Zasekané PC
Napsal: 12 úno 2016 14:36
Zdravím,
mám zasekané pc. Když jsem na pc tak se mi +- po 5 minutách sekne na 30s a projevuje se to opakovaně. Přidávám log.
RSITLog:
Logfile of random's system information tool 1.10 (written by random/random)
Run by zdend_000 at 2016-02-12 14:28:57
Microsoft Windows 8.1 Pro
System drive C: has 928 GB (97%) free of 954 GB
Total RAM: 8190 MB (82% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:33:54, on 12. 2. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16384)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\win32cldefender.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\zdend_000.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - Startup: googlecpupdate.exe
O4 - Startup: win32cldefender.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 5587 bytes
======Listing Processes======
wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {8c56f2a1-b706-40f0-b7af0a9305bbe34e}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ef65b594-542c-4fde-be4f-c375b8d8b8ef -SystemEventPortName:HostProcess-5082eeca-8972-430b-aff0-61d505a7d8ca -IoCancelEventPortName:HostProcess-848754ca-019e-46e0-979b-4310c1d590bc -NonStateChangingEventPortName:HostProcess-57534eb7-b4fa-41b9-baf6-65d500ba6bfe -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e5b24b02-9c7d-42da-9191-c340f4dc0cf9 -DeviceGroupId:WpdFsGroup
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskhost.exe $(Arg0)
winlogon.exe
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
C:\Windows\Explorer.EXE
taskhostex.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\googlecpupdate.exe"
"C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\win32cldefender.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1668.0.581141145\1141534764" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,24,52,62 --gpu-vendor-id=0x10de --gpu-device-id=0x1244 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.5891 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.2.1874422892\790565080" --font-cache-shared-handle=2304 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.6.1388817661\1664544770" --font-cache-shared-handle=2956 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.9.1867708113\801313276" --font-cache-shared-handle=5256 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.18.19964286\285585844" --font-cache-shared-handle=6584 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.22.1605267666\1207063265" --font-cache-shared-handle=4320 /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\zdend_000\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-11-10 1804432]
C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
googlecpupdate.exe
win32cldefender.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-02-12 14:28:58 ----D---- C:\Program Files\trend micro
2016-02-12 14:28:57 ----D---- C:\rsit
2016-02-10 12:08:45 ----D---- C:\Windows\AutoKMS
2016-02-10 12:08:25 ----A---- C:\Windows\system32\drivers\tap0901.sys
2016-02-10 12:07:37 ----D---- C:\ProgramData\Microsoft Toolkit
2016-02-10 12:07:31 ----D---- C:\ProgramData\MicrosoftToolkit
2016-02-10 11:28:12 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-02-10 11:28:12 ----D---- C:\Program Files (x86)\MSBuild
2016-02-10 11:28:04 ----D---- C:\Windows\SYSWOW64\XPSViewer
2016-02-10 11:28:03 ----D---- C:\Program Files\Reference Assemblies
2016-02-10 11:28:03 ----D---- C:\Program Files\MSBuild
2016-02-10 11:21:04 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2016-02-10 11:21:04 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2016-02-10 11:21:04 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-02-10 11:21:01 ----A---- C:\Windows\system32\TsWpfWrp.exe
2016-02-10 11:21:01 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2016-02-10 11:21:01 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-02-10 08:25:12 ----A---- C:\Windows\system32\aspnet_counters.dll
2016-02-10 08:25:11 ----A---- C:\Windows\SYSWOW64\aspnet_counters.dll
2016-02-10 07:13:40 ----A---- C:\Windows\system32\winbici.dll
2016-02-10 07:13:17 ----A---- C:\Windows\SYSWOW64\authui.dll
2016-02-10 07:13:16 ----A---- C:\Windows\system32\SyncEngine.dll
2016-02-10 07:13:16 ----A---- C:\Windows\system32\authui.dll
2016-02-10 07:13:08 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2016-02-10 07:13:08 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2016-02-10 07:13:06 ----A---- C:\Windows\system32\wlansvc.dll
2016-02-10 07:13:06 ----A---- C:\Windows\system32\winmde.dll
2016-02-10 07:13:06 ----A---- C:\Windows\system32\drivers\ndis.sys
2016-02-10 07:13:05 ----A---- C:\Windows\system32\wmpmde.dll
2016-02-10 07:13:05 ----A---- C:\Windows\system32\SystemEventsBrokerServer.dll
2016-02-10 07:13:05 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-02-10 07:13:05 ----A---- C:\Windows\system32\bisrv.dll
2016-02-10 07:13:05 ----A---- C:\Windows\system32\audiosrv.dll
2016-02-10 07:13:04 ----A---- C:\Windows\SYSWOW64\winmde.dll
2016-02-10 07:13:04 ----A---- C:\Windows\system32\ubpm.dll
2016-02-10 07:13:04 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-02-10 07:13:03 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-02-10 07:13:03 ----A---- C:\Windows\system32\ploptin.dll
2016-02-10 07:13:03 ----A---- C:\Windows\system32\oleaut32.dll
2016-02-10 07:13:03 ----A---- C:\Windows\system32\mfds.dll
2016-02-10 07:13:02 ----A---- C:\Windows\SYSWOW64\mfds.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\Windows.Graphics.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\psmsrv.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\lsasrv.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\drivers\ipnat.sys
2016-02-10 07:13:01 ----A---- C:\Windows\SYSWOW64\Windows.Graphics.dll
2016-02-10 07:13:01 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2016-02-10 07:13:01 ----A---- C:\Windows\system32\rastls.dll
2016-02-10 07:13:01 ----A---- C:\Windows\system32\msieftp.dll
2016-02-10 07:13:01 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2016-02-10 07:13:00 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2016-02-10 07:13:00 ----A---- C:\Windows\SYSWOW64\mispace.dll
2016-02-10 07:13:00 ----A---- C:\Windows\system32\mispace.dll
2016-02-10 07:13:00 ----A---- C:\Windows\system32\drivers\BtaMPM.sys
2016-02-10 07:13:00 ----A---- C:\Windows\system32\bi.dll
2016-02-10 07:12:59 ----A---- C:\Windows\SYSWOW64\rastls.dll
2016-02-10 07:12:59 ----A---- C:\Windows\system32\deviceregistration.dll
2016-02-10 07:08:49 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2016-02-10 07:08:49 ----A---- C:\Windows\system32\twinui.appcore.dll
2016-02-10 07:08:49 ----A---- C:\Windows\system32\actxprxy.dll
2016-02-10 07:08:48 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2016-02-10 07:08:03 ----A---- C:\Windows\system32\mshtml.dll
2016-02-10 07:08:02 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-02-10 07:07:56 ----A---- C:\Windows\system32\ieframe.dll
