Stránka 1 z 1

Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 06:47
od stsam
Dobrý den, poslední dobou mi dělá, že proces Antimalware Service Executable mi disk zatíží na 100% a počítač se stává nepoužitelným. Proces ukončit nejde, tak prosím o pomoc, radu. Děkuji za Váš čas i um.

Přikládám log z RSIT

omalLogfile of random's system information tool 1.10 (written by random/random)
Run by stsam at 2016-08-13 07:34:49
Microsoft Windows 10 Pro
System drive C: has 81 GB (36%) free of 228 GB
Total RAM: 8136 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:38:57, on 13.08.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0545)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
C:\Windows\SysWOW64\muachost.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
C:\Program Files (x86)\MuralPix\MpAgent.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Windows\SysWOW64\mshta.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\stsam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=Vic ... gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [MuralPixAgent] C:\Program Files (x86)\MuralPix\MpAgent.exe /r
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [DriverPack Notifier] C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe --run startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKCU\..\Run: [OneDrive] "C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [VideoViewer] C:\Program Files (x86)\VideoViewer\VideoViewer.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {53049A9A-1122-4673-B8D4-12F545AE3285} (CV781Object Object) - http://192.168.2.167:88/AVC_AX_764.cab
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
O23 - Service: GamingHotkey_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_ActiveX_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
O23 - Service: MSI Live Update Service (MSI_LiveUpdate_Service) - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - @ByELDI - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12644 bytes

======Listing Processes======







C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\system32\svchost.exe -k appmodel
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\KMSpico\Service_KMS.exe"
C:\Windows\system32\locator.exe
"C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"

C:\Windows\system32\wbem\WmiApSrv.exe
dashost.exe {f29b50ff-5e19-49a5-b96293e28b726f7e}
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey F3E936E2-7DA4-282B-59F6-8DF65DF92D48 -Reinvoke

C:\Windows\System32\WinLogon.exe -SpecialSession
"dwm.exe"
atieclxx
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe"
C:\Windows\SysWOW64\muachost.exe
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe"
"C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe" scan upload
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
KHALMNPR.EXE /API
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\MuralPix\MpAgent.exe" /r
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Windows\System32\mshta.exe" "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\bin\Tools\run.hta" "--relaunch" "true" "--run" "startup"
"C:\Windows\System32\cmd.exe" /C powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression" > "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stdout.log" 2> "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stderr.log"
\??\C:\Windows\system32\conhost.exe 0x4
powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression"
C:\Windows\System32\svchost.exe -k UnistackSvcGroup

C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\system32\compattelrunner.exe
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"fontdrvhost.exe"
"C:\Windows\System32\Taskmgr.exe" /3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=52.0.2743.116 --handshake-handle=0x1a8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="8124.0.1249233551\2077789560" --mojo-application-channel-token=4C9C3347F88DE3ED5A5AC6AF44178535 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,13,27,55 --gpu-vendor-id=0x1002 --gpu-device-id=0x67df --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=16.300.0.0 --gpu-driver-date=6-28-2016 --mojo-platform-channel-handle=1252 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8C85144625CBBC6A43D4F0A8D662C520 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=4A11360B9A616B99C86859AD85EA7E26 --mojo-application-channel-token=E3D21900503249DB050C3E550396B40B --channel="8124.1.851544708\271718450" --mojo-platform-channel-handle=2300 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4043DA56AE328F5B28158319D606BB99 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=73A91C7171BBCB6CB79AE829E7EE9460 --mojo-application-channel-token=A4E8F60DA7BE25D142220E90ABE5C406 --channel="8124.2.999908557\476529172" --mojo-platform-channel-handle=2360 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=02C7F62EE586097A824BD762B08488CF --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=C88306070C12463BC522BC6A2C16621D --mojo-application-channel-token=F54653761001648A97BD6F2B3A004717 --channel="8124.4.109337816\1038838931" --mojo-platform-channel-handle=2852 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4E77192C7A2A60640E84DF815352B0EE --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=2D8F7758716730A90FB6D9114D19C24B --mojo-application-channel-token=551E7BEBBC7DECC3E002809E339B90CD --channel="8124.5.1904356563\358751761" --mojo-platform-channel-handle=2856 /prefetch:1
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$308CE,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
"C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$208E0,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
C:\Windows\system32\DeviceCensus.exe -cv:T3yKlP98OEOWJnjQ.4

"C:\Users\stsam\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=017128FA7225A853CC443198E9F4B795 --lang=cs --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=468FC8E89E058427F50926EB3E166896 --mojo-application-channel-token=5D58BFDF807FB820C5AC8D33644D7E1C --channel="8124.8.1453647312\1240125929" --mojo-platform-channel-handle=4968 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8D5F062C0B7B3EB2CB0ADFEDED3AF79B --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=60BB871A0CAC383459120B55396F8573 --mojo-application-channel-token=6388244A2EC53327F63A75D5995B5E92 --channel="8124.10.794626780\683474137" --mojo-platform-channel-handle=2336 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="8124.11.1238816108\1743907658" --ppapi-flash-args --lang=cs --device-scale-factor=1 --mojo-platform-channel-handle=4864 --ignored=" --type=renderer " /prefetch:3

