redirect okno v chrome appforchrome.com
Napsal: 17 dub 2016 23:24
Ahoj, mám problém, občas mi vyskočí v prohlížeči Chrome samovolně stránka appforchrome.com nebo appforpc.com nebo appforex.com atd.
Zřejmě jsem obět nějakého malwaru.
Může mi prosím někdo poradit?
Předem velké díky!
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martinita at 2016-04-18 00:07:17
Microsoft Windows 10 Home
System drive C: has 220 GB (48%) free of 454 GB
Total RAM: 4046 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:07:46, on 18.4.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal
Running processes:
C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe
C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Martinita.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [SafeInCloud] "C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe" /auto-start
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: OneDrive pro firmy.lnk = C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Vystřihnout záložku - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @oem9.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem20.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12646 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-7c95a89f-7270-44fc-be05-e12b8bb83a1c -SystemEventPortName:HostProcess-ffa027de-fdf2-4125-a496-6bbbf036cf74 -IoCancelEventPortName:HostProcess-69cb9518-1048-42e6-95e8-f02ef9058e3d -NonStateChangingEventPortName:HostProcess-002e750c-e131-4463-a3b1-6239b212835f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:8752beae-6a90-4196-ac5b-09f5f3da4827 -DeviceGroupId:
C:\WINDOWS\system32\svchost.exe -k netsvcs
dashost.exe {4d7ccc55-5ce8-4d10-86d8896bb5b48709}
C:\WINDOWS\system32\Hpservice.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\WINDOWS\system32\BtwRSupportService.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
atieclxx
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe" /auto-start
"C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE" /RunFolderSync /TrayOnly
"C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE" /tsr
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"fontdrvhost.exe"
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.19761.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\WINDOWS\System32\Taskmgr.exe" /3
"C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Martinita\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=49.0.2623.112 --handshake-handle=0x1bc
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4028.0.733635660\1205702108" --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,11,25,54 --gpu-vendor-id=0x1002 --gpu-device-id=0x6841 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.201.1301.0 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/7DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_67/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4028.2.1713631277\92526787" /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/7DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_67/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4028.4.1102178169\1767162192" /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/7DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_67/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4028.12.954079599\1454968615" /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 604 608 616 8192 612
"C:\Users\Martinita\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-15 228552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-22 901600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-03-15 2348336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-03-15 163016]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-22 678656]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-03-15 1741096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-09-17 3944136]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-03-12 551104]
"SafeInCloud"=C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe [2015-11-15 2161664]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-03-28 7139256]
C:\Users\Martinita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneDrive pro firmy.lnk - C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-04-18 00:07:18 ----D---- C:\Program Files\trend micro
2016-04-18 00:07:17 ----D---- C:\rsit
2016-04-15 22:23:21 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-04-15 22:23:19 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-04-15 22:23:14 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-04-15 22:23:12 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-15 22:23:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-04-15 22:23:07 ----A---- C:\WINDOWS\system32\twinui.dll
2016-04-15 22:23:06 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-04-15 22:23:02 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-04-15 22:23:00 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-04-15 22:22:59 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-15 22:22:55 ----A---- C:\WINDOWS\system32\wininet.dll
2016-04-15 22:22:54 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-04-15 22:22:52 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-04-15 22:22:51 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-04-15 22:22:51 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-04-15 22:22:51 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-15 22:22:50 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-04-15 22:22:48 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-04-15 22:22:47 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-04-15 22:22:47 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-04-15 22:22:46 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-15 22:22:46 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-04-15 22:22:45 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-04-15 22:22:44 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-04-15 22:22:44 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-04-15 22:22:44 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-15 22:22:43 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-04-15 22:22:43 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-15 22:22:43 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-04-15 22:22:42 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-04-15 22:22:42 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-04-15 22:22:41 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-04-15 22:22:41 ----A---- C:\WINDOWS\system32\esent.dll
