Stránka 1 z 1

vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 03 bře 2016 21:37
od Olivis
Prosím o kontrolu logu, ve všech prohlížečích se mi začly nechtěně vyskakovat okna a otvírat se nechtěné webové stránky.

Nejdříve jsem systém projel AdwCleaner v5.037, viz. log:

# AdwCleaner v5.037 - Logfile created 03/03/2016 at 21:21:54
# Updated 28/02/2016 by Xplode
# Database : 2016-03-02.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Petr - NAS_ASUS
# Running from : C:\Users\Petr\Downloads\adwcleaner_5.037.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\OneSystemCare
[-] Folder Deleted : C:\Program Files (x86)\TNT2
[-] Folder Deleted : C:\ProgramData\1846eb38-5855-0
[-] Folder Deleted : C:\ProgramData\1846eb38-79b7-0
[-] Folder Deleted : C:\ProgramData\2dd62d7e-5185-0
[-] Folder Deleted : C:\ProgramData\2dd62d7e-6981-1
[-] Folder Deleted : C:\ProgramData\3d703a42
[-] Folder Deleted : C:\ProgramData\{08b09f01-112c-0}
[-] Folder Deleted : C:\ProgramData\{0db89a1c-212c-1}
[-] Folder Deleted : C:\ProgramData\{1d5f7c43-212c-0}
[-] Folder Deleted : C:\Users\Petr\AppData\Local\TNT2
[-] Folder Deleted : C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}

***** [ Files ] *****

[-] File Deleted : C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\searchplugins\eshield-safe-web.xml

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : {40B5A8B1-5C17-19F6-38EB-4618A1722C4F}

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\MozillaPlugins\@tnt2npapi.com/Plugin
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3d703a42}
[-] Key Deleted : HKCU\Software\Classes\CLSID\{554EBE31-AEC1-4E34-BCE3-606467760D88}
[-] Key Deleted : HKCU\Software\Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2AF343DD-3102-4F9D-AC95-DCA4C95382C7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4CA2AC92-971B-47B1-ACB6-357B552155AC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{52C5395B-1FCD-47FA-A834-FD830701C2D5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{762D463B-C45A-456D-A80D-8689C297C91E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7A6BE473-7960-44D0-BD54-D23DA76353DF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{803F550E-BAAE-42BB-8917-64BA0006AB17}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{991C9D8D-A789-4DB9-BDFC-5F33398B04BF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A5ACC874-D943-483F-A2D1-14598D51F872}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0474212-0D9D-4361-90B3-B89D1A44275D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83C83BF-3EDD-4410-ADAB-5295116DD8C7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD260902-9420-4055-A956-9152EB4F3E6A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F1912128-469A-4138-AA26-9699C15BB13E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DEDAF650-12B8-48F5-A843-BBA100716106}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FEB2313-F89B-4AC6-8153-84025604A06A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2AF343DD-3102-4F9D-AC95-DCA4C95382C7}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4CA2AC92-971B-47B1-ACB6-357B552155AC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{52C5395B-1FCD-47FA-A834-FD830701C2D5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{762D463B-C45A-456D-A80D-8689C297C91E}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7A6BE473-7960-44D0-BD54-D23DA76353DF}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{803F550E-BAAE-42BB-8917-64BA0006AB17}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{991C9D8D-A789-4DB9-BDFC-5F33398B04BF}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A5ACC874-D943-483F-A2D1-14598D51F872}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B0474212-0D9D-4361-90B3-B89D1A44275D}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D83C83BF-3EDD-4410-ADAB-5295116DD8C7}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DD260902-9420-4055-A956-9152EB4F3E6A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F1912128-469A-4138-AA26-9699C15BB13E}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}
[-] Key Deleted : HKCU\Software\Appscion
[-] Key Deleted : HKCU\Software\TNT2
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{D5B774B9-EF21-434F-8928-07E8E8CD4C74}]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E74430FF-CA87-4F42-9954-EB913B2E5133}
[-] Data Restored : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{30632c23-aa33-4e44-9dea-00ba3daa0398} [NameServer]
[-] Data Restored : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{cefaab1f-fb7f-4a01-a6ed-6dc2a3b1a4f2} [NameServer]
[-] Data Restored : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{cf7005b4-8c43-4166-879c-070875500dcc} [NameServer]
[-] Data Restored : HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{30632c23-aa33-4e44-9dea-00ba3daa0398} [NameServer]
[-] Data Restored : HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{cefaab1f-fb7f-4a01-a6ed-6dc2a3b1a4f2} [NameServer]
[-] Data Restored : HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{cf7005b4-8c43-4166-879c-070875500dcc} [NameServer]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\eshield.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\nps.pastaleads.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pastaleads.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.eshield.com
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nps.pastaleads.com
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pastaleads.com
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nps.pastaleads.com
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pastaleads.com

