mrzne ntbk
Napsal: 02 čer 2016 15:07
Dobry den,
prosim o pomoc s ntbk. Po 10 - 15 min prace zamrzne, nepohybuje sa sipka mysi, nefunguje klavesnica. Jedine mozne riesenie je tvrdy restart.
Doteraz vyskusane programy combofix, adwcleaner, mbam, norton sec., superant.sp.ware nepomohli.
Dakujem.
Logfile of random's system information tool 1.10 (written by random/random)
Run by europe at 2016-06-02 15:47:43
Microsoft Windows 8
System drive C: has 360 GB (79%) free of 458 GB
Total RAM: 3986 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:47:53, on 2.6.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17568)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\europe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPNTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPNTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKCU\..\Run: [Power2GoExpress8] "C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Advanced SystemCare 9] "C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service 9 (AdvancedSystemCareService9) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @oem23.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10129 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
--
End of file - 10987 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe"
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
atieclxx
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\WINDOWS\system32\Hpservice.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
dashost.exe {045c503e-d43b-42ce-a2e3e146ed7e1280}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\diMaster.dll" /prefetch:1
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe" /Task
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe" /c /a /s UserSession
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\WINDOWS\System32\hkcmd.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\europe\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=51.0.2704.63 --handshake-handle=0x128
"C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/OutOfProcessPac/Default/PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Disable/PreRead/Default/*QUIC/EnabledNoId/RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SyncHttpContentCompression/Disabled/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --type=gpu-process --channel="4836.0.1260588905\1530341719" --disable-d3d11 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,10,12,13,25,46,54 --gpu-vendor-id=0x1002 --gpu-device-id=0x0000 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.982.6.0 --mojo-platform-channel-handle=1036 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" -byrunkey
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=C23E17BB3D0D41866DC49C38BD70C2F0 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.12.866702404\87773006" --mojo-platform-channel-handle=2980 /prefetch:1
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=480B8948377F85F00F517836B58C3BFD --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.13.1164192649\656705994" --mojo-platform-channel-handle=1064 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=45F4268320F77A828AAE1508BB915BE9 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.14.210707660\421806896" --mojo-platform-channel-handle=2260 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=89A5E25400209ECA5766501BAA47BA2C --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.15.1625941362\826271702" --mojo-platform-channel-handle=3420 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=36CA64AA72301EEC9F36FC08DBBB3168 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.16.770885885\781691296" --mojo-platform-channel-handle=2840 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 552 556 564 65536 560
"C:\Users\europe\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\ASC9_SkipUac_europe.job - C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe /SkipUac
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\HPCeeScheduleForeurope.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForeurope (null)
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12 2472224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 209504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21 1051320]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21 805560]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 6141528]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21 1051320]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21 805560]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-08-24 170304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-08-24 398656]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2016-05-25 1664000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress8"=C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [2013-01-27 1711680]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-05-13 8721624]
"Advanced SystemCare 9"=C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2016-04-26 2022688]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2012-07-26 1475072]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2016-05-31 7943072]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"HP CoolSense"=C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2012-11-05 1343904]
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2012-09-07 581024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-08-24 441856]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-06-02 15:47:43 ----D---- C:\rsit
2016-06-02 15:47:43 ----D---- C:\Program Files\trend micro
2016-06-02 09:44:49 ----D---- C:\WINDOWS\temp
2016-06-02 09:44:47 ----A---- C:\ComboFix.txt
2016-06-02 09:38:16 ----SHD---- C:\$RECYCLE.BIN
2016-06-02 09:25:06 ----A---- C:\WINDOWS\zip.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\SWXCACLS.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\SWSC.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\SWREG.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\sed.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\PEV.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\NIRCMD.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\MBR.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\grep.exe
2016-06-02 09:24:56 ----D---- C:\Qoobox
2016-06-02 09:24:17 ----D---- C:\WINDOWS\erdnt
2016-06-01 14:57:19 ----D---- C:\Users\europe\AppData\Roaming\SUPERAntiSpyware.com
2016-06-01 14:56:01 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2016-06-01 14:56:01 ----D---- C:\Program Files\SUPERAntiSpyware
2016-06-01 14:43:32 ----N---- C:\bootsqm.dat
2016-05-31 22:13:08 ----ASH---- C:\pagefile.sys
2016-05-31 18:30:52 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2016-05-31 18:30:10 ----D---- C:\ProgramData\Malwarebytes
2016-05-31 18:30:10 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-05-31 18:30:10 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2016-05-31 18:30:10 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2016-05-31 18:30:10 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2016-05-31 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_7.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_5.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2016-05-31 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_7.dll
2016-05-31 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_43.dll
2016-05-31 00:28:55 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2016-05-31 00:28:52 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2016-05-31 00:28:51 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2016-05-31 00:28:51 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2016-05-31 00:28:51 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_6.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_4.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_6.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_7.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2016-05-31 00:28:45 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2016-05-31 00:28:45 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2016-05-31 00:28:44 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2016-05-31 00:28:44 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2016-05-31 00:28:36 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2016-05-31 00:28:36 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2016-05-31 00:28:36 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2016-05-31 00:28:35 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2016-05-31 00:28:34 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2016-05-31 00:28:34 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2016-05-31 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2016-05-31 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2016-05-31 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2016-05-31 00:28:30 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2016-05-31 00:28:24 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2016-05-31 00:28:17 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2016-05-31 00:28:17 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2016-05-31 00:28:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2016-05-31 00:28:14 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2016-05-31 00:28:11 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2016-05-31 00:28:10 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2016-05-31 00:28:08 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2016-05-31 00:28:07 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2016-05-31 00:28:06 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2016-05-31 00:28:02 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2016-05-31 00:28:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2016-05-31 00:28:00 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2016-05-31 00:28:00 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2016-05-31 00:28:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2016-05-31 00:27:58 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2016-05-31 00:27:57 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2016-05-31 00:27:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2016-05-31 00:27:55 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2016-05-31 00:27:55 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2016-05-31 00:27:54 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2016-05-31 00:27:53 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2016-05-31 00:27:53 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2016-05-31 00:27:51 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2016-05-31 00:27:50 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2016-05-31 00:27:48 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2016-05-31 00:27:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2016-05-31 00:27:46 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2016-05-31 00:27:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2016-05-31 00:27:44 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2016-05-31 00:27:44 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2016-05-31 00:27:43 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2016-05-31 00:27:42 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2016-05-31 00:27:42 ----A---- C:\WINDOWS\system32\d3dx10.dll
