Stránka 1 z 1

Asi zavírený počítač

Napsal: 10 lis 2015 00:00
od 7777
Takže mám problém, priečinky v knižnici záhadne zmenili názov na anglicky. Tesne pred tým som sa pokúšal zmenšiť veľkosť USB disku z dôvodu že som nachtiac kúpil Fake usb čínsky disk. Chcel by som zmenšiť iba jeho veľkosť lebo vrátiť sa už nedá. Bohužiaľ som si asi zavíril disk... Iba dnes som sa vrátil na win7 po tom čo som nebol spokojný z win10, myslel som že to napraví obnovanie systému bohužiaľ nefunguje to.
Log tu:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Tomas at 2015-11-09 23:35:13
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 46 GB (46%) free of 100 GB
Total RAM: 8130 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:35:19, on 9. 11. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18057)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Tomas.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Monitor Ink Alerts - HP Deskjet 1050 J410 series.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8601 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-5fd9a3f1-507a-4927-acfb-593e0072b483 -SystemEventPortName:HostProcess-19060e0c-e154-48e4-acbd-cdd96fd517dd -IoCancelEventPortName:HostProcess-fbc64595-3b6a-451c-8022-86bf58db3752 -NonStateChangingEventPortName:HostProcess-3b738dbe-b818-4e81-9398-853062b2cbdc -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:48021e04-12c4-48db-beee-eea9953a6625 -DeviceGroupId:
"taskhost.exe"
taskeng.exe {802D0B73-2AB0-45D5-8A49-8C1A032A8FE3}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\wbengine.exe"
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Windows\system32\RunDll32.exe" "C:\Program Files\HP\HP Deskjet 1050 J410 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN33Q1BJ0H05YC;CONNECTION=USB;MONITOR=1;
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
taskeng.exe {B66E75FD-2F25-47FC-88F9-EEE2ADD81E66}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Tomas\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\jnt2lee8.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 19.0.0.226 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 19.0.0.226 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-09-29 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-06 885152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-10-29 886488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-29 2339032]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-06 664184]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-10-29 712304]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-08-07 36352]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-09-29 7640944]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-10-19 8551848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr]
C:\PROGRA~2\Raptr\raptrstub.exe [2015-10-01 56080]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader]
C:\Program Files\VDownloader\VDownloader4.exe [2015-08-27 2055168]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-04-26 292848]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-11-06 7004376]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]

