows\Prefetch
2015-11-01 19:39:39 ----D---- C:\Users\Peťo\AppData\Roaming\Adobe
2015-11-01 19:39:39 ----D---- C:\ProgramData\Adobe
2015-11-01 18:52:52 ----SD---- C:\Users\Peťo\AppData\Roaming\Microsoft
2015-11-01 18:47:51 ----D---- C:\windows\Minidump
2015-11-01 18:47:51 ----D---- C:\windows\debug
2015-10-27 07:09:33 ----D---- C:\windows\system32\drivers
2015-10-27 07:09:33 ----D---- C:\windows\system32\CodeIntegrity
2015-10-27 07:09:33 ----D---- C:\windows\AppCompat
2015-10-16 18:31:21 ----D---- C:\windows\SysWOW64
2015-10-16 18:31:18 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-10-16 14:24:35 ----SHD---- C:\windows\Installer
2015-10-15 14:43:42 ----RD---- C:\Users
2015-10-15 13:08:42 ----D---- C:\windows\winsxs
2015-10-15 13:08:33 ----SD---- C:\windows\system32\CompatTel
2015-10-15 13:08:31 ----D---- C:\windows\system32\appraiser
2015-10-15 13:08:31 ----D---- C:\windows\AppPatch
2015-10-14 15:02:35 ----D---- C:\windows\rescache
2015-10-14 14:26:01 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-10-14 14:26:01 ----D---- C:\Program Files\Internet Explorer
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\system32\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\cs-CZ
2015-10-14 14:25:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-14 14:25:56 ----D---- C:\windows\system32\Boot
2015-10-14 13:43:08 ----D---- C:\windows\system32\MRT
2015-10-14 13:39:48 ----A---- C:\windows\system32\MRT.exe
2015-10-08 20:22:45 ----SD---- C:\windows\SYSWOW64\GWX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStorA;iaStorA; C:\windows\system32\drivers\iaStorA.sys [2013-09-21 630632]
R0 iaStorF;iaStorF; C:\windows\system32\drivers\iaStorF.sys [2013-09-21 28008]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\drivers\iusb3hcs.sys [2013-04-26 20464]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PinFile;PinFile; C:\windows\system32\DRIVERS\PinFile.sys [2014-02-03 49856]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SDDisk2K;SDDisk2K; C:\windows\system32\DRIVERS\SDDisk2K.sys [2014-02-03 228544]
R0 SDDToki;SDDToki; C:\windows\system32\DRIVERS\SDDToki.sys [2014-02-03 131264]
R0 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
R1 CLVirtualDrive;CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [2011-12-27 90608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-08-31 12528640]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-08-31 618496]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2013-07-05 96256]
R3 IceKore;IceKore; C:\windows\system32\DRIVERS\IceKore.sys [2013-11-14 411608]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-06-03 4438208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2013-07-31 3564376]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\windows\system32\DRIVERS\iusb3hub.sys [2013-04-26 368112]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\drivers\iusb3xhc.sys [2013-04-26 786416]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\drivers\TeeDriverx64.sys [2013-08-08 99288]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2013-08-15 881880]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2013-10-07 65752]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-12-04 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-08-31 239616]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 CreoService;HP Trust Circles Service; C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [2014-03-25 1927640]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 CtAgentService;Absolute Software Agent Service; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [2014-03-31 7168]
R2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [2013-08-12 77576]
R2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [2013-08-12 298760]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2014-04-04 500048]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-01-13 92160]
R2 HpDamServiceHost;HP Device Access Manager Usage Service; c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [2013-11-15 18232]
R2 HPFSService;HP File Sanitizer; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2014-02-05 1758936]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-08-08 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-08-08 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-08-08 390616]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-28 12784]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2013-07-18 1143432]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-06-19 246488]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-28 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-16 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-06-11 279024]
S3 FLCDLOCK;HP Device Locking / Auditing; c:\windows\SysWOW64\flcdlock.exe [2013-11-20 567608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-11-13 1233592]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-09-16 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-16 147624]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-11-13 1255736]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
len pre zaujimavost niekolko dni dozadu som mal aj tzv. modru obrazovku, cize sa objavila modra obrazovka a system sa sam restartoval.