2016-05-31 00:27:41 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2016-05-31 00:27:34 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2016-05-31 00:27:33 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2016-05-31 00:27:32 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2016-05-31 00:27:32 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2016-05-31 00:27:32 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2016-05-31 00:27:31 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2016-05-31 00:27:30 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2016-05-31 00:27:30 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2016-05-31 00:27:29 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2016-05-31 00:27:29 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2016-05-31 00:27:28 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2016-05-31 00:27:28 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2016-05-31 00:27:26 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2016-05-31 00:27:25 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2016-05-31 00:27:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2016-05-31 00:27:18 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2016-05-31 00:27:17 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2016-05-31 00:27:17 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2016-05-31 00:27:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2016-05-31 00:27:16 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2016-05-31 00:27:15 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2016-05-31 00:27:15 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2016-05-31 00:27:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2016-05-31 00:27:14 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2016-05-31 00:27:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2016-05-31 00:27:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2016-05-31 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2016-05-31 00:27:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2016-05-31 00:27:12 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2016-05-31 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2016-05-31 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2016-05-31 00:27:11 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2016-05-31 00:26:06 ----D---- C:\ProgramData\Package Cache
2016-05-31 00:25:44 ----A---- C:\WINDOWS\SYSWOW64\RtCamX.dll
2016-05-31 00:25:44 ----A---- C:\WINDOWS\system32\RtCamX64.dll
2016-05-31 00:25:44 ----A---- C:\WINDOWS\system32\drivers\rtsuvc.sys
2016-05-31 00:25:44 ----A---- C:\WINDOWS\RtsCM64.exe
2016-05-31 00:25:44 ----A---- C:\WINDOWS\RtCamU64.exe
2016-05-30 23:43:43 ----D---- C:\WINDOWS\Minidump
2016-05-28 23:33:14 ----D---- C:\Program Files (x86)\Adobe
2016-05-28 23:32:49 ----D---- C:\ProgramData\Adobe
2016-05-28 23:16:52 ----HD---- C:\ProgramData\CanonIJScan
2016-05-26 13:09:21 ----HD---- C:\ProgramData\CanonIJEPPEX2
2016-05-26 13:09:21 ----HD---- C:\ProgramData\CanonEPP
2016-05-26 13:09:20 ----D---- C:\Users\europe\AppData\Roaming\Canon
2016-05-26 13:05:05 ----A---- C:\WINDOWS\system32\CNMXLMAT.DLL
2016-05-26 13:04:05 ----D---- C:\ProgramData\Canon IJ Network Tool
2016-05-26 13:03:51 ----A---- C:\WINDOWS\SYSWOW64\CNC_ATU.dll
2016-05-26 13:03:51 ----A---- C:\WINDOWS\SYSWOW64\CNC_ATL.dll
2016-05-26 13:03:50 ----A---- C:\WINDOWS\SYSWOW64\CNHMCA.dll
2016-05-26 13:01:42 ----D---- C:\Program Files\Common Files\CANON
2016-05-26 13:01:34 ----D---- C:\ProgramData\CanonIJWSpt
2016-05-26 12:58:42 ----D---- C:\Program Files\Canon
2016-05-26 12:57:28 ----HD---- C:\ProgramData\CanonBJ
2016-05-26 12:57:14 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2016-05-26 12:56:48 ----A---- C:\WINDOWS\system32\CNMLMAT.DLL
2016-05-26 12:56:34 ----A---- C:\WINDOWS\system32\CNMIUAT.DLL
2016-05-26 12:55:37 ----HD---- C:\Program Files\CanonBJ
2016-05-26 12:55:19 ----D---- C:\WINDOWS\system32\STRING
2016-05-26 12:55:19 ----A---- C:\WINDOWS\system32\CNMN6UI.DLL
2016-05-26 12:55:18 ----A---- C:\WINDOWS\SYSWOW64\CNMNPPM.DLL
2016-05-26 12:55:18 ----A---- C:\WINDOWS\system32\CNMN6PPM.DLL
2016-05-26 12:35:45 ----D---- C:\Program Files (x86)\Canon
2016-05-26 11:54:04 ----D---- C:\Program Files (x86)\Microsoft Works
2016-05-26 11:50:24 ----D---- C:\Program Files\Microsoft Office
2016-05-26 11:49:44 ----D---- C:\ProgramData\Microsoft Help
2016-05-26 11:40:24 ----D---- C:\Users\europe\AppData\Roaming\MyPhoneExplorer
2016-05-26 11:40:11 ----D---- C:\Program Files (x86)\MyPhoneExplorer
2016-05-26 01:31:05 ----A---- C:\WINDOWS\system32\RtNicProp64.dll
2016-05-26 01:31:05 ----A---- C:\WINDOWS\system32\drivers\Rt630x64.sys
2016-05-26 01:30:55 ----A---- C:\WINDOWS\SYSWOW64\RsCRIcon.dll
2016-05-26 01:30:55 ----A---- C:\WINDOWS\system32\RtCRX64.dll
2016-05-26 01:30:55 ----A---- C:\WINDOWS\system32\drivers\RtsP2Stor.sys
2016-05-26 01:30:55 ----A---- C:\WINDOWS\RtCRU64.exe
2016-05-26 01:30:11 ----A---- C:\WINDOWS\system32\drivers\athrx.sys
2016-05-26 01:29:59 ----A---- C:\WINDOWS\system32\drivers\btfilter.sys
2016-05-26 01:29:28 ----A---- C:\WINDOWS\system32\drivers\TeeDriverW8x64.sys
2016-05-26 01:08:53 ----D---- C:\WINDOWS\IObit
2016-05-26 01:08:22 ----A---- C:\WINDOWS\SYSWOW64\drivers\HWiNFO64A.SYS
2016-05-26 01:00:17 ----A---- C:\WINDOWS\system32\RegistryDefragBootTime.exe
2016-05-26 00:28:54 ----D---- C:\Program Files\CCleaner
2016-05-25 23:48:32 ----D---- C:\Program Files (x86)\Google
2016-05-25 21:42:24 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-05-25 21:38:37 ----D---- C:\Program Files\Common Files\AV
2016-05-25 20:47:19 ----SD---- C:\WINDOWS\system32\CompatTel
2016-05-25 20:47:19 ----D---- C:\WINDOWS\Migration
2016-05-25 20:47:18 ----D---- C:\WINDOWS\system32\appraiser
2016-05-25 20:44:36 ----D---- C:\WINDOWS\system32\AutoUpdateLicense
2016-05-25 18:13:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2016-05-25 18:13:26 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2016-05-25 18:12:04 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2016-05-25 17:56:48 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2016-05-25 17:56:42 ----A---- C:\WINDOWS\SYSWOW64\aspnet_counters.dll
2016-05-25 17:54:06 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2016-05-25 17:53:32 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\invagent.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\devinv.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\aepic.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-05-25 17:53:29 ----A---- C:\WINDOWS\SYSWOW64\apphelp.dll
2016-05-25 17:53:29 ----A---- C:\WINDOWS\system32\apphelp.dll
2016-05-25 17:53:29 ----A---- C:\WINDOWS\system32\aelupsvc.dll
2016-05-25 17:53:28 ----A---- C:\WINDOWS\SYSWOW64\sdbinst.exe
2016-05-25 17:53:28 ----A---- C:\WINDOWS\system32\sdbinst.exe
2016-05-25 17:53:15 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-05-25 17:53:14 ----A---- C:\WINDOWS\system32\msxml3.dll
2016-05-25 17:53:13 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-05-25 17:53:13 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2016-05-25 17:52:19 ----A---- C:\WINDOWS\system32\cryptcatsvc.dll
2016-05-25 17:51:14 ----A---- C:\WINDOWS\system32\msctf.dll
2016-05-25 17:51:13 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-05-25 17:48:50 ----A---- C:\WINDOWS\SYSWOW64\ReAgentc.exe
2016-05-25 17:48:50 ----A---- C:\WINDOWS\system32\ReAgentc.exe
2016-05-25 17:48:49 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\sysreset.exe
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\resetengmig.dll
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\reseteng.dll
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\ReAgent.dll
2016-05-25 17:47:24 ----A---- C:\WINDOWS\SYSWOW64\cryptdlg.dll
2016-05-25 17:47:24 ----A---- C:\WINDOWS\system32\cryptdlg.dll
2016-05-25 17:47:03 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-05-25 17:47:02 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2016-05-25 17:47:02 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-05-25 17:47:02 ----A---- C:\WINDOWS\system32\oleaut32.dll
2016-05-25 17:46:57 ----A---- C:\WINDOWS\system32\msdrm.dll
2016-05-25 17:46:56 ----A---- C:\WINDOWS\SYSWOW64\msdrm.dll
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcasvc.dll
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcalua.exe
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcaevts.dll
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcadm.dll
2016-05-25 17:46:54 ----A---- C:\WINDOWS\SYSWOW64\wpdshext.dll
2016-05-25 17:46:54 ----A---- C:\WINDOWS\system32\WPDShServiceObj.dll