C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Monitor Ink Alerts - HP Deskjet 1050 J410 series.lnk - C:\Windows\system32\RunDll32.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-09 23:35:13 ----D---- C:\rsit
2015-11-09 23:35:13 ----D---- C:\Program Files\trend micro
2015-11-09 11:33:33 ----D---- C:\ProgramData\ATI
2015-11-09 11:30:34 ----ASH---- C:\pagefile.sys
2015-11-09 11:30:30 ----ASH---- C:\hiberfil.sys
2015-11-09 11:24:44 ----D---- C:\$SysReset
2015-11-07 13:00:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-11-06 09:07:57 ----A---- C:\Windows\system32\aswBoot.exe
2015-11-06 09:07:53 ----A---- C:\Windows\avastSS.scr
2015-10-31 15:44:52 ----A---- C:\Windows\RtlExUpd.dll
2015-10-30 16:51:16 ----SHD---- C:\Recovery
2015-10-30 13:22:48 ----D---- C:\Program Files\Microsoft Silverlight
2015-10-30 13:22:48 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-10-30 13:21:49 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-10-30 13:21:49 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-10-30 13:21:49 ----A---- C:\Windows\system32\iernonce.dll
2015-10-30 13:21:49 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-10-30 13:21:49 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-10-30 13:21:49 ----A---- C:\Windows\system32\ie4uinit.exe
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-10-30 13:21:48 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-10-30 13:21:48 ----A---- C:\Windows\system32\urlmon.dll
2015-10-30 13:21:48 ----A---- C:\Windows\system32\occache.dll
2015-10-30 13:21:48 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-10-30 13:21:48 ----A---- C:\Windows\system32\msfeeds.dll
2015-10-30 13:21:48 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-10-30 13:21:48 ----A---- C:\Windows\system32\iedkcs32.dll
2015-10-30 13:21:48 ----A---- C:\Windows\system32\dxtrans.dll
2015-10-30 13:21:47 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-10-30 13:21:47 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-10-30 13:21:47 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-10-30 13:21:47 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-10-30 13:21:47 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-10-30 13:21:47 ----A---- C:\Windows\system32\vbscript.dll
2015-10-30 13:21:47 ----A---- C:\Windows\system32\iesetup.dll
2015-10-30 13:21:47 ----A---- C:\Windows\system32\iertutil.dll
2015-10-30 13:21:47 ----A---- C:\Windows\system32\ieapfltr.dll
2015-10-30 13:21:46 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-10-30 13:21:46 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-10-30 13:21:46 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-10-30 13:21:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-10-30 13:21:46 ----A---- C:\Windows\system32\jsproxy.dll
2015-10-30 13:21:46 ----A---- C:\Windows\system32\ieUnatt.exe
2015-10-30 13:21:46 ----A---- C:\Windows\system32\ieui.dll
2015-10-30 13:21:46 ----A---- C:\Windows\system32\ieframe.dll
2015-10-30 13:21:46 ----A---- C:\Windows\system32\dxtmsft.dll
2015-10-30 13:21:45 ----A---- C:\Windows\system32\wininet.dll
2015-10-30 13:21:45 ----A---- C:\Windows\system32\webcheck.dll
2015-10-30 13:21:45 ----A---- C:\Windows\system32\msrating.dll
2015-10-30 13:21:45 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-10-30 13:21:45 ----A---- C:\Windows\system32\jscript9diag.dll
2015-10-30 13:21:45 ----A---- C:\Windows\system32\jscript9.dll
2015-10-30 13:21:45 ----A---- C:\Windows\system32\jscript.dll
2015-10-30 13:21:44 ----A---- C:\Windows\system32\mshtml.dll
2015-10-30 13:21:39 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-10-30 13:21:39 ----A---- C:\Windows\system32\schannel.dll
2015-10-30 13:21:39 ----A---- C:\Windows\system32\rpcrt4.dll
2015-10-30 13:21:39 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-10-30 13:21:39 ----A---- C:\Windows\system32\lsasrv.dll
2015-10-30 13:21:39 ----A---- C:\Windows\system32\kerberos.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-10-30 13:21:38 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-10-30 13:21:38 ----A---- C:\Windows\system32\wdigest.dll
2015-10-30 13:21:38 ----A---- C:\Windows\system32\TSpkg.dll
2015-10-30 13:21:38 ----A---- C:\Windows\system32\ntdll.dll
2015-10-30 13:21:38 ----A---- C:\Windows\system32\ncrypt.dll
2015-10-30 13:21:38 ----A---- C:\Windows\system32\msv1_0.dll
2015-10-30 13:21:38 ----A---- C:\Windows\system32\kernel32.dll
2015-10-30 13:21:38 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-10-30 13:21:38 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-10-30 13:21:38 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-10-30 13:21:38 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-10-30 13:21:38 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-10-30 13:21:38 ----A---- C:\Windows\system32\adtschema.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-10-30 13:21:37 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\user.exe
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-10-30 13:21:37 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\wow64win.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\wow64cpu.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\wow64.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\winsrv.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\sspisrv.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\sspicli.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\srcore.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\srclient.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\smss.exe
2015-10-30 13:21:37 ----A---- C:\Windows\system32\secur32.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\rstrui.exe
2015-10-30 13:21:37 ----A---- C:\Windows\system32\ntvdm64.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\msobjs.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\msaudite.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\lsass.exe
2015-10-30 13:21:37 ----A---- C:\Windows\system32\KernelBase.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\csrsrv.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\cryptbase.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\credssp.dll
2015-10-30 13:21:37 ----A---- C:\Windows\system32\conhost.exe
2015-10-30 13:21:37 ----A---- C:\Windows\system32\auditpol.exe
2015-10-30 13:21:37 ----A---- C:\Windows\system32\apisetschema.dll
2015-10-30 13:21:32 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-10-30 13:21:32 ----A---- C:\Windows\system32\tracerpt.exe
2015-10-30 13:21:31 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-10-30 13:21:31 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-10-30 13:21:31 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-10-30 13:21:31 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-10-30 13:21:31 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-10-30 13:21:31 ----A---- C:\Windows\system32\typeperf.exe
2015-10-30 13:21:31 ----A---- C:\Windows\system32\sechost.dll
2015-10-30 13:21:31 ----A---- C:\Windows\system32\relog.exe
2015-10-30 13:21:31 ----A---- C:\Windows\system32\logman.exe
2015-10-30 13:21:31 ----A---- C:\Windows\system32\diskperf.exe
2015-10-30 13:21:24 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-10-30 13:21:23 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-10-30 13:21:23 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-10-30 13:21:23 ----A---- C:\Windows\system32\drivers\appid.sys
2015-10-30 13:21:23 ----A---- C:\Windows\system32\appidsvc.dll
2015-10-30 13:21:23 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-10-30 13:21:23 ----A---- C:\Windows\system32\appidapi.dll
2015-10-30 13:21:18 ----A---- C:\Windows\system32\UtcResources.dll
2015-10-30 13:21:18 ----A---- C:\Windows\system32\diagtrack.dll
2015-10-30 13:21:17 ----A---- C:\Windows\system32\tdh.dll
2015-10-30 13:21:17 ----A---- C:\Windows\system32\advapi32.dll
2015-10-30 13:21:16 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-10-30 13:21:16 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-10-30 13:21:09 ----A---- C:\Windows\system32\icaapi.dll
2015-10-30 13:21:09 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2015-10-30 13:21:06 ----A---- C:\Windows\system32\shell32.dll
2015-10-30 13:21:05 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-10-30 13:21:05 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-10-30 13:21:05 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-10-30 13:21:00 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-10-30 13:21:00 ----A---- C:\Windows\system32\tzres.dll
2015-10-30 13:20:56 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-10-30 13:20:56 ----A---- C:\Windows\system32\jnwmon.dll
2015-10-30 13:20:56 ----A---- C:\Windows\system32\InkEd.dll
2015-10-30 13:20:55 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-10-30 13:20:55 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-10-30 13:20:55 ----A---- C:\Windows\system32\invagent.dll
2015-10-30 13:20:55 ----A---- C:\Windows\system32\dwmcore.dll
2015-10-30 13:20:55 ----A---- C:\Windows\system32\dwmapi.dll
2015-10-30 13:20:55 ----A---- C:\Windows\system32\devinv.dll
2015-10-30 13:20:55 ----A---- C:\Windows\system32\appraiser.dll
2015-10-30 13:20:54 ----A---- C:\Windows\system32\generaltel.dll
2015-10-30 13:20:54 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-10-30 13:20:54 ----A---- C:\Windows\system32\aeinv.dll
2015-10-30 13:20:54 ----A---- C:\Windows\system32\acmigration.dll
2015-10-30 13:20:53 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-10-30 13:20:53 ----A---- C:\Windows\system32\consent.exe
2015-10-30 13:20:53 ----A---- C:\Windows\system32\authui.dll
2015-10-30 13:20:53 ----A---- C:\Windows\system32\appinfo.dll
2015-10-30 13:20:52 ----A---- C:\Windows\system32\schedsvc.dll
2015-10-30 13:20:51 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-10-30 13:20:51 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-10-30 13:20:51 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-10-30 13:20:51 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-10-30 13:20:51 ----A---- C:\Windows\system32\msxml6r.dll
2015-10-30 13:20:51 ----A---- C:\Windows\system32\msxml6.dll
2015-10-30 13:20:51 ----A---- C:\Windows\system32\msxml3r.dll
2015-10-30 13:20:51 ----A---- C:\Windows\system32\msxml3.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\ucrtbase.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-30 13:20:50 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-30 13:20:49 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-10-30 13:20:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-10-30 13:20:49 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-10-30 13:20:49 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-10-30 13:20:49 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wuwebv.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wups2.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wups.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wudriver.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wucltux.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wuaueng.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wuauclt.exe
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wuapp.exe
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wuapi.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-10-30 13:20:49 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-10-30 13:20:48 ----A---- C:\Windows\system32\win32k.sys
2015-10-30 13:14:55 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-10-30 13:14:55 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-10-30 13:14:55 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-10-30 13:14:55 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-10-30 13:14:55 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-10-30 13:14:55 ----A---- C:\Windows\system32\lpk.dll
2015-10-30 13:14:55 ----A---- C:\Windows\system32\fontsub.dll
2015-10-30 13:14:55 ----A---- C:\Windows\system32\dciman32.dll
2015-10-30 13:14:55 ----A---- C:\Windows\system32\atmlib.dll
2015-10-30 13:14:55 ----A---- C:\Windows\system32\atmfd.dll
2015-10-29 19:02:14 ----D---- C:\Program Files\CCleaner