2016-04-15 22:22:40 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\system32\dosvc.dll
2016-04-15 22:22:38 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-04-15 22:22:38 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-04-15 22:22:38 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-04-15 22:22:37 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-04-15 22:22:37 ----A---- C:\WINDOWS\SYSWOW64\esent.dll
2016-04-15 22:22:36 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-15 22:22:36 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-04-15 22:22:35 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-15 22:22:35 ----A---- C:\WINDOWS\system32\SRH.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\system32\InputService.dll
2016-04-15 22:22:33 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-15 22:22:33 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2016-04-15 22:22:33 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-15 22:22:32 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-04-15 22:22:32 ----A---- C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-15 22:22:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-04-15 22:22:31 ----A---- C:\WINDOWS\system32\winload.exe
2016-04-15 22:22:31 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-04-15 22:22:30 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-15 22:22:29 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-04-15 22:22:28 ----A---- C:\WINDOWS\system32\RDXService.dll
2016-04-15 22:22:26 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-04-15 22:22:26 ----A---- C:\WINDOWS\system32\winresume.exe
2016-04-15 22:22:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-04-15 22:22:25 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-15 22:22:25 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-04-15 22:22:24 ----A---- C:\WINDOWS\system32\tileobjserver.dll
2016-04-15 22:22:24 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-15 22:22:24 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-04-15 22:22:23 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-04-15 22:22:23 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-04-15 22:22:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\system32\AccountsRt.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\SYSWOW64\AccountsRt.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2016-04-15 22:22:19 ----A---- C:\WINDOWS\SYSWOW64\RemoteNaturalLanguage.dll
2016-04-15 22:22:19 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-04-15 22:22:19 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2016-04-15 22:22:19 ----A---- C:\WINDOWS\system32\msxml3.dll
2016-04-15 22:22:19 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-04-15 22:22:18 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2016-04-15 22:22:18 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-04-15 22:22:18 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-15 22:22:18 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-04-15 22:22:16 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2016-04-15 22:22:16 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-04-15 22:22:15 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-15 22:22:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Cred.dll
2016-04-15 22:22:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-04-15 22:22:14 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-04-15 22:22:13 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-15 22:22:13 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-04-15 22:22:12 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-04-15 22:22:12 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-04-15 22:22:09 ----A---- C:\WINDOWS\system32\wuapi.dll
2016-04-15 22:22:08 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-04-15 22:22:08 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-15 22:22:08 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2016-04-15 22:22:08 ----A---- C:\WINDOWS\system32\bdesvc.dll
2016-04-15 22:22:07 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2016-04-15 22:22:07 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2016-04-15 22:22:07 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-04-15 22:22:06 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-04-15 22:22:06 ----A---- C:\WINDOWS\system32\drivers\rfcomm.sys
2016-04-15 22:22:06 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\msi.dll
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\drivers\ufx01000.sys
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\dnsapi.dll
2016-04-15 22:22:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2016-04-15 22:22:03 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\SYSWOW64\MsSpellCheckingFacility.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\system32\dafBth.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2016-04-15 22:22:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\profsvc.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\LsaIso.exe
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-15 22:21:59 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-04-15 22:21:59 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2016-04-15 22:21:59 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-04-15 22:21:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\policymanager.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\ncbservice.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\drivers\http.sys
2016-04-15 22:21:54 ----A---- C:\WINDOWS\system32\fveui.dll
2016-04-15 22:21:54 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2016-04-15 22:21:54 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\samsrv.dll
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\omadmapi.dll
2016-04-15 22:21:52 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2016-04-15 22:21:52 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2016-04-15 22:21:51 ----A---- C:\WINDOWS\SYSWOW64\srvcli.dll
2016-04-15 22:21:51 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-04-15 22:21:51 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-04-15 22:21:50 ----A---- C:\WINDOWS\SYSWOW64\mdmregistration.dll
2016-04-15 22:21:50 ----A---- C:\WINDOWS\system32\srvcli.dll