2016-05-25 17:46:54 ----A---- C:\WINDOWS\system32\wpdshext.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\VmHostAI.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\tssdisai.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\RDWebAI.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\poqexec.exe
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\appserverai.dll
2016-05-25 17:46:28 ----A---- C:\WINDOWS\SYSWOW64\esent.dll
2016-05-25 17:46:28 ----A---- C:\WINDOWS\system32\esent.dll
2016-05-25 17:45:40 ----A---- C:\WINDOWS\system32\sppwinob.dll
2016-05-25 17:45:40 ----A---- C:\WINDOWS\system32\sppsvc.exe
2016-05-25 17:45:40 ----A---- C:\WINDOWS\system32\sppobjs.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\SYSWOW64\PhotoMetadataHandler.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\SYSWOW64\msieftp.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\system32\PhotoMetadataHandler.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\system32\msieftp.dll
2016-05-25 17:10:36 ----D---- C:\Users\europe\AppData\Roaming\CyberLink
2016-05-25 15:21:06 ----A---- C:\WINDOWS\system32\drivers\CLVirtualDrive.sys
2016-05-25 10:41:21 ----A---- C:\WINDOWS\system32\Display.dll
2016-05-25 10:41:20 ----A---- C:\WINDOWS\SYSWOW64\KBDKURD.DLL
2016-05-25 10:41:20 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2016-05-25 10:41:20 ----A---- C:\WINDOWS\system32\KBDKURD.DLL
2016-05-25 10:41:16 ----A---- C:\WINDOWS\system32\dskquota.dll
2016-05-25 10:41:15 ----A---- C:\WINDOWS\SYSWOW64\dskquota.dll
2016-05-25 10:40:57 ----A---- C:\WINDOWS\system32\hal.dll
2016-05-25 10:39:29 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2016-05-25 10:39:24 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2016-05-25 10:39:22 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2016-05-25 10:39:18 ----A---- C:\WINDOWS\system32\Windows.Storage.Compression.dll
2016-05-25 10:39:18 ----A---- C:\WINDOWS\system32\bdesvc.dll
2016-05-25 10:39:17 ----A---- C:\WINDOWS\system32\ListSvc.dll
2016-05-25 10:39:17 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2016-05-25 10:39:16 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2016-05-25 10:39:16 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2016-05-25 10:39:16 ----A---- C:\WINDOWS\system32\drivers\battc.sys
2016-05-25 10:39:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.Compression.dll
2016-05-25 10:39:15 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2016-05-25 10:39:15 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2016-05-25 10:39:14 ----A---- C:\WINDOWS\SYSWOW64\mswsock.dll
2016-05-25 10:39:14 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc6.dll
2016-05-25 10:39:14 ----A---- C:\WINDOWS\system32\input.dll
2016-05-25 10:39:14 ----A---- C:\WINDOWS\system32\dhcpcsvc6.dll
2016-05-25 10:39:13 ----A---- C:\WINDOWS\system32\microsoft-windows-pdc.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\system32\mswsock.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\system32\dhcpcore.dll
2016-05-25 10:39:11 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2016-05-25 10:39:11 ----A---- C:\WINDOWS\system32\AppxSip.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\system32\BdeUISrv.exe
2016-05-25 10:39:07 ----A---- C:\WINDOWS\SYSWOW64\kbdhebl3.dll
2016-05-25 10:39:07 ----A---- C:\WINDOWS\system32\kbdhebl3.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\SYSWOW64\shdocvw.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\system32\shdocvw.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\SYSWOW64\wvc.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\SYSWOW64\wdc.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\system32\wvc.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\system32\wdc.dll
2016-05-25 10:37:18 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-05-25 10:37:15 ----A---- C:\WINDOWS\system32\XpsGdiConverter.dll
2016-05-25 10:37:14 ----A---- C:\WINDOWS\SYSWOW64\XpsGdiConverter.dll
2016-05-25 10:37:14 ----A---- C:\WINDOWS\system32\WSDApi.dll
2016-05-25 10:37:14 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2016-05-25 10:37:14 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2016-05-25 10:37:13 ----A---- C:\WINDOWS\SYSWOW64\WSDApi.dll
2016-05-25 10:37:13 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2016-05-25 10:36:07 ----A---- C:\WINDOWS\SYSWOW64\Taskmgr.exe
2016-05-25 10:36:07 ----A---- C:\WINDOWS\system32\Taskmgr.exe
2016-05-25 10:36:06 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2016-05-25 10:36:04 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2016-05-25 10:36:04 ----A---- C:\WINDOWS\system32\UserLanguagesCpl.dll
2016-05-25 10:35:59 ----A---- C:\WINDOWS\system32\wpnapps.dll
2016-05-25 10:35:57 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2016-05-25 10:35:57 ----A---- C:\WINDOWS\SYSWOW64\UserLanguagesCpl.dll
2016-05-25 10:35:53 ----A---- C:\WINDOWS\SYSWOW64\vds_ps.dll
2016-05-25 10:35:53 ----A---- C:\WINDOWS\system32\vdsldr.exe
2016-05-25 10:35:53 ----A---- C:\WINDOWS\system32\vds_ps.dll
2016-05-25 10:35:38 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-05-25 10:35:36 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-05-25 10:35:35 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-05-25 10:35:35 ----A---- C:\WINDOWS\explorer.exe
2016-05-25 10:35:33 ----A---- C:\WINDOWS\system32\samsrv.dll
2016-05-25 10:35:25 ----A---- C:\WINDOWS\system32\vds.exe
2016-05-25 10:35:25 ----A---- C:\WINDOWS\system32\mscms.dll
2016-05-25 10:35:25 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\vdsutil.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\samlib.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\MbaeParserTask.exe
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\DeviceSetupManager.dll
2016-05-25 10:35:23 ----A---- C:\WINDOWS\SYSWOW64\samlib.dll
2016-05-25 10:35:22 ----A---- C:\WINDOWS\system32\drivers\BthAvrcpTg.sys
2016-05-25 10:35:19 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-05-25 10:34:27 ----A---- C:\WINDOWS\system32\glcndFilter.dll
2016-05-25 10:34:10 ----A---- C:\WINDOWS\SYSWOW64\glcndFilter.dll
2016-05-25 10:34:08 ----A---- C:\WINDOWS\system32\winhttp.dll
2016-05-25 10:34:01 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2016-05-25 10:33:55 ----A---- C:\WINDOWS\HelpPane.exe
2016-05-25 10:33:46 ----A---- C:\WINDOWS\system32\wlansvc.dll
2016-05-25 10:33:42 ----A---- C:\WINDOWS\system32\wlanapi.dll
2016-05-25 10:33:41 ----A---- C:\WINDOWS\system32\dafWCN.dll
2016-05-25 10:33:40 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2016-05-25 10:33:38 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2016-05-25 10:33:38 ----A---- C:\WINDOWS\system32\wlansec.dll
2016-05-25 10:33:37 ----A---- C:\WINDOWS\SYSWOW64\wlansec.dll
2016-05-25 10:33:37 ----A---- C:\WINDOWS\system32\rdpclip.exe
2016-05-25 10:33:37 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-05-25 10:33:36 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\SYSWOW64\WcnApi.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\system32\wcncsvc.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\system32\WcnApi.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\SYSWOW64\fdWCN.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\wfdprov.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\WcnEapPeerProxy.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\WcnEapAuthProxy.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\fdWCN.dll
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\processr.sys
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\intelppm.sys
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\amdppm.sys
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\amdk8.sys
2016-05-25 10:33:31 ----A---- C:\WINDOWS\SYSWOW64\wlanhlp.dll
2016-05-25 10:33:31 ----A---- C:\WINDOWS\system32\wlanhlp.dll
2016-05-25 10:33:31 ----A---- C:\WINDOWS\system32\drivers\fxppm.sys
2016-05-25 10:33:30 ----A---- C:\WINDOWS\system32\iscsilog.dll
2016-05-25 10:10:06 ----A---- C:\WINDOWS\system32\drivers\evbda.sys
2016-05-25 10:09:51 ----A---- C:\WINDOWS\system32\WpcMon.exe
2016-05-25 10:09:46 ----A---- C:\WINDOWS\system32\WinSAT.exe
2016-05-25 10:09:44 ----A---- C:\WINDOWS\system32\drivers\bxvbda.sys
2016-05-25 10:09:38 ----A---- C:\WINDOWS\system32\RacEngn.dll
2016-05-25 10:09:38 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-05-25 10:09:37 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-05-25 10:09:36 ----A---- C:\WINDOWS\system32\uDWM.dll
2016-05-25 10:09:36 ----A---- C:\WINDOWS\system32\provcore.dll
2016-05-25 10:09:36 ----A---- C:\WINDOWS\system32\MMDevAPI.dll
2016-05-25 10:09:31 ----A---- C:\WINDOWS\system32\WinSATAPI.dll
2016-05-25 10:09:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2016-05-25 10:09:29 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2016-05-25 10:09:28 ----A---- C:\WINDOWS\SYSWOW64\MsSpellCheckingFacility.dll
2016-05-25 10:09:28 ----A---- C:\WINDOWS\system32\IPHLPAPI.DLL
2016-05-25 10:09:27 ----A---- C:\WINDOWS\system32\MFPlay.dll
2016-05-25 10:09:27 ----A---- C:\WINDOWS\system32\combase.dll
2016-05-25 10:09:26 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2016-05-25 10:09:26 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-05-25 10:09:25 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-05-25 10:09:25 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\wlidcredprov.dll
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\taskeng.exe
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\bcdsrv.dll
2016-05-25 10:09:23 ----A---- C:\WINDOWS\system32\wpnprv.dll
2016-05-25 10:09:22 ----A---- C:\WINDOWS\system32\VAN.dll
2016-05-25 10:09:22 ----A---- C:\WINDOWS\system32\propsys.dll
2016-05-25 10:09:22 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2016-05-25 10:09:21 ----A---- C:\WINDOWS\SYSWOW64\WinSATAPI.dll
2016-05-25 10:09:20 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-05-25 10:09:19 ----A---- C:\WINDOWS\system32\mmcss.dll
2016-05-25 10:09:18 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-05-25 10:09:18 ----A---- C:\WINDOWS\system32\PackageStateRoaming.dll
2016-05-25 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2016-05-25 10:09:16 ----A---- C:\WINDOWS\SYSWOW64\RacEngn.dll
