Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
fingot
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 22 pro 2015 21:53

Prosím o kontrolu.

#1 Příspěvek od fingot »

Dobrý den, prosím o kontrolu logu, pomalé načítání stránek.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Honzan at 2015-12-22 21:46:51
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 147 GB (42%) free of 354 GB
Total RAM: 16328 MB (84% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:46:59, on 22.12.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal

Running processes:
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
C:\Program Files (x86)\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Razer\Razer Game Booster\main.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files (x86)\Nginx\nginx.exe
C:\Program Files (x86)\Nginx\nginx.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
F:\SteamLibrary\Steam\Steam.exe
F:\SteamLibrary\Steam\bin\steamwebhelper.exe
F:\SteamLibrary\Steam\bin\steamwebhelper.exe
f:\Program Files (x86)\Origin\Origin.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\taskmgr.exe
C:\Program Files\trend micro\Honzan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~3\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [RazerGameBooster] C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Nginx] C:\Program Files (x86)\Nginx\shortcut.lnk
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Boxoft Tools] "C:\ProgramData\Boxtools\Boxofttoolbox.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [{80655FC2-A38F-4B8C-8775-9A3C68A6C305}] "C:\MSILU\DL_FILE\Killer_Network_Drivers_1.1.42.1045\Setup.exe" /silent (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [{80655FC2-A38F-4B8C-8775-9A3C68A6C305}] "C:\MSILU\DL_FILE\Killer_Network_Drivers_1.1.42.1045\Setup.exe" /silent (User 'Default user')
O4 - Global Startup: Killer Network Manager.lnk = ?
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MIF5BA~1\Office15\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BitRaider Mini-Support Service Stub Loader (BRSptStub) - BitRaider, LLC - C:\ProgramData\BitRaider\BRSptStub.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - F:\SteamLibrary\Steam\steamapps\common\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_LiveUpdate_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - F:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: RzKLService - Razer Inc. - C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11648 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"taskhost.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\AMD\CNext\CNext\cnext.exe" atlogon
"C:\Program Files (x86)\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\RocketDock\RocketDock.exe"
"C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe"
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
"C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe"
"C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Razer\Razer Game Booster\main.exe" StartWithWindows
WLIDSvcM.exe 2260
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Nginx\nginx.exe"
"C:\Program Files (x86)\Nginx\nginx.exe"
\??\C:\Windows\system32\conhost.exe "-1205605937851670747541907327-1418025253-1820964619260840503-9449519631849759874
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --channel="3632.0.1878368673\672266539" /prefetch:3
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=gpu-process --channel="3632.1.666508854\668717932" --no-sandbox --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --supports-dual-gpus=false --reduce-gpu-sandbox --disable-image-transport-surface --gpu-vendor-id=0x1002 --gpu-device-id=0x6810 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.300.1025.0 --ignored=" --type=renderer " --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable /prefetch:12
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"F:\SteamLibrary\Steam\Steam.exe"
"F:\SteamLibrary\Steam\bin\steamwebhelper.exe" -cachedir="C:\Users\Honzan\AppData\Local\Steam\htmlcache" -steampid=9320 -buildid=1450127196 -steamid="0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"F:\SteamLibrary\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="F:\SteamLibrary\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="4544.0.1674960178\170288117" --font-cache-shared-handle=696 /prefetch:673131151
explorer.exe

"f:\Program Files (x86)\Origin\Origin.exe" "origin://LaunchGame/71073,71338,71183,71400,71404,71402,71406,1005692?Title=Mass%u0020Effect%u2122%u00203&ProductId=DR:229644400&CommandParams=" /Installed:9.11.2.10120
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\System32\taskmgr.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
"C:\Users\Honzan\Downloads\RSITx64.exe"
"C:\Users\Honzan\AppData\Local\JDownloader 2.0\JDownloader2.exe" -updateOnExit

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@photodex.com/PhotodexPresenter]
"Description"=Photodex Presenter Plugin
"Path"=C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MIF5BA~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class