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-30 213192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 209504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26 435320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-30 2101040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-30 154832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26 366200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-30 1523504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 6141528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-07-18 8842496]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2015-08-26 3113592]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-07-08 6638472]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-05-18 554184]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-06-29 26424960]
"VideoViewer"=C:\Program Files (x86)\VideoViewer\VideoViewer.exe [2015-07-03 286720]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MuralPixAgent"=C:\Program Files (x86)\MuralPix\MpAgent.exe [2006-12-30 102400]
"CanonQuickMenu"=C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [2016-03-11 1314432]
"DriverPack Notifier"=C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [2015-12-18 258560]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2016-07-19 11340752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2015-07-02 65992]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=lvcod64.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-08-13 07:34:49 ----D---- C:\rsit
2016-08-13 07:34:49 ----D---- C:\Program Files\trend micro
2016-08-13 06:58:07 ----HD---- C:\OneDriveTemp
2016-08-12 17:51:22 ----D---- C:\Windows\SYSWOW64\LiveUpdate
2016-08-12 17:51:22 ----A---- C:\Windows\SYSWOW64\ReleaseNote.txt
2016-08-12 15:57:58 ----D---- C:\Program Files\MSI Kombustor 3
2016-08-12 15:57:53 ----A---- C:\Windows\acpimof.dll
2016-08-12 15:57:41 ----D---- C:\Intel
2016-08-12 15:57:24 ----SHD---- C:\Config.Msi
2016-08-12 15:57:09 ----A---- C:\Windows\SYSWOW64\muachost.exe
2016-08-12 15:57:05 ----A---- C:\Windows\system32\FintekIcon1.dll
2016-08-12 15:57:05 ----A---- C:\Windows\system32\drivers\I2cHkBurn.sys
2016-08-12 15:56:54 ----D---- C:\Program Files (x86)\MSI
2016-08-12 15:56:54 ----D---- C:\MSI
2016-08-12 15:56:39 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-08-12 15:56:38 ----A---- C:\Windows\system32\vulkan-1.dll
2016-08-12 15:56:35 ----D---- C:\Program Files (x86)\VulkanRT
2016-08-12 15:55:47 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\coinst_16.30.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_vi_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_FJ_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_el_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_cz_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\amdocl12cl64.dll
2016-08-12 15:55:45 ----A---- C:\Windows\SYSWOW64\amdoclvp9lib32.dll
2016-08-12 15:55:45 ----A---- C:\Windows\system32\amdoclvp9lib64.dll
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativvaxy_cik.dat
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativce03.dat
2016-08-12 15:55:43 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_vi.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_FJ.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativce02.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdocl64.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdmcl64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\clinfo.exe
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_stn_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_cik_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amfrt64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34b.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34a.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde31a.dat
2016-08-12 15:52:10 ----D---- C:\Windows\LastGood.Tmp
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryClient.dll
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\rdpudd.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotificationUx.exe
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotification.exe
2016-08-10 18:55:37 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2016-08-10 18:55:37 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-08-10 18:55:37 ----A---- C:\Windows\system32\rdpcorets.dll
2016-08-10 18:55:36 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-08-10 18:55:36 ----A---- C:\Windows\system32\WWAHost.exe
2016-08-10 18:55:35 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\wldp.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupEngine.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupApi.dll
2016-08-10 18:55:34 ----A---- C:\Windows\system32\wmp.dll
2016-08-10 18:55:33 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2016-08-10 18:55:33 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-08-10 18:55:33 ----A---- C:\Windows\system32\dbgeng.dll
2016-08-10 18:55:32 ----A---- C:\Windows\system32\drivers\cng.sys
2016-08-10 18:55:31 ----A---- C:\Windows\system32\wevtutil.exe
2016-08-10 18:55:31 ----A---- C:\Windows\system32\lsasrv.dll
2016-08-10 18:55:30 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\NetSetupApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\musdialoghandlers.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\win32kbase.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\NetSetupEngine.dll
2016-08-10 18:55:28 ----A---- C:\Windows\system32\cdd.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\usocore.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\NetSetupSvc.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2016-08-10 18:55:26 ----A---- C:\Windows\system32\win32kfull.sys
2016-08-10 18:55:25 ----A---- C:\Windows\system32\TpmTasks.dll
2016-08-10 18:55:24 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-08-10 18:55:22 ----A---- C:\Windows\system32\mstscax.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\tdlrecover.exe
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\wwansvc.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\WUDFPlatform.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\winsrv.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\RecoveryDrive.exe
2016-08-10 18:55:19 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\GdiPlus.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\drivers\pdc.sys
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-08-10 18:55:17 ----A---- C:\Windows\system32\sppwinob.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuaueng.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuauclt.exe
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wininet.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\urlmon.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\sppobjs.dll
2016-08-10 18:55:15 ----A---- C:\Windows\SYSWOW64\wevtutil.exe
2016-08-10 18:55:15 ----A---- C:\Windows\system32\iertutil.dll
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\storport.sys
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\pci.sys
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wuapi.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wshbth.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-08-10 18:55:14 ----A---- C:\Windows\system32\BluetoothApis.dll
2016-08-10 18:55:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\tileobjserver.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\appraiser.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\acmigration.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\wldp.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\tdlrecover.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\LockAppHost.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\IdCtrls.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-08-10 18:55:07 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\ActiveSyncProvider.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\IdCtrls.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2016-08-10 18:55:02 ----A---- C:\Windows\system32\msfeeds.dll
2016-08-10 18:55:01 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-08-10 18:55:01 ----A---- C:\Windows\system32\jscript9.dll
2016-08-10 18:54:59 ----A---- C:\Windows\system32\Chakra.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\ieframe.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\Chakradiag.dll
2016-08-10 18:54:57 ----A---- C:\Windows\system32\edgehtml.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\wuuhext.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\mshtml.dll
2016-08-10 18:54:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\LogonController.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\ieapfltr.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\shell32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\ole32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2016-08-10 18:54:50 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2016-08-10 18:54:50 ----A---- C:\Windows\system32\SensorsApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorsNativeApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorService.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\kerberos.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\drivers\rdbss.sys
2016-08-10 18:54:49 ----A---- C:\Windows\system32\bthserv.dll
2016-08-10 18:54:48 ----A---- C:\Windows\system32\ie4uinit.exe
2016-08-01 08:34:43 ----HD---- C:\ProgramData\CanonIJScan
2016-07-29 14:55:44 ----D---- C:\Users\stsam\AppData\Roaming\Mozilla
2016-07-29 14:26:06 ----D---- C:\ProgramData\ATI
2016-07-29 14:23:37 ----D---- C:\Users\stsam\AppData\Roaming\library_dir
2016-07-29 14:23:33 ----D---- C:\Program Files (x86)\Raptr Inc
2016-07-29 14:11:28 ----D---- C:\Users\stsam\AppData\Roaming\DRPNPS
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\Vb40032.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcrt10.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcr70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSVCP70.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvci70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvbvm50.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSSTKPRP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msstdfmt.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71KOR.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71JPN.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ITA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHT.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHS.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71FRA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ESP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ENU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71DEU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70kor.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70jpn.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70ita.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70cht.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70chs.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70fra.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70esp.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70enu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70deu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl71.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl70.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaeapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\toseaeapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE3.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE2.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\WavesGUILib64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosasfapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosade.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tepeqapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tbb_waves.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo264.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\SRSWOW64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sltech64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slprp64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slcnt64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sl3apo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\audioLibVc.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SECOMN32.DLL
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSX64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSH64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSHP64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRRPTR64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFSS_APO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFNHK64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEHDRA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SECOMN64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtPgEx64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEP64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEL64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEG64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEED64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtDataProc64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DHT64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DAA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RCoInstII64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2016-07-29 14:07:26 ----A---- C:\Windows\system32\RCoRes64.dat
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEP64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEL64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEG64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EED64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEA64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MISS_APO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\KAAPORT64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMUI.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMLimiter.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMHVS.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMClariFi.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\FMAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64F3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CX64APO.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CAF64APO2.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\Caf64api.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAR64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAC64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2016-07-29 14:06:56 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 14:06:55 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-07-29 14:06:46 ----D---- C:\Users\stsam\AppData\Roaming\Opera Software
2016-07-29 14:06:40 ----AD---- C:\Program Files (x86)\Opera
2016-07-29 14:06:28 ----AD---- C:\Users\stsam\AppData\Roaming\DriverPack Notifier
2016-07-29 14:06:27 ----D---- C:\Program Files (x86)\DriverPack Notifier
2016-07-29 14:06:27 ----AD---- C:\Program Files (x86)\WinRAR
2016-07-29 14:06:03 ----D---- C:\Users\stsam\AppData\Roaming\DRPSu
2016-07-27 12:39:36 ----AD---- C:\Program Files (x86)\AMD
2016-07-27 12:19:20 ----D---- C:\Program Files (x86)\Geeks3D
2016-07-27 12:18:34 ----D---- C:\Users\stsam\AppData\Roaming\AMD
2016-07-16 17:57:06 ----ASH---- C:\pagefile.sys
2016-07-15 22:20:36 ----D---- C:\Font
2016-07-14 18:26:03 ----ASH---- C:\swapfile.sys

======List of files/folders modified in the last 1 month======

2016-08-13 07:38:50 ----D---- C:\Windows\Temp
2016-08-13 07:34:49 ----RD---- C:\Program Files
2016-08-13 07:34:49 ----D---- C:\Windows\Prefetch
2016-08-13 07:26:09 ----D---- C:\Users\stsam\AppData\Roaming\Skype
2016-08-13 07:00:59 ----HD---- C:\Program Files\WindowsApps
2016-08-13 07:00:58 ----D---- C:\Windows\AppReadiness
2016-08-13 06:57:38 ----D---- C:\Windows\system32\sru
2016-08-12 21:27:32 ----D---- C:\Program Files (x86)\VideoViewer
2016-08-12 19:02:42 ----D---- C:\Windows\System32
2016-08-12 19:02:42 ----D---- C:\Windows\INF
2016-08-12 19:02:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-08-12 18:29:45 ----AD---- C:\Windows\SysWOW64
2016-08-12 18:07:26 ----D---- C:\Windows\Microsoft.NET
2016-08-12 15:58:50 ----D---- C:\Windows
2016-08-12 15:58:29 ----D---- C:\Windows\system32\CatRoot
2016-08-12 15:57:39 ----D---- C:\Windows\system32\drivers
2016-08-12 15:57:38 ----D---- C:\Windows\system32\Tasks
2016-08-12 15:57:38 ----D---- C:\Windows\system32\DriverStore
2016-08-12 15:57:37 ----D---- C:\ProgramData\Package Cache
2016-08-12 15:57:36 ----SHD---- C:\Windows\Installer
2016-08-12 15:57:24 ----SHD---- C:\System Volume Information
2016-08-12 15:56:54 ----RD---- C:\Program Files (x86)
2016-08-12 15:56:18 ----AD---- C:\Program Files\AMD
2016-08-12 07:02:23 ----D---- C:\ProgramData\CanonIJPLM
2016-08-11 20:36:13 ----D---- C:\Windows\system32\config
2016-08-11 19:09:47 ----D---- C:\Windows\WinSxS
2016-08-11 19:09:21 ----D---- C:\Windows\system32\catroot2
2016-08-11 19:07:41 ----D---- C:\Windows\rescache
2016-08-10 22:32:24 ----RD---- C:\Windows\ImmersiveControlPanel
2016-08-10 22:32:24 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\en-US
2016-08-10 22:32:24 ----D---- C:\Windows\system32\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\appraiser
2016-08-10 22:32:23 ----D---- C:\Program Files\Windows Journal
2016-08-10 22:32:23 ----D---- C:\Program Files\Internet Explorer
2016-08-10 22:32:23 ----D---- C:\Program Files (x86)\Internet Explorer
2016-08-10 21:04:27 ----D---- C:\Windows\system32\SecureBootUpdates
2016-08-10 21:04:27 ----D---- C:\Windows\CbsTemp
2016-08-10 21:04:25 ----D---- C:\Windows\system32\MRT
2016-08-10 21:00:14 ----AC---- C:\Windows\system32\MRT.exe
2016-08-06 17:19:10 ----D---- C:\Windows\Minidump
2016-08-05 11:00:11 ----D---- C:\AMD
2016-08-05 09:06:47 ----AD---- C:\Program Files (x86)\DVDFab 9
2016-08-05 07:47:16 ----D---- C:\Users\stsam\AppData\Roaming\vlc
2016-08-04 14:31:45 ----D---- C:\Windows\system32\NDF
2016-08-01 08:34:43 ----HD---- C:\ProgramData
2016-07-30 12:42:22 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-07-30 12:42:11 ----D---- C:\Program Files (x86)\Common Files
2016-07-30 12:41:35 ----AD---- C:\Program Files (x86)\Microsoft Office
2016-07-29 14:22:59 ----D---- C:\ProgramData\AMD
2016-07-29 14:08:47 ----D---- C:\Windows\system32\wbem
2016-07-29 14:08:06 ----AD---- C:\Windows\System
2016-07-29 14:07:56 ----D---- C:\Windows\system32\DAX2
2016-07-29 14:07:46 ----D---- C:\Windows\SYSWOW64\RTCOM
2016-07-29 09:11:18 ----D---- C:\Windows\Tasks
2016-07-29 08:25:52 ----RSD---- C:\Windows\assembly
2016-07-29 08:25:52 ----D---- C:\Windows\SYSWOW64\directx
2016-07-29 08:25:31 ----D---- C:\Games
2016-07-27 21:25:34 ----N---- C:\Windows\system32\MpSigStub.exe
2016-07-27 11:55:26 ----SHD---- C:\$Recycle.Bin
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCfg64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkApi64.dll
2016-07-18 11:56:32 ----A---- C:\Windows\system32\RltkAPO64.dll
2016-07-15 10:09:34 ----SD---- C:\Users\stsam\AppData\Roaming\Microsoft
2016-07-15 10:09:34 ----SD---- C:\ProgramData\Microsoft
2016-07-15 09:05:07 ----D---- C:\ProgramData\Skype
2016-07-15 09:05:05 ----RD---- C:\Program Files (x86)\Skype
2016-07-14 14:45:00 ----D---- C:\Users\stsam\AppData\Roaming\Seznam.cz
2016-07-14 14:44:56 ----D---- C:\Program Files (x86)\Seznam.cz