2016-05-25 10:09:16 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\SYSWOW64\provcore.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\SYSWOW64\PackageStateRoaming.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\system32\setbcdlocale.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\system32\ProximityService.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\system32\msvproc.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\avrt.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\system32\microsoft-windows-kernel-power-events.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\system32\avrt.dll
2016-05-25 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\svchost.exe
2016-05-25 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-05-25 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\batmeter.dll
2016-05-25 10:09:13 ----A---- C:\WINDOWS\system32\batmeter.dll
2016-05-25 10:09:12 ----A---- C:\WINDOWS\system32\perfdisk.dll
2016-05-25 10:09:11 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-05-25 10:09:11 ----A---- C:\WINDOWS\SYSWOW64\perfdisk.dll
2016-05-25 10:09:11 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2016-05-25 10:09:10 ----A---- C:\WINDOWS\SYSWOW64\wlidcredprov.dll
2016-05-25 10:09:10 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2016-05-25 10:09:10 ----A---- C:\WINDOWS\system32\svchost.exe
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\taskeng.exe
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\mfh264enc.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\system32\winsrv.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\system32\perfnet.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\system32\mfh264enc.dll
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\twinapi.dll
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\lpksetup.exe
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\dwm.exe
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\DevPropMgr.dll
2016-05-25 10:09:07 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2016-05-25 10:09:07 ----A---- C:\WINDOWS\SYSWOW64\drvinst.exe
2016-05-25 10:09:07 ----A---- C:\WINDOWS\system32\dxgi.dll
2016-05-25 10:09:07 ----A---- C:\WINDOWS\system32\drvinst.exe
2016-05-25 10:09:07 ----A---- C:\WINDOWS\system32\DAFWSD.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\SYSWOW64\perfnet.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\system32\webio.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\system32\perfos.dll
2016-05-25 10:09:05 ----A---- C:\WINDOWS\system32\RpcEpMap.dll
2016-05-25 10:09:02 ----A---- C:\WINDOWS\system32\umpo.dll
2016-05-25 10:09:02 ----A---- C:\WINDOWS\system32\lpremove.exe
2016-05-25 10:09:02 ----A---- C:\WINDOWS\system32\drivers\ws2ifsl.sys
2016-05-25 10:09:00 ----A---- C:\WINDOWS\SYSWOW64\perfproc.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\SYSWOW64\perfos.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\SYSWOW64\perfctrs.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\system32\perfproc.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\system32\perfctrs.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\SYSWOW64\shimeng.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\shimeng.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\MUILanguageCleanup.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\lpksetupproxyserv.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\LangCleanupSysprepAction.dll
2016-05-25 10:08:22 ----A---- C:\WINDOWS\SYSWOW64\newdev.exe
2016-05-25 10:08:22 ----A---- C:\WINDOWS\SYSWOW64\newdev.dll
2016-05-25 10:08:22 ----A---- C:\WINDOWS\SYSWOW64\ndadmin.exe
2016-05-25 10:08:22 ----A---- C:\WINDOWS\system32\newdev.exe
2016-05-25 10:08:22 ----A---- C:\WINDOWS\system32\newdev.dll
2016-05-25 10:08:22 ----A---- C:\WINDOWS\system32\ndadmin.exe
2016-05-25 10:08:05 ----A---- C:\WINDOWS\SYSWOW64\wusa.exe
2016-05-25 10:08:05 ----A---- C:\WINDOWS\system32\wusa.exe
2016-05-25 10:07:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-05-25 10:07:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-05-25 10:07:34 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-05-25 10:07:34 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\dumpfve.sys
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\crashdmp.sys
2016-05-25 10:07:15 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-05-25 10:07:15 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\wwanconn.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\WinSCard.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\winmm.dll
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\HdAudio.sys
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\openfiles.exe
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\LocationApi.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\wwanmm.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\Wwanadvui.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\openfiles.exe
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\LocationApi.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\drivers\udfs.sys
2016-05-25 10:06:58 ----A---- C:\WINDOWS\system32\clusapi.dll
2016-05-25 10:06:57 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2016-05-25 10:06:57 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2016-05-25 10:06:57 ----A---- C:\WINDOWS\system32\resutils.dll
2016-05-25 10:06:56 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2016-05-25 10:06:39 ----A---- C:\WINDOWS\SYSWOW64\Robocopy.exe
2016-05-25 10:06:39 ----A---- C:\WINDOWS\system32\Robocopy.exe
2016-05-25 10:06:33 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2016-05-25 10:06:33 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2016-05-25 10:06:33 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2016-05-25 10:06:33 ----A---- C:\WINDOWS\system32\drivers\disk.sys
2016-05-25 10:06:32 ----A---- C:\WINDOWS\system32\icfupgd.dll
2016-05-25 10:06:32 ----A---- C:\WINDOWS\system32\drivers\mpsdrv.sys
2016-05-25 10:06:31 ----A---- C:\WINDOWS\SYSWOW64\wfapigp.dll
2016-05-25 10:06:31 ----A---- C:\WINDOWS\system32\wfapigp.dll
2016-05-25 10:06:22 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2016-05-25 10:06:21 ----A---- C:\WINDOWS\system32\srvsvc.dll
2016-05-25 10:06:21 ----A---- C:\WINDOWS\system32\msdtctm.dll
2016-05-25 10:06:19 ----A---- C:\WINDOWS\SYSWOW64\sscore.dll
2016-05-25 10:06:19 ----A---- C:\WINDOWS\system32\sscore.dll
2016-05-25 10:06:19 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2016-05-25 10:06:19 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2016-05-25 10:06:08 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\WSShared.dll
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\NotificationUI.exe
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\AutoUpdate.exe
2016-05-25 10:06:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-05-25 10:06:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-05-25 10:06:07 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-05-25 10:06:07 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-05-25 10:06:05 ----A---- C:\WINDOWS\system32\kernel32.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\SYSWOW64\kernel32.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\system32\gpedit.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2016-05-25 10:06:04 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys
2016-05-25 09:50:33 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2016-05-25 09:50:32 ----A---- C:\WINDOWS\system32\storagewmi.dll
2016-05-25 09:50:26 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2016-05-25 09:50:23 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2016-05-25 09:50:20 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2016-05-25 09:50:19 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2016-05-25 09:50:19 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-05-25 09:50:19 ----A---- C:\WINDOWS\system32\dwmapi.dll
2016-05-25 09:50:17 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2016-05-25 09:50:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2016-05-25 09:50:13 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2016-05-25 09:50:13 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2016-05-25 09:50:13 ----A---- C:\WINDOWS\system32\Defrag.exe
2016-05-25 09:50:12 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2016-05-25 09:50:12 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2016-05-25 09:37:37 ----D---- C:\ProgramData\Atheros
2016-05-25 09:37:27 ----D---- C:\Users\europe\AppData\Roaming\Atheros
2016-05-25 09:26:15 ----D---- C:\Program Files (x86)\Bluetooth Suite
2016-05-25 08:02:19 ----A---- C:\WINDOWS\system32\drivers\athw8x.sys
2016-05-25 07:59:21 ----N---- C:\WINDOWS\system32\stapi64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\stlang64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\stcplx64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\stapo64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EEP64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EEL64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EED64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EEA64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\sttray64.exe
2016-05-25 07:59:20 ----D---- C:\WINDOWS\system32\SRSLabs
2016-05-25 07:58:26 ----A---- C:\WINDOWS\system32\drivers\stwrt64.sys
2016-05-25 07:58:19 ----A---- C:\WINDOWS\system32\st646425.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\SYSWOW64\SynTPCom.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\SynTPCo18.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\drivers\SynTP.sys
2016-05-25 07:54:32 ----A---- C:\WINDOWS\SYSWOW64\SynCom.dll
2016-05-25 07:54:32 ----A---- C:\WINDOWS\system32\SynCOM.dll
2016-05-25 07:54:30 ----A---- C:\WINDOWS\system32\drivers\Smb_driver_Intel.sys
prosim o pomoc s ntbk. Po 10 - 15 min prace zamrzne, nepohybuje sa sipka mysi, nefunguje klavesnica. Jedine mozne riesenie je tvrdy restart.
Doteraz vyskusane programy combofix, adwcleaner, mbam, norton sec., superant.sp.ware nepomohli.
Dakujem.