======List of files/folders modified in the last 1 month======

2015-11-09 23:35:13 ----RD---- C:\Program Files
2015-11-09 23:34:10 ----D---- C:\Windows\System32
2015-11-09 23:34:10 ----D---- C:\Windows\inf
2015-11-09 23:34:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-11-09 23:32:16 ----D---- C:\Windows\system32\config
2015-11-09 23:29:04 ----D---- C:\Windows\Temp
2015-11-09 23:28:50 ----D---- C:\Windows\Tasks
2015-11-09 23:28:50 ----D---- C:\Windows\system32\wfp
2015-11-09 23:28:49 ----D---- C:\Windows\system32\wbem
2015-11-09 23:28:49 ----D---- C:\Windows
2015-11-09 23:28:24 ----SD---- C:\Windows\system32\GWX
2015-11-09 23:28:24 ----D---- C:\Windows\winsxs
2015-11-09 23:28:24 ----D---- C:\Windows\SysWOW64
2015-11-09 23:28:24 ----D---- C:\Windows\system32\Tasks
2015-11-09 23:28:24 ----D---- C:\Windows\system32\DriverStore
2015-11-09 23:28:24 ----D---- C:\Windows\system32\drivers\UMDF
2015-11-09 23:28:24 ----D---- C:\Windows\system32\drivers
2015-11-09 23:28:24 ----D---- C:\Windows\rescache
2015-11-09 23:28:23 ----D---- C:\Windows\system32\CodeIntegrity
2015-11-09 23:28:23 ----D---- C:\Windows\system32\catroot2
2015-11-09 23:28:23 ----D---- C:\Windows\Intel_Chipset_Win7-8_8-1_VER9401026
2015-11-09 23:28:20 ----D---- C:\Users\Tomas\AppData\Roaming\vlc
2015-11-09 23:28:19 ----D---- C:\Users\Tomas\AppData\Roaming\GHISLER
2015-11-09 23:28:16 ----D---- C:\Program Files (x86)\7-Zip
2015-11-09 23:28:12 ----D---- C:\Windows\registration
2015-11-09 23:27:35 ----RHD---- C:\MSOCache
2015-11-09 23:27:35 ----RD---- C:\Program Files (x86)
2015-11-09 23:23:00 ----SHD---- C:\System Volume Information
2015-11-09 21:12:02 ----D---- C:\Windows\Prefetch
2015-11-09 17:01:27 ----D---- C:\Windows\SoftwareDistribution
2015-11-09 17:00:19 ----D---- C:\Windows\debug
2015-11-09 11:54:29 ----D---- C:\Windows\Microsoft.NET
2015-11-09 11:52:13 ----RSD---- C:\Windows\assembly
2015-11-09 11:35:39 ----SHD---- C:\Windows\Installer
2015-11-09 11:35:39 ----SHD---- C:\Config.Msi
2015-11-09 11:33:33 ----HD---- C:\ProgramData
2015-11-09 11:33:26 ----HD---- C:\$Windows.~BT
2015-11-09 11:26:54 ----RSD---- C:\Windows\Media
2015-11-09 11:26:54 ----D---- C:\Windows\system32\drivers\etc
2015-11-09 11:26:53 ----D---- C:\Windows\twain_32
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\zh-TW
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\zh-HK
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\zh-CN
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\tr-TR
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\sv-SE
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\sk-SK
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\ru-RU
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\pt-PT
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\pt-BR
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\pl-PL
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\nl-NL
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\nb-NO
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\migration
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\ko-KR
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\ja-JP
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\it-IT
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\hu-HU
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\fr-FR
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\fi-FI
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\es-ES
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\el-GR
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\drivers
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\de-DE
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\da-DK
2015-11-09 11:26:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-09 11:26:52 ----D---- C:\Windows\system32\zh-TW
2015-11-09 11:26:52 ----D---- C:\Windows\system32\zh-HK
2015-11-09 11:26:52 ----D---- C:\Windows\system32\zh-CN
2015-11-09 11:26:52 ----D---- C:\Windows\system32\tr-TR
2015-11-09 11:26:52 ----D---- C:\Windows\system32\sv-SE
2015-11-09 11:26:52 ----D---- C:\Windows\system32\sk-SK
2015-11-09 11:26:52 ----D---- C:\Windows\system32\ru-RU
2015-11-09 11:26:52 ----D---- C:\Windows\system32\pt-PT
2015-11-09 11:26:52 ----D---- C:\Windows\system32\pt-BR
2015-11-09 11:26:52 ----D---- C:\Windows\system32\pl-PL
2015-11-09 11:26:52 ----D---- C:\Windows\system32\nl-NL
2015-11-09 11:26:52 ----D---- C:\Windows\system32\NDF
2015-11-09 11:26:52 ----D---- C:\Windows\system32\nb-NO
2015-11-09 11:26:52 ----D---- C:\Windows\system32\migration
2015-11-09 11:26:52 ----D---- C:\Windows\system32\ko-KR
2015-11-09 11:26:52 ----D---- C:\Windows\system32\ja-JP
2015-11-09 11:26:52 ----D---- C:\Windows\system32\it-IT
2015-11-09 11:26:52 ----D---- C:\Windows\system32\hu-HU
2015-11-09 11:26:52 ----D---- C:\Windows\system32\fr-FR
2015-11-09 11:26:52 ----D---- C:\Windows\system32\fi-FI
2015-11-09 11:26:52 ----D---- C:\Windows\system32\es-ES
2015-11-09 11:26:52 ----D---- C:\Windows\system32\en-US
2015-11-09 11:26:52 ----D---- C:\Windows\system32\el-GR
2015-11-09 11:26:52 ----D---- C:\Windows\system32\drivers\en-US
2015-11-09 11:26:52 ----D---- C:\Windows\system32\de-DE
2015-11-09 11:26:52 ----D---- C:\Windows\system32\da-DK
2015-11-09 11:26:52 ----D---- C:\Windows\system32\cs-CZ
2015-11-09 11:26:51 ----D---- C:\Windows\PolicyDefinitions
2015-11-09 11:26:51 ----D---- C:\Windows\LiveKernelReports
2015-11-09 11:26:50 ----SD---- C:\ProgramData\Microsoft
2015-11-09 11:26:50 ----RSD---- C:\Windows\Fonts
2015-11-09 11:26:50 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2015-11-09 11:26:49 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-11-09 11:26:49 ----D---- C:\Program Files\Common Files
2015-11-09 11:26:49 ----D---- C:\Program Files\AMD
2015-11-09 11:26:49 ----D---- C:\Program Files (x86)\Microsoft.NET
2015-11-09 11:26:49 ----D---- C:\Program Files (x86)\Common Files
2015-11-09 11:26:48 ----SD---- C:\Users\Tomas\AppData\Roaming\Microsoft
2015-11-09 11:26:48 ----D---- C:\Windows\system32\Recovery
2015-11-07 15:28:10 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-06 17:25:48 ----D---- C:\Program Files (x86)\OpenOffice 4
2015-11-06 10:26:21 ----D---- C:\Users\Tomas\AppData\Roaming\Raptr
2015-10-31 17:32:21 ----D---- C:\Program Files (x86)\Raptr
2015-10-31 17:30:12 ----D---- C:\AMD
2015-10-31 16:22:30 ----HD---- C:\Program Files (x86)\Temp
2015-10-31 15:41:46 ----D---- C:\Program Files (x86)\Realtek
2015-10-31 15:39:13 ----D---- C:\Program Files\Intel
2015-10-30 16:24:54 ----D---- C:\Windows\Panther
2015-10-30 15:59:44 ----D---- C:\Windows\Logs
2015-10-30 14:05:13 ----D---- C:\Program Files\Windows Journal
2015-10-30 14:05:12 ----D---- C:\Windows\ehome
2015-10-30 14:05:12 ----D---- C:\Program Files\Internet Explorer
2015-10-30 14:05:12 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-30 14:05:11 ----SD---- C:\Windows\system32\CompatTel
2015-10-30 14:05:11 ----D---- C:\Windows\system32\appraiser
2015-10-30 14:05:11 ----D---- C:\Windows\AppPatch
2015-10-30 14:05:10 ----D---- C:\Windows\system32\Boot
2015-10-30 14:05:07 ----SD---- C:\Windows\SYSWOW64\GWX
2015-10-30 13:32:34 ----D---- C:\Windows\system32\MRT
2015-10-30 13:29:31 ----A---- C:\Windows\system32\MRT.exe
2015-10-29 09:15:46 ----D---- C:\Program Files\Microsoft Office 15
2015-10-22 18:51:32 ----D---- C:\Windows\system32\wdi
2015-10-18 15:48:55 ----D---- C:\Windows\system32\LogFiles
2015-10-17 17:31:28 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-11-06 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-11-06 273784]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-08-07 644968]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-08-07 28008]
R0 iusb3hcs;Ovládač prepínača hostiteľského radiča Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-04-26 20464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2015-04-26 15232]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-11-06 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-11-06 1059656]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-11-06 449992]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-11-06 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-11-06 97648]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-11-06 154256]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2010-01-27 47632]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-08-04 21622784]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-08-04 665088]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-07-15 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-09-30 4234456]
R3 iusb3hub;Ovládač rozbočovača Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2013-04-26 368112]
R3 iusb3xhc;Ovládač hostiteľského radiča Intel(R) USB 3.0 eXtensible; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2013-04-26 786416]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2015-01-06 129312]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-06-05 936664]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-08-04 246784]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [2015-04-26 936728]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-11-06 174416]
R2 ClickToRunSvc;Služba Klikni a spusti balíka Microsoft Office; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-10-07 2780856]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-08-07 15720]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-01-06 158496]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2015-01-06 409376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-26 107848]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-17 269000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-26 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-09-16 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-11-07 147624]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-03-31 150600]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2015-03-31 5132888]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-04-26 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]

-----------------EOF-----------------

Re: Asi zavírený počítač

Napsal: 10 lis 2015 18:22
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Asi zavírený počítač

Napsal: 10 lis 2015 21:37
od 7777
# AdwCleaner v5.019 - Logfile created 10/11/2015 at 21:33:46
# Updated 08/11/2015 by Xplode
# Database : 2015-11-09.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Tomas - TOMAS-PC
# Running from : C:\Users\Tomas\Desktop\adwcleaner_5.019.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [680 bytes] ##########

Re: Asi zavírený počítač

Napsal: 10 lis 2015 22:06
od Rudy
Toto je OK.
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Program Files\VDownloader

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader]/64

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.

Re: Asi zavírený počítač

Napsal: 10 lis 2015 22:22
od 7777
All processes killed
========== FILES ==========
File/Folder C:\Windows\tasks\GoogleUpdateTaskMachineCore.job not found.
File/Folder C:\Windows\tasks\GoogleUpdateTaskMachineUA.job not found.
File/Folder C:\Program Files\VDownloader not found.
========== REGISTRY ==========
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Mama
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 368102368 bytes
->Google Chrome cache emptied: 11545437 bytes
->Flash cache emptied: 2265 bytes

User: Public

User: Tomas
->Temp folder emptied: 17977407 bytes
->Temporary Internet Files folder emptied: 11584961 bytes
->FireFox cache emptied: 372518978 bytes
->Google Chrome cache emptied: 433139525 bytes
->Flash cache emptied: 2609 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 418327 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33298 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33298 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1 159,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Mama
->Flash cache emptied: 0 bytes

User: Public

User: Tomas
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 11102015_221628

Files moved on Reboot...
C:\Users\Tomas\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
File C:\Windows\temp\officeclicktorun.exe_c2ruidll(201511102214275C0).log not found!
File C:\Windows\temp\officeclicktorun.exe_streamserver(201511102214275C0).log not found!
C:\Windows\temp\TOMAS-PC-20151110-2214.log moved successfully.
File move failed. C:\Windows\SysWow64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Asi zavírený počítač

Napsal: 10 lis 2015 22:32
od Rudy
Nastala změna?

Re: Asi zavírený počítač

Napsal: 11 lis 2015 09:51
od 7777
Nie. Zložky sú stále anglické. Dajú sa však premenovať aj ručne už som jednu premenoval. Ešte ma napadlo na disku c:/ sa mi objavil divný log a nepochádza zo žiadneho programu, ktorý sme tu používali. Píše sa tam niečo aj o tých zložkách z knižnice ale pre mňa veľmi zložité a hlavne anglicky.
2015-11-09 11:24:45, Info SP Disk space required (Begin: 49319337984, End: 47059611648): 0
2015-11-09 11:24:45, Info SP SPGetOSInformation: Starting the engine online
2015-11-09 11:24:45, Info Entering MigStartupOnline method
2015-11-09 11:24:45, Info Entering MigPlatformStartupOnline method
2015-11-09 11:24:45, Info MIG AdjustPrivilege: Privilege SeSecurityPrivilege will be Enabled
2015-11-09 11:24:45, Info MIG Privilege has been enabled
2015-11-09 11:24:45, Info MIG AdjustPrivilege: Privilege SeBackupPrivilege will be Enabled
2015-11-09 11:24:45, Info MIG Privilege has been enabled
2015-11-09 11:24:45, Info MIG AdjustPrivilege: Privilege SeRestorePrivilege will be Enabled
2015-11-09 11:24:45, Info MIG Privilege has been enabled
2015-11-09 11:24:45, Info MIG AdjustPrivilege: Privilege SeTakeOwnershipPrivilege will be Enabled
2015-11-09 11:24:45, Info MIG Privilege has been enabled
2015-11-09 11:24:45, Info MIG AdjustPrivilege: Privilege SeDebugPrivilege will be Enabled
2015-11-09 11:24:45, Info MIG Privilege has been enabled
2015-11-09 11:24:45, Info MIG AdjustPrivilege: Privilege SeCreateSymbolicLinkPrivilege will be Enabled
2015-11-09 11:24:45, Info MIG Privilege has been enabled
2015-11-09 11:24:45, Info [0x0803ac] MIG Initializing online WinNT platform
2015-11-09 11:24:45, Info MIG Platform is using admin privileges
2015-11-09 11:24:45, Info [0x0803df] MIG Adding direct mapping from HKLM to HKEY_LOCAL_MACHINE (R/W)
2015-11-09 11:24:45, Info [0x0803e1] MIG Successfully mapped HKLM
2015-11-09 11:24:45, Info [0x0803df] MIG Adding direct mapping from HKU to HKEY_USERS (R/W)
2015-11-09 11:24:45, Info [0x0803e1] MIG Successfully mapped HKU
2015-11-09 11:24:46, Info [0x08040e] MIG State data store is available.
2015-11-09 11:24:46, Info MIG GAC Data store: initial version received: v2.0.50727
2015-11-09 11:24:46, Info MIG GAC Data store: higher version found: v4.0.30319
2015-11-09 11:24:46, Info MIG GAC data store: loaded fusion.dll from highest runtime version v4.0.30319
2015-11-09 11:24:46, Info [0x0803b4] MIG COnlineWinNTPlatform: ComputerName=TOMAS-PC
2015-11-09 11:24:46, Info [0x0803b5] MIG COnlineWinNTPlatform: Get Machine Sid S-1-5-21-1110698291-3134169923-3196150024
2015-11-09 11:24:46, Info MIG COnlineWinNTPlatform::GetMachineGuid - return value -> {fe03d327-4984-439b-a983-c469dcf6c45b}
2015-11-09 11:24:46, Info MIG Found connected provider. Name: MicrosoftAccount, Guid: {D7F9888F-E3FC-49B0-9EA6-A85B5F392A4F}
2015-11-09 11:24:46, Info MIG Adding indirect mapping for HKLM\ELAM (C:\WINDOWS\system32\config\elam) to 0x80000002, $ONLINE_RW$ELAM
2015-11-09 11:24:46, Info [0x0803e2] MIG Adding indirect mapping from HKLM\ELAM to <C:\WINDOWS\system32\config\elam> loaded at HKEY_LOCAL_MACHINE\$ONLINE_RW$ELAM (R/W)
2015-11-09 11:24:46, Info [0x0803e4] MIG Successfully mapped HKLM\ELAM
2015-11-09 11:24:46, Info MIG Processing non-renamed user profiles
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\WINDOWS\system32\config\systemprofile
2015-11-09 11:24:46, Info [0x0803bf] MIG User profile HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 excluded because SID S-1-5-18 is excluded by default.
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Windows\ServiceProfiles\LocalService
2015-11-09 11:24:46, Info [0x0803bd] MIG Skipping profile HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19. SID buffer not found.
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Windows\ServiceProfiles\NetworkService
2015-11-09 11:24:46, Info [0x0803bd] MIG Skipping profile HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20. SID buffer not found.
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Users\Tomas
2015-11-09 11:24:46, Info MIG UserIsAdminCheck: Tomas-PC\Tomas IsAdmin = TRUE
2015-11-09 11:24:46, Info MIG Adding direct mapping for HKCU to 0x80000003, S-1-5-21-1110698291-3134169923-3196150024-1000
2015-11-09 11:24:46, Info [0x0803df] MIG Adding direct mapping from HKCU to HKEY_USERS\S-1-5-21-1110698291-3134169923-3196150024-1000 (R/W)
2015-11-09 11:24:46, Info [0x0803e1] MIG Successfully mapped HKCU
2015-11-09 11:24:46, Info MIG Adding direct mapping for HKCU\Software\Classes to 0x80000003, S-1-5-21-1110698291-3134169923-3196150024-1000_Classes
2015-11-09 11:24:46, Info [0x0803df] MIG Adding direct mapping from HKCU\Software\Classes to HKEY_USERS\S-1-5-21-1110698291-3134169923-3196150024-1000_Classes (R/W)
2015-11-09 11:24:46, Info [0x0803e1] MIG Successfully mapped HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e6] MIG Removing mapping for HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e7] MIG Successfully unmapped HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e6] MIG Removing mapping for HKCU
2015-11-09 11:24:46, Info [0x0803e7] MIG Successfully unmapped HKCU
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Users\Mama
2015-11-09 11:24:46, Info MIG Adding indirect mapping for HKCU (C:\Users\Mama\NTUSER.DAT) to 0x80000003, S-1-5-21-1110698291-3134169923-3196150024-1001
2015-11-09 11:24:46, Info [0x0803e2] MIG Adding indirect mapping from HKCU to <C:\Users\Mama\NTUSER.DAT> loaded at HKEY_USERS\S-1-5-21-1110698291-3134169923-3196150024-1001 (R/W)
2015-11-09 11:24:46, Info [0x0803e4] MIG Successfully mapped HKCU
2015-11-09 11:24:46, Info MIG Adding indirect mapping for HKCU\Software\Classes (C:\Users\Mama\AppData\Local\Microsoft\Windows\UsrClass.dat) to 0x80000003, S-1-5-21-1110698291-3134169923-3196150024-1001_Classes
2015-11-09 11:24:46, Info [0x0803e2] MIG Adding indirect mapping from HKCU\Software\Classes to <C:\Users\Mama\AppData\Local\Microsoft\Windows\UsrClass.dat> loaded at HKEY_USERS\S-1-5-21-1110698291-3134169923-3196150024-1001_Classes (R/W)
2015-11-09 11:24:46, Info [0x0803e4] MIG Successfully mapped HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e6] MIG Removing mapping for HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e7] MIG Successfully unmapped HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e6] MIG Removing mapping for HKCU
2015-11-09 11:24:46, Info [0x0803e7] MIG Successfully unmapped HKCU
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Users\DefaultAppPool
2015-11-09 11:24:46, Error [0x0803b6] MIG Can't retrieve group information for user IIS APPPOOL\DefaultAppPool. NetUserGetLocalGroups failed 0x000008AD
2015-11-09 11:24:46, Info MIG Adding direct mapping for HKCU to 0x80000003, S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415
2015-11-09 11:24:46, Info [0x0803df] MIG Adding direct mapping from HKCU to HKEY_USERS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 (R/W)
2015-11-09 11:24:46, Info [0x0803e1] MIG Successfully mapped HKCU
2015-11-09 11:24:46, Info MIG Adding direct mapping for HKCU\Software\Classes to 0x80000003, S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415_Classes
2015-11-09 11:24:46, Info [0x0803df] MIG Adding direct mapping from HKCU\Software\Classes to HKEY_USERS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415_Classes (R/W)
2015-11-09 11:24:46, Info [0x0803e1] MIG Successfully mapped HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e6] MIG Removing mapping for HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e7] MIG Successfully unmapped HKCU\Software\Classes
2015-11-09 11:24:46, Info [0x0803e6] MIG Removing mapping for HKCU
2015-11-09 11:24:46, Info [0x0803e7] MIG Successfully unmapped HKCU
2015-11-09 11:24:46, Info MIG Processing renamed user profiles
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\WINDOWS\system32\config\systemprofile
2015-11-09 11:24:46, Info [0x0803bf] MIG User profile HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 excluded because SID S-1-5-18 is excluded by default.
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Windows\ServiceProfiles\LocalService
2015-11-09 11:24:46, Info [0x0803bd] MIG Skipping profile HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19. SID buffer not found.
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Windows\ServiceProfiles\NetworkService
2015-11-09 11:24:46, Info [0x0803bd] MIG Skipping profile HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20. SID buffer not found.
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Users\Tomas
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Users\Mama
2015-11-09 11:24:46, Info [0x0803b8] MIG Processing profile: C:\Users\DefaultAppPool
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_PublicDownloads: C:\Users\Public\Downloads, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_DESKTOPDIRECTORY: C:\Users\Public\Desktop, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_DOCUMENTS: C:\Users\Public\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_PROGRAMS: C:\ProgramData\Microsoft\Windows\Start Menu\Programs, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_STARTMENU: C:\ProgramData\Microsoft\Windows\Start Menu, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_STARTUP: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_TEMPLATES: C:\ProgramData\Microsoft\Windows\Templates, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_MUSIC: C:\Users\Public\Music, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_PICTURES: C:\Users\Public\Pictures, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COMMON_VIDEO: C:\Users\Public\Videos, default location: Yes
2015-11-09 11:24:46, Info [0x0803ae] MIG Dumping detected users:
2015-11-09 11:24:46, Info [0x0803af] MIG Name: DefaultAppPool, Domain: IIS APPPOOL, Profile: C:\Users\DefaultAppPool, SidString: S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415, ID: USER00000002, IsAdmin: 0, IsBuiltInAdmin: 0, IsDisabled: 0, IsInteractive: 1, Groups:
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_Downloads: C:\Users\DefaultAppPool\Downloads, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDrive: C:\Users\DefaultAppPool\SkyDrive, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDriveDocuments: C:\Users\DefaultAppPool\SkyDrive\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDrivePictures: C:\Users\DefaultAppPool\SkyDrive\Pictures, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDriveCameraRoll: C:\Users\DefaultAppPool\SkyDrive\Pictures\Camera Roll, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_INTERNET_CACHE: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\INetCache, default location: No
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COOKIES: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\INetCookies, default location: No
2015-11-09 11:24:46, Info MIG Known folder CSIDL_DESKTOP: C:\Users\DefaultAppPool\Desktop, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_DESKTOPDIRECTORY: C:\Users\DefaultAppPool\Desktop, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_FAVORITES: C:\Users\DefaultAppPool\Favorites, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_HISTORY: C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\History, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYPICTURES: C:\Users\DefaultAppPool\Pictures, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYMUSIC: C:\Users\DefaultAppPool\Music, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYVIDEO: C:\Users\DefaultAppPool\Videos, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_PERSONAL: C:\Users\DefaultAppPool\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYDOCUMENTS: C:\Users\DefaultAppPool\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_PROGRAMS: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_RECENT: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Recent, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_SENDTO: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_STARTMENU: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_STARTUP: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_TEMPLATES: C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Templates, default location: Yes
2015-11-09 11:24:46, Info [0x0803af] MIG Name: Mama, Domain: Tomas-PC, Profile: C:\Users\Mama, SidString: S-1-5-21-1110698291-3134169923-3196150024-1001, ID: USER00000001, IsAdmin: 0, IsBuiltInAdmin: 0, IsDisabled: 0, IsInteractive: 1, Groups: Users
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_Downloads: C:\Users\Mama\Downloads, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDrive: C:\Users\Mama\SkyDrive, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDriveDocuments: C:\Users\Mama\SkyDrive\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDrivePictures: C:\Users\Mama\SkyDrive\Pictures, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDriveCameraRoll: C:\Users\Mama\SkyDrive\Pictures\Camera Roll, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_INTERNET_CACHE: C:\Users\Mama\AppData\Local\Microsoft\Windows\INetCache, default location: No
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COOKIES: C:\Users\Mama\AppData\Local\Microsoft\Windows\INetCookies, default location: No
2015-11-09 11:24:46, Info MIG Known folder CSIDL_DESKTOP: C:\Users\Mama\Desktop, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_DESKTOPDIRECTORY: C:\Users\Mama\Desktop, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_FAVORITES: C:\Users\Mama\Favorites, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_HISTORY: C:\Users\Mama\AppData\Local\Microsoft\Windows\History, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYPICTURES: C:\Users\Mama\Pictures, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYMUSIC: C:\Users\Mama\Music, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYVIDEO: C:\Users\Mama\Videos, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_PERSONAL: C:\Users\Mama\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYDOCUMENTS: C:\Users\Mama\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_PROGRAMS: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_RECENT: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Recent, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_SENDTO: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\SendTo, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_STARTMENU: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_STARTUP: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_TEMPLATES: C:\Users\Mama\AppData\Roaming\Microsoft\Windows\Templates, default location: Yes
2015-11-09 11:24:46, Info [0x0803af] MIG Name: Tomas, Domain: Tomas-PC, Profile: C:\Users\Tomas, SidString: S-1-5-21-1110698291-3134169923-3196150024-1000, ID: USER00000000, IsAdmin: 1, IsBuiltInAdmin: 0, IsDisabled: 0, IsInteractive: 1, Groups: Administrators
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_Downloads: C:\Users\Tomas\Downloads, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDrive: C:\Users\Tomas\SkyDrive, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDriveDocuments: C:\Users\Tomas\SkyDrive\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDrivePictures: C:\Users\Tomas\SkyDrive\Pictures, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder FOLDERID_SkyDriveCameraRoll: C:\Users\Tomas\SkyDrive\Pictures\Camera Roll, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_INTERNET_CACHE: C:\Users\Tomas\AppData\Local\Microsoft\Windows\INetCache, default location: No
2015-11-09 11:24:46, Info MIG Known folder CSIDL_COOKIES: C:\Users\Tomas\AppData\Local\Microsoft\Windows\INetCookies, default location: No
2015-11-09 11:24:46, Info MIG Known folder CSIDL_DESKTOP: C:\Users\Tomas\Desktop, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_DESKTOPDIRECTORY: C:\Users\Tomas\Desktop, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_FAVORITES: C:\Users\Tomas\Favorites, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_HISTORY: C:\Users\Tomas\AppData\Local\Microsoft\Windows\History, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYPICTURES: C:\Users\Tomas\Pictures, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYMUSIC: C:\Users\Tomas\Music, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYVIDEO: C:\Users\Tomas\Videos, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_PERSONAL: C:\Users\Tomas\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_MYDOCUMENTS: C:\Users\Tomas\Documents, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_PROGRAMS: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_RECENT: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Recent, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_SENDTO: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\SendTo, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_STARTMENU: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_STARTUP: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, default location: Yes
2015-11-09 11:24:46, Info MIG Known folder CSIDL_TEMPLATES: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Templates, default location: Yes
2015-11-09 11:24:46, Info [0x0803af] MIG Name: Guest, Domain: TOMAS-PC, Profile: (NULL), SidString: S-1-5-21-1110698291-3134169923-3196150024-501, ID: USER00000005, IsAdmin: 0, IsBuiltInAdmin: 0, IsDisabled: 1, IsInteractive: 1, Groups: Guests
2015-11-09 11:24:46, Info [0x0803af] MIG Name: DefaultAccount, Domain: TOMAS-PC, Profile: (NULL), SidString: S-1-5-21-1110698291-3134169923-3196150024-503, ID: USER00000004, IsAdmin: 0, IsBuiltInAdmin: 0, IsDisabled: 1, IsInteractive: 0, Groups:
2015-11-09 11:24:46, Info [0x0803af] MIG Name: Administrator, Domain: TOMAS-PC, Profile: (NULL), SidString: S-1-5-21-1110698291-3134169923-3196150024-500, ID: USER00000003, IsAdmin: 1, IsBuiltInAdmin: 1, IsDisabled: 1, IsInteractive: 1, Groups: Administrators
2015-11-09 11:24:46, Info [0x0805a8] MIG Added drive root mapping for 'C:\' (type: 1, file system: 1, bus type: 11, hotplug media: No, hotplug device: No)
2015-11-09 11:24:46, Info [0x0805a8] MIG Added drive root mapping for 'D:\' (type: 1, file system: 1, bus type: 11, hotplug media: No, hotplug device: No)
2015-11-09 11:24:46, Info [0x0805a8] MIG Added drive root mapping for 'E:\' (type: 2, file system: 0, bus type: 0, hotplug media: No, hotplug device: No)
2015-11-09 11:24:46, Info [0x0803e5] MIG Not unmapping HKCU\Software\Classes; it is not mapped
2015-11-09 11:24:46, Info [0x0803e5] MIG Not unmapping HKCU; it is not mapped
2015-11-09 11:24:46, Info [0x080411] MIG Setting SMI registry mappings for system context
2015-11-09 11:24:46, Info MIG This platform supports mandatory labels (LABEL_SECURITY_INFORMATION)
2015-11-09 11:24:46, Info [0x080485] MIG Initializing OS analysis service (data path = C:\$Windows.~BT\Sources)
2015-11-09 11:24:46, Info MIG Mig::CWRFCollection::SearchAndLoad: Search WRF definitions in folder 'C:\$Windows.~BT\Sources\Migration\WTR'.
2015-11-09 11:24:46, Info MIG Mig::CWRFCollection::SearchAndLoad: 17 items found.
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\$TEMP_UPGRADE_WRF_REMOVAL_DEFINITION.INF'.
2015-11-09 11:24:46, Info MIG WRF: File='$TEMP_UPGRADE_WRF_REMOVAL_DEFINITION.INF'
2015-11-09 11:24:46, Info MIG Name='$TEMP_WRF_REMOVAL$', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\adminpack_en-us.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='adminpack_en-us.inf'
2015-11-09 11:24:46, Info MIG Name='Administration Pack for IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{C6E9540C-4B66-4367-A8CF-570DCFD9F030}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\adminpack_en-us_noloc.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='adminpack_en-us_noloc.inf'
2015-11-09 11:24:46, Info MIG Name='Administration Pack for IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{C6E9540C-4B66-4367-A8CF-570DCFD9F030}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\adobe_flash.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='adobe_flash.inf'
2015-11-09 11:24:46, Info MIG Name='Adobe Flash for Windows', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\browserchoice_win7.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='browserchoice_win7.inf'
2015-11-09 11:24:46, Info MIG Name='BrowserChoice Win7', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\browserchoice_win8.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='browserchoice_win8.inf'