2016-02-10 07:07:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-02-10 07:07:49 ----A---- C:\Windows\system32\wuaueng.dll
2016-02-10 07:07:48 ----A---- C:\Windows\system32\iertutil.dll
2016-02-10 07:07:47 ----A---- C:\Windows\system32\Windows.Media.dll
2016-02-10 07:07:47 ----A---- C:\Windows\system32\urlmon.dll
2016-02-10 07:07:46 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-02-10 07:07:46 ----A---- C:\Windows\system32\workfolderssvc.dll
2016-02-10 07:07:46 ----A---- C:\Windows\system32\UIAutomationCore.dll
2016-02-10 07:07:46 ----A---- C:\Windows\explorer.exe
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\d3d9.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\d3d10level9.dll
2016-02-10 07:07:44 ----A---- C:\Windows\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-02-10 07:07:44 ----A---- C:\Windows\system32\Windows.Web.Http.dll
2016-02-10 07:07:43 ----A---- C:\Windows\SYSWOW64\Windows.Web.Http.dll
2016-02-10 07:07:43 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2016-02-10 07:07:43 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2016-02-10 07:07:43 ----A---- C:\Windows\system32\TSWorkspace.dll
2016-02-10 07:07:43 ----A---- C:\Windows\system32\iuilp.dll
2016-02-10 07:07:42 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2016-02-10 07:07:42 ----A---- C:\Windows\SYSWOW64\user32.dll
2016-02-10 07:07:42 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\WWAHost.exe
2016-02-10 07:07:42 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\eapphost.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\drivers\acpi.sys
2016-02-10 07:07:42 ----A---- C:\Windows\system32\dnsapi.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\AppReadiness.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\wintrust.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\tsmf.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\ncryptsslp.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\kd_02_8086.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\eapp3hst.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\drivers\srv.sys
2016-02-10 07:07:41 ----A---- C:\Windows\system32\comdlg32.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\AudioSes.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\apphelp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\ncryptsslp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\wldp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\samsrv.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\profsvc.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\pcsvDevice.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\msched.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\ipnathlp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\iphlpsvc.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\embeddedapplauncher.exe
2016-02-10 07:07:40 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2016-02-10 07:07:40 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2016-02-10 07:07:39 ----A---- C:\Windows\SYSWOW64\shsetup.dll
2016-02-10 07:07:39 ----A---- C:\Windows\SYSWOW64\eappcfg.dll
2016-02-10 07:07:39 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\wuauclt.exe
2016-02-10 07:07:39 ----A---- C:\Windows\system32\WiFiDisplay.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\TSWbPrxy.exe
2016-02-10 07:07:39 ----A---- C:\Windows\system32\shsetup.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-02-10 07:07:39 ----A---- C:\Windows\system32\eappcfg.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\drivers\stornvme.sys
2016-02-10 07:07:39 ----A---- C:\Windows\system32\dnsrslvr.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\dafWfdProvider.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\dafBth.dll
2016-02-10 07:07:38 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-02-10 07:07:38 ----A---- C:\Windows\SYSWOW64\ftp.exe
2016-02-10 07:07:38 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\wucltux.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\WorkFoldersShell.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\wininet.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\jscript9.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\ie4uinit.exe
2016-02-10 07:07:38 ----A---- C:\Windows\system32\eappgnui.dll
2016-02-10 07:07:37 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-02-10 07:07:37 ----A---- C:\Windows\SYSWOW64\miutils.dll
2016-02-10 07:07:37 ----A---- C:\Windows\system32\rdpclip.exe
2016-02-10 07:07:37 ----A---- C:\Windows\system32\miutils.dll
2016-02-10 07:07:37 ----A---- C:\Windows\system32\ftp.exe
2016-02-10 07:07:03 ----A---- C:\Windows\system32\SettingsHandlers.dll
2016-02-10 07:07:01 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-02-10 07:07:01 ----A---- C:\Windows\system32\drivers\spaceport.sys
2016-02-10 07:07:01 ----A---- C:\Windows\system32\drivers\intelpep.sys
2016-02-10 07:06:59 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2016-02-10 07:06:59 ----A---- C:\Windows\system32\dcomp.dll
2016-02-10 07:06:59 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-02-10 07:06:59 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2016-02-10 07:06:58 ----A---- C:\Windows\SYSWOW64\dcomp.dll
2016-02-10 07:06:58 ----A---- C:\Windows\SYSWOW64\AppXDeploymentClient.dll
2016-02-10 07:06:58 ----A---- C:\Windows\system32\WMPDMC.exe
2016-02-10 07:06:58 ----A---- C:\Windows\system32\wlidcli.dll
2016-02-10 07:06:58 ----A---- C:\Windows\system32\SkyDrive.exe
2016-02-10 07:06:58 ----A---- C:\Windows\system32\msftedit.dll
2016-02-10 07:06:58 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2016-02-10 07:06:57 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe
2016-02-10 07:06:57 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\wpncore.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\drivers\SerCx2.sys
2016-02-10 07:06:57 ----A---- C:\Windows\system32\drivers\pdc.sys
2016-02-10 07:06:57 ----A---- C:\Windows\system32\CredentialMigrationHandler.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\appmgr.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\wlidcli.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\Display.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\CredentialMigrationHandler.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2016-02-10 07:06:56 ----A---- C:\Windows\system32\Display.dll
2016-02-10 07:06:51 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2016-02-10 07:06:51 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2016-02-10 07:06:51 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-02-10 07:06:50 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2016-02-10 07:06:50 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2016-02-10 07:06:50 ----A---- C:\Windows\system32\dxgi.dll
2016-02-10 07:06:50 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-02-10 07:06:49 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2016-02-10 07:06:48 ----A---- C:\Windows\system32\dwmcore.dll