Logfile of random's system information tool 1.10 (written by random/random)
Run by europe at 2016-06-02 15:47:43
Microsoft Windows 8
System drive C: has 360 GB (79%) free of 458 GB
Total RAM: 3986 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:47:53, on 2.6.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.17568)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\europe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPNTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPNTDFJS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKCU\..\Run: [Power2GoExpress8] "C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Advanced SystemCare 9] "C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service 9 (AdvancedSystemCareService9) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @oem23.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10129 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
--
End of file - 10987 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe"
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
atieclxx
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\WINDOWS\system32\Hpservice.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
dashost.exe {045c503e-d43b-42ce-a2e3e146ed7e1280}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\diMaster.dll" /prefetch:1
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe" /Task
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe" /c /a /s UserSession
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\WINDOWS\System32\hkcmd.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\europe\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=51.0.2704.63 --handshake-handle=0x128
"C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/OutOfProcessPac/Default/PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Disable/PreRead/Default/*QUIC/EnabledNoId/RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SyncHttpContentCompression/Disabled/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --type=gpu-process --channel="4836.0.1260588905\1530341719" --disable-d3d11 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,10,12,13,25,46,54 --gpu-vendor-id=0x1002 --gpu-device-id=0x0000 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.982.6.0 --mojo-platform-channel-handle=1036 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" -byrunkey
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=C23E17BB3D0D41866DC49C38BD70C2F0 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.12.866702404\87773006" --mojo-platform-channel-handle=2980 /prefetch:1
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=480B8948377F85F00F517836B58C3BFD --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.13.1164192649\656705994" --mojo-platform-channel-handle=1064 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=45F4268320F77A828AAE1508BB915BE9 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.14.210707660\421806896" --mojo-platform-channel-handle=2260 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=89A5E25400209ECA5766501BAA47BA2C --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.15.1625941362\826271702" --mojo-platform-channel-handle=3420 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention,*WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,brotli-encoding<BrotliEncoding --disable-features=RenderingPipelineThrottling<RenderingPipelineThrottling --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/*BrotliEncoding/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/1DaySingleProfile/DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A10_Stable_R2/*OutOfProcessPac/Default/*PageRevisitInstrumentation/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/*PreRead/Default/*QUIC/EnabledNoId/*RenderingPipelineThrottling/Disabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SyncHttpContentCompression/Disabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_37/*UMA-Uniformity-Trial-10-Percent/group_05/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Default/ --primordial-pipe-token=36CA64AA72301EEC9F36FC08DBBB3168 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="4836.16.770885885\781691296" --mojo-platform-channel-handle=2840 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 552 556 564 65536 560
"C:\Users\europe\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\ASC9_SkipUac_europe.job - C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe /SkipUac
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\HPCeeScheduleForeurope.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForeurope (null)
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12 2472224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 209504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21 1051320]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21 805560]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 6141528]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21 1051320]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21 805560]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-08-24 170304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-08-24 398656]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2016-05-25 1664000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress8"=C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [2013-01-27 1711680]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-05-13 8721624]
"Advanced SystemCare 9"=C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2016-04-26 2022688]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2012-07-26 1475072]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2016-05-31 7943072]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"HP CoolSense"=C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2012-11-05 1343904]
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2012-09-07 581024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-08-24 441856]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-06-02 15:47:43 ----D---- C:\rsit
2016-06-02 15:47:43 ----D---- C:\Program Files\trend micro
2016-06-02 09:44:49 ----D---- C:\WINDOWS\temp
2016-06-02 09:44:47 ----A---- C:\ComboFix.txt
2016-06-02 09:38:16 ----SHD---- C:\$RECYCLE.BIN
2016-06-02 09:25:06 ----A---- C:\WINDOWS\zip.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\SWXCACLS.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\SWSC.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\SWREG.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\sed.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\PEV.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\NIRCMD.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\MBR.exe
2016-06-02 09:25:06 ----A---- C:\WINDOWS\grep.exe
2016-06-02 09:24:56 ----D---- C:\Qoobox
2016-06-02 09:24:17 ----D---- C:\WINDOWS\erdnt
2016-06-01 14:57:19 ----D---- C:\Users\europe\AppData\Roaming\SUPERAntiSpyware.com
2016-06-01 14:56:01 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2016-06-01 14:56:01 ----D---- C:\Program Files\SUPERAntiSpyware
2016-06-01 14:43:32 ----N---- C:\bootsqm.dat
2016-05-31 22:13:08 ----ASH---- C:\pagefile.sys
2016-05-31 18:30:52 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2016-05-31 18:30:10 ----D---- C:\ProgramData\Malwarebytes
2016-05-31 18:30:10 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-05-31 18:30:10 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2016-05-31 18:30:10 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2016-05-31 18:30:10 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2016-05-31 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_7.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_5.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2016-05-31 00:28:56 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2016-05-31 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_7.dll
2016-05-31 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_43.dll
2016-05-31 00:28:55 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2016-05-31 00:28:54 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2016-05-31 00:28:52 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2016-05-31 00:28:51 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2016-05-31 00:28:51 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2016-05-31 00:28:51 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_6.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_4.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_6.dll
2016-05-31 00:28:50 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_7.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2016-05-31 00:28:47 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2016-05-31 00:28:46 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2016-05-31 00:28:45 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2016-05-31 00:28:45 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2016-05-31 00:28:44 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2016-05-31 00:28:44 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2016-05-31 00:28:40 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2016-05-31 00:28:36 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2016-05-31 00:28:36 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2016-05-31 00:28:36 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2016-05-31 00:28:35 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2016-05-31 00:28:34 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2016-05-31 00:28:34 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2016-05-31 00:28:33 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2016-05-31 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2016-05-31 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2016-05-31 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2016-05-31 00:28:30 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2016-05-31 00:28:29 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2016-05-31 00:28:27 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2016-05-31 00:28:24 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2016-05-31 00:28:23 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2016-05-31 00:28:20 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2016-05-31 00:28:19 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2016-05-31 00:28:18 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2016-05-31 00:28:17 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2016-05-31 00:28:17 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2016-05-31 00:28:16 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2016-05-31 00:28:15 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2016-05-31 00:28:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2016-05-31 