2015-11-09 11:24:46, Info MIG Name='BrowserChoice Win8', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\compattelemetry.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='compattelemetry.inf'
2015-11-09 11:24:46, Info MIG Name='Compat Telemetry', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.0.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='ftp_7.0.inf'
2015-11-09 11:24:46, Info MIG Name='Microsoft FTP Service for IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{15ABFD45-B97E-483D-A6C9-28AA751A1C01}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.5_en-us_noloc.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='ftp_7.5_en-us_noloc.inf'
2015-11-09 11:24:46, Info MIG Name='FTP Service 7.5 for IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{36599245-6895-4CB9-8108-516E25EC5DC0}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.5_loc.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='ftp_7.5_loc.inf'
2015-11-09 11:24:46, Info MIG Name='FTP Service 7.5 for IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{790AE609-3122-4C3E-9EA8-687F7B00ED0E}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\gwxmig.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='gwxmig.inf'
2015-11-09 11:24:46, Info MIG Name='Microsoft-Windows-GWX', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\netfx45_upgradecleanup.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='netfx45_upgradecleanup.inf'
2015-11-09 11:24:46, Info MIG Name='Microsoft .NET Framework 4.5', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\powershell_en-us_noloc.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='powershell_en-us_noloc.inf'
2015-11-09 11:24:46, Info MIG Name='Microsoft Windows PowerShell snap-in for IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{3C557BC2-9FC4-4293-9E36-F6F5079E3E0C}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\powershell_loc.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='powershell_loc.inf'
2015-11-09 11:24:46, Info MIG Name='Microsoft Windows PowerShell snap-in for IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{3C557BC2-9FC4-4293-9E36-F6F5079E3E0C}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.0.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='webdav_7.0.inf'
2015-11-09 11:24:46, Info MIG Name='Microsoft WebDAV Extension For IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{C4C36B6D-0400-4160-B9A1-7F0E44F626ED}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.5_en-us_noloc.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='webdav_7.5_en-us_noloc.inf'
2015-11-09 11:24:46, Info MIG Name='WebDAV 7.5 For IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{E59555E2-6572-4BA5-90A9-3D2327739979}'
2015-11-09 11:24:46, Info MIG Mig::CWRFFile::Load: Reading WRF file 'C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.5_loc.inf'.
2015-11-09 11:24:46, Info MIG WRF: File='webdav_7.5_loc.inf'
2015-11-09 11:24:46, Info MIG Name='WebDAV 7.5 For IIS 7.0', AddedToList='1'
2015-11-09 11:24:46, Info MIG NotifyUser='0', ReInstallURL='(NULL)'
2015-11-09 11:24:46, Info MIG ProductID[0]='{9BE45AF9-DA11-4577-A6B8-425D32D4285F}'
2015-11-09 11:24:46, Info [0x080466] MIG Creating list-based system object filter
2015-11-09 11:24:46, Info MIG Processing OSDB file: C:\$Windows.~BT\Sources\SFLISTWT.DAT
2015-11-09 11:24:46, Info [0x080469] MIG Opening file list from file: C:\$Windows.~BT\Sources\SFLISTWT.DAT
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\SFPAT.INF (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\SFPATWT.INF (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\$TEMP_UPGRADE_WRF_REMOVAL_DEFINITION.INF (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\adminpack_en-us.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\adminpack_en-us_noloc.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\adobe_flash.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\browserchoice_win7.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\browserchoice_win8.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\compattelemetry.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.0.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.5_en-us_noloc.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.5_loc.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\gwxmig.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\netfx45_upgradecleanup.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\powershell_en-us_noloc.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\powershell_loc.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.0.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.5_en-us_noloc.inf (section prefix: System)
2015-11-09 11:24:48, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.5_loc.inf (section prefix: System)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\SFPAT.INF (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\SFPATWT.INF (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\$TEMP_UPGRADE_WRF_REMOVAL_DEFINITION.INF (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\adminpack_en-us.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\adminpack_en-us_noloc.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\adobe_flash.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\browserchoice_win7.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\browserchoice_win8.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\compattelemetry.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.0.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.5_en-us_noloc.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\ftp_7.5_loc.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\gwxmig.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\netfx45_upgradecleanup.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\powershell_en-us_noloc.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\powershell_loc.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.0.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.5_en-us_noloc.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\Migration\WTR\webdav_7.5_loc.inf (section prefix: User)
2015-11-09 11:24:49, Info [0x080481] MIG Retrieving patterns from C:\$Windows.~BT\Sources\osfilter.inf (section prefix: System)
2015-11-09 11:24:49, Info MIG Successfully loaded drvfiles.dat with filter System
2015-11-09 11:24:49, Info [0x080486] MIG Initialized OS analysis service
2015-11-09 11:24:49, Info [0x080489] MIG Setting system object filter context (System)
2015-11-09 11:24:49, Info Startup exclusions - Adding excluded file pattern: C:\$WINDOWS.~BT\Sources\Rollback\Work\* [*]
2015-11-09 11:24:49, Info Leaving MigPlatformStartupOnline method
2015-11-09 11:24:49, Info Entering MigEngineStartup method
2015-11-09 11:24:49, Info [0x080172] MIG AgentManager: not loading agent CMockAgent in mockagent.dll due to configuration settings
2015-11-09 11:24:49, Info [0x080172] MIG AgentManager: not loading agent CCSIAgent in csiagent.dll due to configuration settings
2015-11-09 11:24:49, Info [0x080172] MIG AgentManager: not loading agent CUpgradeAgent in upgradeagent.dll due to configuration settings
2015-11-09 11:24:49, Info Leaving MigEngineStartup method
2015-11-09 11:24:49, Info Leaving MigStartupOnline method
2015-11-09 11:24:49, Info Entering MigGetRealPlatform method
2015-11-09 11:24:49, Info Leaving MigGetRealPlatform method
2015-11-09 11:24:49, Info SP SPGetOSInformation: Adding OS piece: Original path: C:\Users\DefaultAppPool, Current path: C:\Users\DefaultAppPool (do not allow relocation)
2015-11-09 11:24:49, Info SP SPGetOSInformation: Adding OS piece: Original path: C:\Users\Mama, Current path: C:\Users\Mama (do not allow relocation)
2015-11-09 11:24:49, Info SP SPGetOSInformation: Adding OS piece: Original path: C:\Users\Tomas, Current path: C:\Users\Tomas (do not allow relocation)
2015-11-09 11:24:49, Info Entering MigShutdown method
2015-11-09 11:24:49, Info [0x0803e6] MIG Removing mapping for HKLM\ELAM
2015-11-09 11:24:49, Info [0x0803e7] MIG Successfully unmapped HKLM\ELAM
2015-11-09 11:24:49, Info [0x0803e6] MIG Removing mapping for HKLM
2015-11-09 11:24:49, Info [0x0803e7] MIG Successfully unmapped HKLM
2015-11-09 11:24:49, Info [0x0803e6] MIG Removing mapping for HKU
2015-11-09 11:24:49, Info [0x0803e7] MIG Successfully unmapped HKU
2015-11-09 11:24:49, Info MIG AdjustPrivilege: Privilege SeCreateSymbolicLinkPrivilege will be Disabled
2015-11-09 11:24:49, Info MIG Privilege has been disabled
2015-11-09 11:24:49, Info MIG AdjustPrivilege: Privilege SeDebugPrivilege will be Disabled
2015-11-09 11:24:49, Info MIG Privilege has been disabled
2015-11-09 11:24:49, Info MIG AdjustPrivilege: Privilege SeTakeOwnershipPrivilege will be Disabled
2015-11-09 11:24:49, Info MIG Privilege has been disabled
2015-11-09 11:24:49, Info MIG AdjustPrivilege: Privilege SeRestorePrivilege will be Disabled
2015-11-09 11:24:49, Info MIG Privilege has been disabled
2015-11-09 11:24:49, Info MIG AdjustPrivilege: Privilege SeBackupPrivilege will be Disabled
2015-11-09 11:24:49, Info MIG Privilege has been disabled
2015-11-09 11:24:49, Info MIG AdjustPrivilege: Privilege SeSecurityPrivilege will be Disabled
2015-11-09 11:24:49, Info MIG Privilege has been disabled
2015-11-09 11:24:49, Info [0x080487] MIG Destroying OS analysis service
2015-11-09 11:24:49, Info [0x080488] MIG Destroyed OS analysis service
2015-11-09 11:24:49, Info Leaving MigShutdown method
2015-11-09 11:24:49, Info SP CUninstall::ValidateUninstall: Verifying profile for IIS APPPOOL\DefaultAppPool(S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415), path: C:\Users\DefaultAppPool, linked path: <NULL>
2015-11-09 11:24:49, Info SP CUninstall::ValidateUninstall: Profile for IIS APPPOOL\DefaultAppPool(S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415) not found in rollback info. Ignoring because of well-known SID.
2015-11-09 11:24:49, Info SP CUninstall::ValidateUninstall: Verifying profile for Mama(S-1-5-21-1110698291-3134169923-3196150024-1001), path: C:\Users\Mama, linked path: <NULL>
2015-11-09 11:24:49, Info SP CUninstall::ValidateUninstall: Verifying profile for Tomas(S-1-5-21-1110698291-3134169923-3196150024-1000), path: C:\Users\Tomas, linked path: <NULL>
2015-11-09 11:25:28, Info Entering RjvUninitializeEngine