2016-04-15 22:21:50 ----A---- C:\WINDOWS\system32\netapi32.dll
2016-04-15 22:21:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2016-04-15 22:21:49 ----A---- C:\WINDOWS\SYSWOW64\netapi32.dll
2016-04-15 22:21:49 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Devices.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\SYSWOW64\VEDataLayerHelpers.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\system32\wkscli.dll
2016-04-15 22:21:47 ----A---- C:\WINDOWS\SYSWOW64\wkscli.dll
2016-04-15 22:21:47 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-04-15 22:21:46 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-04-15 22:21:46 ----A---- C:\WINDOWS\system32\iuilp.dll
2016-04-15 22:21:46 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2016-04-15 22:21:46 ----A---- C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-15 22:21:45 ----A---- C:\WINDOWS\SYSWOW64\SensorsNativeApi.dll
2016-04-15 22:21:45 ----A---- C:\WINDOWS\system32\oleacc.dll
2016-04-15 22:21:45 ----A---- C:\WINDOWS\system32\easinvoker.exe
2016-04-15 22:21:45 ----A---- C:\WINDOWS\system32\drivers\WdiWiFi.sys
2016-04-15 22:21:44 ----A---- C:\WINDOWS\SYSWOW64\WSDApi.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\win32spl.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\ieproxy.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-04-15 22:21:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2016-04-15 22:21:43 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2016-04-15 22:21:43 ----A---- C:\WINDOWS\system32\wsdchngr.dll
2016-04-15 22:21:43 ----A---- C:\WINDOWS\system32\DAFWSD.dll
2016-04-15 22:21:42 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2016-04-15 22:21:42 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2016-04-15 22:21:41 ----A---- C:\WINDOWS\SYSWOW64\VEEventDispatcher.dll
2016-04-15 22:21:41 ----A---- C:\WINDOWS\system32\credprovhost.dll
2016-04-15 22:21:40 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-04-15 22:21:38 ----A---- C:\WINDOWS\system32\easwrt.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\SYSWOW64\wsdchngr.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\SYSWOW64\NotificationObjFactory.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\dmcsps.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\browserbroker.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\system32\WSDApi.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-15 22:21:35 ----A---- C:\WINDOWS\SYSWOW64\credprovhost.dll
2016-04-15 22:21:35 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2016-04-15 22:21:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-15 22:21:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-15 22:21:34 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-15 22:21:34 ----A---- C:\WINDOWS\system32\actxprxy.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\SYSWOW64\browcli.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\fvewiz.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\browser.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\basesrv.dll
2016-04-15 22:21:32 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-04-15 22:21:32 ----A---- C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-15 22:21:32 ----A---- C:\WINDOWS\system32\drivers\bthenum.sys
2016-04-15 22:21:32 ----A---- C:\WINDOWS\system32\browcli.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\SYSWOW64\msorcl32.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\system32\fvecpl.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\system32\tbauth.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\system32\fveskybackup.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\system32\BFE.DLL
2016-04-15 22:21:29 ----A---- C:\WINDOWS\SYSWOW64\easwrt.dll
2016-04-15 22:21:29 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-15 22:21:29 ----A---- C:\WINDOWS\system32\drivers\serial.sys
2016-04-15 22:21:29 ----A---- C:\WINDOWS\system32\drivers\BthLEEnum.sys
2016-04-15 22:21:28 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-04-15 22:21:27 ----A---- C:\WINDOWS\system32\samlib.dll
2016-04-15 22:21:26 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-04-15 22:21:26 ----A---- C:\WINDOWS\SYSWOW64\FWPUCLNT.DLL
2016-04-15 22:21:26 ----A---- C:\WINDOWS\system32\wups.dll
2016-04-15 22:21:26 ----A---- C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-15 22:21:25 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2016-04-15 22:21:25 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2016-04-15 22:21:25 ----A---- C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-15 22:21:25 ----A---- C:\WINDOWS\system32\moshost.dll
2016-04-15 22:21:25 ----A---- C:\WINDOWS\system32\FontProvider.dll
2016-04-15 22:21:24 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-15 22:21:24 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2016-04-15 22:21:23 ----A---- C:\WINDOWS\system32\mos.dll
2016-04-15 22:21:23 ----A---- C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-15 22:21:22 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-04-15 22:21:22 ----A---- C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-15 22:21:21 ----A---- C:\WINDOWS\SYSWOW64\mtxoci.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\mtxoci.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\SensorsNativeApi.V2.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\samlib.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\OnDemandConnRouteHelper.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\SYSWOW64\oleacchooks.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\system32\oleacchooks.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-04-15 22:21:18 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-04-15 22:21:18 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-04-15 22:21:18 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-04-15 22:21:18 ----A---- C:\WINDOWS\system32\drivers\xinputhid.sys
2016-04-15 22:21:18 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-04-15 22:21:17 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-04-15 22:21:17 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-04-15 22:21:17 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-04-15 22:21:17 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-04-15 22:21:16 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-04-15 22:21:16 ----A---- C:\WINDOWS\system32\MTF.dll