00:28:14 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2016-05-31 00:28:11 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2016-05-31 00:28:10 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2016-05-31 00:28:08 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2016-05-31 00:28:07 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2016-05-31 00:28:06 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2016-05-31 00:28:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2016-05-31 00:28:02 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2016-05-31 00:28:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2016-05-31 00:28:00 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2016-05-31 00:28:00 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2016-05-31 00:28:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2016-05-31 00:27:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2016-05-31 00:27:58 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2016-05-31 00:27:57 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2016-05-31 00:27:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2016-05-31 00:27:55 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2016-05-31 00:27:55 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2016-05-31 00:27:54 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2016-05-31 00:27:53 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2016-05-31 00:27:53 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2016-05-31 00:27:51 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2016-05-31 00:27:50 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2016-05-31 00:27:49 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2016-05-31 00:27:48 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2016-05-31 00:27:47 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2016-05-31 00:27:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2016-05-31 00:27:46 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2016-05-31 00:27:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2016-05-31 00:27:44 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2016-05-31 00:27:44 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2016-05-31 00:27:43 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2016-05-31 00:27:42 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2016-05-31 00:27:42 ----A---- C:\WINDOWS\system32\d3dx10.dll
2016-05-31 00:27:41 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2016-05-31 00:27:34 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2016-05-31 00:27:33 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2016-05-31 00:27:32 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2016-05-31 00:27:32 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2016-05-31 00:27:32 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2016-05-31 00:27:31 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2016-05-31 00:27:30 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2016-05-31 00:27:30 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2016-05-31 00:27:29 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2016-05-31 00:27:29 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2016-05-31 00:27:28 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2016-05-31 00:27:28 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2016-05-31 00:27:26 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2016-05-31 00:27:25 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2016-05-31 00:27:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2016-05-31 00:27:18 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2016-05-31 00:27:17 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2016-05-31 00:27:17 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2016-05-31 00:27:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2016-05-31 00:27:16 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2016-05-31 00:27:15 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2016-05-31 00:27:15 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2016-05-31 00:27:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2016-05-31 00:27:14 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2016-05-31 00:27:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2016-05-31 00:27:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2016-05-31 00:27:12 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2016-05-31 00:27:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2016-05-31 00:27:12 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2016-05-31 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2016-05-31 00:27:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2016-05-31 00:27:11 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2016-05-31 00:26:06 ----D---- C:\ProgramData\Package Cache
2016-05-31 00:25:44 ----A---- C:\WINDOWS\SYSWOW64\RtCamX.dll
2016-05-31 00:25:44 ----A---- C:\WINDOWS\system32\RtCamX64.dll
2016-05-31 00:25:44 ----A---- C:\WINDOWS\system32\drivers\rtsuvc.sys
2016-05-31 00:25:44 ----A---- C:\WINDOWS\RtsCM64.exe
2016-05-31 00:25:44 ----A---- C:\WINDOWS\RtCamU64.exe
2016-05-30 23:43:43 ----D---- C:\WINDOWS\Minidump
2016-05-28 23:33:14 ----D---- C:\Program Files (x86)\Adobe
2016-05-28 23:32:49 ----D---- C:\ProgramData\Adobe
2016-05-28 23:16:52 ----HD---- C:\ProgramData\CanonIJScan
2016-05-26 13:09:21 ----HD---- C:\ProgramData\CanonIJEPPEX2
2016-05-26 13:09:21 ----HD---- C:\ProgramData\CanonEPP
2016-05-26 13:09:20 ----D---- C:\Users\europe\AppData\Roaming\Canon
2016-05-26 13:05:05 ----A---- C:\WINDOWS\system32\CNMXLMAT.DLL
2016-05-26 13:04:05 ----D---- C:\ProgramData\Canon IJ Network Tool
2016-05-26 13:03:51 ----A---- C:\WINDOWS\SYSWOW64\CNC_ATU.dll
2016-05-26 13:03:51 ----A---- C:\WINDOWS\SYSWOW64\CNC_ATL.dll
2016-05-26 13:03:50 ----A---- C:\WINDOWS\SYSWOW64\CNHMCA.dll
2016-05-26 13:01:42 ----D---- C:\Program Files\Common Files\CANON
2016-05-26 13:01:34 ----D---- C:\ProgramData\CanonIJWSpt
2016-05-26 12:58:42 ----D---- C:\Program Files\Canon
2016-05-26 12:57:28 ----HD---- C:\ProgramData\CanonBJ
2016-05-26 12:57:14 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2016-05-26 12:56:48 ----A---- C:\WINDOWS\system32\CNMLMAT.DLL
2016-05-26 12:56:34 ----A---- C:\WINDOWS\system32\CNMIUAT.DLL
2016-05-26 12:55:37 ----HD---- C:\Program Files\CanonBJ
2016-05-26 12:55:19 ----D---- C:\WINDOWS\system32\STRING
2016-05-26 12:55:19 ----A---- C:\WINDOWS\system32\CNMN6UI.DLL
2016-05-26 12:55:18 ----A---- C:\WINDOWS\SYSWOW64\CNMNPPM.DLL
2016-05-26 12:55:18 ----A---- C:\WINDOWS\system32\CNMN6PPM.DLL
2016-05-26 12:35:45 ----D---- C:\Program Files (x86)\Canon
2016-05-26 11:54:04 ----D---- C:\Program Files (x86)\Microsoft Works
2016-05-26 11:50:24 ----D---- C:\Program Files\Microsoft Office
2016-05-26 11:49:44 ----D---- C:\ProgramData\Microsoft Help
2016-05-26 11:40:24 ----D---- C:\Users\europe\AppData\Roaming\MyPhoneExplorer
2016-05-26 11:40:11 ----D---- C:\Program Files (x86)\MyPhoneExplorer
2016-05-26 01:31:05 ----A---- C:\WINDOWS\system32\RtNicProp64.dll
2016-05-26 01:31:05 ----A---- C:\WINDOWS\system32\drivers\Rt630x64.sys
2016-05-26 01:30:55 ----A---- C:\WINDOWS\SYSWOW64\RsCRIcon.dll
2016-05-26 01:30:55 ----A---- C:\WINDOWS\system32\RtCRX64.dll
2016-05-26 01:30:55 ----A---- C:\WINDOWS\system32\drivers\RtsP2Stor.sys
2016-05-26 01:30:55 ----A---- C:\WINDOWS\RtCRU64.exe
2016-05-26 01:30:11 ----A---- C:\WINDOWS\system32\drivers\athrx.sys
2016-05-26 01:29:59 ----A---- C:\WINDOWS\system32\drivers\btfilter.sys
2016-05-26 01:29:28 ----A---- C:\WINDOWS\system32\drivers\TeeDriverW8x64.sys
2016-05-26 01:08:53 ----D---- C:\WINDOWS\IObit
2016-05-26 01:08:22 ----A---- C:\WINDOWS\SYSWOW64\drivers\HWiNFO64A.SYS
2016-05-26 01:00:17 ----A---- C:\WINDOWS\system32\RegistryDefragBootTime.exe
2016-05-26 00:28:54 ----D---- C:\Program Files\CCleaner
2016-05-25 23:48:32 ----D---- C:\Program Files (x86)\Google
2016-05-25 21:42:24 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-05-25 21:38:37 ----D---- C:\Program Files\Common Files\AV
2016-05-25 20:47:19 ----SD---- C:\WINDOWS\system32\CompatTel
2016-05-25 20:47:19 ----D---- C:\WINDOWS\Migration
2016-05-25 20:47:18 ----D---- C:\WINDOWS\system32\appraiser
2016-05-25 20:44:36 ----D---- C:\WINDOWS\system32\AutoUpdateLicense
2016-05-25 18:13:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2016-05-25 18:13:26 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2016-05-25 18:12:04 ----A---- C:\WINDOWS\system32\drivers\hdaudbus.sys
2016-05-25 17:56:48 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2016-05-25 17:56:42 ----A---- C:\WINDOWS\SYSWOW64\aspnet_counters.dll
2016-05-25 17:54:06 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2016-05-25 17:53:32 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\invagent.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\devinv.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\aepic.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-05-25 17:53:31 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-05-25 17:53:29 ----A---- C:\WINDOWS\SYSWOW64\apphelp.dll
2016-05-25 17:53:29 ----A---- C:\WINDOWS\system32\apphelp.dll
2016-05-25 17:53:29 ----A---- C:\WINDOWS\system32\aelupsvc.dll
2016-05-25 17:53:28 ----A---- C:\WINDOWS\SYSWOW64\sdbinst.exe
2016-05-25 17:53:28 ----A---- C:\WINDOWS\system32\sdbinst.exe
2016-05-25 17:53:15 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-05-25 17:53:14 ----A---- C:\WINDOWS\system32\msxml3.dll
2016-05-25 17:53:13 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-05-25 17:53:13 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2016-05-25 17:52:19 ----A---- C:\WINDOWS\system32\cryptcatsvc.dll
2016-05-25 17:51:14 ----A---- C:\WINDOWS\system32\msctf.dll
2016-05-25 17:51:13 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-05-25 17:48:50 ----A---- C:\WINDOWS\SYSWOW64\ReAgentc.exe
2016-05-25 17:48:50 ----A---- C:\WINDOWS\system32\ReAgentc.exe
2016-05-25 17:48:49 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\sysreset.exe
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\resetengmig.dll
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\reseteng.dll
2016-05-25 17:48:49 ----A---- C:\WINDOWS\system32\ReAgent.dll
2016-05-25 17:47:24 ----A---- C:\WINDOWS\SYSWOW64\cryptdlg.dll
2016-05-25 17:47:24 ----A---- C:\WINDOWS\system32\cryptdlg.dll
2016-05-25 17:47:03 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-05-25 17:47:02 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2016-05-25 17:47:02 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-05-25 17:47:02 ----A---- C:\WINDOWS\system32\oleaut32.dll
2016-05-25 17:46:57 ----A---- C:\WINDOWS\system32\msdrm.dll
2016-05-25 17:46:56 ----A---- C:\WINDOWS\SYSWOW64\msdrm.dll
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcasvc.dll