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-08-03 84640]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-08-03 263296]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-08-03 197288]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-08-03 208552]
R1 EpfwLWF;@oem24.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-08-03 61608]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2016-08-03 153248]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-10-30 47616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-06-29 26689024]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-06-29 500736]
R3 AtiHDAudioService;@oem13.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWT6.sys [2016-04-26 110096]
R3 I2cHkBurn;I2cHkBurn; C:\Windows\system32\drivers\I2cHkBurn.sys [2015-07-27 41760]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-07-18 5193736]
R3 LEqdUsb;@oem29.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2015-06-18 87696]
R3 LHidEqd;@oem30.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2015-06-18 23184]
R3 LHidFilt;@oem35.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2015-06-18 86672]
R3 LMouFilt;@oem35.inf,%LMouFilt.SvcDesc%;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2015-06-18 69264]
S0 amdkmafd;@oem3.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2015-07-28 40720]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2016-08-03 15488]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-10-30 58720]
S3 athur;@oem25.inf,%ATHR.Service.DispName%;Atheros AR9271 Wireless Network Adapter Service; C:\Windows\System32\drivers\athurx.sys [2010-01-05 1847296]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\Windows\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2016-02-13 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Users\stsam\AppData\Local\Temp\HWiNFO64A.SYS [2016-07-26 27552]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\Windows\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 LVRS64;@oem16.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-10-26 351520]
S3 LVUVC64;@oem15.inf,%PID_0825_DD%(UVC);Logitech HD Webcam C270(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-10-26 4758176]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 MSICDSetup;MSICDSetup; \??\W:\CDriver64.sys [2009-08-12 28984]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\W:\NTIOLib_X64.sys [2011-06-29 11888]

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 06:54
od stsam
Zbytek logu:

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2016-06-29 269824]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-08-04 344064]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-07-25 2950856]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-08-03 2780160]
R2 GamingApp_Service;GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [2016-05-19 39888]
R2 GamingHotkey_Service;GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2016-05-16 2019792]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
R2 MSI_ActiveX_Service;MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [2016-06-01 54200]
R2 MSI_LiveUpdate_Service;MSI Live Update Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2016-07-19 2227152]
R2 OneSyncSvc_123f272;Hostitel synchronizace_123f272; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-10-30 43944]
R3 PimIndexMaintenanceSvc_123f272;Data kontaktů_123f272; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16 154440]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_115d2ac;Hostitel synchronizace_115d2ac; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_13ee79d;Hostitel synchronizace_13ee79d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_13eea554;Hostitel synchronizace_13eea554; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_14aa3f5;Hostitel synchronizace_14aa3f5; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_161c72;Hostitel synchronizace_161c72; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_1e00770;Hostitel synchronizace_1e00770; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_1ebcc87;Hostitel synchronizace_1ebcc87; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_20cd149;Hostitel synchronizace_20cd149; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_234b5e9;Hostitel synchronizace_234b5e9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_24ac328;Hostitel synchronizace_24ac328; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_25752c;Hostitel synchronizace_25752c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_26bf420;Hostitel synchronizace_26bf420; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_29c2d73;Hostitel synchronizace_29c2d73; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_2ead2fb;Hostitel synchronizace_2ead2fb; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_3009ab1;Hostitel synchronizace_3009ab1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_310187d;Hostitel synchronizace_310187d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_34006;Hostitel synchronizace_34006; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_34787;Hostitel synchronizace_34787; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_359dc;Hostitel synchronizace_359dc; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_36511;Hostitel synchronizace_36511; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_3ea52;Hostitel synchronizace_3ea52; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_3ebe8d8;Hostitel synchronizace_3ebe8d8; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_4005483;Hostitel synchronizace_4005483; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_41c45;Hostitel synchronizace_41c45; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_42c69;Hostitel synchronizace_42c69; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_448b2;Hostitel synchronizace_448b2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_44e51;Hostitel synchronizace_44e51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_44fa2;Hostitel synchronizace_44fa2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_45331;Hostitel synchronizace_45331; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_466e4;Hostitel synchronizace_466e4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47585;Hostitel synchronizace_47585; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_477a7;Hostitel synchronizace_477a7; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47a94;Hostitel synchronizace_47a94; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47dee;Hostitel synchronizace_47dee; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47eba;Hostitel synchronizace_47eba; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_48013;Hostitel synchronizace_48013; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_48e5e;Hostitel synchronizace_48e5e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_4950e;Hostitel synchronizace_4950e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_4afe2;Hostitel synchronizace_4afe2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_5252c;Hostitel synchronizace_5252c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_54a7d76;Hostitel synchronizace_54a7d76; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_55a65;Hostitel synchronizace_55a65; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_57785;Hostitel synchronizace_57785; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_5abca;Hostitel synchronizace_5abca; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_5f7e05;Hostitel synchronizace_5f7e05; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_60d4422;Hostitel synchronizace_60d4422; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_696a4;Hostitel synchronizace_696a4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_6acd0;Hostitel synchronizace_6acd0; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_6d7dad;Hostitel synchronizace_6d7dad; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_771b7;Hostitel synchronizace_771b7; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_77b8d;Hostitel synchronizace_77b8d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_7bac8a9;Hostitel synchronizace_7bac8a9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_851b4;Hostitel synchronizace_851b4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_88263;Hostitel synchronizace_88263; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_89b9a51;Hostitel synchronizace_89b9a51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_a513f1;Hostitel synchronizace_a513f1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_b2397b;Hostitel synchronizace_b2397b; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_b35df3;Hostitel synchronizace_b35df3; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bb1c9e;Hostitel synchronizace_bb1c9e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_c9e84c;Hostitel synchronizace_c9e84c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_fe8085;Hostitel synchronizace_fe8085; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16 154440]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2015-07-02 356808]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_115d2ac;Služba zasílání zpráv_115d2ac; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_123f272;Služba zasílání zpráv_123f272; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_13ee79d;Služba zasílání zpráv_13ee79d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_13eea554;Služba zasílání zpráv_13eea554; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_14aa3f5;Služba zasílání zpráv_14aa3f5; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_161c72;Služba zasílání zpráv_161c72; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_1e00770;Služba zasílání zpráv_1e00770; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_1ebcc87;Služba zasílání zpráv_1ebcc87; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_20cd149;Služba zasílání zpráv_20cd149; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_234b5e9;Služba zasílání zpráv_234b5e9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_24ac328;Služba zasílání zpráv_24ac328; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_25752c;Služba zasílání zpráv_25752c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_26bf420;Služba zasílání zpráv_26bf420; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_29c2d73;Služba zasílání zpráv_29c2d73; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2ead2fb;Služba zasílání zpráv_2ead2fb; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_3009ab1;Služba zasílání zpráv_3009ab1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_310187d;Služba zasílání zpráv_310187d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_34006;Služba zasílání zpráv_34006; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_34787;Služba zasílání zpráv_34787; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_359dc;Služba zasílání zpráv_359dc; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_36511;Služba zasílání zpráv_36511; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_3ea52;Služba zasílání zpráv_3ea52; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_3ebe8d8;Služba zasílání zpráv_3ebe8d8; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4005483;Služba zasílání zpráv_4005483; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_41c45;Služba zasílání zpráv_41c45; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_42c69;Služba zasílání zpráv_42c69; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_448b2;Služba zasílání zpráv_448b2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_44e51;Služba zasílání zpráv_44e51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_44fa2;Služba zasílání zpráv_44fa2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_45331;Služba zasílání zpráv_45331; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_466e4;Služba zasílání zpráv_466e4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47585;Služba zasílání zpráv_47585; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47a94;Služba zasílání zpráv_47a94; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47dee;Služba zasílání zpráv_47dee; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47eba;Služba zasílání zpráv_47eba; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_48013;Služba zasílání zpráv_48013; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_48e5e;Služba zasílání zpráv_48e5e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4950e;Služba zasílání zpráv_4950e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4afe2;Služba zasílání zpráv_4afe2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_5252c;Služba zasílání zpráv_5252c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_54a7d76;Služba zasílání zpráv_54a7d76; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_55a65;Služba zasílání zpráv_55a65; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_57785;Služba zasílání zpráv_57785; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_5abca;Služba zasílání zpráv_5abca; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_5f7e05;Služba zasílání zpráv_5f7e05; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_60d4422;Služba zasílání zpráv_60d4422; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_696a4;Služba zasílání zpráv_696a4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_6acd0;Služba zasílání zpráv_6acd0; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_6d7dad;Služba zasílání zpráv_6d7dad; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_771b7;Služba zasílání zpráv_771b7; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_77b8d;Služba zasílání zpráv_77b8d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_7bac8a9;Služba zasílání zpráv_7bac8a9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_851b4;Služba zasílání zpráv_851b4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_88263;Služba zasílání zpráv_88263; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_89b9a51;Služba zasílání zpráv_89b9a51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_a513f1;Služba zasílání zpráv_a513f1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_b2397b;Služba zasílání zpráv_b2397b; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_b35df3;Služba zasílání zpráv_b35df3; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bb1c9e;Služba zasílání zpráv_bb1c9e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_c9e84c;Služba zasílání zpráv_c9e84c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_fe8085;Služba zasílání zpráv_fe8085; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-06-03 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2016-07-23 200240]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_115d2ac;Data kontaktů_115d2ac; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_13ee79d;Data kontaktů_13ee79d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_13eea554;Data kontaktů_13eea554; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_14aa3f5;Data kontaktů_14aa3f5; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_161c72;Data kontaktů_161c72; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_1e00770;Data kontaktů_1e00770; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_1ebcc87;Data kontaktů_1ebcc87; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_20cd149;Data kontaktů_20cd149; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_234b5e9;Data kontaktů_234b5e9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_24ac328;Data kontaktů_24ac328; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_25752c;Data kontaktů_25752c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_26bf420;Data kontaktů_26bf420; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_29c2d73;Data kontaktů_29c2d73; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2ead2fb;Data kontaktů_2ead2fb; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_3009ab1;Data kontaktů_3009ab1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_310187d;Data kontaktů_310187d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_34006;Data kontaktů_34006; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_34787;Data kontaktů_34787; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_359dc;Data kontaktů_359dc; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_36511;Data kontaktů_36511; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_3ea52;Data kontaktů_3ea52; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_3ebe8d8;Data kontaktů_3ebe8d8; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_4005483;Data kontaktů_4005483; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_41c45;Data kontaktů_41c45; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_42c69;Data kontaktů_42c69; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_448b2;Data kontaktů_448b2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_44e51;Data kontaktů_44e51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_44fa2;Data kontaktů_44fa2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_45331;Data kontaktů_45331; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 17:08
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 18:53
od stsam
# AdwCleaner v6.000 - *Logfile created 13/08/2016 *at 19:43:31
# *Updated on 12/08/2016 by ToolsLib
# *Database : 2016-08-13.2 [*Server]
# *Operating System : Windows 10 Pro (X64)
# *Username : stsam - STSAM
# *Running from : C:\Users\stsam\Desktop\adwcleaner_6.000.exe
# *Mode: Clean
# *Support : https://toolslib.net/forum



***** [ *Services ] *****



***** [ *Folders ] *****

[-] *Folder deleted: C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoViewer
[-] *Folder deleted: C:\Program Files (x86)\VideoViewer
[#] *Folder deleted on reboot: C:\Users\stsam\AppData\Local\temp
[-] *Folder deleted: C:\Users\stsam\AppData\LocalLow\temp
[#] *Folder deleted on reboot: C:\Windows\temp


***** [ *Files ] *****

[-] *File deleted: C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\vb@yandex.ru.xpi
[-] *File deleted: C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\yasearch@yandex.ru.xpi
[-] *File deleted: C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
[-] *File deleted: C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal


***** [ DLL ] *****



***** [ WMI ] *****



***** [ *Shortcuts ] *****



***** [ *Scheduled Tasks ] *****



***** [ *Registry ] *****

[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{0BF85F37-ECD3-462C-8F41-902FD170F42E}
[#] *Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{0BF85F37-ECD3-462C-8F41-902FD170F42E}
[#] *Key deleted on reboot: HKLM\SOFTWARE\Classes\WebCommObj.ExtCommObj.WebCommObj.ExtCommObj
[#] *Key deleted on reboot: HKLM\SOFTWARE\Classes\WebCommObj.ExtCommObj.WebCommObj.ExtCommObj.1
[#] *Key deleted on reboot: {C81DCEEB-4F70-497A-B8B5-E16727825B43}


***** [ *Browsers ] *****

[-] [mysearchdial.com] [Search Provider] *Deleted: mysearchdial.com
[-] [omiga-plus] [Search Provider] *Deleted: omiga-plus
[-] [babylon.com] [Search Provider] *Deleted: babylon.com
[-] [zapmeta.cz] [Search Provider] *Deleted: zapmeta.cz
[-] [teamspeak.en.softonic.com] [Search Provider] *Deleted: teamspeak.en.softonic.com
[-] [search.ask.com] [Search Provider] *Deleted: search.ask.com
[-] [trovi.search] [Search Provider] *Deleted: trovi.search
[-] [mysearch.avg.com] [Search Provider] *Deleted: mysearch.avg.com
[-] [isearch.omiga-plus.com] [Search Provider] *Deleted: isearch.omiga-plus.com
[-] [C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default] [extension] *Deleted: afpabppcibfahafilhkbbgfnlncppdnc
[-] [C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default] [extension] *Deleted: pelmeidfhdlhlbjimpabfcbnnojbboma


*************************

:: *"Tracing" keys deleted
:: *Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2987 *Bytes] - [13/08/2016 19:43:31]
C:\AdwCleaner\AdwCleaner[S0].txt - [3550 *Bytes] - [13/08/2016 19:34:22]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3135 *Bytes] ##########