tu je log
Logfile of random's system information tool 1.10 (written by random/random)
Run by Peťo at 2015-11-07 15:32:01
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 877 GB (93%) free of 941 GB
Total RAM: 4024 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:36:17, on 7. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18057)
Boot mode: Normal
Running processes:
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Peťo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [HP File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: HP Trust Circles Service (CreoService) - CryptoMill Technologies Ltd. - C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe
O23 - Service: Absolute Software Agent Service (CtAgentService) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\windows\SysWOW64\flcdlock.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Device Access Manager Usage Service (HpDamServiceHost) - Hewlett-Packard Development Company - c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe
O23 - Service: HP File Sanitizer (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12240 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPSP
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPCardEngine.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe"
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c4acc489-0124-41db-bb31-13c1ecad0a25 -SystemEventPortName:HostProcess-c00f7656-51cd-4f5e-923f-fd212baa033f -IoCancelEventPortName:HostProcess-e4ef6838-0f12-4701-8f64-731b8804dcdf -NonStateChangingEventPortName:HostProcess-18a5306a-df8d-429a-899a-e4beca0de111 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:05418221-34d4-4c1d-8678-7c9e6c3a0763 -DeviceGroupId:WpdFsGroup
C:\windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe"
HydraDM64.exe -h:66084 "Maximize to full desktop" "Maximize to window corners" "Restore desktop"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4316.0.1917683359\1480359320" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6771 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.152.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group23 stable:pp1 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_3/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4316.1.1924626602\1799321690" --font-cache-shared-handle=1824 /prefetch:673131151
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\windows\system32\GWX\GWX.exe"
"c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5888 CREDAT:275457 /prefetch:2
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5888 CREDAT:3748900 /prefetch:2
C:\windows\system32\wbem\wmiprvse.exe
"C:\Users\Peťo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U18KFEB2\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k WerSvcGroup
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_cab_01e6c85d"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c86d"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_a1a9c040be80fb638654f34d19837ef1ba5e8b_cab_01e6c87c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_2152759308_fbba4499ee721a68a91dbf50df77d6fe6c94f742_cab_01e6c88c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c89c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c8ab"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c8bb"
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1cffeff3732ce5a.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1d040bee0413f91.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1cffeff37d4abed.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1d040bee0d766ae.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default
prefs.js - "browser.startup.homepage" - "google.com"
prefs.js - "keyword.URL" - "http://www.bing.com/search?FORM=U303DF&PC=U303&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\digitalpersona.com/ChromeDPAgent]
"Description"=
"Path"=c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default\extensions\
bingsearch.full@microsoft.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
HP File Sanitizer - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2014-02-05 129240]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-06-11 165872]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-06-11 407536]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-06-11 444400]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-07-27 7194840]
""= []
"CryptoMill Refresh"=C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2013-08-31 389120]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-10-20 811848]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-04-26 292848]
"StartCCC"=c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-08-31 766208]
"CLMLServer_For_P2G8"=c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05 111576]
"CLVirtualDrive"=c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [2013-08-07 490760]
"HP File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2014-02-05 2213592]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2013-07-18 683656]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-06-03 441344]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-11-07 15:32:02 ----D---- C:\Program Files\trend micro
2015-11-07 15:32:01 ----D---- C:\rsit
2015-10-16 08:06:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-10-15 08:36:03 ----A---- C:\windows\system32\appraiser.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\invagent.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\generaltel.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\devinv.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\aeinv.dll