C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\extensions\
{2d3fbcf7-be69-4433-8858-c621a8d0e58d}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MIF5BA~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-22 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~3\Office15\GROOVEEX.DLL [2015-10-13 1731800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-22 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2015-04-30 1337000]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
"ISCT Tray"=C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [2014-08-25 5860656]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-07-15 7637208]
"StartCN"=C:\Program Files\AMD\CNext\CNext\cnext.exe [2015-11-18 4859592]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21 1174016]
"RocketDock"=C:\Program Files (x86)\RocketDock\RocketDock.exe [2007-09-02 495616]
"AdobeBridge"= []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-12-12 7394584]
"Boxoft Tools"=C:\ProgramData\Boxtools\Boxofttoolbox.exe -autorun []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2015-03-23 296216]
"RazerGameBooster"=C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe [2014-02-25 61152]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2014-07-22 2694040]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2014-10-02 421888]
"Nginx"=C:\Program Files (x86)\Nginx\shortcut.lnk [2015-07-26 1765]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2015-07-30 3458728]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-11-09 596528]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{4692B750-DE88-4DCF-9163-745AF5604B24}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-12-19 03:01:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-12-16 10:54:29 ----D---- C:\Users\Honzan\AppData\Roaming\calibre
2015-12-16 10:51:53 ----D---- C:\ProgramData\Boxtools
2015-12-16 10:50:54 ----D---- C:\Program Files (x86)\FlipPDF to ePUB (freeware)
2015-12-03 12:15:51 ----D---- C:\rsit
2015-12-03 12:15:51 ----D---- C:\Program Files\trend micro
2015-12-03 10:03:45 ----D---- C:\ProgramData\Malwarebytes
2015-11-29 23:16:32 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 23:16:32 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-11-29 22:36:45 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-11-29 22:36:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\iernonce.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\ie4uinit.exe
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\urlmon.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\occache.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-29 22:36:43 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\iedkcs32.dll
2015-11-29 22:36:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-11-29 22:36:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\msfeeds.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\iesetup.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\iertutil.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\ieapfltr.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\dxtrans.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-11-29 22:36:41 ----A---- C:\Windows\system32\vbscript.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\jsproxy.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\ieui.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\dxtmsft.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\webcheck.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\mshtmled.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript9diag.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript9.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\ieUnatt.exe
2015-11-29 22:36:40 ----A---- C:\Windows\system32\ieframe.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\wininet.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\msrating.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\mshtml.dll
2015-11-29 22:30:50 ----A---- C:\Windows\system32\blackbox.dll
2015-11-29 22:30:49 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-11-29 22:30:49 ----A---- C:\Windows\system32\drmv2clt.dll
2015-11-29 22:30:48 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-11-29 22:30:46 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-11-29 22:30:46 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\mf.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-11-29 22:30:45 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-11-29 22:30:45 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-11-29 22:30:45 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-11-29 22:30:45 ----A---- C:\Windows\system32\crypt32.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\wintrust.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\quartz.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\evr.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\cryptui.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\cryptsvc.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\audiosrv.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\qdvd.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\mfplat.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\AudioEng.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\pcasvc.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\msscp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\msnetobj.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\EncDump.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\cryptsp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\cryptnet.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\AudioSes.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\rrinstaller.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\pcawrk.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\pcadm.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\mfps.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\mfpmp.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\audiodg.exe
2015-11-29 22:30:40 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-11-29 22:30:40 ----A---- C:\Windows\system32\pcalua.exe
2015-11-29 22:30:40 ----A---- C:\Windows\system32\pcaevts.dll
2015-11-29 22:30:40 ----A---- C:\Windows\system32\mferror.dll
2015-11-29 22:30:30 ----A---- C:\Windows\system32\basesrv.dll
2015-11-29 22:30:22 ----A---- C:\Windows\system32\winresume.exe
2015-11-29 22:30:22 ----A---- C:\Windows\system32\winload.exe
2015-11-29 22:30:22 ----A---- C:\Windows\system32\ci.dll
2015-11-29 22:30:22 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-11-29 22:30:21 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\drivers\appid.sys
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidsvc.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidapi.dll
2015-11-29 22:30:17 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2015-11-29 22:30:17 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-11-29 22:30:17 ----A---- C:\Windows\system32\wksprt.exe
2015-11-29 22:30:17 ----A---- C:\Windows\system32\rdvidcrl.dll
2015-11-29 22:30:17 ----A---- C:\Windows\system32\mstscax.dll
2015-11-29 22:30:16 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-11-29 22:30:16 ----A---- C:\Windows\system32\tsgqec.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\rpcrt4.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-11-29 22:30:13 ----A---- C:\Windows\system32\ntdll.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\lsasrv.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\schannel.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\ncrypt.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\msv1_0.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\KernelBase.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\kernel32.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\kerberos.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-11-29 22:30:12 ----A---- C:\Windows\system32\drivers\cng.sys
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wow64win.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wow64.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\winsrv.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wdigest.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\TSpkg.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\sspicli.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\srcore.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\smss.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\rstrui.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\lsass.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\csrsrv.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\cryptbase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\conhost.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\bcryptprimitives.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\auditpol.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\adtschema.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\wow64cpu.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\sspisrv.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\srclient.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\secur32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\ntvdm64.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\msaudite.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\credssp.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\apisetschema.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-29 22:30:09 ----A---- C:\Windows\SYSWOW64\user.exe
2015-11-29 22:30:09 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-11-29 22:30:09 ----A---- C:\Windows\system32\msobjs.dll
2015-11-29 22:30:02 ----A---- C:\Windows\system32\sysmain.dll
2015-11-29 22:30:02 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-11-29 22:30:01 ----A---- C:\Windows\system32\msmmsp.dll
2015-11-29 22:29:56 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-11-29 22:29:56 ----A---- C:\Windows\system32\FntCache.dll
2015-11-29 22:29:56 ----A---- C:\Windows\system32\DWrite.dll
2015-11-29 22:29:54 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-11-29 22:29:54 ----A---- C:\Windows\system32\d3d10warp.dll
2015-11-29 22:29:52 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2015-11-29 22:29:52 ----A---- C:\Windows\system32\pku2u.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-11-29 22:29:49 ----A---- C:\Windows\system32\wuauclt.exe
2015-11-29 22:29:49 ----A---- C:\Windows\system32\wuapp.exe
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuwebv.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wups2.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wups.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wudriver.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wucltux.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuaueng.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuapi.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-11-29 22:29:36 ----A---- C:\Windows\SYSWOW64\winsta.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\winsta.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\winlogon.exe
2015-11-29 22:29:36 ----A---- C:\Windows\system32\rdpcorekmts.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2015-11-29 22:29:36 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2015-11-29 22:29:32 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-11-29 22:29:32 ----A---- C:\Windows\system32\poqexec.exe
2015-11-29 22:29:21 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-11-29 22:29:21 ----A---- C:\Windows\system32\tzres.dll
2015-11-29 22:29:17 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-11-29 22:29:17 ----A---- C:\Windows\system32\certcli.dll
2015-11-29 22:29:11 ----A---- C:\Windows\system32\termsrv.dll
2015-11-29 22:29:08 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-11-29 22:29:08 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2015-11-29 22:29:08 ----A---- C:\Windows\system32\nlasvc.dll
2015-11-29 22:29:06 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-11-29 22:29:06 ----A---- C:\Windows\system32\wmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-11-29 22:29:05 ----A---- C:\Windows\system32\wmploc.DLL
2015-11-29 22:29:05 ----A---- C:\Windows\system32\spwmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\system32\dxmasf.dll
2015-11-29 22:28:58 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-11-29 22:28:58 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-11-29 22:28:58 ----A---- C:\Windows\system32\msxml6.dll
2015-11-29 22:28:58 ----A---- C:\Windows\system32\msxml3.dll
2015-11-29 22:28:57 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\system32\msxml6r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\system32\msxml3r.dll
2015-11-29 22:28:55 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-11-29 22:28:55 ----A---- C:\Windows\system32\msi.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msimsg.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msihnd.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msiexec.exe
2015-11-29 22:28:54 ----A---- C:\Windows\system32\consent.exe
2015-11-29 22:28:54 ----A---- C:\Windows\system32\authui.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\appinfo.dll
2015-11-29 22:28:52 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-11-29 22:28:52 ----A---- C:\Windows\system32\shell32.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2015-11-29 22:28:51 ----A---- C:\Windows\system32\mscorier.dll
2015-11-29 22:28:51 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-11-29 22:28:50 ----A---- C:\Windows\SYSWOW64\mscories.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\profsvc.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\mscories.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\dfshim.dll
2015-11-29 22:28:49 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-11-29 22:28:47 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-11-29 22:28:46 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2015-11-29 22:28:46 ----A---- C:\Windows\system32\IMJP10K.DLL
2015-11-29 22:28:46 ----A---- C:\Windows\system32\drivers\http.sys
2015-11-29 22:28:45 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-11-29 22:28:45 ----A---- C:\Windows\system32\gdi32.dll
2015-11-29 22:28:44 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-11-29 22:28:44 ----A---- C:\Windows\system32\notepad.exe
2015-11-29 22:28:44 ----A---- C:\Windows\notepad.exe
2015-11-29 22:28:42 ----A---- C:\Windows\system32\rdpudd.dll
2015-11-29 22:28:42 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-11-29 22:28:42 ----A---- C:\Windows\system32\rdpcorets.dll
2015-11-29 22:28:39 ----A---- C:\Windows\system32\win32k.sys
2015-11-29 22:28:37 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\system32\WebClnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\system32\davclnt.dll
2015-11-29 22:28:36 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-11-29 22:28:36 ----A---- C:\Windows\system32\drivers\tdx.sys
2015-11-29 22:28:36 ----A---- C:\Windows\system32\drivers\afd.sys
2015-11-29 22:28:36 ----A---- C:\Windows\system32\comctl32.dll
2015-11-29 22:28:34 ----A---- C:\Windows\system32\ubpm.dll
2015-11-29 22:28:33 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-11-29 22:28:32 ----A---- C:\Windows\system32\schedsvc.dll
2015-11-29 22:28:32 ----A---- C:\Windows\system32\ole32.dll
2015-11-29 22:28:31 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-11-29 22:28:30 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-11-29 22:28:30 ----A---- C:\Windows\system32\services.exe
2015-11-29 22:28:30 ----A---- C:\Windows\system32\cewmdm.dll
2015-11-29 22:26:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-11-29 22:26:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-11-29 22:26:26 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-11-29 22:26:25 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-11-29 22:26:25 ----A---- C:\Windows\system32\scesrv.dll
2015-11-29 22:26:23 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-11-29 22:26:23 ----A---- C:\Windows\system32\msctf.dll
2015-11-29 22:26:22 ----A---- C:\Windows\SYSWOW64\rastls.dll
2015-11-29 22:26:22 ----A---- C:\Windows\system32\rastls.dll
2015-11-29 22:26:07 ----A---- C:\Windows\SYSWOW64\packager.dll
2015-11-29 22:26:07 ----A---- C:\Windows\system32\packager.dll
2015-11-29 22:24:51 ----A---- C:\Windows\system32\InkEd.dll
2015-11-29 22:24:49 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-11-29 22:24:49 ----A---- C:\Windows\system32\jnwmon.dll
2015-11-29 22:18:09 ----A---- C:\Windows\system32\clfsw32.dll
2015-11-29 22:18:09 ----A---- C:\Windows\system32\clfs.sys
2015-11-29 22:18:08 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-11-29 22:18:08 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-11-29 22:18:08 ----A---- C:\Windows\system32\oleaut32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\lpk.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\fontsub.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\dciman32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\atmlib.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\atmfd.dll
2015-11-29 22:14:03 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-11-29 22:14:03 ----A---- C:\Windows\system32\WMPhoto.dll
2015-11-27 13:07:56 ----D---- C:\Program Files (x86)\Mozilla Thunderbird

======List of files/folders modified in the last 1 month======

2015-12-22 21:47:00 ----D---- C:\Windows\Prefetch
2015-12-22 21:45:10 ----D---- C:\Windows\Temp
2015-12-22 21:31:38 ----D---- C:\Users\Honzan\AppData\Roaming\TS3Client
2015-12-22 20:59:06 ----D---- C:\Windows
2015-12-22 15:58:16 ----SHD---- C:\System Volume Information
2015-12-22 01:26:31 ----D---- C:\Windows\system32\config
2015-12-22 00:01:09 ----D---- C:\Windows\inf
2015-12-21 07:31:51 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-21 07:31:47 ----RD---- C:\Program Files (x86)
2015-12-18 10:44:10 ----RSD---- C:\Windows\Fonts
2015-12-17 18:08:04 ----D---- C:\ProgramData\Origin
2015-12-17 18:03:08 ----D---- C:\ProgramData\EA Logs
2015-12-16 22:54:20 ----D---- C:\Windows\system32\NDF
2015-12-16 10:51:53 ----HD---- C:\ProgramData
2015-12-15 19:06:05 ----D---- C:\Windows\System32
2015-12-15 19:06:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-12-08 21:48:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-12-08 21:48:18 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2015-12-08 11:07:48 ----D---- C:\Windows\SysWOW64
2015-12-08 11:07:19 ----D---- C:\Windows\system32\catroot
2015-12-08 11:07:10 ----D---- C:\Windows\system32\Tasks
2015-12-08 10:50:55 ----SHD---- C:\Windows\Installer
2015-12-08 10:50:23 ----D---- C:\Program Files\AMD
2015-12-08 10:50:20 ----D---- C:\Program Files (x86)\AMD
2015-12-08 10:50:19 ----D---- C:\Windows\Microsoft.NET
2015-12-08 10:49:45 ----D---- C:\Windows\system32\drivers
2015-12-08 10:49:44 ----D---- C:\Windows\system32\DriverStore
2015-12-08 10:49:38 ----D---- C:\Windows\system32\catroot2
2015-12-08 10:47:23 ----D---- C:\AMD
2015-12-03 16:35:10 ----D---- C:\Users\Honzan\AppData\Roaming\Origin
2015-12-03 16:25:14 ----D---- C:\ProgramData\Package Cache
2015-12-03 12:15:51 ----RD---- C:\Program Files
2015-12-03 11:56:13 ----D---- C:\Windows\PolicyDefinitions
2015-12-03 11:37:47 ----D---- C:\Windows\Logs
2015-12-03 11:37:47 ----D---- C:\Windows\debug
2015-12-03 11:37:46 ----D---- C:\Windows\Minidump
2015-12-03 10:50:08 ----D---- C:\Windows\PCHEALTH
2015-12-02 12:09:51 ----D---- C:\Windows\rescache
2015-11-30 08:37:07 ----RSD---- C:\Windows\assembly
2015-11-30 08:17:28 ----D---- C:\Windows\winsxs
2015-11-30 08:13:03 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Windows\system32\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Program Files\Windows Media Player
2015-11-30 08:13:03 ----D---- C:\Program Files (x86)\Windows Media Player
2015-11-30 08:13:02 ----D---- C:\Windows\SYSWOW64\Dism
2015-11-30 08:13:01 ----D---- C:\Windows\system32\Dism
2015-11-30 08:13:00 ----D---- C:\Windows\ehome
2015-11-30 08:12:59 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-30 08:12:59 ----D---- C:\Windows\system32\en-US
2015-11-30 08:12:59 ----D---- C:\Program Files\Internet Explorer
2015-11-30 08:12:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-11-30 08:12:56 ----D---- C:\Windows\system32\CodeIntegrity
2015-11-30 08:12:56 ----D---- C:\Windows\system32\Boot
2015-11-30 08:12:56 ----D---- C:\Windows\AppPatch
2015-11-30 08:12:55 ----D---- C:\Windows\system32\migration
2015-11-30 08:12:55 ----D---- C:\Program Files\Windows Journal
2015-11-29 23:24:54 ----D---- C:\Windows\system32\MRT
2015-11-29 23:20:30 ----D---- C:\ProgramData\Microsoft Help
2015-11-29 23:10:14 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-11-29 20:14:37 ----D---- C:\Program Files\Microsoft Silverlight
2015-11-29 20:14:36 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-11-29 19:46:35 ----D---- C:\Program Files\Microsoft Security Client
2015-11-29 19:46:35 ----D---- C:\Program Files (x86)\Microsoft Security Client