2016-02-10 07:06:47 ----A---- C:\Windows\system32\d3d11.dll
2016-02-10 07:06:45 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\schedsvc.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\ReAgent.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\mfsvr.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\MFMediaEngine.dll
2016-02-10 07:06:44 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-02-10 07:06:44 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2016-02-10 07:06:44 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2016-02-10 07:06:44 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2016-02-10 07:06:44 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-02-10 07:06:44 ----A---- C:\Windows\system32\SettingSyncCore.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\WSClient.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\MsSpellCheckingFacility.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\WSClient.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\reseteng.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\pnrpsvc.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\ntdll.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\hal.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\easinvoker.exe
2016-02-10 07:06:43 ----A---- C:\Windows\system32\drivers\rdbss.sys
2016-02-10 07:06:42 ----A---- C:\Windows\SYSWOW64\sti.dll
2016-02-10 07:06:42 ----A---- C:\Windows\SYSWOW64\OEMLicense.dll
2016-02-10 07:06:42 ----A---- C:\Windows\SYSWOW64\easwrt.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\sti.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\OEMLicense.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\easwrt.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\drivers\USBXHCI.SYS
2016-02-10 07:01:48 ----D---- C:\Windows\system32\MRT
2016-02-10 07:01:45 ----A---- C:\Windows\system32\MRT.exe
2016-02-10 06:59:07 ----A---- C:\Windows\SYSWOW64\msctf.dll
2016-02-10 06:59:07 ----A---- C:\Windows\system32\msctf.dll
2016-02-10 06:59:06 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.dll
2016-02-10 06:59:06 ----A---- C:\Windows\system32\Windows.Media.Streaming.dll
2016-02-10 06:59:04 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2016-02-10 06:59:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2016-02-10 06:57:57 ----A---- C:\Windows\system32\winresume.exe
2016-02-10 06:57:57 ----A---- C:\Windows\system32\winload.exe
2016-02-10 06:57:55 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2016-02-10 06:57:55 ----A---- C:\Windows\system32\msdrm.dll
2016-02-10 06:57:52 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2016-02-10 06:57:52 ----A---- C:\Windows\system32\imagehlp.dll
2016-02-10 06:57:43 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2016-02-10 06:57:43 ----A---- C:\Windows\system32\poqexec.exe
2016-02-10 06:57:27 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2016-02-10 06:57:27 ----A---- C:\Windows\system32\msxml3.dll
2016-02-10 06:57:26 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2016-02-10 06:57:26 ----A---- C:\Windows\system32\WMPhoto.dll
2016-02-10 06:57:25 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-02-10 06:57:25 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-02-10 06:57:25 ----A---- C:\Windows\system32\KernelBase.dll
2016-02-10 06:57:25 ----A---- C:\Windows\system32\kernel32.dll
2016-02-10 06:57:25 ----A---- C:\Windows\system32\IKEEXT.DLL
2016-02-10 06:57:25 ----A---- C:\Windows\system32\drivers\wfplwfs.sys
2016-02-10 06:57:25 ----A---- C:\Windows\system32\BFE.DLL
2016-02-10 06:57:24 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2016-02-10 06:57:24 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2016-02-10 06:57:24 ----A---- C:\Windows\system32\d3d10warp.dll
2016-02-10 06:57:24 ----A---- C:\Windows\system32\d2d1.dll
2016-02-10 06:57:22 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2016-02-10 06:57:22 ----A---- C:\Windows\system32\gdi32.dll
2016-02-10 06:57:21 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-02-10 06:57:21 ----A---- C:\Windows\system32\sppsvc.exe
2016-02-10 06:57:21 ----A---- C:\Windows\system32\mstscax.dll
2016-02-10 06:57:21 ----A---- C:\Windows\system32\drivers\tcpip.sys
2016-02-10 06:57:20 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2016-02-10 06:57:20 ----A---- C:\Windows\SYSWOW64\combase.dll
2016-02-10 06:57:20 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2016-02-10 06:57:20 ----A---- C:\Windows\system32\mfcore.dll
2016-02-10 06:57:20 ----A---- C:\Windows\system32\combase.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\WerFault.exe
2016-02-10 06:57:19 ----A---- C:\Windows\system32\rdpencom.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\mfps.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\Faultrep.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\dbghelp.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\dbgeng.dll
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\WerFault.exe
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\DWWIN.EXE
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\tsgqec.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\swprv.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\sppcomapi.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\rdvidcrl.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\DWWIN.EXE
2016-02-10 06:57:18 ----A---- C:\Windows\system32\drivers\volsnap.sys
2016-02-10 06:57:12 ----A---- C:\Windows\system32\WSService.dll
2016-02-10 06:57:12 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-02-10 06:57:12 ----A---- C:\Windows\system32\drivers\clfs.sys
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\twinui.dll
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2016-02-10 06:57:11 ----A---- C:\Windows\system32\WSShared.dll
2016-02-10 06:57:11 ----A---- C:\Windows\system32\WSCollect.exe
2016-02-10 06:57:11 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-02-10 06:57:10 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2016-02-10 06:57:10 ----A---- C:\Windows\system32\twinui.dll
2016-02-10 06:57:10 ----A---- C:\Windows\system32\MrmCoreR.dll
2016-02-10 06:57:09 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2016-02-10 06:57:08 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2016-02-10 06:57:08 ----A---- C:\Windows\SYSWOW64\propsys.dll
2016-02-10 06:57:08 ----A---- C:\Windows\system32\SearchFolder.dll
2016-02-10 06:57:08 ----A---- C:\Windows\system32\propsys.dll
2016-02-10 06:56:07 ----A---- C:\Windows\system32\shell32.dll
2016-02-10 06:56:06 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-02-10 06:55:57 ----N---- C:\Windows\system32\MpSigStub.exe
2016-02-10 06:52:52 ----A---- C:\Windows\SYSWOW64\qedit.dll
2016-02-10 06:52:52 ----A---- C:\Windows\system32\qedit.dll
2016-02-10 06:52:50 ----A---- C:\Windows\SYSWOW64\pcaui.exe
2016-02-10 06:52:50 ----A---- C:\Windows\system32\pcaui.exe