2015-10-15 08:36:01 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-10-15 08:36:01 ----A---- C:\windows\system32\acmigration.dll
2015-10-14 05:33:58 ----A---- C:\windows\system32\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2015-10-14 05:33:57 ----A---- C:\windows\system32\ExplorerFrame.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwcollector.exe
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\occache.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\iernonce.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\ie4uinit.exe
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\occache.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\iedkcs32.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\urlmon.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-10-14 05:33:50 ----A---- C:\windows\system32\msfeeds.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\dxtrans.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iesetup.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iertutil.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\ieapfltr.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-10-14 05:33:48 ----A---- C:\windows\system32\vbscript.dll
2015-10-14 05:33:48 ----A---- C:\windows\system32\jsproxy.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieui.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieframe.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\dxtmsft.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\webcheck.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmled.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9diag.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\ieUnatt.exe
2015-10-14 05:33:45 ----A---- C:\windows\system32\wininet.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\msrating.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\MshtmlDac.dll
2015-10-14 05:33:44 ----A---- C:\windows\system32\mshtml.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wucltux.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuaueng.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuapi.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups2.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuauclt.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\WinSetupUI.dll
2015-10-14 05:33:14 ----A---- C:\windows\SYSWOW64\wups.dll
2015-10-14 05:33:14 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2015-10-14 05:33:07 ----A---- C:\windows\system32\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-10-14 05:33:06 ----A---- C:\windows\system32\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\SYSWOW64\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\ntdll.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\lsasrv.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\wow64.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\winsrv.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\srcore.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\rstrui.exe
2015-10-14 05:33:04 ----A---- C:\windows\system32\rpcrt4.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\KernelBase.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\conhost.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\sspicli.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\smss.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\ntvdm64.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\msv1_0.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\lsass.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\csrsrv.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\cryptbase.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\auditpol.exe
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64win.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64cpu.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\sspisrv.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\credssp.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\user.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\adtschema.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msaudite.dll
2015-10-14 05:32:46 ----A---- C:\windows\SYSWOW64\appidapi.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\setbcdlocale.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidsvc.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidpolicyconverter.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidcertstorecheck.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidapi.dll
2015-10-14 05:32:45 ----A---- C:\windows\system32\drivers\appid.sys
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\ucrtbase.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
======List of files/folders modified in the last 1 month======
2015-11-07 15:32:02 ----RD---- C:\Program Files
2015-11-07 15:31:59 ----D---- C:\windows\Temp
2015-11-07 15:19:07 ----SHD---- C:\System Volume Information
2015-11-07 15:12:28 ----D---- C:\windows\System32
2015-11-07 15:12:28 ----D---- C:\windows\inf
2015-11-07 15:12:28 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-11-07 15:08:49 ----D---- C:\windows\system32\config
2015-11-07 15:07:43 ----D---- C:\ProgramData\PDFC
2015-11-07 15:07:20 ----D---- C:\Windows
2015-11-07 15:07:12 ----D---- C:\windows\Tasks
2015-11-07 15:07:12 ----D---- C:\windows\system32\wfp
2015-11-07 15:07:11 ----D---- C:\windows\system32\wbem
2015-11-07 15:06:35 ----D---- C:\windows\system32\DriverStore
2015-11-07 15:06:35 ----D---- C:\windows\system32\catroot2
2015-11-07 15:06:33 ----D---- C:\windows\system32\Tasks
2015-11-07 15:06:32 ----SD---- C:\windows\system32\GWX
2015-11-07 15:06:32 ----D---- C:\Users\Peťo\AppData\Roaming\MusicBee
2015-11-07 15:06:31 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-07 15:06:29 ----D---- C:\windows\registration
2015-11-07 15:06:19 ----RD---- C:\Program Files (x86)
2015-11-07 14:54:19 ----D---- C:\windows\Prefetch
2015-11-01 19:39:39 ----D---- C:\Users\Peťo\AppData\Roaming\Adobe
2015-11-01 19:39:39 ----D---- C:\ProgramData\Adobe
2015-11-01 18:52:52 ----SD---- C:\Users\Peťo\AppData\Roaming\Microsoft
2015-11-01 18:47:51 ----D---- C:\windows\Minidump
2015-11-01 18:47:51 ----D---- C:\windows\debug
2015-10-27 07:09:33 ----D---- C:\windows\system32\drivers
2015-10-27 07:09:33 ----D---- C:\windows\system32\CodeIntegrity
2015-10-27 07:09:33 ----D---- C:\windows\AppCompat
2015-10-16 18:31:21 ----D---- C:\windows\SysWOW64
2015-10-16 18:31:18 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-10-16 14:24:35 ----SHD---- C:\windows\Installer
2015-10-15 14:43:42 ----RD---- C:\Users
2015-10-15 13:08:42 ----D---- C:\windows\winsxs
2015-10-15 13:08:33 ----SD---- C:\windows\system32\CompatTel
2015-10-15 13:08:31 ----D---- C:\windows\system32\appraiser
2015-10-15 13:08:31 ----D---- C:\windows\AppPatch
2015-10-14 15:02:35 ----D---- C:\windows\rescache
2015-10-14 14:26:01 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-10-14 14:26:01 ----D---- C:\Program Files\Internet Explorer
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\system32\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\cs-CZ
2015-10-14 14:25:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-14 14:25:56 ----D---- C:\windows\system32\Boot
2015-10-14 13:43:08 ----D---- C:\windows\system32\MRT
2015-10-14 13:39:48 ----A---- C:\windows\system32\MRT.exe
2015-10-08 20:22:45 ----SD---- C:\windows\SYSWOW64\GWX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStorA;iaStorA; C:\windows\system32\drivers\iaStorA.sys [2013-09-21 630632]
R0 iaStorF;iaStorF; C:\windows\system32\drivers\iaStorF.sys [2013-09-21 28008]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\drivers\iusb3hcs.sys [2013-04-26 20464]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PinFile;PinFile; C:\windows\system32\DRIVERS\PinFile.sys [2014-02-03 49856]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SDDisk2K;SDDisk2K; C:\windows\system32\DRIVERS\SDDisk2K.sys [2014-02-03 228544]
R0 SDDToki;SDDToki; C:\windows\system32\DRIVERS\SDDToki.sys [2014-02-03 131264]
R0 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
R1 CLVirtualDrive;CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [2011-12-27 90608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-08-31 12528640]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-08-31 618496]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2013-07-05 96256]
R3 IceKore;IceKore; C:\windows\system32\DRIVERS\IceKore.sys [2013-11-14 411608]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-06-03 4438208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2013-07-31 3564376]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\windows\system32\DRIVERS\iusb3hub.sys [2013-04-26 368112]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\drivers\iusb3xhc.sys [2013-04-26 786416]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\drivers\TeeDriverx64.sys [2013-08-08 99288]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2013-08-15 881880]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2013-10-07 65752]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-12-04 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-08-31 239616]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 CreoService;HP Trust Circles Service; C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [2014-03-25 1927640]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 CtAgentService;Absolute Software Agent Service; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [2014-03-31 7168]
R2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [2013-08-12 77576]
R2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [2013-08-12 298760]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2014-04-04 500048]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-01-13 92160]
R2 HpDamServiceHost;HP Device Access Manager Usage Service; c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [2013-11-15 18232]
R2 HPFSService;HP File Sanitizer; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2014-02-05 1758936]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-08-08 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-08-08 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-08-08 390616]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-28 12784]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2013-07-18 1143432]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-06-19 246488]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-28 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-16 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-06-11 279024]
S3 FLCDLOCK;HP Device Locking / Auditing; c:\windows\SysWOW64\flcdlock.exe [2013-11-20 567608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-11-13 1233592]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-09-16 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-16 147624]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-11-13 1255736]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------