2015-11-09 11:25:28, Warning RjvAsimovTraceHandle was null, skipping RjvStopAsimovTrace
2015-11-09 11:25:28, Info RjvStopAsimovTrace returning TRUE

2015-11-09 11:25:28, Info Entering RjvStopTrace

2015-11-09 11:25:28, Warning RjvTraceHandle was null, skipping RjvStopTrace
2015-11-09 11:25:28, Info RjvStopTrace returning TRUE

2015-11-09 11:25:28, Info RjvUninitializeEngine returning TRUE

Re: Asi zavírený počítač

Napsal: 11 lis 2015 17:26
od Rudy
Nevím, z čeho je tento log. Udělejte obnovu systému k datu, kdy korektně fungoval.

Re: Asi zavírený počítač

Napsal: 11 lis 2015 21:21
od 7777
Obnovenie systému nefunguje. Skúšal som bod obnovenia ale ten nefungoval. Všetko sa pokazilo po tom čo som sa vrátil na pôvodný systém win7 lebo microsoft mi urobil uprade na win10.

Re: Asi zavírený počítač

Napsal: 11 lis 2015 21:46
od Rudy
Sám MS vám upgrade neprovedl, pouze nabídl. Upgrade jste provedl sám. V tom případě budete muset složky přejmenovat ručně.