2016-02-10 06:52:47 ----A---- C:\Windows\system32\win32k.sys
2016-02-10 06:52:41 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2016-02-10 06:52:41 ----A---- C:\Windows\system32\scrrun.dll
2016-02-10 06:52:30 ----A---- C:\Windows\SYSWOW64\mdmregistration.dll
2016-02-10 06:52:30 ----A---- C:\Windows\system32\uDWM.dll
2016-02-10 06:52:30 ----A---- C:\Windows\system32\mdmregistration.dll
2016-02-10 06:52:30 ----A---- C:\Windows\system32\MDMAgent.exe
2016-02-07 14:17:10 ----D---- C:\Users\zdend_000\AppData\Roaming\WinRAR
2016-02-07 14:16:40 ----D---- C:\Program Files\WinRAR
2016-02-07 14:14:29 ----D---- C:\Users\zdend_000\AppData\Roaming\NVIDIA
2016-02-07 14:05:14 ----D---- C:\Program Files (x86)\Google
2016-02-07 13:45:06 ----D---- C:\ProgramData\NVIDIA
2016-02-07 13:44:53 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvvsvc.exe
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvsvcr.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvsvc64.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvshext.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvmctray.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvcpl.dll
2016-02-07 13:44:31 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-02-07 13:44:31 ----A---- C:\Windows\system32\OpenCL.dll
2016-02-07 13:44:23 ----D---- C:\ProgramData\NVIDIA Corporation
2016-02-07 13:44:18 ----D---- C:\Program Files\NVIDIA Corporation
2016-02-07 13:44:18 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-02-07 13:39:23 ----D---- C:\Users\zdend_000\AppData\Roaming\Macromedia
2016-02-07 13:32:36 ----D---- C:\Users\zdend_000\AppData\Roaming\Adobe
2016-02-07 13:32:23 ----SD---- C:\Users\zdend_000\AppData\Roaming\Microsoft
2016-02-07 13:29:53 ----D---- C:\Windows\CSC
2016-02-07 13:29:41 ----D---- C:\Windows\SoftwareDistribution
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Šablony
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Plocha
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Nabídka Start
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Dokumenty
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Data aplikací
2016-02-07 13:27:26 ----ASH---- C:\hiberfil.sys
2016-02-07 13:23:36 ----D---- C:\Windows\Prefetch
2016-02-07 13:23:07 ----ASH---- C:\swapfile.sys
2016-02-07 13:23:07 ----ASH---- C:\pagefile.sys
2016-02-07 13:23:03 ----SHD---- C:\System Volume Information
2016-02-07 13:20:35 ----D---- C:\Windows\Panther
======List of files/folders modified in the last 1 month======
2016-02-12 14:28:58 ----RD---- C:\Program Files
2016-02-12 14:28:47 ----D---- C:\Windows\Temp
2016-02-12 13:21:25 ----D---- C:\Windows\Microsoft.NET
2016-02-12 13:00:00 ----D---- C:\Windows\system32\sru
2016-02-12 12:47:24 ----D---- C:\Windows\system32\LogFiles
2016-02-11 21:01:12 ----D---- C:\Windows\system32\Tasks
2016-02-11 20:54:20 ----RD---- C:\Windows\System32
2016-02-11 20:54:20 ----D---- C:\Windows\Inf
2016-02-11 20:54:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-02-11 10:11:54 ----D---- C:\Windows\rescache
2016-02-11 08:01:17 ----RD---- C:\Windows\assembly
2016-02-10 14:29:23 ----D---- C:\Windows\Logs
2016-02-10 12:14:19 ----D---- C:\Windows\Tasks
2016-02-10 12:12:37 ----D---- C:\Windows\system32\config
2016-02-10 12:08:45 ----D---- C:\Windows
2016-02-10 12:08:27 ----D---- C:\Windows\system32\DriverStore
2016-02-10 12:08:27 ----D---- C:\Windows\system32\drivers
2016-02-10 12:07:37 ----HD---- C:\ProgramData
2016-02-10 12:04:59 ----D---- C:\Windows\SysWOW64
2016-02-10 12:04:55 ----D---- C:\Windows\WinSxS
2016-02-10 12:04:31 ----RD---- C:\Windows\ToastData
2016-02-10 11:45:43 ----D---- C:\Windows\WinStore
2016-02-10 11:45:43 ----D---- C:\Windows\system32\migration
2016-02-10 11:37:33 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-02-10 11:37:33 ----D---- C:\Windows\system32\cs-CZ
2016-02-10 11:28:12 ----RD---- C:\Program Files (x86)
2016-02-10 11:28:04 ----D---- C:\Windows\SYSWOW64\MUI
2016-02-10 11:28:03 ----RSD---- C:\Windows\Fonts
2016-02-10 11:28:03 ----D---- C:\Windows\system32\MUI
2016-02-10 11:28:02 ----D---- C:\Windows\SYSWOW64\Dism
2016-02-10 11:28:02 ----D---- C:\Windows\MediaViewer
2016-02-10 11:28:02 ----D---- C:\Windows\FileManager
2016-02-10 11:28:02 ----D---- C:\Windows\Camera
2016-02-10 11:28:01 ----D---- C:\Windows\system32\Dism
2016-02-10 11:27:53 ----D---- C:\Windows\PolicyDefinitions
2016-02-10 11:27:53 ----D---- C:\Program Files\Internet Explorer
2016-02-10 11:27:52 ----D---- C:\Windows\system32\migwiz
2016-02-10 11:27:52 ----D---- C:\Windows\system32\en-US
2016-02-10 11:27:49 ----D---- C:\Windows\system32\Boot
2016-02-10 11:27:39 ----D---- C:\Windows\apppatch
2016-02-10 11:27:33 ----D---- C:\Windows\system32\drivers\UMDF
2016-02-10 10:23:54 ----HD---- C:\Program Files\WindowsApps
2016-02-10 08:29:32 ----D---- C:\Windows\CbsTemp
2016-02-10 07:06:20 ----D---- C:\Windows\system32\catroot2
2016-02-10 07:01:48 ----D---- C:\Windows\debug
2016-02-10 07:01:30 ----D---- C:\Program Files\Common Files\microsoft shared
2016-02-10 07:01:21 ----D---- C:\Windows\system32\SecureBootUpdates
2016-02-10 07:01:13 ----D---- C:\Windows\system32\wbem
2016-02-10 07:00:07 ----D---- C:\Windows\system32\restore
2016-02-10 06:46:48 ----D---- C:\Windows\AppReadiness
2016-02-09 06:51:12 ----D---- C:\Windows\system32\wdi
2016-02-09 06:51:01 ----D---- C:\Windows\system32\NDF
2016-02-07 14:11:09 ----SHD---- C:\Windows\Installer
2016-02-07 13:44:43 ----D---- C:\Windows\Help
2016-02-07 13:42:56 ----SD---- C:\ProgramData\Microsoft
2016-02-07 13:37:42 ----D---- C:\Windows\system32\CodeIntegrity
2016-02-07 13:36:15 ----SHD---- C:\$Recycle.Bin
2016-02-07 13:32:23 ----RD---- C:\Users
2016-02-07 13:27:52 ----D---- C:\Program Files\Windows NT
2016-02-07 13:24:26 ----D---- C:\Windows\system32\Recovery
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\C:\Users\zdend_000\Desktop\AIDA64 Extreme\kerneld.x64 []
R3 NVHDA;@oem4.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-11-10 214168]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2015-11-10 11139216]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 tap0901;@oem6.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-22 40664]
R3 WUDFSensorLP;@locationprovider.inf,%WudfLocationProviderDisplayName%;Služba Reflektor UMDF pro zprostředkovatele umístění (LocationProvider); C:\Windows\System32\drivers\WUDFRd.sys [2013-08-22 230912]
R3 WUDFWpdFs;WUDFWpdFs; C:\Windows\system32\DRIVERS\WUDFRd.sys [2013-08-22 230912]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-11-05 938616]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-11-05 417584]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-07 154440]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-10 269504]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-07 154440]
-----------------EOF-----------------
mám zasekané pc. Když jsem na pc tak se mi +- po 5 minutách sekne na 30s a projevuje se to opakovaně. Přidávám log.