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2015-03-23 22800]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 280376]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 BfLwf;Qualcomm Atheros Bandwidth Control; C:\Windows\system32\DRIVERS\bflwfx64.sys [2014-04-10 82096]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 124568]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-11-18 23960064]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-11-18 671232]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-09-18 96256]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\Windows\system32\DRIVERS\ikbevent.sys [2014-05-27 22216]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\Windows\system32\DRIVERS\imsevent.sys [2014-05-27 22728]
R3 INETMON;INETMON; \??\C:\Windows\System32\Drivers\INETMON.sys [2014-05-27 25800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-15 4012632]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver; C:\Windows\system32\DRIVERS\ISCTD.sys [2014-02-03 44744]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2015-03-23 390416]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2015-03-23 800016]
R3 KbFilter_Kb_FlexDef3x;HID Keyboard(FlexDef3x) Driver Service; C:\Windows\system32\DRIVERS\KbFilter_FlexDef3x.sys [2012-10-16 22016]
R3 Ke2200;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\e22w7x64.sys [2014-03-27 129200]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-17 99288]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2009-07-14 60288]
S3 Avc;Zařízení AVC; C:\Windows\system32\DRIVERS\avc.sys [2009-07-14 48768]
S3 AVCSTRM;AVC Streaming Filter Driver; C:\Windows\system32\DRIVERS\avcstrm.sys [2009-07-14 17664]
S3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [2014-11-05 78088]
S3 cpuz137;cpuz137; \??\C:\Windows\TEMP\cpuz137\cpuz137_x64.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1yexpress;Ovladač gigabitových síťových připojení Intel(R); C:\Windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 MSICDSetup;MSICDSetup; \??\D:\CDriver64.sys []
S3 MSTAPE;Microsoft AV/C Tape Subunit Device; C:\Windows\system32\DRIVERS\mstape.sys [2009-07-14 56448]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 TrueSight;TrueSight; \??\C:\Windows\System32\drivers\TrueSight.sys [2015-01-26 35064]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-11-18 246272]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-05-16 2266296]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 ISCTAgent;Intel(R) Smart Connect Technology Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2014-08-25 209712]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-17 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-17 390616]
R2 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2015-07-30 1741992]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 23816]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2014-04-17 344576]
R2 RzKLService;RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [2014-02-25 105448]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe [2014-09-21 186760]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 366544]
R3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-08 269504]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 BRSptStub;BitRaider Mini-Support Service Stub Loader; C:\ProgramData\BitRaider\BRSptStub.exe [2014-10-19 363208]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; F:\SteamLibrary\Steam\steamapps\common\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe [2014-11-15 25832]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [2014-02-28 520416]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-10-31 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-12-19 147624]
S3 Origin Client Service;Origin Client Service; F:\Program Files (x86)\Origin\OriginClientService.exe [2015-12-17 2104840]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-25 568512]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-04-11 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

fingot
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 22 pro 2015 21:53

Re: Prosím o kontrolu.

#3 Příspěvek od fingot »

# AdwCleaner v5.026 - Logfile created 22/12/2015 at 22:27:52
# Updated 21/12/2015 by Xplode
# Database : 2015-12-21.3 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Honzan - HONZAN-PC
# Running from : C:\Users\Honzan\Desktop\adwcleaner_5.026.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Honzan\AppData\Roaming\SimpleFiles
[-] Folder Deleted : C:\Users\Honzan\Desktop\Save

***** [ Files ] *****

[-] File Deleted : C:\END
[-] File Deleted : C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\user.js

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{1F91A9A1-01BA-4C81-863D-3BA0751E1419}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\SimpleFiles
[-] Key Deleted : HKCU\Software\simplytech
[-] Key Deleted : HKCU\Software\Kromtech
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\SearchProtect
[-] Key Deleted : HKLM\SOFTWARE\SimpleFiles
[-] Key Deleted : HKLM\SOFTWARE\SpeedBit
[-] Key Deleted : HKLM\SOFTWARE\AIM Toolbar
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D01A33E2-0A34-4659-82AA-8A90C51C0D21}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D01A33E2-0A34-4659-82AA-8A90C51C0D21}

***** [ Web browsers ] *****

[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.FF19Solved", "true");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.UserID", "UN41017714632049173");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.dum", "2");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.fullUserID", "UN41017714632049173.IN.20140412134932");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.installDate", "12/04/2014 13:49:33");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.installSessionId", "3fd142d9-3271-4ea0-b3cd-430ecf0df452");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.installSp", "FALSE");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.installerVersion", "1.10.0.6");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.searchRevert", "false");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.searchUninstallUserMode", "1");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.searchUserMode", "1");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.toolbarInstallDate", "12-04-2014 13:49:32");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.versionFromInstaller", "10.29.0.20");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("CT1750559.xpeMode", "1");
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("extensions.quick_start.enable_search1", false);
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[-] [C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\prefs.js] [Preference] Deleted : user_pref("smartbar.machineId", "AUF6COO5MWEVRHSU5QKQU62IRQ075LPNERA8PXRUZZCLJUR6KDYD7CXPMQHNDMKVLRW6PEVAC5DBXF6RFD4Y3A");

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [5094 bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

fingot
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 22 pro 2015 21:53

Re: Prosím o kontrolu.

#5 Příspěvek od fingot »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Honzan at 2015-12-22 22:58:26
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 147 GB (42%) free of 354 GB
Total RAM: 16328 MB (85% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:58:34, on 22.12.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal

Running processes:
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
C:\Program Files (x86)\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Razer\Razer Game Booster\main.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Nginx\nginx.exe
C:\Program Files (x86)\Nginx\nginx.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files\trend micro\Honzan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~3\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [RazerGameBooster] C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Nginx] C:\Program Files (x86)\Nginx\shortcut.lnk
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Boxoft Tools] "C:\ProgramData\Boxtools\Boxofttoolbox.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [{80655FC2-A38F-4B8C-8775-9A3C68A6C305}] "C:\MSILU\DL_FILE\Killer_Network_Drivers_1.1.42.1045\Setup.exe" /silent (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [{80655FC2-A38F-4B8C-8775-9A3C68A6C305}] "C:\MSILU\DL_FILE\Killer_Network_Drivers_1.1.42.1045\Setup.exe" /silent (User 'Default user')
O4 - Global Startup: Killer Network Manager.lnk = ?
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MIF5BA~1\Office15\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BitRaider Mini-Support Service Stub Loader (BRSptStub) - BitRaider, LLC - C:\ProgramData\BitRaider\BRSptStub.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - F:\SteamLibrary\Steam\steamapps\common\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_LiveUpdate_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - F:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: RzKLService - Razer Inc. - C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11396 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
"C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe"
"C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\AMD\CNext\CNext\cnext.exe" atlogon
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Windows Sidebar\sidebar.exe" /autoRun
WLIDSvcM.exe 2648
"C:\Program Files (x86)\RocketDock\RocketDock.exe"
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Razer\Razer Game Booster\main.exe" StartWithWindows
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
"C:\Program Files (x86)\Nginx\nginx.exe"
"C:\Program Files (x86)\Nginx\nginx.exe"
\??\C:\Windows\system32\conhost.exe "11832668341187353057217205406326662653389278927-12583516201111429134-1120770952
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --channel="1260.0.794562005\342694020" /prefetch:3
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=gpu-process --channel="1260.1.816708917\1425011897" --no-sandbox --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --supports-dual-gpus=false --reduce-gpu-sandbox --disable-image-transport-surface --gpu-vendor-id=0x1002 --gpu-device-id=0x6810 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.300.1025.0 --ignored=" --type=renderer " --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable /prefetch:12
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Users\Honzan\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@photodex.com/PhotodexPresenter]
"Description"=Photodex Presenter Plugin
"Path"=C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MIF5BA~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class