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 19:07
od Rudy

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 19:38
od stsam
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2016 01
Ran by stsam (2016-08-13 20:30:40)
Running from C:\Users\stsam\Desktop
Windows 10 Pro Version 1511 (X64) (2016-04-16 10:14:17)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-331433692-3961677159-1017512419-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-331433692-3961677159-1017512419-503 - Limited - Disabled)
Guest (S-1-5-21-331433692-3961677159-1017512419-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-331433692-3961677159-1017512419-1005 - Limited - Enabled)
stsam (S-1-5-21-331433692-3961677159-1017512419-1001 - Administrator - Enabled) => C:\Users\stsam
wctxjybu (S-1-5-21-331433692-3961677159-1017512419-1003 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 9.0.395.2 (Disabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personální firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 20.2.1 - HP Inc.) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.)
Aslain's WoT Modpack verze 9.15.1.1.00 (HKLM-x32\...\Aslains_WoT_Modpack_Installer_is1) (Version: 9.15.1.1.00 - Aslain)
Aslain's XVM WoT Modpack verze 9.15.34 (HKLM-x32\...\ZRwTINhSZfduKONYrSCTiCiGPggQZdcLRvoAVxyCOXXpkHeC~1DC3968F_is1) (Version: 9.15.34 - Aslain)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
Canon MG5600 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5600_series) (Version: 1.01 - Canon Inc.)
Canon MG5600 series On-screen Manual (HKLM-x32\...\Canon MG5600 series On-screen Manual) (Version: 7.7.1 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.5.0 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.5.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.7.0 - Canon Inc.)
Catalyst Control Center Next Localization BR (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
CDRoller version 9.30 (HKLM-x32\...\CDRoller_is1) (Version: 9.30 - Digital Atlantic Corp.)
Corel Graphics - Windows Shell Extension (HKLM\...\_{EBDC2D0D-1E26-4EF2-BB48-C7E18F7800C6}) (Version: 16.0.0.707 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 16.0.707 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit (Version: 16.0.707 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Capture (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Common (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Connect (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Custom Data (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - CZ (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Draw (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Filters (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - FontNav (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - PHOTO-PAINT (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Redist (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Setup Files (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VBA (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VideoBrowser (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VSTA (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Writing Tools (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 (64-Bit) (HKLM\...\_{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.0.0.707 - Corel Corporation)
CorelDRAW Graphics Suite X6 (x64) (Version: 16.0 - Corel Corporation) Hidden
DriverPack Notifier (HKLM-x32\...\DriverPack Notifier) (Version: 2.1.2 - DriverPack Solution)
DVDFab 9.2.1.5 (28/09/2015) (HKLM-x32\...\DVDFab 9_is1) (Version: - Fengtao Software Inc.)
ESET Smart Security (HKLM\...\{5F04A9BE-7E95-4133-B23C-6BCAA3222C21}) (Version: 9.0.374.1 - ESET, spol. s r.o.)
FinePrint (HKLM\...\FinePrint) (Version: 8.16 - FinePrint Software, LLC)
Geeks3D FurMark 1.17.0.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
IPScan (HKLM-x32\...\IPScan) (Version: 1.0.2.8 - Avtech)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
Light Image Resizer 4.7.7.0 (HKLM-x32\...\{EBE030DD-D404-4D92-85E9-8C3624820808}_is1) (Version: 4.7.7.0 - ObviousIdea)
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 16.0.7070.2033 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 CSY (HKLM\...\{F0E39311-E741-4374-963A-8E899DC2C7B6}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 47.0 (x86 ru) (HKLM-x32\...\Mozilla Firefox 47.0 (x86 ru)) (Version: 47.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0 - Mozilla)
MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.0.0.13 - MSI)
MSI Kombustor 3.5.0 (HKLM\...\{9598DA62-2AE8-426D-9C86-BEA96AC6721E}_is1) (Version: - MSI Co., LTD)
MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.1.021 - MSI)
MuralPix 1.07 (HKLM-x32\...\MuralPix) (Version: - )
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Rajče průvodce verze 1.59.54.269 (HKLM-x32\...\rajce.net_is1) (Version: - rajce.net)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7878 - Realtek Semiconductor Corp.)
Registrace uživatele zařízení Canon MG5600 series (HKLM-x32\...\Registrace uživatele zařízení Canon MG5600 series) (Version: - ‭Canon Inc.)
Skype™ 7.25 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.25.106 - Skype Technologies S.A.)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH)
Video Viewer (HKLM-x32\...\Video Viewer) (Version: 0.2.1.4 - AVTECH Corporation, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.3 - VideoLAN)
Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.)
WinRAR 5.30 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
World of Tanks (HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net)
Záruky (HKLM\...\Zaruky) (Version: 4.1.9 - pyramidak)
Záruky (HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\Zaruky) (Version: 4.1.8 - pyramidak)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-331433692-3961677159-1017512419-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\stsam\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {07A59BAB-F48C-4A6F-A92F-EF23C62D8310} - System32\Tasks\{F85AB10B-D146-4EC6-904C-8CC654092F00} => pcalua.exe -a "C:\Users\stsam\Desktop\avech kamera\AVTECH_vyhledavac_IP_V1028\IPScan_1028_Setup.exe" -d "C:\Users\stsam\Desktop\avech kamera\AVTECH_vyhledavac_IP_V1028"
Task: {0F111AC4-EAF8-4AF4-BA7F-CB37349AB8C9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16] (Google Inc.)
Task: {118F2575-CCBF-487F-B061-19F874E67D87} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-07-30] (Microsoft Corporation)
Task: {30683A32-0157-4CF8-8723-7563C32ACE40} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2015-12-02] (@ByELDI)
Task: {5B11343B-B0F1-495B-A162-B251DD60CDFC} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [2015-08-18] (MSI)
Task: {5E930ED9-2D3A-4CDF-857A-37D074573BB4} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation)
Task: {7D3F1AA2-8E79-44F5-AC0E-4CC4C4300498} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation)
Task: {A8227952-4DE2-4ABB-B604-59207270FEB3} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2016-06-30] (Micro-Star INT'L CO., LTD.)
Task: {AA589AED-2F49-4F17-B906-A67101F5B12B} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-06-28] (Advanced Micro Devices, Inc.)
Task: {C19272AA-B3F0-4023-8CB6-729109D3F281} - System32\Tasks\pyramidak Zaruky => C:\Program Files\Zaruky\Zaruky.exe [2016-05-18] (pyramidak)
Task: {C2B3B54F-7909-4418-8BF8-AB696DFAA05E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16] (Google Inc.)
Task: {CE5CDED6-4409-470B-A464-85F9B10D264F} - System32\Tasks\DriverPack Notifier => C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [2015-12-18] ()
Task: {DE2BB7EB-9733-419D-A051-45921FBC4307} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {E9BB552A-1734-4CA5-A03C-17C2316BE372} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2016-06-30] (Micro-Star INT'L CO., LTD.)
Task: {F83EBB2E-58A1-46A2-A6D7-6290FA830EA6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-07-30] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\Windows\SYSTEM32\ism32k.dll
2016-06-14 08:19 - 2013-06-28 15:28 - 00084616 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2015-08-04 00:25 - 2015-08-04 00:25 - 00214528 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 00817152 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Device.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 03650560 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Platform.dll
2016-07-12 21:45 - 2016-07-01 06:48 - 02656408 _____ () C:\Windows\system32\CoreUIComponents.dll
2016-08-12 15:57 - 2016-06-14 16:35 - 00187392 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\D3D11FontDraw.dll
2016-07-12 21:45 - 2016-07-01 06:48 - 02656408 _____ () C:\Windows\System32\CoreUIComponents.dll
2016-05-18 16:33 - 2016-05-18 16:33 - 00959168 _____ () C:\Users\stsam\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-04-19 06:35 - 2016-04-19 06:35 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-02-13 14:53 - 2016-02-13 14:53 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-12 21:46 - 2016-07-01 05:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-07-12 21:45 - 2016-07-01 05:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-07-12 21:45 - 2016-07-01 05:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-07-12 21:45 - 2016-07-01 05:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-07-12 21:45 - 2016-07-01 05:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-06-25 17:34 - 2015-06-25 17:34 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2015-06-25 17:37 - 2015-06-25 17:37 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-06-25 17:35 - 2015-06-25 17:35 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2015-06-25 17:38 - 2015-06-25 17:38 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-06-25 16:53 - 2015-06-25 16:53 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2015-06-25 16:51 - 2015-06-25 16:51 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2015-08-04 00:25 - 2015-08-04 00:25 - 00102400 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2016-08-12 17:51 - 2005-07-18 13:43 - 00160256 _____ () C:\Program Files (x86)\MSI\Live Update\unrar.dll
2016-08-12 15:57 - 2016-06-14 16:35 - 00163328 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\D3D11FontDraw.dll
2016-04-19 06:35 - 2016-04-19 06:35 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 06:35 - 2016-04-19 06:35 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-05-18 16:33 - 2016-05-18 16:33 - 00679624 _____ () C:\Users\stsam\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2016-08-11 19:32 - 2016-07-13 16:33 - 00043520 _____ () C:\Games\World_of_Tanks\voip.dll
2016-07-29 08:32 - 2016-07-13 16:33 - 00140288 _____ () C:\Games\World_of_Tanks\ILU.dll
2016-07-29 08:32 - 2016-07-13 16:33 - 01529344 _____ () C:\Games\World_of_Tanks\ResIL.dll
2016-07-29 08:32 - 2016-07-13 16:33 - 00323568 _____ () C:\Games\World_of_Tanks\ortp.dll
2016-08-09 10:50 - 2016-08-03 02:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-09 10:42 - 2016-08-03 02:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-30 09:24 - 2015-10-30 09:21 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-331433692-3961677159-1017512419-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\stsam\AppData\Roaming\MuralPix\MuralPix_wallpaper.bmp
DNS Servers: 192.168.20.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKLM\...\StartupApproved\Run32: => "seznam-listicka-distribuce"
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\StartupApproved\Run: => "cz.seznam.software.autoupdate"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{CE100C6B-AC97-4D96-B551-FBDECCD55E89}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{829DB21C-E6EC-4D3E-8C2A-5DB1DEDC7C8C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{C7DB543E-D68C-4217-8014-F566B836B666}F:\ovladace\sdi_x64_r439.exe] => (Allow) F:\ovladace\sdi_x64_r439.exe
FirewallRules: [UDP Query User{BA7FA420-0752-4F95-ADB3-75DB81A051CF}F:\ovladace\sdi_x64_r439.exe] => (Allow) F:\ovladace\sdi_x64_r439.exe
FirewallRules: [{D6A3EFFD-2816-4953-A59B-20251668A39A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{31B9C348-12F9-48F2-92A5-7136E080058A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{28295459-CF83-44DD-8EAB-A248EEFEA2BC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{0BC5B39B-75E4-4212-A834-0AF33A964FC8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{47F6AE9B-FAAC-4026-B727-28D5D182EF6E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{88C0BF9F-EA14-408D-A9EE-755CEA1D6F87}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2F5ACDD7-B156-4223-B349-46980FD9F68D}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{8F9AA44A-DCAD-47C2-8290-331D698E3D2C}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{66EDB261-4A3D-4E89-8D5A-BC1D8D33EA2E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{7FC689E6-E301-4F2A-AEA9-60332B8A806C}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{BC25588C-DCD9-4621-8544-6283E6ACC82C}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{FD9FC909-B186-456C-98F2-B9B2BE5177FF}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{20FC2BE8-A097-4D42-AD4A-2802E6123FB5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9D873294-6509-4A21-B240-2D50E015D386}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe
FirewallRules: [{3DB24814-17BE-45D2-A71B-B25C25DADFCC}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe
FirewallRules: [{142F0368-46FE-4F21-8883-D959448CCB72}] => (Allow) C:\Games\World_of_Tanks\worldoftanks.exe
FirewallRules: [{628B31A1-B4BA-448D-8196-BE98DCE86164}] => (Allow) C:\Games\World_of_Tanks\worldoftanks.exe
FirewallRules: [{8966535F-497E-4F1A-A6BB-D3D4FAE1C817}] => (Allow) LPort=26789