2016-04-15 22:21:16 ----A---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2016-04-15 22:21:16 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-04-15 22:21:15 ----A---- C:\WINDOWS\SYSWOW64\MTF.dll
2016-04-03 19:56:25 ----AD---- C:\Program Files (x86)\XMind
======List of files/folders modified in the last 1 month======
2016-04-18 00:07:18 ----RD---- C:\Program Files
2016-04-17 23:57:36 ----RSD---- C:\WINDOWS\assembly
2016-04-17 23:57:36 ----D---- C:\WINDOWS\Microsoft.NET
2016-04-17 23:54:09 ----D---- C:\WINDOWS\Temp
2016-04-17 23:40:57 ----D---- C:\WINDOWS\Prefetch
2016-04-17 23:36:27 ----D---- C:\WINDOWS\system32\sru
2016-04-17 19:26:51 ----D---- C:\WINDOWS\INF
2016-04-17 19:26:51 ----AD---- C:\WINDOWS\System32
2016-04-17 19:26:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-17 04:11:24 ----D---- C:\WINDOWS\system32\config
2016-04-17 04:08:55 ----D---- C:\WINDOWS\WinSxS
2016-04-17 04:08:54 ----D---- C:\WINDOWS\SysWOW64
2016-04-17 04:08:38 ----D---- C:\WINDOWS\CbsTemp
2016-04-17 04:06:02 ----HD---- C:\Program Files\WindowsApps
2016-04-17 04:05:05 ----D---- C:\WINDOWS\AppReadiness
2016-04-17 03:56:55 ----D---- C:\WINDOWS\system32\drivers
2016-04-17 03:56:54 ----SHDC---- C:\WINDOWS\Installer
2016-04-17 03:56:54 ----SHD---- C:\Config.Msi
2016-04-17 03:52:42 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-04-17 03:52:34 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2016-04-17 03:52:34 ----D---- C:\WINDOWS\system32\cs-CZ
2016-04-17 03:52:33 ----D---- C:\WINDOWS\system32\Boot
2016-04-17 03:52:33 ----D---- C:\WINDOWS\system32\appraiser
2016-04-17 03:52:27 ----D---- C:\WINDOWS\PolicyDefinitions
2016-04-17 03:52:26 ----D---- C:\WINDOWS\bcastdvr
2016-04-17 03:52:26 ----D---- C:\WINDOWS\AppPatch
2016-04-17 03:52:19 ----D---- C:\WINDOWS\system32\DriverStore
2016-04-16 14:06:57 ----SHD---- C:\System Volume Information
2016-04-15 23:01:01 ----D---- C:\ProgramData\Microsoft Help
2016-04-15 22:52:54 ----D---- C:\WINDOWS\system32\MRT
2016-04-15 22:42:28 ----A---- C:\WINDOWS\system32\MRT.exe
2016-04-15 22:02:11 ----D---- C:\WINDOWS\system32\catroot2
2016-04-11 19:19:13 ----HD---- C:\ProgramData
2016-04-07 19:36:24 ----D---- C:\WINDOWS\system32\Tasks
2016-04-06 20:32:08 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-04-03 19:56:58 ----RSD---- C:\WINDOWS\Fonts
2016-04-03 19:56:25 ----RD---- C:\Program Files (x86)
2016-03-25 16:40:29 ----D---- C:\WINDOWS\system32\NDF
2016-03-25 01:23:04 ----D---- C:\Program Files (x86)\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-02-22 74544]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-02-22 287016]
R0 hpdskflt;@oem20.inf,%service_desc%;HP Filter; C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [2013-11-13 31040]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2016-02-22 37144]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2016-02-22 103064]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-03-12 1070904]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-02-26 463744]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-02-22 37656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-03-12 107792]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2016-02-22 165344]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 Accelerometer;@oem20.inf,%accelerometer_desc%;HP Mobile Data Protection Sensor; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2013-11-13 43328]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-10-09 21654032]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-10-09 685064]
R3 AtiHDAudioService;@oem2.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2015-05-28 102912]
R3 bcbtums;@oem9.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-10-14 208176]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2016-03-29 112640]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-03-29 245760]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2016-03-29 84992]
R3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\System32\drivers\e1i63x64.sys [2015-10-30 472576]
R3 JMCR;JMCR; C:\WINDOWS\System32\drivers\jmcr.sys [2013-10-30 176880]
R3 MEIx64;@oem3.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2013-10-24 62784]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2015-12-11 175616]
R3 NETwNe64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\WINDOWS\System32\drivers\NETwew01.sys [2015-10-30 3343872]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2016-03-29 181248]
R3 SNP2UVC;@oem23.inf,%SERVICE_DISPLAY_NAME%;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2015-12-10 1866080]
R3 SynTP;@oem12.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-09-17 614088]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-03-29 954368]
S3 btwampfl;@oem9.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-10-14 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-11 117248]
S3 dg_ssudbus;@oem11.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2015-12-08 122160]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 ssudmdm;@oem5.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2015-12-08 214832]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2016-03-29 258912]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-14 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-10-09 264224]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-02-22 237096]
R2 BcmBtRSupport;@oem9.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-10-14 2286848]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2016-02-09 2828016]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 hpsrv;@oem20.inf,%hpservice_desc%;HP Service; C:\WINDOWS\system32\Hpservice.exe [2013-11-13 33600]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2015-12-11 26624]
R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
R2 OneSyncSvc_728c7;Hostitel synchronizace_728c7; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-09-17 246472]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-09-11 150600]
R3 PimIndexMaintenanceSvc_728c7;Data kontaktů_728c7; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-13 269000]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2015-10-18 654848]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_728c7;Služba zasílání zpráv_728c7; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S4 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------
Zřejmě jsem obět nějakého malwaru.
Může mi prosím někdo poradit?
Předem velké díky!