C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\extensions\
{2d3fbcf7-be69-4433-8858-c621a8d0e58d}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MIF5BA~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-22 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~3\Office15\GROOVEEX.DLL [2015-10-13 1731800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-22 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2015-04-30 1337000]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
"ISCT Tray"=C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [2014-08-25 5860656]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-07-15 7637208]
"StartCN"=C:\Program Files\AMD\CNext\CNext\cnext.exe [2015-11-18 4859592]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21 1174016]
"RocketDock"=C:\Program Files (x86)\RocketDock\RocketDock.exe [2007-09-02 495616]
"AdobeBridge"= []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-12-12 7394584]
"Boxoft Tools"=C:\ProgramData\Boxtools\Boxofttoolbox.exe -autorun []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2015-03-23 296216]
"RazerGameBooster"=C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe [2014-02-25 61152]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2014-07-22 2694040]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2014-10-02 421888]
"Nginx"=C:\Program Files (x86)\Nginx\shortcut.lnk [2015-07-26 1765]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2015-07-30 3458728]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-11-09 596528]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{4692B750-DE88-4DCF-9163-745AF5604B24}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-12-22 22:23:28 ----D---- C:\AdwCleaner
2015-12-19 03:01:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-12-16 10:54:29 ----D---- C:\Users\Honzan\AppData\Roaming\calibre
2015-12-16 10:51:53 ----D---- C:\ProgramData\Boxtools
2015-12-16 10:50:54 ----D---- C:\Program Files (x86)\FlipPDF to ePUB (freeware)
2015-12-03 12:15:51 ----D---- C:\rsit
2015-12-03 12:15:51 ----D---- C:\Program Files\trend micro
2015-12-03 10:03:45 ----D---- C:\ProgramData\Malwarebytes
2015-11-29 23:16:32 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 23:16:32 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-11-29 22:36:45 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-11-29 22:36:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\iernonce.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\ie4uinit.exe
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\urlmon.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\occache.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-29 22:36:43 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\iedkcs32.dll
2015-11-29 22:36:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-11-29 22:36:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\msfeeds.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\iesetup.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\iertutil.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\ieapfltr.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\dxtrans.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-11-29 22:36:41 ----A---- C:\Windows\system32\vbscript.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\jsproxy.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\ieui.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\dxtmsft.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\webcheck.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\mshtmled.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript9diag.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript9.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\ieUnatt.exe
2015-11-29 22:36:40 ----A---- C:\Windows\system32\ieframe.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\wininet.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\msrating.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\mshtml.dll
2015-11-29 22:30:50 ----A---- C:\Windows\system32\blackbox.dll
2015-11-29 22:30:49 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-11-29 22:30:49 ----A---- C:\Windows\system32\drmv2clt.dll
2015-11-29 22:30:48 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-11-29 22:30:46 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-11-29 22:30:46 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\mf.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-11-29 22:30:45 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-11-29 22:30:45 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-11-29 22:30:45 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-11-29 22:30:45 ----A---- C:\Windows\system32\crypt32.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\wintrust.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\quartz.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\evr.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\cryptui.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\cryptsvc.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\audiosrv.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\qdvd.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\mfplat.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\AudioEng.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\pcasvc.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\msscp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\msnetobj.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\EncDump.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\cryptsp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\cryptnet.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\AudioSes.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\rrinstaller.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\pcawrk.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\pcadm.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\mfps.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\mfpmp.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\audiodg.exe
2015-11-29 22:30:40 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-11-29 22:30:40 ----A---- C:\Windows\system32\pcalua.exe
2015-11-29 22:30:40 ----A---- C:\Windows\system32\pcaevts.dll
2015-11-29 22:30:40 ----A---- C:\Windows\system32\mferror.dll
2015-11-29 22:30:30 ----A---- C:\Windows\system32\basesrv.dll
2015-11-29 22:30:22 ----A---- C:\Windows\system32\winresume.exe
2015-11-29 22:30:22 ----A---- C:\Windows\system32\winload.exe
2015-11-29 22:30:22 ----A---- C:\Windows\system32\ci.dll
2015-11-29 22:30:22 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-11-29 22:30:21 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\drivers\appid.sys
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidsvc.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidapi.dll
2015-11-29 22:30:17 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2015-11-29 22:30:17 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-11-29 22:30:17 ----A---- C:\Windows\system32\wksprt.exe
2015-11-29 22:30:17 ----A---- C:\Windows\system32\rdvidcrl.dll
2015-11-29 22:30:17 ----A---- C:\Windows\system32\mstscax.dll
2015-11-29 22:30:16 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-11-29 22:30:16 ----A---- C:\Windows\system32\tsgqec.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\rpcrt4.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-11-29 22:30:13 ----A---- C:\Windows\system32\ntdll.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\lsasrv.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\schannel.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\ncrypt.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\msv1_0.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\KernelBase.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\kernel32.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\kerberos.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-11-29 22:30:12 ----A---- C:\Windows\system32\drivers\cng.sys
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wow64win.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wow64.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\winsrv.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wdigest.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\TSpkg.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\sspicli.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\srcore.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\smss.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\rstrui.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\lsass.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\csrsrv.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\cryptbase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\conhost.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\bcryptprimitives.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\auditpol.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\adtschema.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\wow64cpu.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\sspisrv.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\srclient.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\secur32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\ntvdm64.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\msaudite.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\credssp.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\apisetschema.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-29 22:30:09 ----A---- C:\Windows\SYSWOW64\user.exe
2015-11-29 22:30:09 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-11-29 22:30:09 ----A---- C:\Windows\system32\msobjs.dll
2015-11-29 22:30:02 ----A---- C:\Windows\system32\sysmain.dll
2015-11-29 22:30:02 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-11-29 22:30:01 ----A---- C:\Windows\system32\msmmsp.dll
2015-11-29 22:29:56 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-11-29 22:29:56 ----A---- C:\Windows\system32\FntCache.dll
2015-11-29 22:29:56 ----A---- C:\Windows\system32\DWrite.dll
2015-11-29 22:29:54 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-11-29 22:29:54 ----A---- C:\Windows\system32\d3d10warp.dll
2015-11-29 22:29:52 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2015-11-29 22:29:52 ----A---- C:\Windows\system32\pku2u.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-11-29 22:29:49 ----A---- C:\Windows\system32\wuauclt.exe
2015-11-29 22:29:49 ----A---- C:\Windows\system32\wuapp.exe
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuwebv.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wups2.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wups.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wudriver.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wucltux.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuaueng.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuapi.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-11-29 22:29:36 ----A---- C:\Windows\SYSWOW64\winsta.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\winsta.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\winlogon.exe
2015-11-29 22:29:36 ----A---- C:\Windows\system32\rdpcorekmts.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2015-11-29 22:29:36 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2015-11-29 22:29:32 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-11-29 22:29:32 ----A---- C:\Windows\system32\poqexec.exe
2015-11-29 22:29:21 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-11-29 22:29:21 ----A---- C:\Windows\system32\tzres.dll
2015-11-29 22:29:17 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-11-29 22:29:17 ----A---- C:\Windows\system32\certcli.dll
2015-11-29 22:29:11 ----A---- C:\Windows\system32\termsrv.dll
2015-11-29 22:29:08 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-11-29 22:29:08 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2015-11-29 22:29:08 ----A---- C:\Windows\system32\nlasvc.dll
2015-11-29 22:29:06 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-11-29 22:29:06 ----A---- C:\Windows\system32\wmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-11-29 22:29:05 ----A---- C:\Windows\system32\wmploc.DLL
2015-11-29 22:29:05 ----A---- C:\Windows\system32\spwmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\system32\dxmasf.dll
2015-11-29 22:28:58 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-11-29 22:28:58 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-11-29 22:28:58 ----A---- C:\Windows\system32\msxml6.dll
2015-11-29 22:28:58 ----A---- C:\Windows\system32\msxml3.dll
2015-11-29 22:28:57 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\system32\msxml6r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\system32\msxml3r.dll
2015-11-29 22:28:55 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-11-29 22:28:55 ----A---- C:\Windows\system32\msi.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msimsg.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msihnd.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msiexec.exe
2015-11-29 22:28:54 ----A---- C:\Windows\system32\consent.exe
2015-11-29 22:28:54 ----A---- C:\Windows\system32\authui.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\appinfo.dll
2015-11-29 22:28:52 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-11-29 22:28:52 ----A---- C:\Windows\system32\shell32.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2015-11-29 22:28:51 ----A---- C:\Windows\system32\mscorier.dll
2015-11-29 22:28:51 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-11-29 22:28:50 ----A---- C:\Windows\SYSWOW64\mscories.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\profsvc.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\mscories.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\dfshim.dll
2015-11-29 22:28:49 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-11-29 22:28:47 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-11-29 22:28:46 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2015-11-29 22:28:46 ----A---- C:\Windows\system32\IMJP10K.DLL
2015-11-29 22:28:46 ----A---- C:\Windows\system32\drivers\http.sys
2015-11-29 22:28:45 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-11-29 22:28:45 ----A---- C:\Windows\system32\gdi32.dll
2015-11-29 22:28:44 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-11-29 22:28:44 ----A---- C:\Windows\system32\notepad.exe
2015-11-29 22:28:44 ----A---- C:\Windows\notepad.exe
2015-11-29 22:28:42 ----A---- C:\Windows\system32\rdpudd.dll
2015-11-29 22:28:42 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-11-29 22:28:42 ----A---- C:\Windows\system32\rdpcorets.dll
2015-11-29 22:28:39 ----A---- C:\Windows\system32\win32k.sys
2015-11-29 22:28:37 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\system32\WebClnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\system32\davclnt.dll
2015-11-29 22:28:36 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-11-29 22:28:36 ----A---- C:\Windows\system32\drivers\tdx.sys
2015-11-29 22:28:36 ----A---- C:\Windows\system32\drivers\afd.sys
2015-11-29 22:28:36 ----A---- C:\Windows\system32\comctl32.dll
2015-11-29 22:28:34 ----A---- C:\Windows\system32\ubpm.dll
2015-11-29 22:28:33 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-11-29 22:28:32 ----A---- C:\Windows\system32\schedsvc.dll
2015-11-29 22:28:32 ----A---- C:\Windows\system32\ole32.dll
2015-11-29 22:28:31 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-11-29 22:28:30 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-11-29 22:28:30 ----A---- C:\Windows\system32\services.exe
2015-11-29 22:28:30 ----A---- C:\Windows\system32\cewmdm.dll
2015-11-29 22:26:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-11-29 22:26:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-11-29 22:26:26 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-11-29 22:26:25 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-11-29 22:26:25 ----A---- C:\Windows\system32\scesrv.dll
2015-11-29 22:26:23 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-11-29 22:26:23 ----A---- C:\Windows\system32\msctf.dll
2015-11-29 22:26:22 ----A---- C:\Windows\SYSWOW64\rastls.dll
2015-11-29 22:26:22 ----A---- C:\Windows\system32\rastls.dll
2015-11-29 22:26:07 ----A---- C:\Windows\SYSWOW64\packager.dll
2015-11-29 22:26:07 ----A---- C:\Windows\system32\packager.dll
2015-11-29 22:24:51 ----A---- C:\Windows\system32\InkEd.dll
2015-11-29 22:24:49 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-11-29 22:24:49 ----A---- C:\Windows\system32\jnwmon.dll
2015-11-29 22:18:09 ----A---- C:\Windows\system32\clfsw32.dll
2015-11-29 22:18:09 ----A---- C:\Windows\system32\clfs.sys
2015-11-29 22:18:08 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-11-29 22:18:08 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-11-29 22:18:08 ----A---- C:\Windows\system32\oleaut32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\lpk.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\fontsub.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\dciman32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\atmlib.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\atmfd.dll
2015-11-29 22:14:03 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-11-29 22:14:03 ----A---- C:\Windows\system32\WMPhoto.dll
2015-11-27 13:07:56 ----D---- C:\Program Files (x86)\Mozilla Thunderbird

