Stránka 1 z 2

poprosil by som o kontrolu logu

Napsal: 07 lis 2015 15:53
od petob
mam windows 7, 64-bit. problem sa tyka toho ze mi dnes po prihlaseni viac krat nenabehol system to znamena ze som mal ciernu obrazovku alebo nabehol ale bol neskutocne pomaly. ked mi system nabehol tak hoci bol pomaly nastastie sa mi podarilo spustit obnovenie systemu cize som zadal datum ktory bol v ponuke 3.11.
len pre zaujimavost niekolko dni dozadu som mal aj tzv. modru obrazovku, cize sa objavila modra obrazovka a system sa sam restartoval.
tu je log

Logfile of random's system information tool 1.10 (written by random/random)
Run by Peťo at 2015-11-07 15:32:01
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 877 GB (93%) free of 941 GB
Total RAM: 4024 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:36:17, on 7. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18057)
Boot mode: Normal

Running processes:
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Peťo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [HP File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: HP Trust Circles Service (CreoService) - CryptoMill Technologies Ltd. - C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe
O23 - Service: Absolute Software Agent Service (CtAgentService) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\windows\SysWOW64\flcdlock.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Device Access Manager Usage Service (HpDamServiceHost) - Hewlett-Packard Development Company - c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe
O23 - Service: HP File Sanitizer (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12240 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPSP
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPCardEngine.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe"
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c4acc489-0124-41db-bb31-13c1ecad0a25 -SystemEventPortName:HostProcess-c00f7656-51cd-4f5e-923f-fd212baa033f -IoCancelEventPortName:HostProcess-e4ef6838-0f12-4701-8f64-731b8804dcdf -NonStateChangingEventPortName:HostProcess-18a5306a-df8d-429a-899a-e4beca0de111 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:05418221-34d4-4c1d-8678-7c9e6c3a0763 -DeviceGroupId:WpdFsGroup
C:\windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe"
HydraDM64.exe -h:66084 "Maximize to full desktop" "Maximize to window corners" "Restore desktop"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4316.0.1917683359\1480359320" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6771 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.152.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group23 stable:pp1 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_3/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4316.1.1924626602\1799321690" --font-cache-shared-handle=1824 /prefetch:673131151
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\windows\system32\GWX\GWX.exe"
"c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5888 CREDAT:275457 /prefetch:2
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:5888 CREDAT:3748900 /prefetch:2
C:\windows\system32\wbem\wmiprvse.exe
"C:\Users\Peťo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U18KFEB2\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k WerSvcGroup
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_cab_01e6c85d"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c86d"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_a1a9c040be80fb638654f34d19837ef1ba5e8b_cab_01e6c87c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_2152759308_fbba4499ee721a68a91dbf50df77d6fe6c94f742_cab_01e6c88c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c89c"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c8ab"
"C:\windows\system32\wermgr.exe" "-queuereporting_s_machine" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_515b6c287936328f333ecbf1a2fd7ace7b3e84d_01e6c8bb"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1cffeff3732ce5a.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1d040bee0413f91.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1cffeff37d4abed.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1d040bee0d766ae.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default

prefs.js - "browser.startup.homepage" - "google.com"
prefs.js - "keyword.URL" - "http://www.bing.com/search?FORM=U303DF&PC=U303&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\digitalpersona.com/ChromeDPAgent]
"Description"=
"Path"=c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default\extensions\
bingsearch.full@microsoft.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
HP File Sanitizer - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2014-02-05 129240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-06-11 165872]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-06-11 407536]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-06-11 444400]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-07-27 7194840]
""= []
"CryptoMill Refresh"=C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2013-08-31 389120]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-10-20 811848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-04-26 292848]
"StartCCC"=c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-08-31 766208]
"CLMLServer_For_P2G8"=c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05 111576]
"CLVirtualDrive"=c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [2013-08-07 490760]
"HP File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2014-02-05 2213592]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2013-07-18 683656]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-06-03 441344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-07 15:32:02 ----D---- C:\Program Files\trend micro
2015-11-07 15:32:01 ----D---- C:\rsit
2015-10-16 08:06:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-10-15 08:36:03 ----A---- C:\windows\system32\appraiser.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\invagent.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\generaltel.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\devinv.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\aeinv.dll
2015-10-15 08:36:01 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-10-15 08:36:01 ----A---- C:\windows\system32\acmigration.dll
2015-10-14 05:33:58 ----A---- C:\windows\system32\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2015-10-14 05:33:57 ----A---- C:\windows\system32\ExplorerFrame.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwcollector.exe
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\occache.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\iernonce.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\ie4uinit.exe
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\occache.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\iedkcs32.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\urlmon.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-10-14 05:33:50 ----A---- C:\windows\system32\msfeeds.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\dxtrans.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iesetup.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iertutil.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\ieapfltr.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-10-14 05:33:48 ----A---- C:\windows\system32\vbscript.dll
2015-10-14 05:33:48 ----A---- C:\windows\system32\jsproxy.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieui.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieframe.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\dxtmsft.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\webcheck.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmled.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9diag.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\ieUnatt.exe
2015-10-14 05:33:45 ----A---- C:\windows\system32\wininet.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\msrating.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\MshtmlDac.dll
2015-10-14 05:33:44 ----A---- C:\windows\system32\mshtml.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wucltux.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuaueng.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuapi.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups2.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuauclt.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\WinSetupUI.dll
2015-10-14 05:33:14 ----A---- C:\windows\SYSWOW64\wups.dll
2015-10-14 05:33:14 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2015-10-14 05:33:07 ----A---- C:\windows\system32\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-10-14 05:33:06 ----A---- C:\windows\system32\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\SYSWOW64\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\ntdll.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\lsasrv.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\wow64.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\winsrv.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\srcore.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\rstrui.exe
2015-10-14 05:33:04 ----A---- C:\windows\system32\rpcrt4.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\KernelBase.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\conhost.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\sspicli.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\smss.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\ntvdm64.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\msv1_0.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\lsass.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\csrsrv.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\cryptbase.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\auditpol.exe
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64win.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64cpu.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\sspisrv.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\credssp.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\user.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\adtschema.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msaudite.dll
2015-10-14 05:32:46 ----A---- C:\windows\SYSWOW64\appidapi.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\setbcdlocale.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidsvc.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidpolicyconverter.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidcertstorecheck.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidapi.dll
2015-10-14 05:32:45 ----A---- C:\windows\system32\drivers\appid.sys
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\ucrtbase.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l1-2-0.dll