RSITLog:
Logfile of random's system information tool 1.10 (written by random/random)
Run by zdend_000 at 2016-02-12 14:28:57
Microsoft Windows 8.1 Pro
System drive C: has 928 GB (97%) free of 954 GB
Total RAM: 8190 MB (82% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:33:54, on 12. 2. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16384)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\win32cldefender.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\zdend_000.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - Startup: googlecpupdate.exe
O4 - Startup: win32cldefender.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 5587 bytes
======Listing Processes======
wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {8c56f2a1-b706-40f0-b7af0a9305bbe34e}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ef65b594-542c-4fde-be4f-c375b8d8b8ef -SystemEventPortName:HostProcess-5082eeca-8972-430b-aff0-61d505a7d8ca -IoCancelEventPortName:HostProcess-848754ca-019e-46e0-979b-4310c1d590bc -NonStateChangingEventPortName:HostProcess-57534eb7-b4fa-41b9-baf6-65d500ba6bfe -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e5b24b02-9c7d-42da-9191-c340f4dc0cf9 -DeviceGroupId:WpdFsGroup
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
taskhost.exe $(Arg0)
winlogon.exe
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session
C:\Windows\Explorer.EXE
taskhostex.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\googlecpupdate.exe"
"C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\win32cldefender.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1668.0.581141145\1141534764" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,24,52,62 --gpu-vendor-id=0x10de --gpu-device-id=0x1244 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.5891 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.2.1874422892\790565080" --font-cache-shared-handle=2304 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.6.1388817661\1664544770" --font-cache-shared-handle=2956 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.9.1867708113\801313276" --font-cache-shared-handle=5256 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.18.19964286\285585844" --font-cache-shared-handle=6584 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=*AffiliationBasedMatching/EnabledThroughFieldTrial/AppBannerTriggering/Aggressive/AsyncSetAsDefault/Enabled/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Control2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/Control/*ExtensionActionRedesign/Default/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR5/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes/SafeBrowsingUpdateFrequency/Default/SlimmingPaint/EnableSlimmingPaint/*SpdyEnableDependencies/Control/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/WebRTC-LocalIPPermissionCheck/Default/WebRTC-PeerConnectionDTLS1.2/Enabled/ --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="1668.22.1605267666\1207063265" --font-cache-shared-handle=4320 /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\zdend_000\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-11-10 1804432]
C:\Users\zdend_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
googlecpupdate.exe
win32cldefender.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-02-12 14:28:58 ----D---- C:\Program Files\trend micro
2016-02-12 14:28:57 ----D---- C:\rsit
2016-02-10 12:08:45 ----D---- C:\Windows\AutoKMS
2016-02-10 12:08:25 ----A---- C:\Windows\system32\drivers\tap0901.sys
2016-02-10 12:07:37 ----D---- C:\ProgramData\Microsoft Toolkit
2016-02-10 12:07:31 ----D---- C:\ProgramData\MicrosoftToolkit
2016-02-10 11:28:12 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-02-10 11:28:12 ----D---- C:\Program Files (x86)\MSBuild
2016-02-10 11:28:04 ----D---- C:\Windows\SYSWOW64\XPSViewer
2016-02-10 11:28:03 ----D---- C:\Program Files\Reference Assemblies
2016-02-10 11:28:03 ----D---- C:\Program Files\MSBuild
2016-02-10 11:21:04 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2016-02-10 11:21:04 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2016-02-10 11:21:04 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-02-10 11:21:01 ----A---- C:\Windows\system32\TsWpfWrp.exe
2016-02-10 11:21:01 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2016-02-10 11:21:01 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-02-10 08:25:12 ----A---- C:\Windows\system32\aspnet_counters.dll
2016-02-10 08:25:11 ----A---- C:\Windows\SYSWOW64\aspnet_counters.dll
2016-02-10 07:13:40 ----A---- C:\Windows\system32\winbici.dll
2016-02-10 07:13:17 ----A---- C:\Windows\SYSWOW64\authui.dll
2016-02-10 07:13:16 ----A---- C:\Windows\system32\SyncEngine.dll
2016-02-10 07:13:16 ----A---- C:\Windows\system32\authui.dll
2016-02-10 07:13:08 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2016-02-10 07:13:08 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2016-02-10 07:13:06 ----A---- C:\Windows\system32\wlansvc.dll
2016-02-10 07:13:06 ----A---- C:\Windows\system32\winmde.dll
2016-02-10 07:13:06 ----A---- C:\Windows\system32\drivers\ndis.sys
2016-02-10 07:13:05 ----A---- C:\Windows\system32\wmpmde.dll
2016-02-10 07:13:05 ----A---- C:\Windows\system32\SystemEventsBrokerServer.dll
2016-02-10 07:13:05 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-02-10 07:13:05 ----A---- C:\Windows\system32\bisrv.dll
2016-02-10 07:13:05 ----A---- C:\Windows\system32\audiosrv.dll
2016-02-10 07:13:04 ----A---- C:\Windows\SYSWOW64\winmde.dll
2016-02-10 07:13:04 ----A---- C:\Windows\system32\ubpm.dll
2016-02-10 07:13:04 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-02-10 07:13:03 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-02-10 07:13:03 ----A---- C:\Windows\system32\ploptin.dll
2016-02-10 07:13:03 ----A---- C:\Windows\system32\oleaut32.dll
2016-02-10 07:13:03 ----A---- C:\Windows\system32\mfds.dll
2016-02-10 07:13:02 ----A---- C:\Windows\SYSWOW64\mfds.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\Windows.Graphics.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\psmsrv.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\lsasrv.dll
2016-02-10 07:13:02 ----A---- C:\Windows\system32\drivers\ipnat.sys
2016-02-10 07:13:01 ----A---- C:\Windows\SYSWOW64\Windows.Graphics.dll
2016-02-10 07:13:01 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2016-02-10 07:13:01 ----A---- C:\Windows\system32\rastls.dll
2016-02-10 07:13:01 ----A---- C:\Windows\system32\msieftp.dll
2016-02-10 07:13:01 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2016-02-10 07:13:00 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2016-02-10 07:13:00 ----A---- C:\Windows\SYSWOW64\mispace.dll
2016-02-10 07:13:00 ----A---- C:\Windows\system32\mispace.dll
2016-02-10 07:13:00 ----A---- C:\Windows\system32\drivers\BtaMPM.sys
2016-02-10 07:13:00 ----A---- C:\Windows\system32\bi.dll
2016-02-10 07:12:59 ----A---- C:\Windows\SYSWOW64\rastls.dll
2016-02-10 07:12:59 ----A---- C:\Windows\system32\deviceregistration.dll
2016-02-10 07:08:49 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2016-02-10 07:08:49 ----A---- C:\Windows\system32\twinui.appcore.dll
2016-02-10 07:08:49 ----A---- C:\Windows\system32\actxprxy.dll
2016-02-10 07:08:48 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2016-02-10 07:08:03 ----A---- C:\Windows\system32\mshtml.dll
2016-02-10 07:08:02 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-02-10 07:07:56 ----A---- C:\Windows\system32\ieframe.dll
2016-02-10 07:07:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-02-10 07:07:49 ----A---- C:\Windows\system32\wuaueng.dll
2016-02-10 07:07:48 ----A---- C:\Windows\system32\iertutil.dll
2016-02-10 07:07:47 ----A---- C:\Windows\system32\Windows.Media.dll
2016-02-10 07:07:47 ----A---- C:\Windows\system32\urlmon.dll
2016-02-10 07:07:46 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-02-10 07:07:46 ----A---- C:\Windows\system32\workfolderssvc.dll
2016-02-10 07:07:46 ----A---- C:\Windows\system32\UIAutomationCore.dll
2016-02-10 07:07:46 ----A---- C:\Windows\explorer.exe
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2016-02-10 07:07:45 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\d3d9.dll
2016-02-10 07:07:45 ----A---- C:\Windows\system32\d3d10level9.dll
2016-02-10 07:07:44 ----A---- C:\Windows\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-02-10 07:07:44 ----A---- C:\Windows\system32\Windows.Web.Http.dll
2016-02-10 07:07:43 ----A---- C:\Windows\SYSWOW64\Windows.Web.Http.dll
2016-02-10 07:07:43 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2016-02-10 07:07:43 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2016-02-10 07:07:43 ----A---- C:\Windows\system32\TSWorkspace.dll
2016-02-10 07:07:43 ----A---- C:\Windows\system32\iuilp.dll
2016-02-10 07:07:42 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2016-02-10 07:07:42 ----A---- C:\Windows\SYSWOW64\user32.dll
2016-02-10 07:07:42 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\WWAHost.exe
2016-02-10 07:07:42 ----A---- C:\Windows\system32\WorkfoldersControl.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\eapphost.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\drivers\acpi.sys
2016-02-10 07:07:42 ----A---- C:\Windows\system32\dnsapi.dll
2016-02-10 07:07:42 ----A---- C:\Windows\system32\AppReadiness.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2016-02-10 07:07:41 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\wintrust.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\tsmf.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\ncryptsslp.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\kd_02_8086.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\eapp3hst.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\drivers\srv.sys
2016-02-10 07:07:41 ----A---- C:\Windows\system32\comdlg32.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\AudioSes.dll
2016-02-10 07:07:41 ----A---- C:\Windows\system32\apphelp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\ncryptsslp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\eapphost.dll
2016-02-10 07:07:40 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\wldp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\samsrv.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\profsvc.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\pcsvDevice.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\msched.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\ipnathlp.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\iphlpsvc.dll
2016-02-10 07:07:40 ----A---- C:\Windows\system32\embeddedapplauncher.exe
2016-02-10 07:07:40 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2016-02-10 07:07:40 ----A---- C:\Windows\system32\drivers\rdyboost.sys
2016-02-10 07:07:39 ----A---- C:\Windows\SYSWOW64\shsetup.dll
2016-02-10 07:07:39 ----A---- C:\Windows\SYSWOW64\eappcfg.dll
2016-02-10 07:07:39 ----A---- C:\Windows\SYSWOW64\eapp3hst.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\wuauclt.exe
2016-02-10 07:07:39 ----A---- C:\Windows\system32\WiFiDisplay.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\TSWbPrxy.exe
2016-02-10 07:07:39 ----A---- C:\Windows\system32\shsetup.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-02-10 07:07:39 ----A---- C:\Windows\system32\eappcfg.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\drivers\stornvme.sys
2016-02-10 07:07:39 ----A---- C:\Windows\system32\dnsrslvr.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\dafWfdProvider.dll
2016-02-10 07:07:39 ----A---- C:\Windows\system32\dafBth.dll
2016-02-10 07:07:38 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-02-10 07:07:38 ----A---- C:\Windows\SYSWOW64\ftp.exe
2016-02-10 07:07:38 ----A---- C:\Windows\SYSWOW64\eappgnui.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\wucltux.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\WorkFoldersShell.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\wininet.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\jscript9.dll
2016-02-10 07:07:38 ----A---- C:\Windows\system32\ie4uinit.exe
2016-02-10 07:07:38 ----A---- C:\Windows\system32\eappgnui.dll
2016-02-10 07:07:37 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-02-10 07:07:37 ----A---- C:\Windows\SYSWOW64\miutils.dll
2016-02-10 07:07:37 ----A---- C:\Windows\system32\rdpclip.exe
2016-02-10 07:07:37 ----A---- C:\Windows\system32\miutils.dll
2016-02-10 07:07:37 ----A---- C:\Windows\system32\ftp.exe
2016-02-10 07:07:03 ----A---- C:\Windows\system32\SettingsHandlers.dll
2016-02-10 07:07:01 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-02-10 07:07:01 ----A---- C:\Windows\system32\drivers\spaceport.sys
2016-02-10 07:07:01 ----A---- C:\Windows\system32\drivers\intelpep.sys
2016-02-10 07:06:59 ----A---- C:\Windows\SYSWOW64\AppxAllUserStore.dll
2016-02-10 07:06:59 ----A---- C:\Windows\system32\dcomp.dll
2016-02-10 07:06:59 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-02-10 07:06:59 ----A---- C:\Windows\system32\AppxAllUserStore.dll
2016-02-10 07:06:58 ----A---- C:\Windows\SYSWOW64\dcomp.dll
2016-02-10 07:06:58 ----A---- C:\Windows\SYSWOW64\AppXDeploymentClient.dll
2016-02-10 07:06:58 ----A---- C:\Windows\system32\WMPDMC.exe
2016-02-10 07:06:58 ----A---- C:\Windows\system32\wlidcli.dll
2016-02-10 07:06:58 ----A---- C:\Windows\system32\SkyDrive.exe
2016-02-10 07:06:58 ----A---- C:\Windows\system32\msftedit.dll
2016-02-10 07:06:58 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2016-02-10 07:06:57 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe
2016-02-10 07:06:57 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\wpncore.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\drivers\SerCx2.sys
2016-02-10 07:06:57 ----A---- C:\Windows\system32\drivers\pdc.sys
2016-02-10 07:06:57 ----A---- C:\Windows\system32\CredentialMigrationHandler.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-02-10 07:06:57 ----A---- C:\Windows\system32\appmgr.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\wlidcli.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\Display.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\CredentialMigrationHandler.dll
2016-02-10 07:06:56 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2016-02-10 07:06:56 ----A---- C:\Windows\system32\Display.dll
2016-02-10 07:06:51 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2016-02-10 07:06:51 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2016-02-10 07:06:51 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-02-10 07:06:50 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2016-02-10 07:06:50 ----A---- C:\Windows\SYSWOW64\d3d11.dll
2016-02-10 07:06:50 ----A---- C:\Windows\system32\dxgi.dll
2016-02-10 07:06:50 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-02-10 07:06:49 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2016-02-10 07:06:48 ----A---- C:\Windows\system32\dwmcore.dll
2016-02-10 07:06:47 ----A---- C:\Windows\system32\d3d11.dll
2016-02-10 07:06:45 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\schedsvc.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\ReAgent.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\mfsvr.dll
2016-02-10 07:06:45 ----A---- C:\Windows\system32\MFMediaEngine.dll
2016-02-10 07:06:44 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-02-10 07:06:44 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2016-02-10 07:06:44 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2016-02-10 07:06:44 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2016-02-10 07:06:44 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-02-10 07:06:44 ----A---- C:\Windows\system32\SettingSyncCore.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\WSClient.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-02-10 07:06:43 ----A---- C:\Windows\SYSWOW64\MsSpellCheckingFacility.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\WSClient.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\reseteng.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\pnrpsvc.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\ntdll.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\hal.dll
2016-02-10 07:06:43 ----A---- C:\Windows\system32\easinvoker.exe
2016-02-10 07:06:43 ----A---- C:\Windows\system32\drivers\rdbss.sys
2016-02-10 07:06:42 ----A---- C:\Windows\SYSWOW64\sti.dll
2016-02-10 07:06:42 ----A---- C:\Windows\SYSWOW64\OEMLicense.dll
2016-02-10 07:06:42 ----A---- C:\Windows\SYSWOW64\easwrt.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\sti.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\OEMLicense.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\easwrt.dll
2016-02-10 07:06:42 ----A---- C:\Windows\system32\drivers\USBXHCI.SYS
2016-02-10 07:01:48 ----D---- C:\Windows\system32\MRT
2016-02-10 07:01:45 ----A---- C:\Windows\system32\MRT.exe
2016-02-10 06:59:07 ----A---- C:\Windows\SYSWOW64\msctf.dll
2016-02-10 06:59:07 ----A---- C:\Windows\system32\msctf.dll
2016-02-10 06:59:06 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.dll
2016-02-10 06:59:06 ----A---- C:\Windows\system32\Windows.Media.Streaming.dll
2016-02-10 06:59:04 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2016-02-10 06:59:04 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2016-02-10 06:57:57 ----A---- C:\Windows\system32\winresume.exe
2016-02-10 06:57:57 ----A---- C:\Windows\system32\winload.exe
2016-02-10 06:57:55 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2016-02-10 06:57:55 ----A---- C:\Windows\system32\msdrm.dll
2016-02-10 06:57:52 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2016-02-10 06:57:52 ----A---- C:\Windows\system32\imagehlp.dll
2016-02-10 06:57:43 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2016-02-10 06:57:43 ----A---- C:\Windows\system32\poqexec.exe
2016-02-10 06:57:27 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2016-02-10 06:57:27 ----A---- C:\Windows\system32\msxml3.dll
2016-02-10 06:57:26 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2016-02-10 06:57:26 ----A---- C:\Windows\system32\WMPhoto.dll
2016-02-10 06:57:25 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-02-10 06:57:25 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-02-10 06:57:25 ----A---- C:\Windows\system32\KernelBase.dll
2016-02-10 06:57:25 ----A---- C:\Windows\system32\kernel32.dll
2016-02-10 06:57:25 ----A---- C:\Windows\system32\IKEEXT.DLL
2016-02-10 06:57:25 ----A---- C:\Windows\system32\drivers\wfplwfs.sys
2016-02-10 06:57:25 ----A---- C:\Windows\system32\BFE.DLL
2016-02-10 06:57:24 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2016-02-10 06:57:24 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2016-02-10 06:57:24 ----A---- C:\Windows\system32\d3d10warp.dll
2016-02-10 06:57:24 ----A---- C:\Windows\system32\d2d1.dll
2016-02-10 06:57:22 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2016-02-10 06:57:22 ----A---- C:\Windows\system32\gdi32.dll
2016-02-10 06:57:21 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-02-10 06:57:21 ----A---- C:\Windows\system32\sppsvc.exe
2016-02-10 06:57:21 ----A---- C:\Windows\system32\mstscax.dll
2016-02-10 06:57:21 ----A---- C:\Windows\system32\drivers\tcpip.sys
2016-02-10 06:57:20 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2016-02-10 06:57:20 ----A---- C:\Windows\SYSWOW64\combase.dll
2016-02-10 06:57:20 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2016-02-10 06:57:20 ----A---- C:\Windows\system32\mfcore.dll
2016-02-10 06:57:20 ----A---- C:\Windows\system32\combase.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\rdpencom.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2016-02-10 06:57:19 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\WerFault.exe
2016-02-10 06:57:19 ----A---- C:\Windows\system32\rdpencom.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\mfps.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\Faultrep.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\dbghelp.dll
2016-02-10 06:57:19 ----A---- C:\Windows\system32\dbgeng.dll
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\WerFault.exe
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\DWWIN.EXE
2016-02-10 06:57:18 ----A---- C:\Windows\SYSWOW64\dbghelp.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\tsgqec.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\swprv.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\sppcomapi.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\rdvidcrl.dll
2016-02-10 06:57:18 ----A---- C:\Windows\system32\DWWIN.EXE
2016-02-10 06:57:18 ----A---- C:\Windows\system32\drivers\volsnap.sys
2016-02-10 06:57:12 ----A---- C:\Windows\system32\WSService.dll
2016-02-10 06:57:12 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-02-10 06:57:12 ----A---- C:\Windows\system32\drivers\clfs.sys
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\WSShared.dll
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\twinui.dll
2016-02-10 06:57:11 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
2016-02-10 06:57:11 ----A---- C:\Windows\system32\WSShared.dll
2016-02-10 06:57:11 ----A---- C:\Windows\system32\WSCollect.exe
2016-02-10 06:57:11 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-02-10 06:57:10 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2016-02-10 06:57:10 ----A---- C:\Windows\system32\twinui.dll
2016-02-10 06:57:10 ----A---- C:\Windows\system32\MrmCoreR.dll
2016-02-10 06:57:09 ----A---- C:\Windows\SYSWOW64\Windows.UI.Search.dll
2016-02-10 06:57:08 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2016-02-10 06:57:08 ----A---- C:\Windows\SYSWOW64\propsys.dll
2016-02-10 06:57:08 ----A---- C:\Windows\system32\SearchFolder.dll
2016-02-10 06:57:08 ----A---- C:\Windows\system32\propsys.dll
2016-02-10 06:56:07 ----A---- C:\Windows\system32\shell32.dll
2016-02-10 06:56:06 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-02-10 06:55:57 ----N---- C:\Windows\system32\MpSigStub.exe
2016-02-10 06:52:52 ----A---- C:\Windows\SYSWOW64\qedit.dll
2016-02-10 06:52:52 ----A---- C:\Windows\system32\qedit.dll
2016-02-10 06:52:50 ----A---- C:\Windows\SYSWOW64\pcaui.exe
2016-02-10 06:52:50 ----A---- C:\Windows\system32\pcaui.exe
2016-02-10 06:52:47 ----A---- C:\Windows\system32\win32k.sys
2016-02-10 06:52:41 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2016-02-10 06:52:41 ----A---- C:\Windows\system32\scrrun.dll
2016-02-10 06:52:30 ----A---- C:\Windows\SYSWOW64\mdmregistration.dll
2016-02-10 06:52:30 ----A---- C:\Windows\system32\uDWM.dll
2016-02-10 06:52:30 ----A---- C:\Windows\system32\mdmregistration.dll
2016-02-10 06:52:30 ----A---- C:\Windows\system32\MDMAgent.exe
2016-02-07 14:17:10 ----D---- C:\Users\zdend_000\AppData\Roaming\WinRAR
2016-02-07 14:16:40 ----D---- C:\Program Files\WinRAR
2016-02-07 14:14:29 ----D---- C:\Users\zdend_000\AppData\Roaming\NVIDIA
2016-02-07 14:05:14 ----D---- C:\Program Files (x86)\Google
2016-02-07 13:45:06 ----D---- C:\ProgramData\NVIDIA
2016-02-07 13:44:53 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvvsvc.exe
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvsvcr.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvsvc64.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvshext.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvmctray.dll
2016-02-07 13:44:44 ----A---- C:\Windows\system32\nvcpl.dll
2016-02-07 13:44:31 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-02-07 13:44:31 ----A---- C:\Windows\system32\OpenCL.dll
2016-02-07 13:44:23 ----D---- C:\ProgramData\NVIDIA Corporation
2016-02-07 13:44:18 ----D---- C:\Program Files\NVIDIA Corporation
2016-02-07 13:44:18 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-02-07 13:39:23 ----D---- C:\Users\zdend_000\AppData\Roaming\Macromedia
2016-02-07 13:32:36 ----D---- C:\Users\zdend_000\AppData\Roaming\Adobe
2016-02-07 13:32:23 ----SD---- C:\Users\zdend_000\AppData\Roaming\Microsoft
2016-02-07 13:29:53 ----D---- C:\Windows\CSC
2016-02-07 13:29:41 ----D---- C:\Windows\SoftwareDistribution
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Šablony
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Plocha
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Nabídka Start
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Dokumenty
2016-02-07 13:27:52 ----SHD---- C:\ProgramData\Data aplikací
2016-02-07 13:27:26 ----ASH---- C:\hiberfil.sys
2016-02-07 13:23:36 ----D---- C:\Windows\Prefetch
2016-02-07 13:23:07 ----ASH---- C:\swapfile.sys
2016-02-07 13:23:07 ----ASH---- C:\pagefile.sys
2016-02-07 13:23:03 ----SHD---- C:\System Volume Information
2016-02-07 13:20:35 ----D---- C:\Windows\Panther
======List of files/folders modified in the last 1 month======
2016-02-12 14:28:58 ----RD---- C:\Program Files
2016-02-12 14:28:47 ----D---- C:\Windows\Temp
2016-02-12 13:21:25 ----D---- C:\Windows\Microsoft.NET
2016-02-12 13:00:00 ----D---- C:\Windows\system32\sru
2016-02-12 12:47:24 ----D---- C:\Windows\system32\LogFiles
2016-02-11 21:01:12 ----D---- C:\Windows\system32\Tasks
2016-02-11 20:54:20 ----RD---- C:\Windows\System32
2016-02-11 20:54:20 ----D---- C:\Windows\Inf
2016-02-11 20:54:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-02-11 10:11:54 ----D---- C:\Windows\rescache
2016-02-11 08:01:17 ----RD---- C:\Windows\assembly
2016-02-10 14:29:23 ----D---- C:\Windows\Logs
2016-02-10 12:14:19 ----D---- C:\Windows\Tasks
2016-02-10 12:12:37 ----D---- C:\Windows\system32\config
2016-02-10 12:08:45 ----D---- C:\Windows
2016-02-10 12:08:27 ----D---- C:\Windows\system32\DriverStore
2016-02-10 12:08:27 ----D---- C:\Windows\system32\drivers
2016-02-10 12:07:37 ----HD---- C:\ProgramData
2016-02-10 12:04:59 ----D---- C:\Windows\SysWOW64
2016-02-10 12:04:55 ----D---- C:\Windows\WinSxS
2016-02-10 12:04:31 ----RD---- C:\Windows\ToastData
2016-02-10 11:45:43 ----D---- C:\Windows\WinStore
2016-02-10 11:45:43 ----D---- C:\Windows\system32\migration
2016-02-10 11:37:33 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-02-10 11:37:33 ----D---- C:\Windows\system32\cs-CZ
2016-02-10 11:28:12 ----RD---- C:\Program Files (x86)
2016-02-10 11:28:04 ----D---- C:\Windows\SYSWOW64\MUI
2016-02-10 11:28:03 ----RSD---- C:\Windows\Fonts
2016-02-10 11:28:03 ----D---- C:\Windows\system32\MUI
2016-02-10 11:28:02 ----D---- C:\Windows\SYSWOW64\Dism
2016-02-10 11:28:02 ----D---- C:\Windows\MediaViewer
2016-02-10 11:28:02 ----D---- C:\Windows\FileManager
2016-02-10 11:28:02 ----D---- C:\Windows\Camera
2016-02-10 11:28:01 ----D---- C:\Windows\system32\Dism
2016-02-10 11:27:53 ----D---- C:\Windows\PolicyDefinitions
2016-02-10 11:27:53 ----D---- C:\Program Files\Internet Explorer
2016-02-10 11:27:52 ----D---- C:\Windows\system32\migwiz
2016-02-10 11:27:52 ----D---- C:\Windows\system32\en-US
2016-02-10 11:27:49 ----D---- C:\Windows\system32\Boot
2016-02-10 11:27:39 ----D---- C:\Windows\apppatch
2016-02-10 11:27:33 ----D---- C:\Windows\system32\drivers\UMDF
2016-02-10 10:23:54 ----HD---- C:\Program Files\WindowsApps
2016-02-10 08:29:32 ----D---- C:\Windows\CbsTemp
2016-02-10 07:06:20 ----D---- C:\Windows\system32\catroot2
2016-02-10 07:01:48 ----D---- C:\Windows\debug
2016-02-10 07:01:30 ----D---- C:\Program Files\Common Files\microsoft shared
2016-02-10 07:01:21 ----D---- C:\Windows\system32\SecureBootUpdates
2016-02-10 07:01:13 ----D---- C:\Windows\system32\wbem
2016-02-10 07:00:07 ----D---- C:\Windows\system32\restore
2016-02-10 06:46:48 ----D---- C:\Windows\AppReadiness
2016-02-09 06:51:12 ----D---- C:\Windows\system32\wdi
2016-02-09 06:51:01 ----D---- C:\Windows\system32\NDF
2016-02-07 14:11:09 ----SHD---- C:\Windows\Installer
2016-02-07 13:44:43 ----D---- C:\Windows\Help
2016-02-07 13:42:56 ----SD---- C:\ProgramData\Microsoft
2016-02-07 13:37:42 ----D---- C:\Windows\system32\CodeIntegrity
2016-02-07 13:36:15 ----SHD---- C:\$Recycle.Bin
2016-02-07 13:32:23 ----RD---- C:\Users
2016-02-07 13:27:52 ----D---- C:\Program Files\Windows NT
2016-02-07 13:24:26 ----D---- C:\Windows\system32\Recovery
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\C:\Users\zdend_000\Desktop\AIDA64 Extreme\kerneld.x64 []
R3 NVHDA;@oem4.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-11-10 214168]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2015-11-10 11139216]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 tap0901;@oem6.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-22 40664]
R3 WUDFSensorLP;@locationprovider.inf,%WudfLocationProviderDisplayName%;Služba Reflektor UMDF pro zprostředkovatele umístění (LocationProvider); C:\Windows\System32\drivers\WUDFRd.sys [2013-08-22 230912]
R3 WUDFWpdFs;WUDFWpdFs; C:\Windows\system32\DRIVERS\WUDFRd.sys [2013-08-22 230912]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-11-05 938616]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-11-05 417584]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-07 154440]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-10 269504]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-07 154440]
-----------------EOF-----------------