======List of files/folders modified in the last 1 month======

2015-12-22 22:58:27 ----D---- C:\Windows\Temp
2015-12-22 22:35:21 ----D---- C:\Windows\System32
2015-12-22 22:35:21 ----D---- C:\Windows\inf
2015-12-22 22:35:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-12-22 22:25:11 ----D---- C:\Windows\Prefetch
2015-12-22 22:20:26 ----D---- C:\Windows
2015-12-22 22:19:57 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-22 21:58:34 ----D---- C:\Users\Honzan\AppData\Roaming\TS3Client
2015-12-22 15:58:16 ----SHD---- C:\System Volume Information
2015-12-22 01:26:31 ----D---- C:\Windows\system32\config
2015-12-21 07:31:47 ----RD---- C:\Program Files (x86)
2015-12-18 10:44:10 ----RSD---- C:\Windows\Fonts
2015-12-17 18:08:04 ----D---- C:\ProgramData\Origin
2015-12-17 18:03:08 ----D---- C:\ProgramData\EA Logs
2015-12-16 22:54:20 ----D---- C:\Windows\system32\NDF
2015-12-16 10:51:53 ----HD---- C:\ProgramData
2015-12-08 21:48:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-12-08 21:48:18 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2015-12-08 11:07:48 ----D---- C:\Windows\SysWOW64
2015-12-08 11:07:19 ----D---- C:\Windows\system32\catroot
2015-12-08 11:07:10 ----D---- C:\Windows\system32\Tasks
2015-12-08 10:50:55 ----SHD---- C:\Windows\Installer
2015-12-08 10:50:23 ----D---- C:\Program Files\AMD
2015-12-08 10:50:20 ----D---- C:\Program Files (x86)\AMD
2015-12-08 10:50:19 ----D---- C:\Windows\Microsoft.NET
2015-12-08 10:49:45 ----D---- C:\Windows\system32\drivers
2015-12-08 10:49:44 ----D---- C:\Windows\system32\DriverStore
2015-12-08 10:49:38 ----D---- C:\Windows\system32\catroot2
2015-12-08 10:47:23 ----D---- C:\AMD
2015-12-03 16:35:10 ----D---- C:\Users\Honzan\AppData\Roaming\Origin
2015-12-03 16:25:14 ----D---- C:\ProgramData\Package Cache
2015-12-03 12:15:51 ----RD---- C:\Program Files
2015-12-03 11:56:13 ----D---- C:\Windows\PolicyDefinitions
2015-12-03 11:37:47 ----D---- C:\Windows\Logs
2015-12-03 11:37:47 ----D---- C:\Windows\debug
2015-12-03 11:37:46 ----D---- C:\Windows\Minidump
2015-12-03 10:50:08 ----D---- C:\Windows\PCHEALTH
2015-12-02 12:09:51 ----D---- C:\Windows\rescache
2015-11-30 08:37:07 ----RSD---- C:\Windows\assembly
2015-11-30 08:17:28 ----D---- C:\Windows\winsxs
2015-11-30 08:13:03 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Windows\system32\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Program Files\Windows Media Player
2015-11-30 08:13:03 ----D---- C:\Program Files (x86)\Windows Media Player
2015-11-30 08:13:02 ----D---- C:\Windows\SYSWOW64\Dism
2015-11-30 08:13:01 ----D---- C:\Windows\system32\Dism
2015-11-30 08:13:00 ----D---- C:\Windows\ehome
2015-11-30 08:12:59 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-30 08:12:59 ----D---- C:\Windows\system32\en-US
2015-11-30 08:12:59 ----D---- C:\Program Files\Internet Explorer
2015-11-30 08:12:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-11-30 08:12:56 ----D---- C:\Windows\system32\CodeIntegrity
2015-11-30 08:12:56 ----D---- C:\Windows\system32\Boot
2015-11-30 08:12:56 ----D---- C:\Windows\AppPatch
2015-11-30 08:12:55 ----D---- C:\Windows\system32\migration
2015-11-30 08:12:55 ----D---- C:\Program Files\Windows Journal
2015-11-29 23:24:54 ----D---- C:\Windows\system32\MRT
2015-11-29 23:20:30 ----D---- C:\ProgramData\Microsoft Help
2015-11-29 23:10:14 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-11-29 20:14:37 ----D---- C:\Program Files\Microsoft Silverlight
2015-11-29 20:14:36 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-11-29 19:46:35 ----D---- C:\Program Files\Microsoft Security Client
2015-11-29 19:46:35 ----D---- C:\Program Files (x86)\Microsoft Security Client

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2015-03-23 22800]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 280376]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 BfLwf;Qualcomm Atheros Bandwidth Control; C:\Windows\system32\DRIVERS\bflwfx64.sys [2014-04-10 82096]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 124568]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-11-18 23960064]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-11-18 671232]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-09-18 96256]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\Windows\system32\DRIVERS\ikbevent.sys [2014-05-27 22216]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\Windows\system32\DRIVERS\imsevent.sys [2014-05-27 22728]
R3 INETMON;INETMON; \??\C:\Windows\System32\Drivers\INETMON.sys [2014-05-27 25800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-15 4012632]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver; C:\Windows\system32\DRIVERS\ISCTD.sys [2014-02-03 44744]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2015-03-23 390416]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2015-03-23 800016]
R3 KbFilter_Kb_FlexDef3x;HID Keyboard(FlexDef3x) Driver Service; C:\Windows\system32\DRIVERS\KbFilter_FlexDef3x.sys [2012-10-16 22016]
R3 Ke2200;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\e22w7x64.sys [2014-03-27 129200]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-17 99288]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2009-07-14 60288]
S3 Avc;Zařízení AVC; C:\Windows\system32\DRIVERS\avc.sys [2009-07-14 48768]
S3 AVCSTRM;AVC Streaming Filter Driver; C:\Windows\system32\DRIVERS\avcstrm.sys [2009-07-14 17664]
S3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [2014-11-05 78088]
S3 cpuz137;cpuz137; \??\C:\Windows\TEMP\cpuz137\cpuz137_x64.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1yexpress;Ovladač gigabitových síťových připojení Intel(R); C:\Windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 MSICDSetup;MSICDSetup; \??\D:\CDriver64.sys []
S3 MSTAPE;Microsoft AV/C Tape Subunit Device; C:\Windows\system32\DRIVERS\mstape.sys [2009-07-14 56448]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 TrueSight;TrueSight; \??\C:\Windows\System32\drivers\TrueSight.sys [2015-01-26 35064]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-11-18 246272]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-05-16 2266296]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 ISCTAgent;Intel(R) Smart Connect Technology Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2014-08-25 209712]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-17 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-17 390616]
R2 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2015-07-30 1741992]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 23816]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2014-04-17 344576]
R2 RzKLService;RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [2014-02-25 105448]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe [2014-09-21 186760]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 366544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-08 269504]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 BRSptStub;BitRaider Mini-Support Service Stub Loader; C:\ProgramData\BitRaider\BRSptStub.exe [2014-10-19 363208]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; F:\SteamLibrary\Steam\steamapps\common\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe [2014-11-15 25832]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [2014-02-28 520416]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-10-31 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-12-19 147624]
S3 Origin Client Service;Origin Client Service; F:\Program Files (x86)\Origin\OriginClientService.exe [2015-12-17 2104840]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-25 568512]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-04-11 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:reg
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