***** [ Web browsers ] *****

[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "hxxp://services.eshield.com/general/newhometab.php?hometab=tab&partner=11433&guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&i=");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\prefs.js] [Preference] Deleted : user_pref("browser.search.selectedEngine", "eShield Safe Web");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\prefs.js] [Preference] Deleted : user_pref("extensions.tnt.engine.name", "eShield Safe Web");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\prefs.js] [Preference] Deleted : user_pref("extensions.tnt.engine.url", "hxxp://search.eshield.com/serp?guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&action=default_search&k={searchTerms}");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\prefs.js] [Preference] Deleted : user_pref("extensions.tnt.newtaburl", "hxxp://services.eshield.com/general/newhometab.php?hometab=tab&partner=11433&guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&i=");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxp://search.eshield.com/serp?guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&action=default_search&k=");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\prefs.js] [Preference] Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 0);
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\py8ts5ra.default\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxp://search.eshield.com/serp?guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&action=default_search&k=");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\py8ts5ra.default\prefs.js] [Preference] Deleted : user_pref("browser.search.defaultenginename", "eShield Safe Web");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\py8ts5ra.default\prefs.js] [Preference] Deleted : user_pref("extensions.tnt.engine.name", "eShield Safe Web");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\py8ts5ra.default\prefs.js] [Preference] Deleted : user_pref("extensions.tnt.engine.url", "hxxp://search.eshield.com/serp?guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&action=default_search&k={searchTerms}");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\py8ts5ra.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://services.eshield.com/general/newhometab.php?hometab=home&partner=11433&guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&i=");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\py8ts5ra.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "hxxp://services.eshield.com/general/newhometab.php?hometab=tab&partner=11433&guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&i=");
[-] [C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\py8ts5ra.default\prefs.js] [Preference] Deleted : user_pref("extensions.tnt.newtaburl", "hxxp://services.eshield.com/general/newhometab.php?hometab=tab&partner=11433&guid={F1459A62-A272-4787-81C7-04F70E6AF31B}&i=");

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [12830 bytes] - [03/03/2016 21:21:54]
C:\AdwCleaner\AdwCleaner[S1].txt - [12779 bytes] - [03/03/2016 21:19:59]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [12978 bytes] ##########

a zde ještě zasílám log po skenu AdwCleaner:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Petr at 2016-03-03 21:32:17
Microsoft Windows 10 Home
System drive C: has 207 GB (72%) free of 286 GB
Total RAM: 8078 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:32:25, on 03.03.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal

Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe
C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe
C:\Program Files\trend micro\Petr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O3 - Toolbar: eShield - {C45CC4A0-915D-4B42-B3FB-EB52FD41F896} - C:\Program Files (x86)\TNT2\2.0.0.2030\IEToolbar.dll (file missing)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe" -s
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.142.7 95.211.158.134
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: Asus WebStorage Windows Service - Unknown owner - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 12388 bytes

======Listing Processes======







winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\WINDOWS\system32\nvvsvc.exe"
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
dashost.exe {77bf7f9f-81ec-4603-85edfa2da4791b85}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe"
sihost.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
KBFiltr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
igfxEM.exe
igfxHK.exe
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
igfxTray.exe
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX3
"C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe" -s
"C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="5532.0.806737658\1592679397" "C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 5532 "\\.\pipe\gecko-crash-server-pipe.5532" plugin
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe" --proxy-stub-channel=Flash6500.6E34F3E8.22097 --host-broker-channel=Flash6500.6E34F3E8.22842 --host-pid=6500 --host-npapi-version=28 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_16_0_0_296.dll"
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe" --channel=6544.0018F2C8.956533041 --proxy-stub-channel=Flash6500.6E34F3E8.22097 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_16_0_0_296.dll" --host-npapi-version=28 --type=renderer
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="5532.1.1333405910\2025852642" "C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 5532 "\\.\pipe\gecko-crash-server-pipe.5532" plugin
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe" --proxy-stub-channel=Flash6684.6E34F3E8.26490 --host-broker-channel=Flash6684.6E34F3E8.11834 --host-pid=6684 --host-npapi-version=28 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_20_0_0_306.dll"
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe" --channel=6728.0018F7A4.1682782324 --proxy-stub-channel=Flash6684.6E34F3E8.26490 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_20_0_0_306.dll" --host-npapi-version=28 --type=renderer
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 636 640 648 8192 644

"C:\Users\Petr\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App V2 Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\synology.com/SurveillancePlugin]
"Description"=
"Path"=C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.429\npSurveillancePlugin.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll


C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\searchplugins\
firmycz.xml
mapycz.xml
yahoo.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2013-03-27 66688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08 2134656]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08 1725056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{C45CC4A0-915D-4B42-B3FB-EB52FD41F896} - eShield - C:\Program Files (x86)\TNT2\2.0.0.2030\IEToolbar64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{C45CC4A0-915D-4B42-B3FB-EB52FD41F896} - eShield - C:\Program Files (x86)\TNT2\2.0.0.2030\IEToolbar.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-05-30 13550152]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-05-20 1308232]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-02-17 2789248]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-02-17 1903344]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe [2012-01-10 491040]
"OneDrive"=C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-02-05 551112]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2015-09-24 40336]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2013-05-01 3187360]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [2012-12-19 3576784]
"RemoteControl10"=C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2012-03-28 91432]
"CLMLServer"=C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2012-05-24 111120]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe []

C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableCAD"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NOFOLDEROPTIONS"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-03-03 21:32:17 ----D---- C:\rsit
2016-03-03 21:32:17 ----D---- C:\Program Files\trend micro
2016-03-03 21:19:50 ----D---- C:\AdwCleaner
2016-03-03 20:58:47 ----HD---- C:\OneDriveTemp
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFTH264.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvumdshimx.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvinitx.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvEncMFTH264.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvdispgenco6436200.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvdispco6436200.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2016-03-02 21:05:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-02 21:05:24 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-02 21:05:22 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-03-02 21:05:19 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-03-02 21:05:17 ----A---- C:\WINDOWS\system32\shell32.dll
2016-03-02 21:05:09 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-03-02 21:05:06 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-03-02 21:05:02 ----A---- C:\WINDOWS\system32\twinui.dll
2016-03-02 21:05:01 ----A---- C:\WINDOWS\system32\windows.storage.dll
2016-03-02 21:04:59 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2016-03-02 21:04:58 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-03-02 21:04:55 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-03-02 21:04:54 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-03-02 21:04:53 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-03-02 21:04:52 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-03-02 21:04:51 ----A---- C:\WINDOWS\system32\wmp.dll
2016-03-02 21:04:49 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-02 21:04:49 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-03-02 21:04:48 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-02 21:04:47 ----A---- C:\WINDOWS\system32\wininet.dll
2016-03-02 21:04:47 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-03-02 21:04:46 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-03-02 21:04:46 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-03-02 21:04:46 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-02 21:04:45 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-03-02 21:04:44 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-02 21:04:44 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-03-02 21:04:44 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 21:04:43 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-03-02 21:04:43 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-03-02 21:04:42 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-03-02 21:04:42 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2016-03-02 21:04:42 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-03-02 21:04:41 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-03-02 21:04:40 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-03-02 21:04:40 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-02 21:04:38 ----A---- C:\WINDOWS\system32\XblGameSave.dll
2016-03-02 21:04:38 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-03-02 21:04:38 ----A---- C:\WINDOWS\system32\InputService.dll
2016-03-02 21:04:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-03-02 21:04:37 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-02 21:04:37 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-03-02 21:04:36 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-03-02 21:04:35 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-03-02 21:04:35 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-03-02 21:04:35 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-03-02 21:04:34 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-03-02 21:04:34 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-03-02 21:04:34 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\system32\UserDataService.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-03-02 21:04:32 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-03-02 21:04:32 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-02 21:04:32 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-03-02 21:04:32 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-03-02 21:04:31 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-03-02 21:04:31 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-02 21:04:31 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-02 21:04:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-03-02 21:04:30 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-03-02 21:04:30 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-03-02 21:04:29 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2016-03-02 21:04:29 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-03-02 21:04:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-03-02 21:04:28 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2016-03-02 21:04:28 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-02 21:04:27 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-03-02 21:04:27 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-02 21:04:27 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-03-02 21:04:25 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-03-02 21:04:25 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-02 21:04:25 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-02 21:04:25 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\vaultsvc.dll
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\system32\Unistore.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\wer.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\invagent.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\system32\SettingSync.dll
2016-03-02 21:04:19 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-03-02 21:04:19 ----A---- C:\WINDOWS\system32\usbmon.dll
2016-03-02 21:04:19 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-02 21:04:19 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-03-02 21:04:18 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2016-03-02 21:04:18 ----A---- C:\WINDOWS\system32\wlansvc.dll
2016-03-02 21:04:18 ----A---- C:\WINDOWS\system32\winload.exe
2016-03-02 21:04:17 ----A---- C:\WINDOWS\system32\winresume.exe
2016-03-02 21:04:17 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\SYSWOW64\taskschd.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-03-02 21:04:16 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\system32\sqmapi.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\system32\localspl.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-03-02 21:04:14 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2016-03-02 21:04:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\uDWM.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\SYSWOW64\sqmapi.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\thumbcache.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\taskschd.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\msvproc.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\system32\netlogon.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-03-02 21:04:11 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2016-03-02 21:04:11 ----A---- C:\WINDOWS\system32\drivers\xinputhid.sys
2016-03-02 21:04:11 ----A---- C:\WINDOWS\system32\configurationclient.dll
2016-03-02 21:04:11 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\wuuhext.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-03-02 21:04:09 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\sharemediacpl.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2016-03-02 21:04:08 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2016-03-02 21:04:08 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\system32\MDEServer.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\SYSWOW64\WiFiDisplay.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2016-03-02 21:04:06 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\SMSRouter.dll
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2016-03-02 21:04:05 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-03-02 21:04:05 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\wlanapi.dll
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\wermgr.exe
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\vaultcli.dll
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-03-02 21:04:03 ----A---- C:\WINDOWS\SYSWOW64\wermgr.exe
2016-03-02 21:04:03 ----A---- C:\WINDOWS\system32\psmsrv.dll
2016-03-02 21:04:03 ----A---- C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-02 21:04:03 ----A---- C:\WINDOWS\system32\devinv.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\wlansec.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\werui.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2016-03-02 21:04:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\provpackageapidll.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\ngckeyenum.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\scapi.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\werui.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\wfdprov.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\irmon.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2016-03-02 21:03:58 ----A---- C:\WINDOWS\SYSWOW64\TimeBrokerClient.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-03-02 21:03:58 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\srpapi.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-02-21 13:52:22 ----A---- C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-21 13:52:22 ----A---- C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-13 09:55:15 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-02-10 19:37:02 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-02-10 19:36:56 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-02-10 19:36:54 ----A---- C:\WINDOWS\explorer.exe
2016-02-10 19:36:53 ----A---- C:\WINDOWS\system32\combase.dll
2016-02-10 19:36:52 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-02-10 19:36:52 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2016-02-10 19:36:50 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2016-02-10 19:36:50 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-02-10 19:36:48 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-02-10 19:36:48 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-02-10 19:36:47 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-02-10 19:36:47 ----A---- C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-10 19:36:46 ----A---- C:\WINDOWS\system32\systemreset.exe
2016-02-10 19:36:45 ----A---- C:\WINDOWS\SYSWOW64\OpenWith.exe
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\OpenWith.exe
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\mtxoci.dll
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\iassam.dll
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-02-10 19:36:44 ----A---- C:\WINDOWS\SYSWOW64\ztrace_maps.dll
2016-02-10 19:36:44 ----A---- C:\WINDOWS\SYSWOW64\msorcl32.dll
2016-02-10 19:36:44 ----A---- C:\WINDOWS\system32\ztrace_maps.dll
2016-02-10 19:36:44 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2016-02-10 19:36:43 ----A---- C:\WINDOWS\SYSWOW64\mtxoci.dll
2016-02-10 19:36:43 ----A---- C:\WINDOWS\system32\hlink.dll
2016-02-10 19:36:42 ----A---- C:\WINDOWS\SYSWOW64\cfgbkend.dll
2016-02-10 19:36:42 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2016-02-10 19:36:41 ----A---- C:\WINDOWS\SYSWOW64\iassam.dll
2016-02-10 19:36:38 ----A---- C:\WINDOWS\SYSWOW64\hlink.dll
2016-02-10 19:36:38 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-02-10 19:36:37 ----A---- C:\WINDOWS\system32\reseteng.dll