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martinita at 2016-04-18 00:07:17
Microsoft Windows 10 Home
System drive C: has 220 GB (48%) free of 454 GB
Total RAM: 4046 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:07:46, on 18.4.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal
Running processes:
C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe
C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Martinita.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [SafeInCloud] "C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe" /auto-start
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: OneDrive pro firmy.lnk = C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Vystřihnout záložku - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @oem9.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem20.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12646 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-7c95a89f-7270-44fc-be05-e12b8bb83a1c -SystemEventPortName:HostProcess-ffa027de-fdf2-4125-a496-6bbbf036cf74 -IoCancelEventPortName:HostProcess-69cb9518-1048-42e6-95e8-f02ef9058e3d -NonStateChangingEventPortName:HostProcess-002e750c-e131-4463-a3b1-6239b212835f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:8752beae-6a90-4196-ac5b-09f5f3da4827 -DeviceGroupId:
C:\WINDOWS\system32\svchost.exe -k netsvcs
dashost.exe {4d7ccc55-5ce8-4d10-86d8896bb5b48709}
C:\WINDOWS\system32\Hpservice.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\WINDOWS\system32\BtwRSupportService.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
atieclxx
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
sihost.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe" /auto-start
"C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE" /RunFolderSync /TrayOnly
"C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE" /tsr
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"fontdrvhost.exe"
"C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" "C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE" -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.19761.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\WINDOWS\System32\Taskmgr.exe" /3
"C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Martinita\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=49.0.2623.112 --handshake-handle=0x1bc
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4028.0.733635660\1205702108" --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,11,25,54 --gpu-vendor-id=0x1002 --gpu-device-id=0x6841 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.201.1301.0 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/7DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_67/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4028.2.1713631277\92526787" /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/7DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_67/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4028.4.1102178169\1767162192" /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/7DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_67/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_02/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="4028.12.954079599\1454968615" /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 604 608 616 8192 612
"C:\Users\Martinita\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-15 228552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-22 901600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-03-15 2348336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-03-15 163016]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-22 678656]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-03-15 1741096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-09-17 3944136]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-03-12 551104]
"SafeInCloud"=C:\Program Files (x86)\Safe In Cloud\SafeInCloud.exe [2015-11-15 2161664]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
"Uninstall C:\Users\Martinita\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-03-28 7139256]
C:\Users\Martinita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneDrive pro firmy.lnk - C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-04-18 00:07:18 ----D---- C:\Program Files\trend micro
2016-04-18 00:07:17 ----D---- C:\rsit
2016-04-15 22:23:21 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-04-15 22:23:19 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-04-15 22:23:14 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-04-15 22:23:12 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-15 22:23:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-04-15 22:23:07 ----A---- C:\WINDOWS\system32\twinui.dll
2016-04-15 22:23:06 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-04-15 22:23:02 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-04-15 22:23:00 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-04-15 22:22:59 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-15 22:22:55 ----A---- C:\WINDOWS\system32\wininet.dll
2016-04-15 22:22:54 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-04-15 22:22:52 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-04-15 22:22:51 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-04-15 22:22:51 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-04-15 22:22:51 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-15 22:22:50 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-04-15 22:22:48 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-04-15 22:22:47 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-04-15 22:22:47 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-04-15 22:22:46 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-15 22:22:46 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-04-15 22:22:45 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-04-15 22:22:44 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-04-15 22:22:44 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-04-15 22:22:44 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-15 22:22:43 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-04-15 22:22:43 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-15 22:22:43 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-04-15 22:22:42 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-04-15 22:22:42 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-04-15 22:22:41 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-04-15 22:22:41 ----A---- C:\WINDOWS\system32\esent.dll