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcalua.exe
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcaevts.dll
2016-05-25 17:46:55 ----A---- C:\WINDOWS\system32\pcadm.dll
2016-05-25 17:46:54 ----A---- C:\WINDOWS\SYSWOW64\wpdshext.dll
2016-05-25 17:46:54 ----A---- C:\WINDOWS\system32\WPDShServiceObj.dll
2016-05-25 17:46:54 ----A---- C:\WINDOWS\system32\wpdshext.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\VmHostAI.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\tssdisai.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\RDWebAI.dll
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\poqexec.exe
2016-05-25 17:46:31 ----A---- C:\WINDOWS\system32\appserverai.dll
2016-05-25 17:46:28 ----A---- C:\WINDOWS\SYSWOW64\esent.dll
2016-05-25 17:46:28 ----A---- C:\WINDOWS\system32\esent.dll
2016-05-25 17:45:40 ----A---- C:\WINDOWS\system32\sppwinob.dll
2016-05-25 17:45:40 ----A---- C:\WINDOWS\system32\sppsvc.exe
2016-05-25 17:45:40 ----A---- C:\WINDOWS\system32\sppobjs.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-05-25 17:45:08 ----A---- C:\WINDOWS\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\SYSWOW64\PhotoMetadataHandler.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\SYSWOW64\msieftp.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\system32\PhotoMetadataHandler.dll
2016-05-25 17:43:56 ----A---- C:\WINDOWS\system32\msieftp.dll
2016-05-25 17:10:36 ----D---- C:\Users\europe\AppData\Roaming\CyberLink
2016-05-25 15:21:06 ----A---- C:\WINDOWS\system32\drivers\CLVirtualDrive.sys
2016-05-25 10:41:21 ----A---- C:\WINDOWS\system32\Display.dll
2016-05-25 10:41:20 ----A---- C:\WINDOWS\SYSWOW64\KBDKURD.DLL
2016-05-25 10:41:20 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2016-05-25 10:41:20 ----A---- C:\WINDOWS\system32\KBDKURD.DLL
2016-05-25 10:41:16 ----A---- C:\WINDOWS\system32\dskquota.dll
2016-05-25 10:41:15 ----A---- C:\WINDOWS\SYSWOW64\dskquota.dll
2016-05-25 10:40:57 ----A---- C:\WINDOWS\system32\hal.dll
2016-05-25 10:39:29 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2016-05-25 10:39:24 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2016-05-25 10:39:22 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2016-05-25 10:39:18 ----A---- C:\WINDOWS\system32\Windows.Storage.Compression.dll
2016-05-25 10:39:18 ----A---- C:\WINDOWS\system32\bdesvc.dll
2016-05-25 10:39:17 ----A---- C:\WINDOWS\system32\ListSvc.dll
2016-05-25 10:39:17 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2016-05-25 10:39:16 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2016-05-25 10:39:16 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2016-05-25 10:39:16 ----A---- C:\WINDOWS\system32\drivers\battc.sys
2016-05-25 10:39:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.Compression.dll
2016-05-25 10:39:15 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2016-05-25 10:39:15 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2016-05-25 10:39:14 ----A---- C:\WINDOWS\SYSWOW64\mswsock.dll
2016-05-25 10:39:14 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc6.dll
2016-05-25 10:39:14 ----A---- C:\WINDOWS\system32\input.dll
2016-05-25 10:39:14 ----A---- C:\WINDOWS\system32\dhcpcsvc6.dll
2016-05-25 10:39:13 ----A---- C:\WINDOWS\system32\microsoft-windows-pdc.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\system32\mswsock.dll
2016-05-25 10:39:12 ----A---- C:\WINDOWS\system32\dhcpcore.dll
2016-05-25 10:39:11 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2016-05-25 10:39:11 ----A---- C:\WINDOWS\system32\AppxSip.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2016-05-25 10:39:10 ----A---- C:\WINDOWS\system32\BdeUISrv.exe
2016-05-25 10:39:07 ----A---- C:\WINDOWS\SYSWOW64\kbdhebl3.dll
2016-05-25 10:39:07 ----A---- C:\WINDOWS\system32\kbdhebl3.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\SYSWOW64\shdocvw.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\system32\shdocvw.dll
2016-05-25 10:38:02 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\SYSWOW64\wvc.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\SYSWOW64\wdc.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\system32\wvc.dll
2016-05-25 10:37:57 ----A---- C:\WINDOWS\system32\wdc.dll
2016-05-25 10:37:18 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-05-25 10:37:15 ----A---- C:\WINDOWS\system32\XpsGdiConverter.dll
2016-05-25 10:37:14 ----A---- C:\WINDOWS\SYSWOW64\XpsGdiConverter.dll
2016-05-25 10:37:14 ----A---- C:\WINDOWS\system32\WSDApi.dll
2016-05-25 10:37:14 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2016-05-25 10:37:14 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2016-05-25 10:37:13 ----A---- C:\WINDOWS\SYSWOW64\WSDApi.dll
2016-05-25 10:37:13 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2016-05-25 10:36:07 ----A---- C:\WINDOWS\SYSWOW64\Taskmgr.exe
2016-05-25 10:36:07 ----A---- C:\WINDOWS\system32\Taskmgr.exe
2016-05-25 10:36:06 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2016-05-25 10:36:04 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2016-05-25 10:36:04 ----A---- C:\WINDOWS\system32\UserLanguagesCpl.dll
2016-05-25 10:35:59 ----A---- C:\WINDOWS\system32\wpnapps.dll
2016-05-25 10:35:57 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2016-05-25 10:35:57 ----A---- C:\WINDOWS\SYSWOW64\UserLanguagesCpl.dll
2016-05-25 10:35:53 ----A---- C:\WINDOWS\SYSWOW64\vds_ps.dll
2016-05-25 10:35:53 ----A---- C:\WINDOWS\system32\vdsldr.exe
2016-05-25 10:35:53 ----A---- C:\WINDOWS\system32\vds_ps.dll
2016-05-25 10:35:38 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-05-25 10:35:36 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-05-25 10:35:35 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-05-25 10:35:35 ----A---- C:\WINDOWS\explorer.exe
2016-05-25 10:35:33 ----A---- C:\WINDOWS\system32\samsrv.dll
2016-05-25 10:35:25 ----A---- C:\WINDOWS\system32\vds.exe
2016-05-25 10:35:25 ----A---- C:\WINDOWS\system32\mscms.dll
2016-05-25 10:35:25 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\vdsutil.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\samlib.dll
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\MbaeParserTask.exe
2016-05-25 10:35:24 ----A---- C:\WINDOWS\system32\DeviceSetupManager.dll
2016-05-25 10:35:23 ----A---- C:\WINDOWS\SYSWOW64\samlib.dll
2016-05-25 10:35:22 ----A---- C:\WINDOWS\system32\drivers\BthAvrcpTg.sys
2016-05-25 10:35:19 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-05-25 10:34:27 ----A---- C:\WINDOWS\system32\glcndFilter.dll
2016-05-25 10:34:10 ----A---- C:\WINDOWS\SYSWOW64\glcndFilter.dll
2016-05-25 10:34:08 ----A---- C:\WINDOWS\system32\winhttp.dll
2016-05-25 10:34:01 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2016-05-25 10:33:55 ----A---- C:\WINDOWS\HelpPane.exe
2016-05-25 10:33:46 ----A---- C:\WINDOWS\system32\wlansvc.dll
2016-05-25 10:33:42 ----A---- C:\WINDOWS\system32\wlanapi.dll
2016-05-25 10:33:41 ----A---- C:\WINDOWS\system32\dafWCN.dll
2016-05-25 10:33:40 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2016-05-25 10:33:38 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2016-05-25 10:33:38 ----A---- C:\WINDOWS\system32\wlansec.dll
2016-05-25 10:33:37 ----A---- C:\WINDOWS\SYSWOW64\wlansec.dll
2016-05-25 10:33:37 ----A---- C:\WINDOWS\system32\rdpclip.exe
2016-05-25 10:33:37 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-05-25 10:33:36 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\SYSWOW64\WcnApi.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\system32\wcncsvc.dll
2016-05-25 10:33:35 ----A---- C:\WINDOWS\system32\WcnApi.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\SYSWOW64\fdWCN.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\wfdprov.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\WcnEapPeerProxy.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\WcnEapAuthProxy.dll
2016-05-25 10:33:34 ----A---- C:\WINDOWS\system32\fdWCN.dll
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\processr.sys
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\intelppm.sys
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\amdppm.sys
2016-05-25 10:33:32 ----A---- C:\WINDOWS\system32\drivers\amdk8.sys
2016-05-25 10:33:31 ----A---- C:\WINDOWS\SYSWOW64\wlanhlp.dll
2016-05-25 10:33:31 ----A---- C:\WINDOWS\system32\wlanhlp.dll
2016-05-25 10:33:31 ----A---- C:\WINDOWS\system32\drivers\fxppm.sys
2016-05-25 10:33:30 ----A---- C:\WINDOWS\system32\iscsilog.dll
2016-05-25 10:10:06 ----A---- C:\WINDOWS\system32\drivers\evbda.sys
2016-05-25 10:09:51 ----A---- C:\WINDOWS\system32\WpcMon.exe
2016-05-25 10:09:46 ----A---- C:\WINDOWS\system32\WinSAT.exe
2016-05-25 10:09:44 ----A---- C:\WINDOWS\system32\drivers\bxvbda.sys
2016-05-25 10:09:38 ----A---- C:\WINDOWS\system32\RacEngn.dll
2016-05-25 10:09:38 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-05-25 10:09:37 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-05-25 10:09:36 ----A---- C:\WINDOWS\system32\uDWM.dll
2016-05-25 10:09:36 ----A---- C:\WINDOWS\system32\provcore.dll
2016-05-25 10:09:36 ----A---- C:\WINDOWS\system32\MMDevAPI.dll
2016-05-25 10:09:31 ----A---- C:\WINDOWS\system32\WinSATAPI.dll
2016-05-25 10:09:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2016-05-25 10:09:29 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2016-05-25 10:09:28 ----A---- C:\WINDOWS\SYSWOW64\MsSpellCheckingFacility.dll
2016-05-25 10:09:28 ----A---- C:\WINDOWS\system32\IPHLPAPI.DLL
2016-05-25 10:09:27 ----A---- C:\WINDOWS\system32\MFPlay.dll
2016-05-25 10:09:27 ----A---- C:\WINDOWS\system32\combase.dll
2016-05-25 10:09:26 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2016-05-25 10:09:26 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-05-25 10:09:25 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-05-25 10:09:25 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\wlidcredprov.dll
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\taskeng.exe
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-05-25 10:09:24 ----A---- C:\WINDOWS\system32\bcdsrv.dll
2016-05-25 10:09:23 ----A---- C:\WINDOWS\system32\wpnprv.dll
2016-05-25 10:09:22 ----A---- C:\WINDOWS\system32\VAN.dll
2016-05-25 10:09:22 ----A---- C:\WINDOWS\system32\propsys.dll
2016-05-25 10:09:22 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2016-05-25 10:09:21 ----A---- C:\WINDOWS\SYSWOW64\WinSATAPI.dll
2016-05-25 10:09:20 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-05-25 10:09:19 ----A---- C:\WINDOWS\system32\mmcss.dll
2016-05-25 10:09:18 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-05-25 10:09:18 ----A---- C:\WINDOWS\system32\PackageStateRoaming.dll
2016-05-25 10:09:17 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2016-05-25 10:09:16 ----A---- C:\WINDOWS\SYSWOW64\RacEngn.dll