======List of files/folders modified in the last 1 month======

2016-03-03 21:32:17 ----RD---- C:\Program Files
2016-03-03 21:31:32 ----D---- C:\WINDOWS\Temp
2016-03-03 21:27:17 ----D---- C:\WINDOWS\AppReadiness
2016-03-03 21:26:12 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2016-03-03 21:25:43 ----D---- C:\ProgramData\ASUS Smart Gesture
2016-03-03 21:25:33 ----D---- C:\WINDOWS\Prefetch
2016-03-03 21:24:43 ----D---- C:\WINDOWS\INF
2016-03-03 21:22:10 ----D---- C:\WINDOWS\system32\sru
2016-03-03 21:21:56 ----D---- C:\WINDOWS\system32\Tasks
2016-03-03 21:21:54 ----RD---- C:\Program Files (x86)
2016-03-03 21:21:54 ----HD---- C:\ProgramData
2016-03-03 21:02:47 ----D---- C:\WINDOWS\System32
2016-03-03 21:02:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-03 21:02:34 ----D---- C:\WINDOWS\system32\config
2016-03-03 20:56:45 ----D---- C:\WINDOWS\Microsoft.NET
2016-03-03 20:56:42 ----D---- C:\WINDOWS\WinSxS
2016-03-03 20:54:48 ----D---- C:\WINDOWS\system32\drivers
2016-03-03 20:54:47 ----D---- C:\WINDOWS\SysWOW64
2016-03-03 20:54:47 ----D---- C:\Windows
2016-03-03 20:52:59 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-03-03 20:52:59 ----D---- C:\WINDOWS\SYSWOW64\Dism
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\wbem
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\migration
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\Dism
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\Boot
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\appraiser
2016-03-03 20:52:54 ----RSD---- C:\WINDOWS\Media
2016-03-03 20:52:54 ----RD---- C:\WINDOWS\PurchaseDialog
2016-03-03 20:52:53 ----RSD---- C:\WINDOWS\Fonts
2016-03-03 20:52:53 ----D---- C:\WINDOWS\bcastdvr
2016-03-03 20:52:53 ----D---- C:\WINDOWS\AppPatch
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Portable Devices
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Multimedia Platform
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Media Player
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Journal
2016-03-03 20:52:53 ----D---- C:\Program Files\Internet Explorer
2016-03-03 20:52:53 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-03-03 20:52:53 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2016-03-03 20:52:53 ----D---- C:\Program Files (x86)\Internet Explorer
2016-03-03 20:52:51 ----D---- C:\WINDOWS\system32\DriverStore
2016-03-03 20:51:18 ----D---- C:\WINDOWS\CbsTemp
2016-03-03 20:48:31 ----SHD---- C:\System Volume Information
2016-03-03 19:14:25 ----D---- C:\ProgramData\NVIDIA
2016-03-03 19:12:32 ----HD---- C:\Program Files\WindowsApps
2016-03-02 20:56:09 ----D---- C:\WINDOWS\system32\catroot2
2016-02-28 12:45:08 ----D---- C:\WINDOWS\SoftwareDistribution
2016-02-28 09:38:41 ----D---- C:\WINDOWS\debug
2016-02-27 13:17:23 ----RSD---- C:\WINDOWS\assembly
2016-02-27 13:15:22 ----HD---- C:\$WINDOWS.~BT
2016-02-24 00:57:34 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-02-24 00:57:34 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-02-23 21:28:33 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-02-23 21:28:33 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-02-17 07:40:22 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2016-02-17 07:40:22 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-02-14 18:13:25 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-02-14 18:13:24 ----D---- C:\WINDOWS\system32\cs-CZ
2016-02-14 12:44:35 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-13 13:23:13 ----D---- C:\WINDOWS\Logs
2016-02-13 13:08:34 ----D---- C:\WINDOWS\rescache
2016-02-13 10:44:12 ----SHDC---- C:\WINDOWS\Installer
2016-02-13 10:44:11 ----D---- C:\ProgramData\Microsoft Help
2016-02-13 10:42:47 ----D---- C:\WINDOWS\system32\MRT
2016-02-13 10:38:31 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [2014-10-10 241368]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2016-02-25 48704]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2015-11-20 263528]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2015-11-20 186784]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [2015-11-20 170792]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 athr;@oem40.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\System32\drivers\athw10x.sys [2015-06-26 4325544]
R3 ATP;@oem21.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2015-08-23 100776]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2015-06-29 609992]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2015-10-30 84992]
R3 HIDSwitch;@oem34.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2015-05-13 19976]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2015-08-27 3797424]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-06-04 3441992]
R3 IntcDAud;@oem45.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 iwdbus;@oem41.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2015-07-20 38976]
R3 kbfiltr;@oem7.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 MEIx64;@oem22.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-02-25 12479040]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-02-17 28032]
R3 nvvad_WaveExtensible;@oem51.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2015-12-18 47760]
R3 RSBASTOR;@oem32.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\WINDOWS\system32\DRIVERS\RtsBaStor.sys [2015-07-08 321792]
R3 rt640x64;@oem39.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-07-07 895256]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2015-11-20 14976]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-02-23 954368]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-01-16 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 intaud_WaveExtensible;@oem3.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2015-07-20 50240]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2012-10-05 110976]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [2012-12-19 72192]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2016-01-08 1433216]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2016-01-08 1773696]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2015-11-20 2522616]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-02-17 1164672]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-09-13 2466448]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2015-08-27 330136]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-02-17 1880960]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-02-17 2609024]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2016-02-23 1263040]
R2 OneSyncSvc_360af;Hostitel synchronizace_360af; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
R3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2015-08-27 291744]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-02-17 6474112]
R3 PimIndexMaintenanceSvc_360af;Data kontaktů_360af; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 UnistoreSvc_360af;Úložiště uživatelských dat_360af; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-21 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_360af;Služba zasílání zpráv_360af; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-02-13 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 03 bře 2016 21:55
od Rudy
Zdravím!
Předně se mi nelíbí ty IP adresy doménových serverů. Jeden patří Nizozemsku a druhý Izraeli. Podivné, že? Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\Skype\Toolbars

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]/64

:services
c2cautoupdatesvc
c2cpnrsvc

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 03 bře 2016 22:05
od Olivis
Logfile of random's system information tool 1.10 (written by random/random)
Run by Petr at 2016-03-03 22:04:46
Microsoft Windows 10 Home
System drive C: has 207 GB (72%) free of 286 GB
Total RAM: 8078 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:04:49, on 03.03.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal

Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe
C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\ASUS\APRP\aprp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe
C:\Program Files\trend micro\Petr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O3 - Toolbar: eShield - {C45CC4A0-915D-4B42-B3FB-EB52FD41F896} - C:\Program Files (x86)\TNT2\2.0.0.2030\IEToolbar.dll (file missing)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe" -s
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.142.7 95.211.158.134
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: Asus WebStorage Windows Service - Unknown owner - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 12316 bytes

======Listing Processes======







winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\WINDOWS\system32\nvvsvc.exe"
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
dashost.exe {cd0836c6-2eaf-42c6-96268801fbf31408}
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
sihost.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe"
KBFiltr.exe
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
C:\WINDOWS\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\servicing\TrustedInstaller.exe
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\03032016_215848.log
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.113_none_7689896a26389b16\TiWorker.exe -Embedding
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe"
igfxEM.exe
igfxHK.exe
igfxTray.exe
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 628 632 640 8192 636
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX3
"C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe" -s
"C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\ASUS\APRP\aprp.exe"
taskhostw.exe

"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3916813832-2111371360-2176882180-10022_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3916813832-2111371360-2176882180-10022 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="6760.0.1762475642\1819411466" "C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 6760 "\\.\pipe\gecko-crash-server-pipe.6760" plugin
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe" --proxy-stub-channel=Flash6216.6EE1F3E8.12651 --host-broker-channel=Flash6216.6EE1F3E8.11425 --host-pid=6216 --host-npapi-version=28 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_16_0_0_296.dll"
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_16_0_0_296.exe" --channel=6260.0018F7DC.477210167 --proxy-stub-channel=Flash6216.6EE1F3E8.12651 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_16_0_0_296.dll" --host-npapi-version=28 --type=renderer
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="6760.1.118472227\1040548974" "C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 6760 "\\.\pipe\gecko-crash-server-pipe.6760" plugin
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe" --proxy-stub-channel=Flash4700.6EE1F3E8.26058 --host-broker-channel=Flash4700.6EE1F3E8.17601 --host-pid=4700 --host-npapi-version=28 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_20_0_0_306.dll"
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_20_0_0_306.exe" --channel=4864.0018F574.433231857 --proxy-stub-channel=Flash4700.6EE1F3E8.26058 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_20_0_0_306.dll" --host-npapi-version=28 --type=renderer
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca
"C:\Users\Petr\Desktop\RSITx64.exe"
C:\Windows\System32\InstallAgent.exe -Embedding

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App V2 Presence Detector Plugin
"Path"=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\synology.com/SurveillancePlugin]
"Description"=
"Path"=C:\Program Files (x86)\Synology\SurveillancePlugin\1.0.0.429\npSurveillancePlugin.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll


C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\n19ppt3q.default\searchplugins\
firmycz.xml
mapycz.xml
yahoo.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2013-03-27 66688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{C45CC4A0-915D-4B42-B3FB-EB52FD41F896} - eShield - C:\Program Files (x86)\TNT2\2.0.0.2030\IEToolbar64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{C45CC4A0-915D-4B42-B3FB-EB52FD41F896} - eShield - C:\Program Files (x86)\TNT2\2.0.0.2030\IEToolbar.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-05-30 13550152]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-05-20 1308232]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-02-17 2789248]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-02-17 1903344]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Petr\AppData\Local\Seznam.cz\bin\postak.exe [2012-01-10 491040]
"OneDrive"=C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-02-05 551112]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2015-09-24 40336]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2013-05-01 3187360]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [2012-12-19 3576784]
"RemoteControl10"=C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2012-03-28 91432]
"CLMLServer"=C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2012-05-24 111120]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe []

C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableCAD"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NOFOLDEROPTIONS"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-03-03 21:58:48 ----D---- C:\_OTM
2016-03-03 21:32:17 ----D---- C:\rsit
2016-03-03 21:32:17 ----D---- C:\Program Files\trend micro
2016-03-03 21:19:50 ----D---- C:\AdwCleaner
2016-03-03 20:58:47 ----HD---- C:\OneDriveTemp
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFTH264.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvumdshimx.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvinitx.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\nvEncMFTH264.dll
2016-03-03 19:12:46 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvdispgenco6436200.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvdispco6436200.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-03-03 19:12:45 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2016-03-02 21:05:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-02 21:05:24 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-02 21:05:22 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-03-02 21:05:19 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-03-02 21:05:17 ----A---- C:\WINDOWS\system32\shell32.dll
2016-03-02 21:05:09 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-03-02 21:05:06 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-03-02 21:05:02 ----A---- C:\WINDOWS\system32\twinui.dll
2016-03-02 21:05:01 ----A---- C:\WINDOWS\system32\windows.storage.dll
2016-03-02 21:04:59 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2016-03-02 21:04:58 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-03-02 21:04:55 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-03-02 21:04:54 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-03-02 21:04:53 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-03-02 21:04:52 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-03-02 21:04:51 ----A---- C:\WINDOWS\system32\wmp.dll
2016-03-02 21:04:49 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-02 21:04:49 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-03-02 21:04:48 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-02 21:04:47 ----A---- C:\WINDOWS\system32\wininet.dll
2016-03-02 21:04:47 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-03-02 21:04:46 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-03-02 21:04:46 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-03-02 21:04:46 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-02 21:04:45 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-03-02 21:04:44 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-02 21:04:44 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-03-02 21:04:44 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-02 21:04:43 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-03-02 21:04:43 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-03-02 21:04:42 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-03-02 21:04:42 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2016-03-02 21:04:42 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-03-02 21:04:41 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-03-02 21:04:40 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-03-02 21:04:40 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
2016-03-02 21:04:39 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-02 21:04:38 ----A---- C:\WINDOWS\system32\XblGameSave.dll
2016-03-02 21:04:38 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-03-02 21:04:38 ----A---- C:\WINDOWS\system32\InputService.dll
2016-03-02 21:04:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-03-02 21:04:37 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-02 21:04:37 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-03-02 21:04:36 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-03-02 21:04:35 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-03-02 21:04:35 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-03-02 21:04:35 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-03-02 21:04:34 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-03-02 21:04:34 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-03-02 21:04:34 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\system32\UserDataService.dll
2016-03-02 21:04:33 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-03-02 21:04:32 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-03-02 21:04:32 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-02 21:04:32 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-03-02 21:04:32 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-03-02 21:04:31 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-03-02 21:04:31 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-02 21:04:31 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-02 21:04:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-03-02 21:04:30 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-03-02 21:04:30 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-03-02 21:04:29 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2016-03-02 21:04:29 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-03-02 21:04:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-03-02 21:04:28 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2016-03-02 21:04:28 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-02 21:04:27 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-03-02 21:04:27 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-02 21:04:27 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2016-03-02 21:04:26 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-03-02 21:04:25 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-03-02 21:04:25 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-02 21:04:25 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-02 21:04:25 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\vaultsvc.dll
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2016-03-02 21:04:24 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\system32\Unistore.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-02 21:04:23 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-03-02 21:04:22 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\wer.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-02 21:04:21 ----A---- C:\WINDOWS\system32\invagent.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-03-02 21:04:20 ----A---- C:\WINDOWS\system32\SettingSync.dll
2016-03-02 21:04:19 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-03-02 21:04:19 ----A---- C:\WINDOWS\system32\usbmon.dll
2016-03-02 21:04:19 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-02 21:04:19 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-03-02 21:04:18 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2016-03-02 21:04:18 ----A---- C:\WINDOWS\system32\wlansvc.dll
2016-03-02 21:04:18 ----A---- C:\WINDOWS\system32\winload.exe
2016-03-02 21:04:17 ----A---- C:\WINDOWS\system32\winresume.exe
2016-03-02 21:04:17 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\SYSWOW64\taskschd.dll
2016-03-02 21:04:16 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-03-02 21:04:16 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\system32\sqmapi.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\system32\localspl.dll
2016-03-02 21:04:15 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-03-02 21:04:14 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2016-03-02 21:04:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\uDWM.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2016-03-02 21:04:14 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\SYSWOW64\sqmapi.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\thumbcache.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\taskschd.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\msvproc.dll
2016-03-02 21:04:13 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\system32\netlogon.dll
2016-03-02 21:04:12 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-03-02 21:04:11 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2016-03-02 21:04:11 ----A---- C:\WINDOWS\system32\drivers\xinputhid.sys
2016-03-02 21:04:11 ----A---- C:\WINDOWS\system32\configurationclient.dll
2016-03-02 21:04:11 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\wuuhext.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-03-02 21:04:10 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-03-02 21:04:09 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\sharemediacpl.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2016-03-02 21:04:09 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2016-03-02 21:04:08 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2016-03-02 21:04:08 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\system32\MDEServer.exe
2016-03-02 21:04:08 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\SYSWOW64\WiFiDisplay.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2016-03-02 21:04:07 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2016-03-02 21:04:06 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\SMSRouter.dll
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2016-03-02 21:04:06 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2016-03-02 21:04:05 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-03-02 21:04:05 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\wlanapi.dll
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\wermgr.exe
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\vaultcli.dll
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-02 21:04:04 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-03-02 21:04:03 ----A---- C:\WINDOWS\SYSWOW64\wermgr.exe
2016-03-02 21:04:03 ----A---- C:\WINDOWS\system32\psmsrv.dll
2016-03-02 21:04:03 ----A---- C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-02 21:04:03 ----A---- C:\WINDOWS\system32\devinv.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\wlansec.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\werui.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-03-02 21:04:02 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2016-03-02 21:04:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\provpackageapidll.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\ngckeyenum.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-03-02 21:04:01 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\scapi.dll
2016-03-02 21:04:00 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\werui.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\wfdprov.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\irmon.dll
2016-03-02 21:03:59 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2016-03-02 21:03:58 ----A---- C:\WINDOWS\SYSWOW64\TimeBrokerClient.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-03-02 21:03:58 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\srpapi.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-03-02 21:03:58 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-02-21 13:52:22 ----A---- C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-21 13:52:22 ----A---- C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-13 09:55:15 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-02-10 19:37:02 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-02-10 19:36:56 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-02-10 19:36:54 ----A---- C:\WINDOWS\explorer.exe
2016-02-10 19:36:53 ----A---- C:\WINDOWS\system32\combase.dll
2016-02-10 19:36:52 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-02-10 19:36:52 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2016-02-10 19:36:50 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2016-02-10 19:36:50 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-02-10 19:36:49 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-02-10 19:36:48 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-02-10 19:36:48 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-02-10 19:36:47 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-02-10 19:36:47 ----A---- C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-10 19:36:46 ----A---- C:\WINDOWS\system32\systemreset.exe
2016-02-10 19:36:45 ----A---- C:\WINDOWS\SYSWOW64\OpenWith.exe
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\OpenWith.exe
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\mtxoci.dll
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\iassam.dll
2016-02-10 19:36:45 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-02-10 19:36:44 ----A---- C:\WINDOWS\SYSWOW64\ztrace_maps.dll
2016-02-10 19:36:44 ----A---- C:\WINDOWS\SYSWOW64\msorcl32.dll
2016-02-10 19:36:44 ----A---- C:\WINDOWS\system32\ztrace_maps.dll
2016-02-10 19:36:44 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2016-02-10 19:36:43 ----A---- C:\WINDOWS\SYSWOW64\mtxoci.dll
2016-02-10 19:36:43 ----A---- C:\WINDOWS\system32\hlink.dll
2016-02-10 19:36:42 ----A---- C:\WINDOWS\SYSWOW64\cfgbkend.dll
2016-02-10 19:36:42 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2016-02-10 19:36:41 ----A---- C:\WINDOWS\SYSWOW64\iassam.dll
2016-02-10 19:36:38 ----A---- C:\WINDOWS\SYSWOW64\hlink.dll
2016-02-10 19:36:38 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-02-10 19:36:37 ----A---- C:\WINDOWS\system32\reseteng.dll