2016-04-15 22:22:40 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-04-15 22:22:39 ----A---- C:\WINDOWS\system32\dosvc.dll
2016-04-15 22:22:38 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-04-15 22:22:38 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-04-15 22:22:38 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-04-15 22:22:37 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-04-15 22:22:37 ----A---- C:\WINDOWS\SYSWOW64\esent.dll
2016-04-15 22:22:36 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-15 22:22:36 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-04-15 22:22:35 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-15 22:22:35 ----A---- C:\WINDOWS\system32\SRH.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-04-15 22:22:34 ----A---- C:\WINDOWS\system32\InputService.dll
2016-04-15 22:22:33 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-15 22:22:33 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2016-04-15 22:22:33 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-15 22:22:32 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-04-15 22:22:32 ----A---- C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-15 22:22:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-04-15 22:22:31 ----A---- C:\WINDOWS\system32\winload.exe
2016-04-15 22:22:31 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-04-15 22:22:30 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-15 22:22:29 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-04-15 22:22:28 ----A---- C:\WINDOWS\system32\RDXService.dll
2016-04-15 22:22:26 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-04-15 22:22:26 ----A---- C:\WINDOWS\system32\winresume.exe
2016-04-15 22:22:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-04-15 22:22:25 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-15 22:22:25 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-04-15 22:22:24 ----A---- C:\WINDOWS\system32\tileobjserver.dll
2016-04-15 22:22:24 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-15 22:22:24 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-04-15 22:22:23 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-04-15 22:22:23 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-04-15 22:22:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-04-15 22:22:22 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-04-15 22:22:21 ----A---- C:\WINDOWS\system32\AccountsRt.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\SYSWOW64\AccountsRt.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-15 22:22:20 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2016-04-15 22:22:19 ----A---- C:\WINDOWS\SYSWOW64\RemoteNaturalLanguage.dll
2016-04-15 22:22:19 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-04-15 22:22:19 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2016-04-15 22:22:19 ----A---- C:\WINDOWS\system32\msxml3.dll
2016-04-15 22:22:19 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-04-15 22:22:18 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2016-04-15 22:22:18 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-04-15 22:22:18 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-15 22:22:18 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-15 22:22:17 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-04-15 22:22:16 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2016-04-15 22:22:16 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-04-15 22:22:15 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-15 22:22:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Cred.dll
2016-04-15 22:22:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-04-15 22:22:14 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-04-15 22:22:13 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-15 22:22:13 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-04-15 22:22:12 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-04-15 22:22:12 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-04-15 22:22:09 ----A---- C:\WINDOWS\system32\wuapi.dll
2016-04-15 22:22:08 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-04-15 22:22:08 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-15 22:22:08 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2016-04-15 22:22:08 ----A---- C:\WINDOWS\system32\bdesvc.dll
2016-04-15 22:22:07 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2016-04-15 22:22:07 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2016-04-15 22:22:07 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-04-15 22:22:06 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-04-15 22:22:06 ----A---- C:\WINDOWS\system32\drivers\rfcomm.sys
2016-04-15 22:22:06 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2016-04-15 22:22:05 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\msi.dll
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\drivers\ufx01000.sys
2016-04-15 22:22:04 ----A---- C:\WINDOWS\system32\dnsapi.dll
2016-04-15 22:22:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2016-04-15 22:22:03 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\SYSWOW64\MsSpellCheckingFacility.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\system32\dafBth.dll
2016-04-15 22:22:02 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2016-04-15 22:22:01 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2016-04-15 22:22:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\profsvc.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\LsaIso.exe
2016-04-15 22:22:00 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-15 22:21:59 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-04-15 22:21:59 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2016-04-15 22:21:59 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-04-15 22:21:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\policymanager.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\ncbservice.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2016-04-15 22:21:55 ----A---- C:\WINDOWS\system32\drivers\http.sys
2016-04-15 22:21:54 ----A---- C:\WINDOWS\system32\fveui.dll
2016-04-15 22:21:54 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2016-04-15 22:21:54 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\samsrv.dll
2016-04-15 22:21:53 ----A---- C:\WINDOWS\system32\omadmapi.dll
2016-04-15 22:21:52 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2016-04-15 22:21:52 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2016-04-15 22:21:51 ----A---- C:\WINDOWS\SYSWOW64\srvcli.dll
2016-04-15 22:21:51 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-04-15 22:21:51 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-04-15 22:21:50 ----A---- C:\WINDOWS\SYSWOW64\mdmregistration.dll
2016-04-15 22:21:50 ----A---- C:\WINDOWS\system32\srvcli.dll
2016-04-15 22:21:50 ----A---- C:\WINDOWS\system32\netapi32.dll
2016-04-15 22:21:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2016-04-15 22:21:49 ----A---- C:\WINDOWS\SYSWOW64\netapi32.dll
2016-04-15 22:21:49 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Devices.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\SYSWOW64\VEDataLayerHelpers.dll
2016-04-15 22:21:48 ----A---- C:\WINDOWS\system32\wkscli.dll
2016-04-15 22:21:47 ----A---- C:\WINDOWS\SYSWOW64\wkscli.dll
2016-04-15 22:21:47 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-04-15 22:21:46 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-04-15 22:21:46 ----A---- C:\WINDOWS\system32\iuilp.dll
2016-04-15 22:21:46 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2016-04-15 22:21:46 ----A---- C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-15 22:21:45 ----A---- C:\WINDOWS\SYSWOW64\SensorsNativeApi.dll
2016-04-15 22:21:45 ----A---- C:\WINDOWS\system32\oleacc.dll
2016-04-15 22:21:45 ----A---- C:\WINDOWS\system32\easinvoker.exe
2016-04-15 22:21:45 ----A---- C:\WINDOWS\system32\drivers\WdiWiFi.sys
2016-04-15 22:21:44 ----A---- C:\WINDOWS\SYSWOW64\WSDApi.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\win32spl.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\ieproxy.dll
2016-04-15 22:21:44 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-04-15 22:21:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2016-04-15 22:21:43 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2016-04-15 22:21:43 ----A---- C:\WINDOWS\system32\wsdchngr.dll
2016-04-15 22:21:43 ----A---- C:\WINDOWS\system32\DAFWSD.dll
2016-04-15 22:21:42 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2016-04-15 22:21:42 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2016-04-15 22:21:41 ----A---- C:\WINDOWS\SYSWOW64\VEEventDispatcher.dll
2016-04-15 22:21:41 ----A---- C:\WINDOWS\system32\credprovhost.dll
2016-04-15 22:21:40 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-04-15 22:21:38 ----A---- C:\WINDOWS\system32\easwrt.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\SYSWOW64\wsdchngr.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\SYSWOW64\NotificationObjFactory.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\dmcsps.dll
2016-04-15 22:21:37 ----A---- C:\WINDOWS\system32\browserbroker.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\system32\WSDApi.dll
2016-04-15 22:21:36 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-15 22:21:35 ----A---- C:\WINDOWS\SYSWOW64\credprovhost.dll
2016-04-15 22:21:35 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2016-04-15 22:21:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-15 22:21:34 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-15 22:21:34 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-15 22:21:34 ----A---- C:\WINDOWS\system32\actxprxy.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\SYSWOW64\browcli.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\fvewiz.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\browser.dll
2016-04-15 22:21:33 ----A---- C:\WINDOWS\system32\basesrv.dll
2016-04-15 22:21:32 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-04-15 22:21:32 ----A---- C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-15 22:21:32 ----A---- C:\WINDOWS\system32\drivers\bthenum.sys
2016-04-15 22:21:32 ----A---- C:\WINDOWS\system32\browcli.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\SYSWOW64\msorcl32.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-04-15 22:21:31 ----A---- C:\WINDOWS\system32\fvecpl.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\system32\tbauth.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\system32\fveskybackup.dll
2016-04-15 22:21:30 ----A---- C:\WINDOWS\system32\BFE.DLL
2016-04-15 22:21:29 ----A---- C:\WINDOWS\SYSWOW64\easwrt.dll
2016-04-15 22:21:29 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-15 22:21:29 ----A---- C:\WINDOWS\system32\drivers\serial.sys
2016-04-15 22:21:29 ----A---- C:\WINDOWS\system32\drivers\BthLEEnum.sys
2016-04-15 22:21:28 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-04-15 22:21:27 ----A---- C:\WINDOWS\system32\samlib.dll
2016-04-15 22:21:26 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-04-15 22:21:26 ----A---- C:\WINDOWS\SYSWOW64\FWPUCLNT.DLL
2016-04-15 22:21:26 ----A---- C:\WINDOWS\system32\wups.dll
2016-04-15 22:21:26 ----A---- C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-15 22:21:25 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2016-04-15 22:21:25 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2016-04-15 22:21:25 ----A---- C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-15 22:21:25 ----A---- C:\WINDOWS\system32\moshost.dll
2016-04-15 22:21:25 ----A---- C:\WINDOWS\system32\FontProvider.dll
2016-04-15 22:21:24 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-15 22:21:24 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2016-04-15 22:21:23 ----A---- C:\WINDOWS\system32\mos.dll
2016-04-15 22:21:23 ----A---- C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-15 22:21:22 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-04-15 22:21:22 ----A---- C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-15 22:21:21 ----A---- C:\WINDOWS\SYSWOW64\mtxoci.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\mtxoci.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-15 22:21:21 ----A---- C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\SensorsNativeApi.V2.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\samlib.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\OnDemandConnRouteHelper.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-04-15 22:21:20 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\SYSWOW64\oleacchooks.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\system32\oleacchooks.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-15 22:21:19 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-04-15 22:21:18 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-04-15 22:21:18 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-04-15 22:21:18 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-04-15 22:21:18 ----A---- C:\WINDOWS\system32\drivers\xinputhid.sys