fingot
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 22 pro 2015 21:53

Re: Prosím o kontrolu.

#7 Příspěvek od fingot »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Honzan at 2015-12-23 18:45:30
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 148 GB (42%) free of 354 GB
Total RAM: 16328 MB (86% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:45:34, on 23.12.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal

Running processes:
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
C:\Program Files (x86)\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Razer\Razer Game Booster\main.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files (x86)\Nginx\nginx.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Program Files (x86)\Nginx\nginx.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Program Files\trend micro\Honzan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~3\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [RazerGameBooster] C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Nginx] C:\Program Files (x86)\Nginx\shortcut.lnk
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKCU\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Boxoft Tools] "C:\ProgramData\Boxtools\Boxofttoolbox.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [{80655FC2-A38F-4B8C-8775-9A3C68A6C305}] "C:\MSILU\DL_FILE\Killer_Network_Drivers_1.1.42.1045\Setup.exe" /silent (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [{80655FC2-A38F-4B8C-8775-9A3C68A6C305}] "C:\MSILU\DL_FILE\Killer_Network_Drivers_1.1.42.1045\Setup.exe" /silent (User 'Default user')
O4 - Global Startup: Killer Network Manager.lnk = ?
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MIF5BA~1\Office15\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{3141CF38-B62B-49BB-858F-9465079E268D}: NameServer = 10.94.10.1,82.117.151.5
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BitRaider Mini-Support Service Stub Loader (BRSptStub) - BitRaider, LLC - C:\ProgramData\BitRaider\BRSptStub.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - F:\SteamLibrary\Steam\steamapps\common\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_LiveUpdate_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - F:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: RzKLService - Razer Inc. - C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11223 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\Windows\Explorer.EXE
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
"C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe"
"C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2396
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\12232015_183951.log
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\AMD\CNext\CNext\cnext.exe" atlogon
"C:\Program Files (x86)\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\RocketDock\RocketDock.exe"
"C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Razer\Razer Game Booster\main.exe" StartWithWindows
taskeng.exe {FB75ABA2-16B4-4E1C-BF89-4F0104134F63}
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan"
"C:\Program Files (x86)\Nginx\nginx.exe"
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\Nginx\nginx.exe"
\??\C:\Windows\system32\conhost.exe "1412894333316961164-1785992775-12548406201504222108-1042683648-12268422181946873079
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --channel="3424.0.856656052\393867407" /prefetch:3
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe" --type=gpu-process --channel="3424.1.1268505118\862955417" --no-sandbox --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable --supports-dual-gpus=false --reduce-gpu-sandbox --disable-image-transport-surface --gpu-vendor-id=0x1002 --gpu-device-id=0x6810 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.300.1025.0 --ignored=" --type=renderer " --lang=en-US --locales-dir-path="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\locales" --log-severity=disable /prefetch:12
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\sppsvc.exe
"C:\Users\Honzan\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@photodex.com/PhotodexPresenter]
"Description"=Photodex Presenter Plugin
"Path"=C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MIF5BA~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class