======List of files/folders modified in the last 1 month======

2016-03-03 22:03:49 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2016-03-03 22:03:33 ----D---- C:\ProgramData\ASUS Smart Gesture
2016-03-03 22:02:46 ----D---- C:\WINDOWS\Prefetch
2016-03-03 22:02:16 ----D---- C:\WINDOWS\Temp
2016-03-03 22:00:04 ----D---- C:\WINDOWS\system32\sru
2016-03-03 21:58:49 ----RD---- C:\Program Files (x86)\Skype
2016-03-03 21:32:17 ----RD---- C:\Program Files
2016-03-03 21:27:24 ----D---- C:\WINDOWS\AppReadiness
2016-03-03 21:24:43 ----D---- C:\WINDOWS\INF
2016-03-03 21:21:56 ----D---- C:\WINDOWS\system32\Tasks
2016-03-03 21:21:54 ----RD---- C:\Program Files (x86)
2016-03-03 21:21:54 ----HD---- C:\ProgramData
2016-03-03 21:02:47 ----D---- C:\WINDOWS\System32
2016-03-03 21:02:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-03 21:02:34 ----D---- C:\WINDOWS\system32\config
2016-03-03 20:56:45 ----D---- C:\WINDOWS\Microsoft.NET
2016-03-03 20:56:42 ----D---- C:\WINDOWS\WinSxS
2016-03-03 20:54:48 ----D---- C:\WINDOWS\system32\drivers
2016-03-03 20:54:47 ----D---- C:\WINDOWS\SysWOW64
2016-03-03 20:54:47 ----D---- C:\Windows
2016-03-03 20:52:59 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-03-03 20:52:59 ----D---- C:\WINDOWS\SYSWOW64\Dism
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\wbem
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\migration
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\Dism
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\Boot
2016-03-03 20:52:55 ----D---- C:\WINDOWS\system32\appraiser
2016-03-03 20:52:54 ----RSD---- C:\WINDOWS\Media
2016-03-03 20:52:54 ----RD---- C:\WINDOWS\PurchaseDialog
2016-03-03 20:52:53 ----RSD---- C:\WINDOWS\Fonts
2016-03-03 20:52:53 ----D---- C:\WINDOWS\bcastdvr
2016-03-03 20:52:53 ----D---- C:\WINDOWS\AppPatch
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Portable Devices
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Multimedia Platform
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Media Player
2016-03-03 20:52:53 ----D---- C:\Program Files\Windows Journal
2016-03-03 20:52:53 ----D---- C:\Program Files\Internet Explorer
2016-03-03 20:52:53 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-03-03 20:52:53 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2016-03-03 20:52:53 ----D---- C:\Program Files (x86)\Internet Explorer
2016-03-03 20:52:51 ----D---- C:\WINDOWS\system32\DriverStore
2016-03-03 20:51:18 ----D---- C:\WINDOWS\CbsTemp
2016-03-03 20:48:31 ----SHD---- C:\System Volume Information
2016-03-03 19:14:25 ----D---- C:\ProgramData\NVIDIA
2016-03-03 19:12:32 ----HD---- C:\Program Files\WindowsApps
2016-03-02 20:56:09 ----D---- C:\WINDOWS\system32\catroot2
2016-02-28 12:45:08 ----D---- C:\WINDOWS\SoftwareDistribution
2016-02-28 09:38:41 ----D---- C:\WINDOWS\debug
2016-02-27 13:17:23 ----RSD---- C:\WINDOWS\assembly
2016-02-27 13:15:22 ----HD---- C:\$WINDOWS.~BT
2016-02-24 00:57:34 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-02-24 00:57:34 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-02-23 21:28:33 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-02-23 21:28:33 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-02-23 21:28:30 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-02-17 07:40:22 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2016-02-17 07:40:22 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-02-14 18:13:25 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-02-14 18:13:24 ----D---- C:\WINDOWS\system32\cs-CZ
2016-02-14 12:44:35 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-13 13:23:13 ----D---- C:\WINDOWS\Logs
2016-02-13 13:08:34 ----D---- C:\WINDOWS\rescache
2016-02-13 10:44:12 ----SHDC---- C:\WINDOWS\Installer
2016-02-13 10:44:11 ----D---- C:\ProgramData\Microsoft Help
2016-02-13 10:42:47 ----D---- C:\WINDOWS\system32\MRT
2016-02-13 10:38:31 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [2014-10-10 241368]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2016-02-25 48704]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2015-11-20 263528]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2015-11-20 186784]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [2015-11-20 170792]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 athr;@oem40.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\System32\drivers\athw10x.sys [2015-06-26 4325544]
R3 ATP;@oem21.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2015-08-23 100776]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2015-06-29 609992]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2015-10-30 84992]
R3 HIDSwitch;@oem34.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2015-05-13 19976]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2015-08-27 3797424]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-06-04 3441992]
R3 IntcDAud;@oem45.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 iwdbus;@oem41.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2015-07-20 38976]
R3 kbfiltr;@oem7.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 MEIx64;@oem22.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-02-25 12479040]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-02-17 28032]
R3 nvvad_WaveExtensible;@oem51.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2015-12-18 47760]
R3 RSBASTOR;@oem32.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\WINDOWS\system32\DRIVERS\RtsBaStor.sys [2015-07-08 321792]
R3 rt640x64;@oem39.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-07-07 895256]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2015-11-20 14976]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-02-23 954368]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-01-16 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 intaud_WaveExtensible;@oem3.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2015-07-20 50240]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-10-28 82128]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2012-10-05 110976]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2015-11-20 2522616]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-02-17 1164672]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-09-13 2466448]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2015-08-27 330136]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-02-17 1880960]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-02-17 2609024]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2016-02-23 1263040]
R2 OneSyncSvc_33cd0;Hostitel synchronizace_33cd0; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
R3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2015-08-27 291744]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
R3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-02-17 6474112]
R3 PimIndexMaintenanceSvc_33cd0;Data kontaktů_33cd0; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 UnistoreSvc_33cd0;Úložiště uživatelských dat_33cd0; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [2012-12-19 72192]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-21 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_33cd0;Služba zasílání zpráv_33cd0; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-02-13 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 03 bře 2016 22:30
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Petr.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
O3 - Toolbar: eShield - {C45CC4A0-915D-4B42-B3FB-EB52FD41F896} - C:\Program Files (x86)\TNT2\2.0.0.2030\IEToolbar.dll (file missing)
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Dále otevřte nastavení sítě a tyto údaje (IP): 82.163.142.7 a 95.211.158.134 přepište tak, aby byly v souladu s tím, co máte uvedeno ve smlouvě o připojení k internetu. Pochybuji, že některý z tuzemských poskytovatelů internetu má doménové servery v Holandsku a Izraeli. Myslím, že to přepsal virus.

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 03 bře 2016 22:58
od Olivis
Díky, stránky již nevyskakují, už to vypadá celkem dobře.

IP adresu získávám z DHCP serveru automaticky, tak nevím.

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 04 bře 2016 19:05
od Rudy
Zkuste to z nastavení sítě vymazat. IP si pro jistotu poznamenejte, kdyby jste to musel vrátit. Ty IP se mi ale pranic nelíbí.

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 04 bře 2016 23:08
od Olivis
Jen bych potřeboval poradit, kde to nastavení ve W10 najdu.

Děkuji

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 05 bře 2016 09:37
od Olivis
Nyní nastal nový problém, nejde mi zpustit nabídka start (levé tlačítko myši), nelze ovládat hlasitost ani otervřít např. nová oznámení :(

Re: vyskakovací okna, otvírání nechtěných web. stránek

Napsal: 05 bře 2016 11:30
od Rudy
Typický problém desítek. Jiná verze vám toto neudělá. Zkuste obnovu systému k datu, kdy korektně fungoval. Návod na nastavení sítě: https://idoc.vsb.cz/xwiki/wiki/infra/vi ... p-ip-win10 .