2016-05-25 10:09:16 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\SYSWOW64\provcore.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\SYSWOW64\PackageStateRoaming.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\system32\setbcdlocale.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\system32\ProximityService.dll
2016-05-25 10:09:15 ----A---- C:\WINDOWS\system32\msvproc.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\VAN.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\SYSWOW64\avrt.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\system32\microsoft-windows-kernel-power-events.dll
2016-05-25 10:09:14 ----A---- C:\WINDOWS\system32\avrt.dll
2016-05-25 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\svchost.exe
2016-05-25 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-05-25 10:09:13 ----A---- C:\WINDOWS\SYSWOW64\batmeter.dll
2016-05-25 10:09:13 ----A---- C:\WINDOWS\system32\batmeter.dll
2016-05-25 10:09:12 ----A---- C:\WINDOWS\system32\perfdisk.dll
2016-05-25 10:09:11 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-05-25 10:09:11 ----A---- C:\WINDOWS\SYSWOW64\perfdisk.dll
2016-05-25 10:09:11 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2016-05-25 10:09:10 ----A---- C:\WINDOWS\SYSWOW64\wlidcredprov.dll
2016-05-25 10:09:10 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2016-05-25 10:09:10 ----A---- C:\WINDOWS\system32\svchost.exe
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\taskeng.exe
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\SYSWOW64\mfh264enc.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\system32\winsrv.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\system32\perfnet.dll
2016-05-25 10:09:09 ----A---- C:\WINDOWS\system32\mfh264enc.dll
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\twinapi.dll
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\lpksetup.exe
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\dwm.exe
2016-05-25 10:09:08 ----A---- C:\WINDOWS\system32\DevPropMgr.dll
2016-05-25 10:09:07 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2016-05-25 10:09:07 ----A---- C:\WINDOWS\SYSWOW64\drvinst.exe
2016-05-25 10:09:07 ----A---- C:\WINDOWS\system32\dxgi.dll
2016-05-25 10:09:07 ----A---- C:\WINDOWS\system32\drvinst.exe
2016-05-25 10:09:07 ----A---- C:\WINDOWS\system32\DAFWSD.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\SYSWOW64\perfnet.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\system32\webio.dll
2016-05-25 10:09:06 ----A---- C:\WINDOWS\system32\perfos.dll
2016-05-25 10:09:05 ----A---- C:\WINDOWS\system32\RpcEpMap.dll
2016-05-25 10:09:02 ----A---- C:\WINDOWS\system32\umpo.dll
2016-05-25 10:09:02 ----A---- C:\WINDOWS\system32\lpremove.exe
2016-05-25 10:09:02 ----A---- C:\WINDOWS\system32\drivers\ws2ifsl.sys
2016-05-25 10:09:00 ----A---- C:\WINDOWS\SYSWOW64\perfproc.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\SYSWOW64\perfos.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\SYSWOW64\perfctrs.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\system32\perfproc.dll
2016-05-25 10:09:00 ----A---- C:\WINDOWS\system32\perfctrs.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\SYSWOW64\shimeng.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\shimeng.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\MUILanguageCleanup.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\lpksetupproxyserv.dll
2016-05-25 10:08:59 ----A---- C:\WINDOWS\system32\LangCleanupSysprepAction.dll
2016-05-25 10:08:22 ----A---- C:\WINDOWS\SYSWOW64\newdev.exe
2016-05-25 10:08:22 ----A---- C:\WINDOWS\SYSWOW64\newdev.dll
2016-05-25 10:08:22 ----A---- C:\WINDOWS\SYSWOW64\ndadmin.exe
2016-05-25 10:08:22 ----A---- C:\WINDOWS\system32\newdev.exe
2016-05-25 10:08:22 ----A---- C:\WINDOWS\system32\newdev.dll
2016-05-25 10:08:22 ----A---- C:\WINDOWS\system32\ndadmin.exe
2016-05-25 10:08:05 ----A---- C:\WINDOWS\SYSWOW64\wusa.exe
2016-05-25 10:08:05 ----A---- C:\WINDOWS\system32\wusa.exe
2016-05-25 10:07:39 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-05-25 10:07:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-05-25 10:07:34 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-05-25 10:07:34 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\dumpfve.sys
2016-05-25 10:07:26 ----A---- C:\WINDOWS\system32\drivers\crashdmp.sys
2016-05-25 10:07:15 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-05-25 10:07:15 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\SYSWOW64\winmmbase.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\SYSWOW64\winmm.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\wwanconn.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\WinSCard.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\winmmbase.dll
2016-05-25 10:07:13 ----A---- C:\WINDOWS\system32\winmm.dll
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\msgpioclx.sys
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\HdAudio.sys
2016-05-25 10:07:10 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\openfiles.exe
2016-05-25 10:07:09 ----A---- C:\WINDOWS\SYSWOW64\LocationApi.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\wwanmm.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\Wwanadvui.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\openfiles.exe
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\LocationApi.dll
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2016-05-25 10:07:09 ----A---- C:\WINDOWS\system32\drivers\udfs.sys
2016-05-25 10:06:58 ----A---- C:\WINDOWS\system32\clusapi.dll
2016-05-25 10:06:57 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2016-05-25 10:06:57 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2016-05-25 10:06:57 ----A---- C:\WINDOWS\system32\resutils.dll
2016-05-25 10:06:56 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2016-05-25 10:06:39 ----A---- C:\WINDOWS\SYSWOW64\Robocopy.exe
2016-05-25 10:06:39 ----A---- C:\WINDOWS\system32\Robocopy.exe
2016-05-25 10:06:33 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2016-05-25 10:06:33 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2016-05-25 10:06:33 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2016-05-25 10:06:33 ----A---- C:\WINDOWS\system32\drivers\disk.sys
2016-05-25 10:06:32 ----A---- C:\WINDOWS\system32\icfupgd.dll
2016-05-25 10:06:32 ----A---- C:\WINDOWS\system32\drivers\mpsdrv.sys
2016-05-25 10:06:31 ----A---- C:\WINDOWS\SYSWOW64\wfapigp.dll
2016-05-25 10:06:31 ----A---- C:\WINDOWS\system32\wfapigp.dll
2016-05-25 10:06:22 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2016-05-25 10:06:21 ----A---- C:\WINDOWS\system32\srvsvc.dll
2016-05-25 10:06:21 ----A---- C:\WINDOWS\system32\msdtctm.dll
2016-05-25 10:06:19 ----A---- C:\WINDOWS\SYSWOW64\sscore.dll
2016-05-25 10:06:19 ----A---- C:\WINDOWS\system32\sscore.dll
2016-05-25 10:06:19 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2016-05-25 10:06:19 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2016-05-25 10:06:08 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\WSShared.dll
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\NotificationUI.exe
2016-05-25 10:06:08 ----A---- C:\WINDOWS\system32\AutoUpdate.exe
2016-05-25 10:06:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-05-25 10:06:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-05-25 10:06:07 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-05-25 10:06:07 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-05-25 10:06:05 ----A---- C:\WINDOWS\system32\kernel32.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\SYSWOW64\kernel32.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\SYSWOW64\gpedit.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\system32\gpedit.dll
2016-05-25 10:06:04 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2016-05-25 10:06:04 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys
2016-05-25 09:50:33 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys
2016-05-25 09:50:32 ----A---- C:\WINDOWS\system32\storagewmi.dll
2016-05-25 09:50:26 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2016-05-25 09:50:23 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2016-05-25 09:50:20 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2016-05-25 09:50:19 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2016-05-25 09:50:19 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-05-25 09:50:19 ----A---- C:\WINDOWS\system32\dwmapi.dll
2016-05-25 09:50:17 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2016-05-25 09:50:16 ----A---- C:\WINDOWS\system32\defragsvc.dll
2016-05-25 09:50:13 ----A---- C:\WINDOWS\SYSWOW64\KBDRUM.DLL
2016-05-25 09:50:13 ----A---- C:\WINDOWS\system32\KBDRUM.DLL
2016-05-25 09:50:13 ----A---- C:\WINDOWS\system32\Defrag.exe
2016-05-25 09:50:12 ----A---- C:\WINDOWS\SYSWOW64\KBDTAT.DLL
2016-05-25 09:50:12 ----A---- C:\WINDOWS\system32\KBDTAT.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDYAK.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDRU1.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDRU.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\SYSWOW64\KBDBASH.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDYAK.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDRU1.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDRU.DLL
2016-05-25 09:50:11 ----A---- C:\WINDOWS\system32\KBDBASH.DLL
2016-05-25 09:37:37 ----D---- C:\ProgramData\Atheros
2016-05-25 09:37:27 ----D---- C:\Users\europe\AppData\Roaming\Atheros
2016-05-25 09:26:15 ----D---- C:\Program Files (x86)\Bluetooth Suite
2016-05-25 08:02:19 ----A---- C:\WINDOWS\system32\drivers\athw8x.sys
2016-05-25 07:59:21 ----N---- C:\WINDOWS\system32\stapi64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\stlang64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\stcplx64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\stapo64.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EEP64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EEL64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EED64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\system32\EEA64A.dll
2016-05-25 07:59:21 ----A---- C:\WINDOWS\sttray64.exe
2016-05-25 07:59:20 ----D---- C:\WINDOWS\system32\SRSLabs
2016-05-25 07:58:26 ----A---- C:\WINDOWS\system32\drivers\stwrt64.sys
2016-05-25 07:58:19 ----A---- C:\WINDOWS\system32\st646425.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\SYSWOW64\SynTPCom.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\WdfCoInstaller01009.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\SynTPCo18.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
2016-05-25 07:54:35 ----A---- C:\WINDOWS\system32\drivers\SynTP.sys
2016-05-25 07:54:32 ----A---- C:\WINDOWS\SYSWOW64\SynCom.dll
2016-05-25 07:54:32 ----A---- C:\WINDOWS\system32\SynCOM.dll
2016-05-25 07:54:30 ----A---- C:\WINDOWS\system32\drivers\Smb_driver_Intel.sys