C:\Users\Honzan\AppData\Roaming\Mozilla\Firefox\Profiles\k1sw0v09.default\extensions\
{2d3fbcf7-be69-4433-8858-c621a8d0e58d}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-10-20 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MIF5BA~1\Office15\URLREDIR.DLL [2014-01-23 881880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-22 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office15\URLREDIR.DLL [2014-01-22 707800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~3\Office15\GROOVEEX.DLL [2015-10-13 1731800]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-22 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2015-04-30 1337000]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27 558496]
"ISCT Tray"=C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [2014-08-25 5860656]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-07-15 7637208]
"StartCN"=C:\Program Files\AMD\CNext\CNext\cnext.exe [2015-11-18 4859592]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21 1174016]
"RocketDock"=C:\Program Files (x86)\RocketDock\RocketDock.exe [2007-09-02 495616]
"AdobeBridge"= []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-12-12 7394584]
"Boxoft Tools"=C:\ProgramData\Boxtools\Boxofttoolbox.exe -autorun []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2015-03-23 296216]
"RazerGameBooster"=C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe [2014-02-25 61152]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2014-07-22 2694040]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2014-10-02 421888]
"Nginx"=C:\Program Files (x86)\Nginx\shortcut.lnk [2015-07-26 1765]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2015-07-30 3458728]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{4692B750-DE88-4DCF-9163-745AF5604B24}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsv64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-12-23 18:39:51 ----D---- C:\_OTM
2015-12-22 22:23:28 ----D---- C:\AdwCleaner
2015-12-19 03:01:17 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-12-16 10:54:29 ----D---- C:\Users\Honzan\AppData\Roaming\calibre
2015-12-16 10:51:53 ----D---- C:\ProgramData\Boxtools
2015-12-16 10:50:54 ----D---- C:\Program Files (x86)\FlipPDF to ePUB (freeware)
2015-12-03 12:15:51 ----D---- C:\rsit
2015-12-03 12:15:51 ----D---- C:\Program Files\trend micro
2015-12-03 10:03:45 ----D---- C:\ProgramData\Malwarebytes
2015-11-29 23:16:32 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 23:16:32 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-11-29 22:36:45 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-11-29 22:36:45 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-11-29 22:36:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-11-29 22:36:44 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\iernonce.dll
2015-11-29 22:36:44 ----A---- C:\Windows\system32\ie4uinit.exe
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-11-29 22:36:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\urlmon.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\occache.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-29 22:36:43 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-11-29 22:36:43 ----A---- C:\Windows\system32\iedkcs32.dll
2015-11-29 22:36:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-11-29 22:36:42 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\msfeeds.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\iesetup.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\iertutil.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\ieapfltr.dll
2015-11-29 22:36:42 ----A---- C:\Windows\system32\dxtrans.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-11-29 22:36:41 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-11-29 22:36:41 ----A---- C:\Windows\system32\vbscript.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\jsproxy.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\ieui.dll
2015-11-29 22:36:41 ----A---- C:\Windows\system32\dxtmsft.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\webcheck.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\mshtmled.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript9diag.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript9.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\jscript.dll
2015-11-29 22:36:40 ----A---- C:\Windows\system32\ieUnatt.exe
2015-11-29 22:36:40 ----A---- C:\Windows\system32\ieframe.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\wininet.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\msrating.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-11-29 22:36:39 ----A---- C:\Windows\system32\mshtml.dll
2015-11-29 22:30:50 ----A---- C:\Windows\system32\blackbox.dll
2015-11-29 22:30:49 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2015-11-29 22:30:49 ----A---- C:\Windows\system32\drmv2clt.dll
2015-11-29 22:30:48 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2015-11-29 22:30:46 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2015-11-29 22:30:46 ----A---- C:\Windows\SYSWOW64\mf.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\wmdrmsdk.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\mf.dll
2015-11-29 22:30:46 ----A---- C:\Windows\system32\AUDIOKSE.dll
2015-11-29 22:30:45 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2015-11-29 22:30:45 ----A---- C:\Windows\system32\drmmgrtn.dll
2015-11-29 22:30:45 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2015-11-29 22:30:45 ----A---- C:\Windows\system32\crypt32.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-11-29 22:30:44 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\wintrust.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\quartz.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\evr.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\cryptui.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\cryptsvc.dll
2015-11-29 22:30:44 ----A---- C:\Windows\system32\audiosrv.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\quartz.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\evr.dll
2015-11-29 22:30:43 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\qdvd.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\mfplat.dll
2015-11-29 22:30:43 ----A---- C:\Windows\system32\AudioEng.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\msscp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2015-11-29 22:30:42 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\pcasvc.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\msscp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\msnetobj.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\EncDump.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\cryptsp.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\cryptnet.dll
2015-11-29 22:30:42 ----A---- C:\Windows\system32\AudioSes.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\mfps.dll
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2015-11-29 22:30:41 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\rrinstaller.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\pcawrk.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\pcadm.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\mfps.dll
2015-11-29 22:30:41 ----A---- C:\Windows\system32\mfpmp.exe
2015-11-29 22:30:41 ----A---- C:\Windows\system32\audiodg.exe
2015-11-29 22:30:40 ----A---- C:\Windows\SYSWOW64\mferror.dll
2015-11-29 22:30:40 ----A---- C:\Windows\system32\pcalua.exe
2015-11-29 22:30:40 ----A---- C:\Windows\system32\pcaevts.dll
2015-11-29 22:30:40 ----A---- C:\Windows\system32\mferror.dll
2015-11-29 22:30:30 ----A---- C:\Windows\system32\basesrv.dll
2015-11-29 22:30:22 ----A---- C:\Windows\system32\winresume.exe
2015-11-29 22:30:22 ----A---- C:\Windows\system32\winload.exe
2015-11-29 22:30:22 ----A---- C:\Windows\system32\ci.dll
2015-11-29 22:30:22 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-11-29 22:30:21 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\drivers\appid.sys
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidsvc.dll
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-11-29 22:30:21 ----A---- C:\Windows\system32\appidapi.dll
2015-11-29 22:30:17 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2015-11-29 22:30:17 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-11-29 22:30:17 ----A---- C:\Windows\system32\wksprt.exe
2015-11-29 22:30:17 ----A---- C:\Windows\system32\rdvidcrl.dll
2015-11-29 22:30:17 ----A---- C:\Windows\system32\mstscax.dll
2015-11-29 22:30:16 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2015-11-29 22:30:16 ----A---- C:\Windows\system32\tsgqec.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\rpcrt4.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-11-29 22:30:13 ----A---- C:\Windows\system32\ntdll.dll
2015-11-29 22:30:13 ----A---- C:\Windows\system32\lsasrv.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-11-29 22:30:12 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\schannel.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\ncrypt.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\msv1_0.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\KernelBase.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\kernel32.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\kerberos.dll
2015-11-29 22:30:12 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-11-29 22:30:12 ----A---- C:\Windows\system32\drivers\cng.sys
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-11-29 22:30:11 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wow64win.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wow64.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\winsrv.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\wdigest.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\TSpkg.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\sspicli.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\srcore.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\smss.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\rstrui.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\lsass.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-11-29 22:30:11 ----A---- C:\Windows\system32\csrsrv.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\cryptbase.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\conhost.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\bcryptprimitives.dll
2015-11-29 22:30:11 ----A---- C:\Windows\system32\auditpol.exe
2015-11-29 22:30:11 ----A---- C:\Windows\system32\adtschema.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-29 22:30:10 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-11-29 22:30:10 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\wow64cpu.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\sspisrv.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\srclient.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\secur32.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\ntvdm64.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\msaudite.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\credssp.dll
2015-11-29 22:30:10 ----A---- C:\Windows\system32\apisetschema.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-29 22:30:09 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-29 22:30:09 ----A---- C:\Windows\SYSWOW64\user.exe
2015-11-29 22:30:09 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-11-29 22:30:09 ----A---- C:\Windows\system32\msobjs.dll
2015-11-29 22:30:02 ----A---- C:\Windows\system32\sysmain.dll
2015-11-29 22:30:02 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2015-11-29 22:30:01 ----A---- C:\Windows\system32\msmmsp.dll
2015-11-29 22:29:56 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-11-29 22:29:56 ----A---- C:\Windows\system32\FntCache.dll
2015-11-29 22:29:56 ----A---- C:\Windows\system32\DWrite.dll
2015-11-29 22:29:54 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2015-11-29 22:29:54 ----A---- C:\Windows\system32\d3d10warp.dll
2015-11-29 22:29:52 ----A---- C:\Windows\SYSWOW64\pku2u.dll
2015-11-29 22:29:52 ----A---- C:\Windows\system32\pku2u.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-11-29 22:29:49 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-11-29 22:29:49 ----A---- C:\Windows\system32\wuauclt.exe
2015-11-29 22:29:49 ----A---- C:\Windows\system32\wuapp.exe
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuwebv.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wups2.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wups.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wudriver.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wucltux.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuaueng.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wuapi.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-11-29 22:29:48 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-11-29 22:29:36 ----A---- C:\Windows\SYSWOW64\winsta.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\winsta.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\winlogon.exe
2015-11-29 22:29:36 ----A---- C:\Windows\system32\rdpcorekmts.dll
2015-11-29 22:29:36 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2015-11-29 22:29:36 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2015-11-29 22:29:32 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-11-29 22:29:32 ----A---- C:\Windows\system32\poqexec.exe
2015-11-29 22:29:21 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-11-29 22:29:21 ----A---- C:\Windows\system32\tzres.dll
2015-11-29 22:29:17 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-11-29 22:29:17 ----A---- C:\Windows\system32\certcli.dll
2015-11-29 22:29:11 ----A---- C:\Windows\system32\termsrv.dll
2015-11-29 22:29:08 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2015-11-29 22:29:08 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2015-11-29 22:29:08 ----A---- C:\Windows\system32\nlasvc.dll
2015-11-29 22:29:06 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-11-29 22:29:06 ----A---- C:\Windows\system32\wmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-11-29 22:29:05 ----A---- C:\Windows\system32\wmploc.DLL
2015-11-29 22:29:05 ----A---- C:\Windows\system32\spwmp.dll
2015-11-29 22:29:05 ----A---- C:\Windows\system32\dxmasf.dll
2015-11-29 22:28:58 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-11-29 22:28:58 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-11-29 22:28:58 ----A---- C:\Windows\system32\msxml6.dll
2015-11-29 22:28:58 ----A---- C:\Windows\system32\msxml3.dll
2015-11-29 22:28:57 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\system32\msxml6r.dll
2015-11-29 22:28:57 ----A---- C:\Windows\system32\msxml3r.dll
2015-11-29 22:28:55 ----A---- C:\Windows\SYSWOW64\msi.dll
2015-11-29 22:28:55 ----A---- C:\Windows\system32\msi.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2015-11-29 22:28:54 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msimsg.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msihnd.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\msiexec.exe
2015-11-29 22:28:54 ----A---- C:\Windows\system32\consent.exe
2015-11-29 22:28:54 ----A---- C:\Windows\system32\authui.dll
2015-11-29 22:28:54 ----A---- C:\Windows\system32\appinfo.dll
2015-11-29 22:28:52 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-11-29 22:28:52 ----A---- C:\Windows\system32\shell32.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\mscorier.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-11-29 22:28:51 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2015-11-29 22:28:51 ----A---- C:\Windows\system32\mscorier.dll
2015-11-29 22:28:51 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-11-29 22:28:50 ----A---- C:\Windows\SYSWOW64\mscories.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\profsvc.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\mscories.dll
2015-11-29 22:28:50 ----A---- C:\Windows\system32\dfshim.dll
2015-11-29 22:28:49 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2015-11-29 22:28:47 ----A---- C:\Windows\system32\TSWbPrxy.exe
2015-11-29 22:28:46 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2015-11-29 22:28:46 ----A---- C:\Windows\system32\IMJP10K.DLL
2015-11-29 22:28:46 ----A---- C:\Windows\system32\drivers\http.sys
2015-11-29 22:28:45 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2015-11-29 22:28:45 ----A---- C:\Windows\system32\gdi32.dll
2015-11-29 22:28:44 ----A---- C:\Windows\SYSWOW64\notepad.exe
2015-11-29 22:28:44 ----A---- C:\Windows\system32\notepad.exe
2015-11-29 22:28:44 ----A---- C:\Windows\notepad.exe
2015-11-29 22:28:42 ----A---- C:\Windows\system32\rdpudd.dll
2015-11-29 22:28:42 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-11-29 22:28:42 ----A---- C:\Windows\system32\rdpcorets.dll
2015-11-29 22:28:39 ----A---- C:\Windows\system32\win32k.sys
2015-11-29 22:28:37 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\system32\WebClnt.dll
2015-11-29 22:28:37 ----A---- C:\Windows\system32\davclnt.dll
2015-11-29 22:28:36 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-11-29 22:28:36 ----A---- C:\Windows\system32\drivers\tdx.sys
2015-11-29 22:28:36 ----A---- C:\Windows\system32\drivers\afd.sys
2015-11-29 22:28:36 ----A---- C:\Windows\system32\comctl32.dll
2015-11-29 22:28:34 ----A---- C:\Windows\system32\ubpm.dll
2015-11-29 22:28:33 ----A---- C:\Windows\SYSWOW64\ubpm.dll
2015-11-29 22:28:32 ----A---- C:\Windows\system32\schedsvc.dll
2015-11-29 22:28:32 ----A---- C:\Windows\system32\ole32.dll
2015-11-29 22:28:31 ----A---- C:\Windows\SYSWOW64\ole32.dll
2015-11-29 22:28:30 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2015-11-29 22:28:30 ----A---- C:\Windows\system32\services.exe
2015-11-29 22:28:30 ----A---- C:\Windows\system32\cewmdm.dll
2015-11-29 22:26:27 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-11-29 22:26:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-11-29 22:26:26 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-11-29 22:26:25 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-11-29 22:26:25 ----A---- C:\Windows\system32\scesrv.dll
2015-11-29 22:26:23 ----A---- C:\Windows\SYSWOW64\msctf.dll
2015-11-29 22:26:23 ----A---- C:\Windows\system32\msctf.dll
2015-11-29 22:26:22 ----A---- C:\Windows\SYSWOW64\rastls.dll
2015-11-29 22:26:22 ----A---- C:\Windows\system32\rastls.dll
2015-11-29 22:26:07 ----A---- C:\Windows\SYSWOW64\packager.dll
2015-11-29 22:26:07 ----A---- C:\Windows\system32\packager.dll
2015-11-29 22:24:51 ----A---- C:\Windows\system32\InkEd.dll
2015-11-29 22:24:49 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-11-29 22:24:49 ----A---- C:\Windows\system32\jnwmon.dll
2015-11-29 22:18:09 ----A---- C:\Windows\system32\clfsw32.dll
2015-11-29 22:18:09 ----A---- C:\Windows\system32\clfs.sys
2015-11-29 22:18:08 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-11-29 22:18:08 ----A---- C:\Windows\SYSWOW64\clfsw32.dll
2015-11-29 22:18:08 ----A---- C:\Windows\system32\oleaut32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-11-29 22:16:12 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\lpk.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\fontsub.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\dciman32.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\atmlib.dll
2015-11-29 22:16:12 ----A---- C:\Windows\system32\atmfd.dll
2015-11-29 22:14:03 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2015-11-29 22:14:03 ----A---- C:\Windows\system32\WMPhoto.dll
2015-11-27 13:07:56 ----D---- C:\Program Files (x86)\Mozilla Thunderbird