2016-04-15 22:21:18 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-04-15 22:21:17 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-04-15 22:21:17 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-04-15 22:21:17 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-04-15 22:21:17 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-04-15 22:21:16 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-04-15 22:21:16 ----A---- C:\WINDOWS\system32\MTF.dll
2016-04-15 22:21:16 ----A---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2016-04-15 22:21:16 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-04-15 22:21:15 ----A---- C:\WINDOWS\SYSWOW64\MTF.dll
2016-04-03 19:56:25 ----AD---- C:\Program Files (x86)\XMind
======List of files/folders modified in the last 1 month======
2016-04-18 00:07:18 ----RD---- C:\Program Files
2016-04-17 23:57:36 ----RSD---- C:\WINDOWS\assembly
2016-04-17 23:57:36 ----D---- C:\WINDOWS\Microsoft.NET
2016-04-17 23:54:09 ----D---- C:\WINDOWS\Temp
2016-04-17 23:40:57 ----D---- C:\WINDOWS\Prefetch
2016-04-17 23:36:27 ----D---- C:\WINDOWS\system32\sru
2016-04-17 19:26:51 ----D---- C:\WINDOWS\INF
2016-04-17 19:26:51 ----AD---- C:\WINDOWS\System32
2016-04-17 19:26:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-17 04:11:24 ----D---- C:\WINDOWS\system32\config
2016-04-17 04:08:55 ----D---- C:\WINDOWS\WinSxS
2016-04-17 04:08:54 ----D---- C:\WINDOWS\SysWOW64
2016-04-17 04:08:38 ----D---- C:\WINDOWS\CbsTemp
2016-04-17 04:06:02 ----HD---- C:\Program Files\WindowsApps
2016-04-17 04:05:05 ----D---- C:\WINDOWS\AppReadiness
2016-04-17 03:56:55 ----D---- C:\WINDOWS\system32\drivers
2016-04-17 03:56:54 ----SHDC---- C:\WINDOWS\Installer
2016-04-17 03:56:54 ----SHD---- C:\Config.Msi
2016-04-17 03:52:42 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-04-17 03:52:34 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2016-04-17 03:52:34 ----D---- C:\WINDOWS\system32\cs-CZ
2016-04-17 03:52:33 ----D---- C:\WINDOWS\system32\Boot
2016-04-17 03:52:33 ----D---- C:\WINDOWS\system32\appraiser
2016-04-17 03:52:27 ----D---- C:\WINDOWS\PolicyDefinitions
2016-04-17 03:52:26 ----D---- C:\WINDOWS\bcastdvr
2016-04-17 03:52:26 ----D---- C:\WINDOWS\AppPatch
2016-04-17 03:52:19 ----D---- C:\WINDOWS\system32\DriverStore
2016-04-16 14:06:57 ----SHD---- C:\System Volume Information
2016-04-15 23:01:01 ----D---- C:\ProgramData\Microsoft Help
2016-04-15 22:52:54 ----D---- C:\WINDOWS\system32\MRT
2016-04-15 22:42:28 ----A---- C:\WINDOWS\system32\MRT.exe
2016-04-15 22:02:11 ----D---- C:\WINDOWS\system32\catroot2
2016-04-11 19:19:13 ----HD---- C:\ProgramData
2016-04-07 19:36:24 ----D---- C:\WINDOWS\system32\Tasks
2016-04-06 20:32:08 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-04-03 19:56:58 ----RSD---- C:\WINDOWS\Fonts
2016-04-03 19:56:25 ----RD---- C:\Program Files (x86)
2016-03-25 16:40:29 ----D---- C:\WINDOWS\system32\NDF
2016-03-25 01:23:04 ----D---- C:\Program Files (x86)\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-02-22 74544]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-02-22 287016]
R0 hpdskflt;@oem20.inf,%service_desc%;HP Filter; C:\WINDOWS\system32\DRIVERS\hpdskflt.sys [2013-11-13 31040]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2016-02-22 37144]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2016-02-22 103064]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-03-12 1070904]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-02-26 463744]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-02-22 37656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-03-12 107792]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2016-02-22 165344]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 Accelerometer;@oem20.inf,%accelerometer_desc%;HP Mobile Data Protection Sensor; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [2013-11-13 43328]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-10-09 21654032]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-10-09 685064]
R3 AtiHDAudioService;@oem2.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2015-05-28 102912]
R3 bcbtums;@oem9.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-10-14 208176]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2016-03-29 112640]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-03-29 245760]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2016-03-29 84992]
R3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\System32\drivers\e1i63x64.sys [2015-10-30 472576]
R3 JMCR;JMCR; C:\WINDOWS\System32\drivers\jmcr.sys [2013-10-30 176880]
R3 MEIx64;@oem3.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2013-10-24 62784]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2015-12-11 175616]
R3 NETwNe64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\WINDOWS\System32\drivers\NETwew01.sys [2015-10-30 3343872]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2016-03-29 181248]
R3 SNP2UVC;@oem23.inf,%SERVICE_DISPLAY_NAME%;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2015-12-10 1866080]
R3 SynTP;@oem12.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-09-17 614088]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-03-29 954368]
S3 btwampfl;@oem9.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-10-14 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-11 117248]
S3 dg_ssudbus;@oem11.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2015-12-08 122160]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 ssudmdm;@oem5.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2015-12-08 214832]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2016-03-29 258912]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-14 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-10-09 264224]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-02-22 237096]
R2 BcmBtRSupport;@oem9.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-10-14 2286848]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2016-02-09 2828016]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 hpsrv;@oem20.inf,%hpservice_desc%;HP Service; C:\WINDOWS\system32\Hpservice.exe [2013-11-13 33600]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2015-12-11 26624]
R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
R2 OneSyncSvc_728c7;Hostitel synchronizace_728c7; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-09-17 246472]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-09-11 150600]
R3 PimIndexMaintenanceSvc_728c7;Data kontaktů_728c7; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-13 269000]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2015-10-18 654848]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_728c7;Služba zasílání zpráv_728c7; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S4 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------