======List of files/folders modified in the last 1 month======

2015-11-07 15:32:02 ----RD---- C:\Program Files
2015-11-07 15:31:59 ----D---- C:\windows\Temp
2015-11-07 15:19:07 ----SHD---- C:\System Volume Information
2015-11-07 15:12:28 ----D---- C:\windows\System32
2015-11-07 15:12:28 ----D---- C:\windows\inf
2015-11-07 15:12:28 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-11-07 15:08:49 ----D---- C:\windows\system32\config
2015-11-07 15:07:43 ----D---- C:\ProgramData\PDFC
2015-11-07 15:07:20 ----D---- C:\Windows
2015-11-07 15:07:12 ----D---- C:\windows\Tasks
2015-11-07 15:07:12 ----D---- C:\windows\system32\wfp
2015-11-07 15:07:11 ----D---- C:\windows\system32\wbem
2015-11-07 15:06:35 ----D---- C:\windows\system32\DriverStore
2015-11-07 15:06:35 ----D---- C:\windows\system32\catroot2
2015-11-07 15:06:33 ----D---- C:\windows\system32\Tasks
2015-11-07 15:06:32 ----SD---- C:\windows\system32\GWX
2015-11-07 15:06:32 ----D---- C:\Users\Peťo\AppData\Roaming\MusicBee
2015-11-07 15:06:31 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-07 15:06:29 ----D---- C:\windows\registration
2015-11-07 15:06:19 ----RD---- C:\Program Files (x86)
2015-11-07 14:54:19 ----D---- C:\windows\Prefetch
2015-11-01 19:39:39 ----D---- C:\Users\Peťo\AppData\Roaming\Adobe
2015-11-01 19:39:39 ----D---- C:\ProgramData\Adobe
2015-11-01 18:52:52 ----SD---- C:\Users\Peťo\AppData\Roaming\Microsoft
2015-11-01 18:47:51 ----D---- C:\windows\Minidump
2015-11-01 18:47:51 ----D---- C:\windows\debug
2015-10-27 07:09:33 ----D---- C:\windows\system32\drivers
2015-10-27 07:09:33 ----D---- C:\windows\system32\CodeIntegrity
2015-10-27 07:09:33 ----D---- C:\windows\AppCompat
2015-10-16 18:31:21 ----D---- C:\windows\SysWOW64
2015-10-16 18:31:18 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-10-16 14:24:35 ----SHD---- C:\windows\Installer
2015-10-15 14:43:42 ----RD---- C:\Users
2015-10-15 13:08:42 ----D---- C:\windows\winsxs
2015-10-15 13:08:33 ----SD---- C:\windows\system32\CompatTel
2015-10-15 13:08:31 ----D---- C:\windows\system32\appraiser
2015-10-15 13:08:31 ----D---- C:\windows\AppPatch
2015-10-14 15:02:35 ----D---- C:\windows\rescache
2015-10-14 14:26:01 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-10-14 14:26:01 ----D---- C:\Program Files\Internet Explorer
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\system32\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\cs-CZ
2015-10-14 14:25:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-14 14:25:56 ----D---- C:\windows\system32\Boot
2015-10-14 13:43:08 ----D---- C:\windows\system32\MRT
2015-10-14 13:39:48 ----A---- C:\windows\system32\MRT.exe
2015-10-08 20:22:45 ----SD---- C:\windows\SYSWOW64\GWX

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\windows\system32\drivers\iaStorA.sys [2013-09-21 630632]
R0 iaStorF;iaStorF; C:\windows\system32\drivers\iaStorF.sys [2013-09-21 28008]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\drivers\iusb3hcs.sys [2013-04-26 20464]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PinFile;PinFile; C:\windows\system32\DRIVERS\PinFile.sys [2014-02-03 49856]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SDDisk2K;SDDisk2K; C:\windows\system32\DRIVERS\SDDisk2K.sys [2014-02-03 228544]
R0 SDDToki;SDDToki; C:\windows\system32\DRIVERS\SDDToki.sys [2014-02-03 131264]
R0 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
R1 CLVirtualDrive;CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [2011-12-27 90608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-08-31 12528640]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-08-31 618496]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2013-07-05 96256]
R3 IceKore;IceKore; C:\windows\system32\DRIVERS\IceKore.sys [2013-11-14 411608]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-06-03 4438208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2013-07-31 3564376]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\windows\system32\DRIVERS\iusb3hub.sys [2013-04-26 368112]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\drivers\iusb3xhc.sys [2013-04-26 786416]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\drivers\TeeDriverx64.sys [2013-08-08 99288]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2013-08-15 881880]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2013-10-07 65752]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-12-04 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-08-31 239616]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 CreoService;HP Trust Circles Service; C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [2014-03-25 1927640]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 CtAgentService;Absolute Software Agent Service; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [2014-03-31 7168]
R2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [2013-08-12 77576]
R2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [2013-08-12 298760]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2014-04-04 500048]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-01-13 92160]
R2 HpDamServiceHost;HP Device Access Manager Usage Service; c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [2013-11-15 18232]
R2 HPFSService;HP File Sanitizer; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2014-02-05 1758936]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-08-08 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-08-08 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-08-08 390616]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-28 12784]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2013-07-18 1143432]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-06-19 246488]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-28 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-16 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-06-11 279024]
S3 FLCDLOCK;HP Device Locking / Auditing; c:\windows\SysWOW64\flcdlock.exe [2013-11-20 567608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-11-13 1233592]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-09-16 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-16 147624]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-11-13 1255736]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: poprosil by som o kontrolu logu

Napsal: 07 lis 2015 17:40
od Rudy
Zdarvím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: poprosil by som o kontrolu logu

Napsal: 07 lis 2015 19:22
od petob
# AdwCleaner v5.018 - Logfile created 07/11/2015 at 19:00:54
# Updated 05/11/2015 by Xplode
# Database : 2015-11-03.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Peťo - HP
# Running from : C:\Users\Peťo\Downloads\adwcleaner_5.018.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.metrolyrics.com_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_academyofrealistart.com_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mkv-player.cs.softonic.com_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mkv-player.en.softonic.com_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_websearch.about.com_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.timeshighereducation.co.uk_0.localstorage-journal
File Found : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.yourtango.com_0.localstorage-journal

***** [ DLL ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1824 bytes] ##########

Re: poprosil by som o kontrolu logu

Napsal: 07 lis 2015 19:34
od Rudy
Nedokončil jste (neklikl na >Clean<). Postup zopakujte.

Re: poprosil by som o kontrolu logu

Napsal: 07 lis 2015 20:50
od petob
# AdwCleaner v5.018 - Logfile created 07/11/2015 at 20:01:04
# Updated 05/11/2015 by Xplode
# Database : 2015-11-03.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Peťo - HP
# Running from : C:\Users\Peťo\Downloads\adwcleaner_5.018.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.metrolyrics.com_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_academyofrealistart.com_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mkv-player.cs.softonic.com_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_mkv-player.en.softonic.com_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_websearch.about.com_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wlogin.icq.com_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.timeshighereducation.co.uk_0.localstorage-journal
[-] File Deleted : C:\Users\Peťo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.yourtango.com_0.localstorage-journal

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1970 bytes] ##########

Re: poprosil by som o kontrolu logu

Napsal: 07 lis 2015 20:54
od Rudy
Teď je to OK. Dejte nový log RSIT.

Re: poprosil by som o kontrolu logu

Napsal: 08 lis 2015 06:58
od petob
dnes rano ked som zapol comp problemy pretrvavaju. asi bude problem v inom.
kazdopadne tu je log z rsit.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Peťo at 2015-11-08 06:51:07
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 877 GB (93%) free of 941 GB
Total RAM: 4024 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:55:01, on 8. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18057)
Boot mode: Normal

Running processes:
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Peťo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [HP File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: HP Trust Circles Service (CreoService) - CryptoMill Technologies Ltd. - C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe
O23 - Service: Absolute Software Agent Service (CtAgentService) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\windows\SysWOW64\flcdlock.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Device Access Manager Usage Service (HpDamServiceHost) - Hewlett-Packard Development Company - c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe
O23 - Service: HP File Sanitizer (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12184 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPSP
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\windows\system32\svchost.exe -k NetworkService
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPCardEngine.exe"
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
"taskhost.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe"
HydraDM64.exe -h:66056 "Maximize to full desktop" "Maximize to window corners" "Restore desktop"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3676.0.827121862\710848867" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6771 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.152.0.0 --ignored=" --type=renderer " /prefetch:822062411
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d1b96eb9-e0b3-4b33-83f4-8bbd3d151d01 -SystemEventPortName:HostProcess-2b7e45e4-effd-4f77-a6a7-5b47e1d73e45 -IoCancelEventPortName:HostProcess-7936f5d8-1538-4bd0-a90b-4a37d087452b -NonStateChangingEventPortName:HostProcess-187c3cf1-1e32-4eb2-b128-2ae870230e25 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:52f04392-4028-46dc-8c30-0547c949b3cf -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group23 stable:pp1 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_3/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="3676.1.1569641818\722139930" --font-cache-shared-handle=1852 /prefetch:673131151
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\windows\system32\GWX\GWX.exe"
C:\windows\servicing\TrustedInstaller.exe
"c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\system32\sppsvc.exe
"C:\Program Files\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:3780 CREDAT:275457 /prefetch:2
"C:\Users\Peťo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U18KFEB2\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1cffeff3732ce5a.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineCore1d040bee0413f91.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1cffeff37d4abed.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\GoogleUpdateTaskMachineUA1d040bee0d766ae.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default

prefs.js - "browser.startup.homepage" - "google.com"
prefs.js - "keyword.URL" - "http://www.bing.com/search?FORM=U303DF&PC=U303&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\digitalpersona.com/ChromeDPAgent]
"Description"=
"Path"=c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default\extensions\
bingsearch.full@microsoft.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
HP File Sanitizer - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2014-02-05 129240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-06-11 165872]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-06-11 407536]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-06-11 444400]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-07-27 7194840]
""= []
"CryptoMill Refresh"=C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2013-08-31 389120]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-10-20 811848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-04-26 292848]
"StartCCC"=c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-08-31 766208]
"CLMLServer_For_P2G8"=c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05 111576]
"CLVirtualDrive"=c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [2013-08-07 490760]
"HP File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2014-02-05 2213592]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2013-07-18 683656]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-06-03 441344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-07 19:00:52 ----D---- C:\AdwCleaner
2015-11-07 15:32:02 ----D---- C:\Program Files\trend micro
2015-11-07 15:32:01 ----D---- C:\rsit
2015-10-16 08:06:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-10-15 08:36:03 ----A---- C:\windows\system32\appraiser.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\invagent.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\generaltel.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\devinv.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\aeinv.dll
2015-10-15 08:36:01 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-10-15 08:36:01 ----A---- C:\windows\system32\acmigration.dll
2015-10-14 05:33:58 ----A---- C:\windows\system32\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2015-10-14 05:33:57 ----A---- C:\windows\system32\ExplorerFrame.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwcollector.exe
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\occache.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\iernonce.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\ie4uinit.exe
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\occache.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\iedkcs32.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\urlmon.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-10-14 05:33:50 ----A---- C:\windows\system32\msfeeds.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\dxtrans.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iesetup.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iertutil.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\ieapfltr.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-10-14 05:33:48 ----A---- C:\windows\system32\vbscript.dll
2015-10-14 05:33:48 ----A---- C:\windows\system32\jsproxy.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieui.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieframe.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\dxtmsft.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\webcheck.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmled.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9diag.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\ieUnatt.exe
2015-10-14 05:33:45 ----A---- C:\windows\system32\wininet.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\msrating.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\MshtmlDac.dll
2015-10-14 05:33:44 ----A---- C:\windows\system32\mshtml.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wucltux.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuaueng.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuapi.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups2.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuauclt.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\WinSetupUI.dll
2015-10-14 05:33:14 ----A---- C:\windows\SYSWOW64\wups.dll
2015-10-14 05:33:14 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2015-10-14 05:33:07 ----A---- C:\windows\system32\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-10-14 05:33:06 ----A---- C:\windows\system32\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\SYSWOW64\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\ntdll.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\lsasrv.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\wow64.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\winsrv.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\srcore.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\rstrui.exe
2015-10-14 05:33:04 ----A---- C:\windows\system32\rpcrt4.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\KernelBase.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\conhost.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\sspicli.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\smss.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\ntvdm64.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\msv1_0.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\lsass.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\csrsrv.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\cryptbase.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\auditpol.exe
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64win.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64cpu.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\sspisrv.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\credssp.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\user.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\adtschema.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msaudite.dll
2015-10-14 05:32:46 ----A---- C:\windows\SYSWOW64\appidapi.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\setbcdlocale.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidsvc.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidpolicyconverter.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidcertstorecheck.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidapi.dll
2015-10-14 05:32:45 ----A---- C:\windows\system32\drivers\appid.sys
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\ucrtbase.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l1-2-0.dll

======List of files/folders modified in the last 1 month======

2015-11-08 06:50:59 ----D---- C:\windows\Temp
2015-11-08 06:50:33 ----D---- C:\windows\System32
2015-11-08 06:50:33 ----D---- C:\windows\inf
2015-11-08 06:50:33 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-11-08 06:43:37 ----D---- C:\windows\system32\config
2015-11-08 06:43:24 ----D---- C:\ProgramData\PDFC
2015-11-08 06:39:10 ----D---- C:\Windows
2015-11-07 15:32:02 ----RD---- C:\Program Files
2015-11-07 15:19:07 ----SHD---- C:\System Volume Information
2015-11-07 15:07:12 ----D---- C:\windows\Tasks
2015-11-07 15:07:12 ----D---- C:\windows\system32\wfp
2015-11-07 15:07:11 ----D---- C:\windows\system32\wbem
2015-11-07 15:06:35 ----D---- C:\windows\system32\DriverStore
2015-11-07 15:06:35 ----D---- C:\windows\system32\catroot2
2015-11-07 15:06:33 ----D---- C:\windows\system32\Tasks
2015-11-07 15:06:32 ----SD---- C:\windows\system32\GWX
2015-11-07 15:06:32 ----D---- C:\Users\Peťo\AppData\Roaming\MusicBee
2015-11-07 15:06:31 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-07 15:06:29 ----D---- C:\windows\registration
2015-11-07 15:06:19 ----RD---- C:\Program Files (x86)
2015-11-07 14:54:19 ----D---- C:\windows\Prefetch
2015-11-01 19:39:39 ----D---- C:\Users\Peťo\AppData\Roaming\Adobe
2015-11-01 19:39:39 ----D---- C:\ProgramData\Adobe
2015-11-01 18:52:52 ----SD---- C:\Users\Peťo\AppData\Roaming\Microsoft
2015-11-01 18:47:51 ----D---- C:\windows\Minidump
2015-11-01 18:47:51 ----D---- C:\windows\debug
2015-10-27 07:09:33 ----D---- C:\windows\system32\drivers
2015-10-27 07:09:33 ----D---- C:\windows\system32\CodeIntegrity
2015-10-27 07:09:33 ----D---- C:\windows\AppCompat
2015-10-16 18:31:21 ----D---- C:\windows\SysWOW64
2015-10-16 18:31:18 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-10-16 14:24:35 ----SHD---- C:\windows\Installer
2015-10-15 14:43:42 ----RD---- C:\Users
2015-10-15 13:08:42 ----D---- C:\windows\winsxs
2015-10-15 13:08:33 ----SD---- C:\windows\system32\CompatTel
2015-10-15 13:08:31 ----D---- C:\windows\system32\appraiser
2015-10-15 13:08:31 ----D---- C:\windows\AppPatch
2015-10-14 15:02:35 ----D---- C:\windows\rescache
2015-10-14 14:26:01 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-10-14 14:26:01 ----D---- C:\Program Files\Internet Explorer
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\system32\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\cs-CZ
2015-10-14 14:25:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-14 14:25:56 ----D---- C:\windows\system32\Boot
2015-10-14 13:43:08 ----D---- C:\windows\system32\MRT
2015-10-14 13:39:48 ----A---- C:\windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\windows\system32\drivers\iaStorA.sys [2013-09-21 630632]
R0 iaStorF;iaStorF; C:\windows\system32\drivers\iaStorF.sys [2013-09-21 28008]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\drivers\iusb3hcs.sys [2013-04-26 20464]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PinFile;PinFile; C:\windows\system32\DRIVERS\PinFile.sys [2014-02-03 49856]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SDDisk2K;SDDisk2K; C:\windows\system32\DRIVERS\SDDisk2K.sys [2014-02-03 228544]
R0 SDDToki;SDDToki; C:\windows\system32\DRIVERS\SDDToki.sys [2014-02-03 131264]
R0 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
R1 CLVirtualDrive;CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [2011-12-27 90608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-08-31 12528640]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-08-31 618496]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2013-07-05 96256]
R3 IceKore;IceKore; C:\windows\system32\DRIVERS\IceKore.sys [2013-11-14 411608]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-06-03 4438208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2013-07-31 3564376]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\windows\system32\DRIVERS\iusb3hub.sys [2013-04-26 368112]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\drivers\iusb3xhc.sys [2013-04-26 786416]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\drivers\TeeDriverx64.sys [2013-08-08 99288]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2013-08-15 881880]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2013-10-07 65752]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-12-04 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-08-31 239616]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 CreoService;HP Trust Circles Service; C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [2014-03-25 1927640]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 CtAgentService;Absolute Software Agent Service; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [2014-03-31 7168]
R2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [2013-08-12 77576]
R2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [2013-08-12 298760]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2014-04-04 500048]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-01-13 92160]
R2 HpDamServiceHost;HP Device Access Manager Usage Service; c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [2013-11-15 18232]
R2 HPFSService;HP File Sanitizer; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2014-02-05 1758936]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-08-08 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-08-08 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-08-08 390616]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-28 12784]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2013-07-18 1143432]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-06-19 246488]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-28 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-16 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-06-11 279024]
S3 FLCDLOCK;HP Device Locking / Auditing; c:\windows\SysWOW64\flcdlock.exe [2013-11-20 567608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-11-13 1233592]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-09-16 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-16 147624]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-11-13 1255736]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: poprosil by som o kontrolu logu

Napsal: 08 lis 2015 11:01
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineCore1cffeff3732ce5a.job
C:\windows\tasks\GoogleUpdateTaskMachineCore1d040bee0413f91.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\GoogleUpdateTaskMachineUA1cffeff37d4abed.job
C:\windows\tasks\GoogleUpdateTaskMachineUA1d040bee0d766ae.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: poprosil by som o kontrolu logu

Napsal: 08 lis 2015 13:10
od petob
problem nadalej dost vazne pretrvava preto aj reagujem az teraz

tu je log z rsit

Logfile of random's system information tool 1.10 (written by random/random)
Run by Peťo at 2015-11-08 13:07:48
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 877 GB (93%) free of 941 GB
Total RAM: 4024 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:07:51, on 8. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18057)
Boot mode: Normal

Running processes:
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Peťo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMDTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [HP File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: HP Trust Circles Service (CreoService) - CryptoMill Technologies Ltd. - C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe
O23 - Service: Absolute Software Agent Service (CtAgentService) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\windows\SysWOW64\flcdlock.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Device Access Manager Usage Service (HpDamServiceHost) - Hewlett-Packard Development Company - c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe
O23 - Service: HP File Sanitizer (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12191 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPSP
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\windows\system32\svchost.exe -k NetworkService
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPCardEngine.exe"
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe"
"taskhost.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
taskeng.exe {7CEBA093-F335-4F6A-9931-9B3C723B37F1}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe"
"c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\windows\system32\GWX\GWX.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe"
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e4cde6c4-40ec-49ed-b044-c2baad4c56fd -SystemEventPortName:HostProcess-3fa78704-4e3f-4778-a588-825e5021554c -IoCancelEventPortName:HostProcess-86d07031-2757-4278-bfe0-dbecc4e49d5a -NonStateChangingEventPortName:HostProcess-a760430b-e4fb-4dea-872e-803342e7971e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:67a36024-cbc3-4680-89e5-43f0c0fac95c -DeviceGroupId:WpdFsGroup
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window

"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
HydraDM64.exe -h:131432 "Maximize to full desktop" "Maximize to window corners" "Restore desktop"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4928.0.1789675133\1162095970" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --gpu-vendor-id=0x1002 --gpu-device-id=0x6771 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.152.0.0 --ignored=" --type=renderer " /prefetch:822062411
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group23 stable:pp1 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_3/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledConnectionRacing/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4928.1.356191392\1449101548" --font-cache-shared-handle=1820 /prefetch:673131151
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
taskeng.exe {4BF0E80B-8161-49B4-AFCF-7EC80ECD24EE}
"c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
C:\windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group23 stable:pp1 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/StableHQPFrequencyBugFix_PrePeriod_3/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledConnectionRacing/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4928.4.1438809841\1750338143" --font-cache-shared-handle=3748 /prefetch:673131151
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
C:\windows\system32\wbem\wmiprvse.exe
"C:\Users\Peťo\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default

prefs.js - "browser.startup.homepage" - "google.com"
prefs.js - "keyword.URL" - "http://www.bing.com/search?FORM=U303DF&PC=U303&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\digitalpersona.com/ChromeDPAgent]
"Description"=
"Path"=c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


C:\Users\Peťo\AppData\Roaming\Mozilla\Firefox\Profiles\wybjuohb.default\extensions\
bingsearch.full@microsoft.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
HP File Sanitizer - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2014-02-05 129240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-06-11 165872]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-06-11 407536]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-06-11 444400]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-07-27 7194840]
""= []
"CryptoMill Refresh"=C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2015-07-08 5595848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2013-08-31 389120]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"GoogleChromeAutoLaunch_CBF760E6948D4582CE9F91695AE24651"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-10-20 811848]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-04-26 292848]
"StartCCC"=c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-08-31 766208]
"CLMLServer_For_P2G8"=c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05 111576]
"CLVirtualDrive"=c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [2013-08-07 490760]
"HP File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2014-02-05 2213592]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2013-07-18 683656]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-06-03 441344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-08 11:50:02 ----D---- C:\_OTM
2015-11-07 19:00:52 ----D---- C:\AdwCleaner
2015-11-07 15:32:02 ----D---- C:\Program Files\trend micro
2015-11-07 15:32:01 ----D---- C:\rsit
2015-10-16 08:06:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-10-15 08:36:03 ----A---- C:\windows\system32\appraiser.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\invagent.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\generaltel.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\devinv.dll
2015-10-15 08:36:02 ----A---- C:\windows\system32\aeinv.dll
2015-10-15 08:36:01 ----A---- C:\windows\system32\CompatTelRunner.exe
2015-10-15 08:36:01 ----A---- C:\windows\system32\acmigration.dll
2015-10-14 05:33:58 ----A---- C:\windows\system32\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\shell32.dll
2015-10-14 05:33:57 ----A---- C:\windows\SYSWOW64\ExplorerFrame.dll
2015-10-14 05:33:57 ----A---- C:\windows\system32\ExplorerFrame.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2015-10-14 05:33:53 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwproxystub.dll
2015-10-14 05:33:53 ----A---- C:\windows\system32\ieetwcollector.exe
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\vbscript.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\urlmon.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\occache.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\mshtml.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2015-10-14 05:33:52 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\iernonce.dll
2015-10-14 05:33:52 ----A---- C:\windows\system32\ie4uinit.exe
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2015-10-14 05:33:51 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\occache.dll
2015-10-14 05:33:51 ----A---- C:\windows\system32\iedkcs32.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\jscript.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieui.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iertutil.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\iernonce.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\ieframe.dll
2015-10-14 05:33:50 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\urlmon.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2015-10-14 05:33:50 ----A---- C:\windows\system32\msfeeds.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\ieetwcollectorres.dll
2015-10-14 05:33:50 ----A---- C:\windows\system32\dxtrans.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iesetup.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\iertutil.dll
2015-10-14 05:33:49 ----A---- C:\windows\system32\ieapfltr.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\wininet.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\webcheck.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\msrating.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\jscript9.dll
2015-10-14 05:33:48 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2015-10-14 05:33:48 ----A---- C:\windows\system32\vbscript.dll
2015-10-14 05:33:48 ----A---- C:\windows\system32\jsproxy.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieui.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\ieframe.dll
2015-10-14 05:33:47 ----A---- C:\windows\system32\dxtmsft.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\webcheck.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmlmedia.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\mshtmled.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9diag.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript9.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\jscript.dll
2015-10-14 05:33:46 ----A---- C:\windows\system32\ieUnatt.exe
2015-10-14 05:33:45 ----A---- C:\windows\system32\wininet.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\msrating.dll
2015-10-14 05:33:45 ----A---- C:\windows\system32\MshtmlDac.dll
2015-10-14 05:33:44 ----A---- C:\windows\system32\mshtml.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\SYSWOW64\wuapi.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuwebv.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wucltux.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuaueng.dll
2015-10-14 05:33:16 ----A---- C:\windows\system32\wuapi.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups2.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wups.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wudriver.dll
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuauclt.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\wuapp.exe
2015-10-14 05:33:15 ----A---- C:\windows\system32\WinSetupUI.dll
2015-10-14 05:33:14 ----A---- C:\windows\SYSWOW64\wups.dll
2015-10-14 05:33:14 ----A---- C:\windows\system32\wu.upgrade.ps.dll
2015-10-14 05:33:07 ----A---- C:\windows\system32\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2015-10-14 05:33:06 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2015-10-14 05:33:06 ----A---- C:\windows\system32\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\SYSWOW64\kernel32.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\ntdll.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\lsasrv.dll
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2015-10-14 05:33:05 ----A---- C:\windows\system32\drivers\ksecdd.sys
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\ntdll.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2015-10-14 05:33:04 ----A---- C:\windows\SYSWOW64\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\wow64.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\winsrv.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\srcore.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\schannel.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\rstrui.exe
2015-10-14 05:33:04 ----A---- C:\windows\system32\rpcrt4.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\KernelBase.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\kerberos.dll
2015-10-14 05:33:04 ----A---- C:\windows\system32\conhost.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\setup16.exe
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\SYSWOW64\auditpol.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\wdigest.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\TSpkg.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\sspicli.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\srclient.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\smss.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\ntvdm64.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\ncrypt.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\msv1_0.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\lsass.exe
2015-10-14 05:33:03 ----A---- C:\windows\system32\csrsrv.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\cryptbase.dll
2015-10-14 05:33:03 ----A---- C:\windows\system32\auditpol.exe
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-10-14 05:33:02 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\wow32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\sspicli.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2015-10-14 05:33:02 ----A---- C:\windows\SYSWOW64\credssp.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64win.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\wow64cpu.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\sspisrv.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\secur32.dll
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2015-10-14 05:33:02 ----A---- C:\windows\system32\credssp.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-10-14 05:33:01 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\user.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\instnm.exe
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\SYSWOW64\adtschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\apisetschema.dll
2015-10-14 05:33:01 ----A---- C:\windows\system32\adtschema.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\SYSWOW64\msaudite.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msobjs.dll
2015-10-14 05:33:00 ----A---- C:\windows\system32\msaudite.dll
2015-10-14 05:32:46 ----A---- C:\windows\SYSWOW64\appidapi.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\setbcdlocale.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidsvc.dll
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidpolicyconverter.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidcertstorecheck.exe
2015-10-14 05:32:46 ----A---- C:\windows\system32\appidapi.dll
2015-10-14 05:32:45 ----A---- C:\windows\system32\drivers\appid.sys
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\ucrtbase.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 05:32:28 ----A---- C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\ucrtbase.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 05:32:27 ----A---- C:\windows\system32\api-ms-win-core-file-l1-2-0.dll

======List of files/folders modified in the last 1 month======

2015-11-08 13:07:51 ----D---- C:\windows\Prefetch
2015-11-08 13:07:40 ----D---- C:\windows\Temp
2015-11-08 13:02:37 ----D---- C:\windows\system32\config
2015-11-08 12:57:35 ----D---- C:\ProgramData\PDFC
2015-11-08 12:52:56 ----D---- C:\Windows
2015-11-08 11:50:03 ----D---- C:\windows\Tasks
2015-11-08 06:50:33 ----D---- C:\windows\System32
2015-11-08 06:50:33 ----D---- C:\windows\inf
2015-11-08 06:50:33 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-11-07 15:32:02 ----RD---- C:\Program Files
2015-11-07 15:19:07 ----SHD---- C:\System Volume Information
2015-11-07 15:07:12 ----D---- C:\windows\system32\wfp
2015-11-07 15:07:11 ----D---- C:\windows\system32\wbem
2015-11-07 15:06:35 ----D---- C:\windows\system32\DriverStore
2015-11-07 15:06:35 ----D---- C:\windows\system32\catroot2
2015-11-07 15:06:33 ----D---- C:\windows\system32\Tasks
2015-11-07 15:06:32 ----SD---- C:\windows\system32\GWX
2015-11-07 15:06:32 ----D---- C:\Users\Peťo\AppData\Roaming\MusicBee
2015-11-07 15:06:31 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-07 15:06:29 ----D---- C:\windows\registration
2015-11-07 15:06:19 ----RD---- C:\Program Files (x86)
2015-11-01 19:39:39 ----D---- C:\Users\Peťo\AppData\Roaming\Adobe
2015-11-01 19:39:39 ----D---- C:\ProgramData\Adobe
2015-11-01 18:52:52 ----SD---- C:\Users\Peťo\AppData\Roaming\Microsoft
2015-11-01 18:47:51 ----D---- C:\windows\Minidump
2015-11-01 18:47:51 ----D---- C:\windows\debug
2015-10-27 07:09:33 ----D---- C:\windows\system32\drivers
2015-10-27 07:09:33 ----D---- C:\windows\system32\CodeIntegrity
2015-10-27 07:09:33 ----D---- C:\windows\AppCompat
2015-10-16 18:31:21 ----D---- C:\windows\SysWOW64
2015-10-16 18:31:18 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2015-10-16 14:24:35 ----SHD---- C:\windows\Installer
2015-10-15 14:43:42 ----RD---- C:\Users
2015-10-15 13:08:42 ----D---- C:\windows\winsxs
2015-10-15 13:08:33 ----SD---- C:\windows\system32\CompatTel
2015-10-15 13:08:31 ----D---- C:\windows\system32\appraiser
2015-10-15 13:08:31 ----D---- C:\windows\AppPatch
2015-10-14 15:02:35 ----D---- C:\windows\rescache
2015-10-14 14:26:01 ----D---- C:\windows\SYSWOW64\cs-CZ
2015-10-14 14:26:01 ----D---- C:\Program Files\Internet Explorer
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\SYSWOW64\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\sk-SK
2015-10-14 14:26:00 ----D---- C:\windows\system32\en-US
2015-10-14 14:26:00 ----D---- C:\windows\system32\cs-CZ
2015-10-14 14:25:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-14 14:25:56 ----D---- C:\windows\system32\Boot
2015-10-14 13:43:08 ----D---- C:\windows\system32\MRT
2015-10-14 13:39:48 ----A---- C:\windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\windows\system32\drivers\iaStorA.sys [2013-09-21 630632]
R0 iaStorF;iaStorF; C:\windows\system32\drivers\iaStorF.sys [2013-09-21 28008]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\drivers\iusb3hcs.sys [2013-04-26 20464]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PinFile;PinFile; C:\windows\system32\DRIVERS\PinFile.sys [2014-02-03 49856]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SDDisk2K;SDDisk2K; C:\windows\system32\DRIVERS\SDDisk2K.sys [2014-02-03 228544]
R0 SDDToki;SDDToki; C:\windows\system32\DRIVERS\SDDToki.sys [2014-02-03 131264]
R0 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
R1 CLVirtualDrive;CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [2011-12-27 90608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2015-07-14 168208]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2013-08-31 12528640]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2013-08-31 618496]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\windows\system32\drivers\AtihdW76.sys [2013-07-05 96256]
R3 IceKore;IceKore; C:\windows\system32\DRIVERS\IceKore.sys [2013-11-14 411608]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-06-03 4438208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2013-07-31 3564376]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\windows\system32\DRIVERS\iusb3hub.sys [2013-04-26 368112]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\drivers\iusb3xhc.sys [2013-04-26 786416]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2015-06-18 25816]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\drivers\TeeDriverx64.sys [2013-08-08 99288]
R3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2013-08-15 881880]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2013-10-07 65752]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2015-06-18 63704]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2011-08-17 27136]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-08-17 9216]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-12-04 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-08-17 9216]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2013-08-31 239616]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 CreoService;HP Trust Circles Service; C:\Program Files\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [2014-03-25 1927640]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 CtAgentService;Absolute Software Agent Service; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [2014-03-31 7168]
R2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [2013-08-12 77576]
R2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [2013-08-12 298760]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2014-04-04 500048]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-07-08 1353720]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-01-13 92160]
R2 HpDamServiceHost;HP Device Access Manager Usage Service; c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [2013-11-15 18232]
R2 HPFSService;HP File Sanitizer; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2014-02-05 1758936]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-05-12 733696]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-08-08 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-08-08 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-08-08 390616]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-28 12784]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2013-07-18 1143432]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-06-19 246488]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-28 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-04-19 161384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-16 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-06-11 279024]
S3 FLCDLOCK;HP Device Locking / Auditing; c:\windows\SysWOW64\flcdlock.exe [2013-11-20 567608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-11-13 1233592]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2015-09-16 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-05-12 822232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-16 147624]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2014-11-13 1255736]
S4 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: poprosil by som o kontrolu logu

Napsal: 08 lis 2015 17:40
od Rudy
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nyní otevřte adresář c:\windows\minidump, jeho obsah zabalte do raru a přiložte k vašemu příštímu postu.

Re: poprosil by som o kontrolu logu

Napsal: 11 lis 2015 12:35
od petob
pišem z nudzoveho režimu a prikladam ten minidump

Re: poprosil by som o kontrolu logu

Napsal: 11 lis 2015 17:42
od Rudy
Žádný minidump tam není, je to jen prázdný adresář. Minidump bych potřeboivak na analýzu, abych zjistil, proč se PC restartuje.

Re: poprosil by som o kontrolu logu

Napsal: 12 lis 2015 04:36
od petob
zdravim. včera večer sa to vratilo spať k normalu. zapol som počitač do normalneho režimu a počkal čo sa bude diať. pred tým totiž niekedy nabehol niekedy nie. tento raz naštastie nabehol. potom mi ukazovalo že po vypnutí si stiahne nejake aktualizacie tak som ho vypol. a taktiež som si prezrel toto
http://windows.microsoft.com/sk-sk/wind ... -windows-7
lebo než nastali tieto problémy pár dní pred tým som mal tzv. modrú obrazovku a tá sa zopakovala aj včera večer. neviem teda čo pomohlo či vaše pokyny alebo mal iba problém s nejakou aktualizáciou ale momentálne naštastie ide.
písali ste že niečo sa zmazalo. čo konkrétne ? ak by bolo ešte treba ten minidump môžem to ešte skúsiť

Re: poprosil by som o kontrolu logu

Napsal: 12 lis 2015 17:49
od Rudy
S aktualizacemi to může souviset (včera proběhly). S tou modrou opbrazovkou vám ale nemohu poradit, dokud neuvidím a neanalyzuji minidump.

Re: poprosil by som o kontrolu logu

Napsal: 13 lis 2015 05:03
od petob
ten minidump