======List of files/folders modified in the last 1 month======

2015-12-23 18:45:12 ----D---- C:\Windows\Temp
2015-12-23 18:41:41 ----D---- C:\Windows
2015-12-23 18:40:19 ----D---- C:\Windows\System32
2015-12-23 18:40:19 ----D---- C:\Windows\inf
2015-12-23 18:40:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-12-22 22:25:11 ----D---- C:\Windows\Prefetch
2015-12-22 22:19:57 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-22 21:58:34 ----D---- C:\Users\Honzan\AppData\Roaming\TS3Client
2015-12-22 15:58:16 ----SHD---- C:\System Volume Information
2015-12-22 01:26:31 ----D---- C:\Windows\system32\config
2015-12-21 07:31:47 ----RD---- C:\Program Files (x86)
2015-12-18 10:44:10 ----RSD---- C:\Windows\Fonts
2015-12-17 18:08:04 ----D---- C:\ProgramData\Origin
2015-12-17 18:03:08 ----D---- C:\ProgramData\EA Logs
2015-12-16 22:54:20 ----D---- C:\Windows\system32\NDF
2015-12-16 10:51:53 ----HD---- C:\ProgramData
2015-12-08 21:48:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-12-08 21:48:18 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2015-12-08 11:07:48 ----D---- C:\Windows\SysWOW64
2015-12-08 11:07:19 ----D---- C:\Windows\system32\catroot
2015-12-08 11:07:10 ----D---- C:\Windows\system32\Tasks
2015-12-08 10:50:55 ----SHD---- C:\Windows\Installer
2015-12-08 10:50:23 ----D---- C:\Program Files\AMD
2015-12-08 10:50:20 ----D---- C:\Program Files (x86)\AMD
2015-12-08 10:50:19 ----D---- C:\Windows\Microsoft.NET
2015-12-08 10:49:45 ----D---- C:\Windows\system32\drivers
2015-12-08 10:49:44 ----D---- C:\Windows\system32\DriverStore
2015-12-08 10:49:38 ----D---- C:\Windows\system32\catroot2
2015-12-08 10:47:23 ----D---- C:\AMD
2015-12-03 16:35:10 ----D---- C:\Users\Honzan\AppData\Roaming\Origin
2015-12-03 16:25:14 ----D---- C:\ProgramData\Package Cache
2015-12-03 12:15:51 ----RD---- C:\Program Files
2015-12-03 11:56:13 ----D---- C:\Windows\PolicyDefinitions
2015-12-03 11:37:47 ----D---- C:\Windows\Logs
2015-12-03 11:37:47 ----D---- C:\Windows\debug
2015-12-03 11:37:46 ----D---- C:\Windows\Minidump
2015-12-03 10:50:08 ----D---- C:\Windows\PCHEALTH
2015-12-02 12:09:51 ----D---- C:\Windows\rescache
2015-11-30 08:37:07 ----RSD---- C:\Windows\assembly
2015-11-30 08:17:28 ----D---- C:\Windows\winsxs
2015-11-30 08:13:03 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Windows\system32\drivers\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Windows\system32\cs-CZ
2015-11-30 08:13:03 ----D---- C:\Program Files\Windows Media Player
2015-11-30 08:13:03 ----D---- C:\Program Files (x86)\Windows Media Player
2015-11-30 08:13:02 ----D---- C:\Windows\SYSWOW64\Dism
2015-11-30 08:13:01 ----D---- C:\Windows\system32\Dism
2015-11-30 08:13:00 ----D---- C:\Windows\ehome
2015-11-30 08:12:59 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-30 08:12:59 ----D---- C:\Windows\system32\en-US
2015-11-30 08:12:59 ----D---- C:\Program Files\Internet Explorer
2015-11-30 08:12:59 ----D---- C:\Program Files (x86)\Internet Explorer
2015-11-30 08:12:56 ----D---- C:\Windows\system32\CodeIntegrity
2015-11-30 08:12:56 ----D---- C:\Windows\system32\Boot
2015-11-30 08:12:56 ----D---- C:\Windows\AppPatch
2015-11-30 08:12:55 ----D---- C:\Windows\system32\migration
2015-11-30 08:12:55 ----D---- C:\Program Files\Windows Journal
2015-11-29 23:24:54 ----D---- C:\Windows\system32\MRT
2015-11-29 23:20:30 ----D---- C:\ProgramData\Microsoft Help
2015-11-29 23:10:14 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-11-29 20:14:37 ----D---- C:\Program Files\Microsoft Silverlight
2015-11-29 20:14:36 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-11-29 19:46:35 ----D---- C:\Program Files\Microsoft Security Client
2015-11-29 19:46:35 ----D---- C:\Program Files (x86)\Microsoft Security Client

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2015-03-23 22800]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 280376]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 BfLwf;Qualcomm Atheros Bandwidth Control; C:\Windows\system32\DRIVERS\bflwfx64.sys [2014-04-10 82096]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 124568]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-11-18 23960064]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-11-18 671232]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2015-09-18 96256]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\Windows\system32\DRIVERS\ikbevent.sys [2014-05-27 22216]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\Windows\system32\DRIVERS\imsevent.sys [2014-05-27 22728]
R3 INETMON;INETMON; \??\C:\Windows\System32\Drivers\INETMON.sys [2014-05-27 25800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-15 4012632]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver; C:\Windows\system32\DRIVERS\ISCTD.sys [2014-02-03 44744]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2015-03-23 390416]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2015-03-23 800016]
R3 KbFilter_Kb_FlexDef3x;HID Keyboard(FlexDef3x) Driver Service; C:\Windows\system32\DRIVERS\KbFilter_FlexDef3x.sys [2012-10-16 22016]
R3 Ke2200;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\e22w7x64.sys [2014-03-27 129200]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-17 99288]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2009-07-14 60288]
S3 Avc;Zařízení AVC; C:\Windows\system32\DRIVERS\avc.sys [2009-07-14 48768]
S3 AVCSTRM;AVC Streaming Filter Driver; C:\Windows\system32\DRIVERS\avcstrm.sys [2009-07-14 17664]
S3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [2014-11-05 78088]
S3 cpuz137;cpuz137; \??\C:\Windows\TEMP\cpuz137\cpuz137_x64.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 e1yexpress;Ovladač gigabitových síťových připojení Intel(R); C:\Windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 MSICDSetup;MSICDSetup; \??\D:\CDriver64.sys []
S3 MSTAPE;Microsoft AV/C Tape Subunit Device; C:\Windows\system32\DRIVERS\mstape.sys [2009-07-14 56448]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 TrueSight;TrueSight; \??\C:\Windows\System32\drivers\TrueSight.sys [2015-01-26 35064]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-11-18 246272]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-05-16 2266296]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 ISCTAgent;Intel(R) Smart Connect Technology Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2014-08-25 209712]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-17 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-17 390616]
R2 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2015-07-30 1741992]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 23816]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2014-04-17 344576]
R2 RzKLService;RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [2014-02-25 105448]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe [2014-09-21 186760]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 366544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-08 269504]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 BRSptStub;BitRaider Mini-Support Service Stub Loader; C:\ProgramData\BitRaider\BRSptStub.exe [2014-10-19 363208]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; F:\SteamLibrary\Steam\steamapps\common\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe [2014-11-15 25832]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [2014-02-28 520416]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-10-31 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-12-19 147624]
S3 Origin Client Service;Origin Client Service; F:\Program Files (x86)\Origin\OriginClientService.exe [2015-12-17 2104840]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-25 568512]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-04-11 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#8 Příspěvek od Rudy »

Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

fingot
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 22 pro 2015 21:53

Re: Prosím o kontrolu.

#9 Příspěvek od fingot »

Smazáno a snad OK. Děkuji za pomoc.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu.

#10 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno