Stránka 1 z 1

Preventivní log

Napsal: 22 lis 2015 12:57
od over1ord
Dobrý den, prosím o kontrolu logu:
=======================
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jan at 2015-11-22 12:54:24
Microsoft Windows 10 Pro
System drive C: has 171 GB (70%) free of 243 GB
Total RAM: 8133 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:54:30, on 22.11.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\avpui.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Users\Jan\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Users\Jan\AppData\Local\Microsoft\BingSvc\BingSvc.exe
C:\Users\Jan\AppData\Local\Akamai\netsession_win.exe
C:\Users\Jan\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\TESORO Gaming\DURANDAL ULTIMATE Gaming Keyboard\HID.exe
C:\Users\Jan\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe
C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files\trend micro\Jan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {C66D064F-82FE-4E1A-B06A-B2490BA48B18} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\IEExt\ie_plugin.dll
O3 - Toolbar: Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [ione] C:\Program Files (x86)\TESORO Gaming\DURANDAL ULTIMATE Gaming Keyboard\HID.exe
O4 - HKLM\..\Run: [ADSKAppManager] "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Sound Blaster Z-Series Control Panel] "C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe" /r
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_1F14D2380DB1DE09582B9D790BD95BA5] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Jan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [BingSvc] C:\Users\Jan\AppData\Local\Microsoft\BingSvc\BingSvc.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Jan\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://files.creative.com/Web/softwareu ... PIDPDE.cab
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
O23 - Service: Služba Kaspersky Anti-Virus 16.0.0 (AVP16.0.0) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\avp.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @oem53.inf,%Creative.CTHdaSvcDesc%;Sound Blaster Audio Service (CtHdaSvc) - Creative Technology Ltd - C:\WINDOWS\sysWow64\CtHdaSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: mental ray Satellite for Autodesk 3ds Max 2016 64-bit (mi-raysat_3dsmax2016_64) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64server.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: vssbrigde64 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\x64\vssbridge64.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11490 bytes

======Listing Processes======







C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6c901542-af43-411c-841e-e8603359551c -SystemEventPortName:HostProcess-f1484f43-77a2-4f1d-99b2-be74c4d1d955 -IoCancelEventPortName:HostProcess-933a245a-8aeb-44ca-8950-f1fc9ed25e36 -NonStateChangingEventPortName:HostProcess-50d86ebb-a94e-459e-929b-5d74c40105d7 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:06e2a25c-c7af-485b-aed0-8bcbf8e4da5d -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalService
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\avp.exe" -r
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\sysWow64\CtHdaSvc.exe
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\IProsetMonitor.exe
dashost.exe {af97a680-c222-4586-a4e7f48bccaa8da2}
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\WINDOWS\SysWOW64\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet

C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"D:\Program files D\Nová složka (2)\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\avpui.exe" -hidden
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
taskhostw.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="9600.0.1308929888\482061663" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,12,20,45,55 --gpu-vendor-id=0x10de --gpu-device-id=0x1004 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.5850 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="9600.2.451823376\623200876" --font-cache-shared-handle=2492 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="9600.3.117597869\187231866" --font-cache-shared-handle=2312 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="9600.4.127096351\1837370217" --font-cache-shared-handle=2732 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Enabled/AudioProcessing48kHzSupport/Default/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Enabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Enabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=4 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="9600.5.1657444616\218912925" --font-cache-shared-handle=2896 /prefetch:673131151
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cachedir="C:\Users\Jan\AppData\Local\Steam\htmlcache" -steampid=11028 -buildid=1447125378 -steamid="0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Users\Jan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Users\Jan\AppData\Local\Microsoft\BingSvc\BingSvc.exe"
"C:\Users\Jan\AppData\Local\Akamai\netsession_win.exe"
"C:/Users/Jan/AppData/Local/Akamai/netsession_win.exe" --client
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\TESORO Gaming\DURANDAL ULTIMATE Gaming Keyboard\HID.exe"
"C:\Users\Jan\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe" -showminimized -checkautorun -peruser
"C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe" /r
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 3e7c12ca-a572-428f-a6b9-6417e495bc24
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=4 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="7852.0.785617464\15679718" --font-cache-shared-handle=1476 /prefetch:673131151
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup

"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe188_ Global\UsGthrCtrlFltPipeMssGthrPipe188 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 620 624 632 8192 628
"D:\Stahování\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12 2134656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C66D064F-82FE-4E1A-B06A-B2490BA48B18}]
Kaspersky Protection plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\x64\IEExt\ie_plugin.dll [2015-10-21 800216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12 1725056]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C66D064F-82FE-4E1A-B06A-B2490BA48B18}]
Kaspersky Protection plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\IEExt\ie_plugin.dll [2015-10-21 584664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{3507FA00-ADA2-4A02-99B9-51AD26CA9120} - Kaspersky Protection toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\x64\IEExt\ie_plugin.dll [2015-10-21 800216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{3507FA00-ADA2-4A02-99B9-51AD26CA9120} - Kaspersky Protection toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\IEExt\ie_plugin.dll [2015-10-21 584664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-06-24 8492800]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-09-28 2730616]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2015-09-28 1793480]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_1F14D2380DB1DE09582B9D790BD95BA5"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-11-07 811848]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2015-11-10 3011152]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-07-17 8418584]
"OneDrive"=C:\Users\Jan\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-11-03 548552]
"BingSvc"=C:\Users\Jan\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-11-11 144008]
"Akamai NetSession Interface"=C:\Users\Jan\AppData\Local\Akamai\netsession_win.exe [2015-07-23 4691384]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-10-14 48138880]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ione"=C:\Program Files (x86)\TESORO Gaming\DURANDAL ULTIMATE Gaming Keyboard\HID.exe [2011-11-05 2019840]
"ADSKAppManager"=C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [2015-09-07 523144]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"Sound Blaster Z-Series Control Panel"=C:\Program Files (x86)\Creative\Sound Blaster Z-Series\Sound Blaster Z-Series Control Panel\SBZ.exe [2014-11-24 877056]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"VIDC.FICV"=ficvdec_x64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-11-22 12:54:24 ----D---- C:\rsit
2015-11-22 12:54:24 ----D---- C:\Program Files\trend micro
2015-11-22 12:03:05 ----HD---- C:\OneDriveTemp
2015-11-19 06:54:07 ----HD---- C:\$WINDOWS.~BT
2015-11-11 17:17:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2015-11-11 17:17:37 ----A---- C:\WINDOWS\SYSWOW64\esent.dll
2015-11-11 17:17:37 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2015-11-11 17:17:37 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-11 17:17:37 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2015-11-11 17:17:37 ----A---- C:\WINDOWS\system32\edgehtml.dll
2015-11-11 17:17:37 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-11 17:17:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2015-11-11 17:17:36 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-11-11 17:17:36 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-11-11 17:17:36 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-11-11 17:17:36 ----A---- C:\WINDOWS\system32\esent.dll
2015-11-11 17:17:36 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2015-11-11 17:17:36 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-11 17:17:35 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-11-11 17:17:35 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\SYSWOW64\dlnashext.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\dlnashext.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-11-11 17:17:34 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\winlogon.exe
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\win32kfull.sys
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\win32kbase.sys
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\usermgr.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\RDXService.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\internetmail.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\dssvc.dll
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2015-11-11 17:17:33 ----A---- C:\WINDOWS\system32\browserbroker.dll
2015-11-11 17:17:32 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-11-11 17:17:32 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2015-11-11 17:17:32 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-11-11 17:17:32 ----A---- C:\WINDOWS\system32\jscript.dll
2015-11-11 17:17:32 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2015-11-01 19:52:20 ----D---- C:\Users\Jan\AppData\Roaming\11bitstudios
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_7.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_5.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_7.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2015-11-01 16:57:19 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_5.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_42.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2015-11-01 16:57:18 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_3.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_41.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_41.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2015-11-01 16:57:17 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2015-11-01 16:57:16 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2015-11-01 16:57:15 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2015-11-01 16:57:14 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2015-11-01 16:57:13 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2015-11-01 16:57:12 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_32.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2015-11-01 16:57:11 ----A---- C:\WINDOWS\system32\d3dx10.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-11-01 16:57:10 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2015-11-01 16:57:09 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-11-01 16:57:09 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-11-01 16:57:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-11-01 16:57:09 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-11-01 16:57:09 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-11-01 16:57:09 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-11-01 16:57:08 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-11-01 16:57:07 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-11-01 16:57:07 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-10-31 07:19:13 ----D---- C:\WINDOWS\system32\appmgmt
2015-10-30 09:52:01 ----D---- C:\Users\Jan\AppData\Roaming\MAXON
2015-10-29 11:52:44 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_6.dll
2015-10-29 11:52:44 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_4.dll
2015-10-29 11:52:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_6.dll
2015-10-29 11:52:44 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_7.dll
2015-10-29 11:52:43 ----D---- C:\Program Files (x86)\Microsoft XNA
2015-10-29 11:52:43 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2015-10-29 11:52:43 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2015-10-29 11:52:43 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2015-10-28 20:40:30 ----D---- C:\Program Files (x86)\Unigine
2015-10-25 12:17:59 ----D---- C:\Users\Jan\AppData\Roaming\GeoGebra 5.0
2015-10-25 12:17:27 ----D---- C:\Program Files (x86)\GeoGebra 5.0
2015-10-25 11:20:04 ----D---- C:\Program Files\Microsoft Office 15

======List of files/folders modified in the last 1 month======

2015-11-22 12:54:28 ----D---- C:\WINDOWS\Prefetch
2015-11-22 12:54:24 ----RD---- C:\Program Files
2015-11-22 12:43:40 ----D---- C:\Users\Jan\AppData\Roaming\Skype
2015-11-22 12:33:58 ----D---- C:\WINDOWS\Temp
2015-11-22 12:18:12 ----D---- C:\ProgramData\Kaspersky Lab
2015-11-22 12:05:16 ----D---- C:\WINDOWS\system32\sru
2015-11-22 12:04:47 ----D---- C:\Program Files (x86)\Steam
2015-11-22 12:02:28 ----D---- C:\WINDOWS\System32
2015-11-22 09:28:25 ----D---- C:\WINDOWS\AppReadiness
2015-11-22 09:21:16 ----SHD---- C:\WINDOWS\Installer
2015-11-21 18:06:03 ----SHD---- C:\System Volume Information
2015-11-21 18:04:40 ----D---- C:\WINDOWS\Microsoft.NET
2015-11-21 14:21:29 ----D---- C:\WINDOWS\system32\config
2015-11-21 07:55:38 ----HD---- C:\Program Files\WindowsApps
2015-11-20 23:33:51 ----D---- C:\WINDOWS\system32\NDF
2015-11-19 06:56:25 ----DC---- C:\WINDOWS\Panther
2015-11-19 06:54:07 ----D---- C:\WINDOWS\Logs
2015-11-18 18:19:45 ----D---- C:\Program Files (x86)\Battle.net
2015-11-18 15:12:09 ----D---- C:\ProgramData\Skype
2015-11-17 21:00:34 ----D---- C:\WINDOWS\INF
2015-11-17 21:00:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-17 20:54:07 ----D---- C:\ProgramData\NVIDIA
2015-11-14 18:24:38 ----D---- C:\WINDOWS\rescache
2015-11-14 16:35:32 ----RSD---- C:\WINDOWS\assembly
2015-11-14 13:42:46 ----D---- C:\WINDOWS\WinSxS
2015-11-14 08:32:32 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-11-14 08:32:32 ----D---- C:\WINDOWS\SysWOW64
2015-11-14 08:32:32 ----D---- C:\WINDOWS\system32\drivers
2015-11-14 08:32:32 ----D---- C:\WINDOWS\system32\cs-CZ
2015-11-14 08:32:32 ----D---- C:\WINDOWS\system32\appraiser
2015-11-14 08:32:32 ----D---- C:\WINDOWS\AppPatch
2015-11-14 08:32:31 ----D---- C:\WINDOWS\system32\DriverStore
2015-11-13 23:37:00 ----D---- C:\ProgramData\Origin
2015-11-13 17:57:09 ----D---- C:\WINDOWS\system32\MRT
2015-11-13 17:55:14 ----A---- C:\WINDOWS\system32\MRT.exe
2015-11-13 17:47:33 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrB.exe
2015-11-12 15:54:52 ----D---- C:\Program Files (x86)\Origin
2015-11-11 19:07:05 ----D---- C:\WINDOWS\CbsTemp
2015-11-11 17:14:39 ----D---- C:\WINDOWS\system32\catroot2
2015-11-05 15:46:42 ----A---- C:\WINDOWS\GPU-Z.INI
2015-11-05 14:44:21 ----D---- C:\WINDOWS\system32\WDI
2015-11-03 19:20:11 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-10-31 08:05:19 ----D---- C:\Users\Jan\AppData\Roaming\TS3Client
2015-10-31 07:19:41 ----RD---- C:\Program Files (x86)
2015-10-31 07:18:42 ----D---- C:\Program Files (x86)\Mirillis
2015-10-31 00:21:12 ----D---- C:\WINDOWS\system32\Tasks
2015-10-25 12:18:31 ----D---- C:\Users\Jan\AppData\Roaming\NVIDIA
2015-10-25 11:22:04 ----RSD---- C:\WINDOWS\Fonts
2015-10-25 11:20:04 ----SD---- C:\ProgramData\Microsoft
2015-10-25 03:30:14 ----D---- C:\WINDOWS\system32\CatRoot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 asstor64;asstor64; C:\WINDOWS\System32\drivers\asstor64.sys [2014-03-14 84816]
R0 cm_km;Kaspersky Lab ZAO Cryptographic Module x64 (Weak); C:\WINDOWS\system32\DRIVERS\cm_km.sys [2015-07-05 389816]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2014-05-28 672104]
R0 kl1;kl1; C:\WINDOWS\system32\DRIVERS\kl1.sys [2015-06-22 478392]
R0 klbackupdisk;Kaspersky Lab klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [2015-06-06 53432]
R1 AsIO;AsIO; C:\WINDOWS\SysWow64\drivers\AsIO.sys [2014-01-28 15232]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-07-10 83968]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-07-10 8192]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [2015-10-10 27552]
R1 klbackupflt;Kaspersky Lab klbackupflt; C:\WINDOWS\system32\DRIVERS\klbackupflt.sys [2015-06-27 70512]
R1 klhk;Kaspersky Lab service driver; C:\WINDOWS\system32\DRIVERS\klhk.sys [2015-10-21 227512]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2015-10-21 925064]
R1 KLIM6;@oem38.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter; C:\WINDOWS\system32\DRIVERS\klim6.sys [2015-06-11 39608]
R1 klpd;Kaspersky Lab format recognizer driver; C:\WINDOWS\system32\DRIVERS\klpd.sys [2015-09-26 41352]
R1 klwfp;klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [2015-10-21 87944]
R1 Klwtp;Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [2015-06-16 102584]
R1 kneps;kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [2015-06-23 187056]
R2 kldisk;kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [2015-06-06 68280]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-07-10 48128]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-07-10 61952]
R3 cthda;@oem53.inf,%Creative.CTHdaDesc%;Sound Blaster Audio Driver; C:\WINDOWS\system32\drivers\cthda.sys [2014-11-17 1065728]
R3 cthdb;@oem53.inf,%Creative.CTHDBDesc%;Sound Blaster Audio Controller Driver; C:\WINDOWS\system32\DRIVERS\cthdb.sys [2014-11-17 34048]
R3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\System32\drivers\e1i63x64.sys [2015-07-10 482328]
R3 I1KBFLTR;@oem35.inf,%DisplayName%;T1 Gaming Keyboard; C:\WINDOWS\system32\drivers\I1KBFLTR.sys [2011-10-19 29440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-06-24 4504320]
R3 klflt;Kaspersky Lab Kernel DLL; C:\WINDOWS\system32\DRIVERS\klflt.sys [2015-10-21 181640]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [2015-06-06 41656]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2015-06-07 41656]
R3 MEIx64;@oem18.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 NVHDA;@oem21.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-08-07 204648]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2015-10-06 11210056]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-09-28 19576]
R3 nvvad_WaveExtensible;@oem37.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2015-08-11 50472]
R3 RTL8168;@oem15.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\System32\drivers\Rt630x64.sys [2015-07-30 848088]
R3 SensorsSimulatorDriver;@oem50.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2015-07-10 214016]
S0 klelam;klelam; C:\WINDOWS\system32\DRIVERS\klelam.sys [2015-06-24 30328]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-07-10 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-07-10 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-07-10 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-07-10 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-07-10 40288]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-09-17 36352]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-07-10 116736]
S3 fcvsc;fcvsc; C:\WINDOWS\System32\drivers\fcvsc.sys [2015-07-10 31232]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-07-10 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-07-10 50016]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-07-10 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-07-10 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-07-10 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-07-10 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-08-09 934752]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-07-10 61952]
S3 UcmUcsi;@ucmucsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-08-09 46080]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-07-10 44032]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-07-10 245088]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-07-10 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-07-10 127840]
S4 klkbdflt2;Kaspersky Lab KlKbdFlt2; C:\WINDOWS\system32\DRIVERS\klkbdflt2.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2015-09-07 1136520]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [2014-01-28 936728]
R2 AVP16.0.0;Služba Kaspersky Anti-Virus 16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.0\avp.exe [2015-08-21 194000]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-10-12 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-10-12 1773696]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-10-07 2780856]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2012-10-08 423424]
R2 CtHdaSvc;@oem53.inf,%Creative.CTHdaSvcDesc%;Sound Blaster Audio Service; C:\WINDOWS\sysWow64\CtHdaSvc.exe [2014-11-17 114176]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-09-28 1155192]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [2014-03-11 260360]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-09-28 1872504]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2015-09-28 5568632]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2015-10-03 938800]
R2 OneSyncSvc_Session5;Hostitel synchronizace_Session5; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2015-08-13 76152]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-10-03 417400]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
R3 PimIndexMaintenanceSvc_Session5;Data kontaktů_Session5; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-11-10 836176]
R3 UnistoreSvc_Session5;Úložiště uživatelských dat_Session5; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S2 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-31 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-07-10 50352]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-07-10 27136]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2015-08-13 1369856]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-06-17 43696]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [2015-08-17 342240]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-31 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 mi-raysat_3dsmax2016_64;mental ray Satellite for Autodesk 3ds Max 2016 64-bit; C:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64server.exe [2011-09-15 86016]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\lsass.exe [2015-07-10 56344]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2015-11-12 2099720]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-08-09 1031680]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-07-10 39856]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-07-10 39856]

-----------------EOF-----------------

=============================
Děkuji

Re: Preventivní log

Napsal: 22 lis 2015 16:33
od Roli
Zdravím, jen trochu uklidíme.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a ulož na plochu AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.