==================== Restore Points =========================

06-08-2016 16:49:43 Naplánovaný kontrolní bod
10-08-2016 20:58:34 Windows Update
12-08-2016 15:57:12 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/13/2016 06:57:18 AM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 10:12:35 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 07:08:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program IPScan_1028_Setup.exe verze 1.0.2.6 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 231c

Čas spuštění: 01d1f4bbfb27f86d

Čas ukončení: 6

Cesta k aplikaci: C:\Users\stsam\Desktop\avech kamera\AVTECH_vyhledavac_IP_V1028\IPScan_1028_Setup.exe

ID hlášení: 58042c7a-60af-11e6-bdf8-08606e757678

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (08/12/2016 06:15:22 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 05:49:55 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 03:57:49 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"1 se nezdařilo. Chyba v souboru manifestu nebo zásady UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"2 na řádku UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definice je UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/12/2016 03:57:15 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (08/12/2016 03:56:50 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"1 se nezdařilo. Chyba v souboru manifestu nebo zásady UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"2 na řádku UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definice je UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/12/2016 07:16:48 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"1 se nezdařilo. Chyba v souboru manifestu nebo zásady UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"2 na řádku UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definice je UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/12/2016 07:16:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp, verze: 51.1052.0.0, časové razítko: 0x57051f89
Název chybujícího modulu: isslideshow.dll_unloaded, verze: 1.0.2.0, časové razítko: 0x2a425e19
Kód výjimky: 0xc000041d
Posun chyby: 0x00023e38
ID chybujícího procesu: 0x173c
Čas spuštění chybující aplikace: 0xAslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp0
Cesta k chybující aplikaci: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp1
Cesta k chybujícímu modulu: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp2
ID zprávy: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp3
Úplný název chybujícího balíčku: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp4
ID aplikace související s chybujícím balíčkem: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp5


System errors:
=============
Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Úložiště uživatelských dat_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Data kontaktů_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Úložiště uživatelských dat_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Data kontaktů_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:36:36 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě:
%%1056 = Instance této služby je již spuštěna.

Error: (08/13/2016 07:36:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.


CodeIntegrity:
===================================
Date: 2016-08-13 19:55:05.417
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:55:05.411
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:55:05.404
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:55:05.397
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.467
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.460
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.454
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.447
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-12 18:57:49.961
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-12 18:57:49.955
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD A10-5800K APU with Radeon(tm) HD Graphics
Percentage of memory in use: 51%
Total physical RAM: 8136.32 MB
Available physical RAM: 3919.59 MB
Total Virtual: 9416.32 MB
Available Virtual: 3025.49 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:223.08 GB) (Free:112.57 GB) NTFS
Drive w: (G71-VAT1029) (CDROM) (Total:1.22 GB) (Free:0 GB) CDFS
Drive z: (Zaloha) (Fixed) (Total:1863.01 GB) (Free:497.74 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: F4D3C445)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.1 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 77A3847A)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 20:54
od Rudy
Potřebuji vidět i log FRST. Toto je pouze Additional.

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 21:13
od stsam
sorry

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-08-2016 01
Ran by stsam (administrator) on STSAM (13-08-2016 20:29:48)
Running from C:\Users\stsam\Desktop
Loaded Profiles: stsam (Available Profiles: stsam)
Platform: Windows 10 Pro Version 1511 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
(Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
(Microsoft Corporation) C:\Windows\System32\Locator.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(MSI) C:\Windows\SysWOW64\muachost.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\logishrd\KHAL3\KHALMNPR.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
(Learsy) C:\Program Files (x86)\MuralPix\MpAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Wargaming.net) C:\Games\World_of_Tanks\WorldOfTanks.exe
(forum.viry.cz) C:\Users\stsam\Desktop\FRSTLauncher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8842496 2016-07-18] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6638472 2016-07-08] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [MuralPixAgent] => C:\Program Files (x86)\MuralPix\MpAgent.exe [102400 2006-12-30] (Learsy)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-03-11] (CANON INC.)
HKLM-x32\...\Run: [DriverPack Notifier] => C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [258560 2015-12-18] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11340752 2016-07-19] (Micro-Star INT'L CO., LTD.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [26424960 2016-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\Run: [VideoViewer] => C:\Program Files (x86)\VideoViewer\VideoViewer.exe [286720 2015-07-03] (AVTECH)
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\MountPoints2: {65edbeaf-03bb-11e6-bd67-806e6f6e6963} - "W:\DVDSetup.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.20.2
Tcpip\..\Interfaces\{de929600-8316-411b-8b4e-c174d279e6f3}: [DhcpNameServer] 192.168.20.2

Internet Explorer:
==================
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.cz/?gfe_rd=cr&ei=VicpVImlGYu ... gws_rd=ssl
SearchScopes: HKU\S-1-5-21-331433692-3961677159-1017512419-1001 -> {636E8C50-C2F5-4A1D-B55F-DE92B134CBC0} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-30] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-30] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-30] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-30] (Microsoft Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
DPF: HKLM-x32 {53049A9A-1122-4673-B8D4-12F545AE3285} hxxp://192.168.2.167:88/AVC_AX_764.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2015-10-29] (CANON INC.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-30] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-07-30] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-04-26] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\vb@yandex.ru.xpi [not found]
FF Extension: No Name - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\yasearch@yandex.ru.xpi [not found]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-04-22] [not signed]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR StartupUrls: Default -> "hxxp://www.google.cz/","hxxp://wiki.wargaming. ... AMX_50_120"
CHR Profile: C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-16]
CHR Extension: (Dokumenty Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-16]
CHR Extension: (Disk Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-16]
CHR Extension: (Seznam Lištička - Email) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2016-07-13]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2016-07-13]
CHR Extension: (YouTube) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-16]
CHR Extension: (Tabulky Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-18]
CHR Extension: (Sudoku) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\jknjmdhcdfnhedcghbjbklllbliheppm [2016-04-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-16]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2016-08-12]
CHR Extension: (Gmail) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-09]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2950856 2016-07-25] (Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2780160 2016-08-03] (ESET)
R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [39888 2016-05-19] (Micro-Star Int'l Co., Ltd.)
R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-05-16] (Micro-Star INT'L CO., LTD.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
R2 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [54200 2016-06-01] (Micro-Star INT'L CO., LTD.)
R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2227152 2016-07-19] (Micro-Star INT'L CO., LTD.)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2015-10-30] (HP Inc.) [File not signed]
S3 ose; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [200240 2016-07-23] (Microsoft Corporation) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2015-10-30] (HP Inc.) [File not signed]
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [743616 2015-12-02] (@ByELDI) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [40720 2015-07-28] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [110096 2016-04-26] (Advanced Micro Devices)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [263296 2016-08-03] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15488 2016-08-03] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [197288 2016-08-03] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [153248 2016-08-03] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [208552 2016-08-03] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [61608 2016-08-03] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [84640 2016-08-03] (ESET)
S3 HWiNFO32; C:\Users\stsam\AppData\Local\Temp\HWiNFO64A.SYS [27552 2016-07-26] (REALiX(tm))
R3 I2cHkBurn; C:\Windows\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.)
S3 MSICDSetup; W:\CDriver64.sys [28984 2009-08-12] (Your Corporation)
S3 NTIOLib_1_0_C; W:\NTIOLib_X64.sys [11888 2011-06-29] (MSI) [File not signed]
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [936192 2016-04-01] (Realtek )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-13 20:29 - 2016-08-13 20:30 - 00017536 _____ C:\Users\stsam\Desktop\FRST.txt
2016-08-13 20:29 - 2016-08-13 20:29 - 00000000 ____D C:\FRST
2016-08-13 20:28 - 2016-08-13 20:28 - 02393600 _____ (Farbar) C:\Users\stsam\Desktop\FRST64.exe
2016-08-13 20:25 - 2016-08-13 20:25 - 00112640 _____ (forum.viry.cz) C:\Users\stsam\Downloads\FRSTLauncher.exe
2016-08-13 20:21 - 2016-08-13 20:21 - 00112640 _____ (forum.viry.cz) C:\Users\stsam\Downloads\FRSTLauncher (1).exe
2016-08-13 20:21 - 2016-08-13 20:21 - 00112640 _____ (forum.viry.cz) C:\Users\stsam\Desktop\FRSTLauncher.exe
2016-08-13 19:56 - 2016-08-13 19:56 - 00000000 ___HD C:\OneDriveTemp
2016-08-13 19:54 - 2016-08-13 19:54 - 00001112 _____ C:\Users\stsam\Desktop\VideoViewer.lnk
2016-08-13 19:54 - 2016-08-13 19:54 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoViewer
2016-08-13 19:53 - 2016-08-13 19:59 - 00000000 ____D C:\Program Files (x86)\VideoViewer
2016-08-13 19:33 - 2016-08-13 19:43 - 00000000 ____D C:\AdwCleaner
2016-08-13 19:30 - 2016-08-13 19:30 - 03784256 _____ C:\Users\stsam\Desktop\adwcleaner_6.000.exe
2016-08-13 07:34 - 2016-08-13 07:39 - 00000000 ____D C:\rsit
2016-08-13 07:34 - 2016-08-13 07:38 - 00000000 ____D C:\Program Files\trend micro
2016-08-13 07:33 - 2016-08-13 07:34 - 01222144 _____ C:\Users\stsam\Desktop\RSITx64.exe
2016-08-12 17:51 - 2016-08-12 17:51 - 00002032 _____ C:\Users\Public\Desktop\MSI Live Update 6.lnk
2016-08-12 17:51 - 2016-08-03 14:27 - 00000000 ____D C:\Windows\SysWOW64\LiveUpdate
2016-08-12 17:51 - 2016-07-19 19:27 - 00012669 _____ C:\Windows\SysWOW64\ReleaseNote.txt
2016-08-12 15:58 - 2016-08-12 15:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 3
2016-08-12 15:57 - 2016-08-12 17:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2016-08-12 15:57 - 2016-08-12 15:58 - 00000000 ____D C:\Program Files\MSI Kombustor 3
2016-08-12 15:57 - 2016-08-12 15:57 - 00003132 _____ C:\Windows\System32\Tasks\MSIOSDx86_Host
2016-08-12 15:57 - 2016-08-12 15:57 - 00003132 _____ C:\Windows\System32\Tasks\MSIOSDx64_Host
2016-08-12 15:57 - 2016-08-12 15:57 - 00003058 _____ C:\Windows\System32\Tasks\MSISW_Host
2016-08-12 15:57 - 2016-08-12 15:57 - 00001194 _____ C:\Users\Public\Desktop\MSI Gaming APP.lnk
2016-08-12 15:57 - 2016-08-12 15:57 - 00000000 ____D C:\Intel
2016-08-12 15:57 - 2015-08-18 09:51 - 01692840 _____ (MSI) C:\Windows\SysWOW64\muachost.exe
2016-08-12 15:57 - 2015-07-27 01:37 - 00041760 _____ (FINTEK Corp.) C:\Windows\system32\Drivers\I2cHkBurn.sys
2016-08-12 15:57 - 2015-07-27 01:37 - 00031520 _____ (TODO: <公司名稱>) C:\Windows\system32\FintekIcon1.dll
2016-08-12 15:57 - 2014-04-30 16:23 - 00011248 _____ (Windows (R) Win 7 DDK provider) C:\Windows\acpimof.dll
2016-08-12 15:56 - 2016-08-13 19:54 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2016-08-12 15:56 - 2016-08-12 20:51 - 00000000 ____D C:\MSI
2016-08-12 15:56 - 2016-08-12 17:51 - 00000000 ____D C:\Program Files (x86)\MSI
2016-08-12 15:56 - 2016-08-12 15:56 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-08-12 15:56 - 2016-06-23 20:22 - 00264992 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-08-12 15:56 - 2016-06-23 20:21 - 00257824 _____ C:\Windows\system32\vulkan-1.dll
2016-08-12 15:56 - 2016-06-23 20:21 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-08-12 15:56 - 2016-06-23 20:20 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2016-08-12 15:55 - 2016-06-29 03:50 - 02129920 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amfrt64.dll
2016-08-12 15:55 - 2016-06-29 03:50 - 01820160 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amfrt32.dll
2016-08-12 15:55 - 2016-06-29 03:49 - 48797696 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2016-08-12 15:55 - 2016-06-29 03:49 - 00252928 _____ C:\Windows\system32\clinfo.exe
2016-08-12 15:55 - 2016-06-29 03:48 - 38248960 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2016-08-12 15:55 - 2016-06-29 03:47 - 00096256 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2016-08-12 15:55 - 2016-06-29 03:47 - 00087040 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2016-08-12 15:55 - 2016-06-29 03:46 - 27471872 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2016-08-12 15:55 - 2016-06-29 03:46 - 21623808 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2016-08-12 15:55 - 2016-06-29 03:26 - 00865792 _____ (AMD) C:\Windows\system32\coinst_16.30.dll
2016-08-12 15:55 - 2016-06-29 03:26 - 00728832 _____ C:\Windows\SysWOW64\atiapfxx.blb
2016-08-12 15:55 - 2016-06-29 03:26 - 00728832 _____ C:\Windows\system32\atiapfxx.blb
2016-08-12 15:55 - 2016-06-29 03:24 - 02359296 _____ C:\Windows\system32\amdoclvp9lib64.dll
2016-08-12 15:55 - 2016-06-29 03:24 - 02269184 _____ C:\Windows\SysWOW64\amdoclvp9lib32.dll
2016-08-12 15:55 - 2016-06-22 23:46 - 00117296 _____ C:\Windows\system32\kapp_ci.sbin
2016-08-12 15:55 - 2016-06-19 20:58 - 00112336 _____ C:\Windows\system32\kapp_si.sbin
2016-08-12 15:55 - 2016-06-17 20:50 - 00270912 _____ C:\Windows\system32\ativvaxy_stn_nd.dat
2016-08-12 15:55 - 2016-06-17 20:45 - 00368672 _____ C:\Windows\system32\ativvaxy_el_nd.dat
2016-08-12 15:55 - 2016-06-16 20:09 - 00260720 _____ C:\Windows\system32\ativvaxy_FJ_nd.dat
2016-08-12 15:55 - 2016-06-06 22:51 - 00260980 _____ C:\Windows\system32\ativvaxy_FJ.dat
2016-08-12 15:55 - 2016-06-06 22:47 - 00266816 _____ C:\Windows\system32\ativvaxy_cz_nd.dat
2016-08-12 15:55 - 2016-05-24 05:29 - 00016827 _____ C:\Windows\system32\AMDKernelEvents.man
2016-08-12 15:55 - 2016-05-17 23:05 - 00322736 _____ C:\Windows\system32\ativvaxy_vi_nd.dat
2016-08-12 15:55 - 2016-05-17 22:25 - 00234032 _____ C:\Windows\system32\ativvaxy_cik_nd.dat
2016-08-12 15:55 - 2016-04-21 16:45 - 00166624 _____ C:\Windows\system32\amde34b.dat
2016-08-12 15:55 - 2016-04-21 16:45 - 00166624 _____ C:\Windows\system32\amde34a.dat
2016-08-12 15:55 - 2016-04-21 16:44 - 00177280 _____ C:\Windows\system32\ativce03.dat
2016-08-12 15:55 - 2016-04-21 16:44 - 00175584 _____ C:\Windows\system32\amde31a.dat
2016-08-12 15:55 - 2016-04-21 16:41 - 00100816 _____ C:\Windows\system32\ativce02.dat
2016-08-12 15:55 - 2016-04-13 21:58 - 00234292 _____ C:\Windows\system32\ativvaxy_cik.dat
2016-08-12 15:55 - 2016-03-30 00:09 - 00322996 _____ C:\Windows\system32\ativvaxy_vi.dat
2016-08-12 15:55 - 2016-02-11 20:11 - 00149008 _____ C:\Windows\system32\samu_krnl_ci.sbin
2016-08-12 15:55 - 2015-11-30 16:54 - 00066560 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmcl64.dll
2016-08-12 15:55 - 2015-11-30 16:54 - 00050176 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmcl32.dll
2016-08-12 15:52 - 2016-08-12 15:56 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-08-11 20:56 - 2016-08-11 20:59 - 67195169 _____ (Aslain ) C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
2016-08-10 18:55 - 2016-08-03 13:14 - 01505984 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-08-10 18:55 - 2016-08-03 13:14 - 00092352 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-08-10 18:55 - 2016-08-03 13:14 - 00050368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-08-10 18:55 - 2016-08-03 12:36 - 07469408 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-08-10 18:55 - 2016-08-03 12:36 - 00099680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2016-08-10 18:55 - 2016-08-03 12:36 - 00037744 _____ (Microsoft Corporation) C:\Windows\system32\wldp.dll
2016-08-10 18:55 - 2016-08-03 12:30 - 00026408 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-08-10 18:55 - 2016-08-03 12:23 - 00693600 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2016-08-10 18:55 - 2016-08-03 12:23 - 00115040 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupApi.dll
2016-08-10 18:55 - 2016-08-03 12:22 - 00808288 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2016-08-10 18:55 - 2016-08-03 12:22 - 00465248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2016-08-10 18:55 - 2016-08-03 12:22 - 00331616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2016-08-10 18:55 - 2016-08-03 12:21 - 03675512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-10 18:55 - 2016-08-03 12:21 - 00566112 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2016-08-10 18:55 - 2016-08-03 12:21 - 00303216 _____ (Microsoft Corporation) C:\Windows\system32\LockAppHost.exe
2016-08-10 18:55 - 2016-08-03 12:20 - 01540224 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-08-10 18:55 - 2016-08-03 12:20 - 00692136 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-08-10 18:55 - 2016-08-03 12:19 - 00604928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-08-10 18:55 - 2016-08-03 12:19 - 00161632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-08-10 18:55 - 2016-08-03 12:13 - 01988448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-08-10 18:55 - 2016-08-03 12:13 - 00576864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2016-08-10 18:55 - 2016-08-03 12:13 - 00393056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2016-08-10 18:55 - 2016-08-03 11:51 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\tdlrecover.exe
2016-08-10 18:55 - 2016-08-03 11:51 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-08-10 18:55 - 2016-08-03 11:44 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2016-08-10 18:55 - 2016-08-03 11:44 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2016-08-10 18:55 - 2016-08-03 11:44 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2016-08-10 18:55 - 2016-08-03 11:43 - 16985088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-10 18:55 - 2016-08-03 11:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-08-10 18:55 - 2016-08-03 11:41 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-08-10 18:55 - 2016-08-03 11:40 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\VEDataLayerHelpers.dll
2016-08-10 18:55 - 2016-08-03 11:40 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2016-08-10 18:55 - 2016-08-03 11:40 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2016-08-10 18:55 - 2016-08-03 11:39 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2016-08-10 18:55 - 2016-08-03 11:39 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\BluetoothApis.dll
2016-08-10 18:55 - 2016-08-03 11:38 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2016-08-10 18:55 - 2016-08-03 11:37 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\IdCtrls.dll
2016-08-10 18:55 - 2016-08-03 11:36 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll
2016-08-10 18:55 - 2016-08-03 11:36 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-08-10 18:55 - 2016-08-03 11:35 - 00200192 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2016-08-10 18:55 - 2016-08-03 11:33 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\VEEventDispatcher.dll
2016-08-10 18:55 - 2016-08-03 11:31 - 00506880 _____ (Microsoft Corporation) C:\Windows\system32\tileobjserver.dll
2016-08-10 18:55 - 2016-08-03 11:31 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe
2016-08-10 18:55 - 2016-08-03 11:30 - 00515072 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 11:29 - 14252544 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-08-10 18:55 - 2016-08-03 11:29 - 02127360 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-10 18:55 - 2016-08-03 11:29 - 01500160 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2016-08-10 18:55 - 2016-08-03 11:29 - 01387520 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2016-08-10 18:55 - 2016-08-03 11:29 - 00784384 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-10 18:55 - 2016-08-03 11:28 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-08-10 18:55 - 2016-08-03 11:28 - 00848896 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-08-10 18:55 - 2016-08-03 11:27 - 07536640 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2016-08-10 18:55 - 2016-08-03 11:27 - 01717760 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2016-08-10 18:55 - 2016-08-03 11:18 - 06974464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-10 18:55 - 2016-08-03 11:18 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-10 18:55 - 2016-08-03 11:18 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-10 18:55 - 2016-08-03 11:17 - 02175488 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-08-10 18:55 - 2016-08-03 11:16 - 05123072 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2016-08-10 18:55 - 2016-08-03 11:16 - 03589120 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2016-08-10 18:55 - 2016-08-03 11:16 - 02635776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-08-10 18:55 - 2016-08-03 11:16 - 01732096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-10 18:55 - 2016-08-03 11:14 - 04895232 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-10 18:55 - 2016-08-03 11:14 - 01997824 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 11:13 - 03025920 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-10 18:55 - 2016-08-03 11:13 - 02280960 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-08-10 18:55 - 2016-08-03 11:12 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2016-08-10 18:55 - 2016-08-03 11:11 - 04171264 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-08-10 18:55 - 2016-08-03 07:52 - 00034088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wldp.dll
2016-08-10 18:55 - 2016-08-03 07:34 - 00501592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2016-08-10 18:55 - 2016-08-03 07:34 - 00084832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupApi.dll
2016-08-10 18:55 - 2016-08-03 07:33 - 00051128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsNativeApi.dll
2016-08-10 18:55 - 2016-08-03 07:31 - 02921368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-10 18:55 - 2016-08-03 07:31 - 00957608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-08-10 18:55 - 2016-08-03 07:31 - 00703840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2016-08-10 18:55 - 2016-08-03 07:30 - 21123320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-08-10 18:55 - 2016-08-03 07:30 - 00465760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2016-08-10 18:55 - 2016-08-03 07:30 - 00255168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppHost.exe
2016-08-10 18:55 - 2016-08-03 06:57 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdlrecover.exe
2016-08-10 18:55 - 2016-08-03 06:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshbth.dll
2016-08-10 18:55 - 2016-08-03 06:47 - 13018112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2016-08-10 18:55 - 2016-08-03 06:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2016-08-10 18:55 - 2016-08-03 06:44 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryBroker.dll
2016-08-10 18:55 - 2016-08-03 06:42 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BluetoothApis.dll
2016-08-10 18:55 - 2016-08-03 06:40 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IdCtrls.dll
2016-08-10 18:55 - 2016-08-03 06:39 - 19351040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-10 18:55 - 2016-08-03 06:37 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEEventDispatcher.dll
2016-08-10 18:55 - 2016-08-03 06:35 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtutil.exe
2016-08-10 18:55 - 2016-08-03 06:34 - 00792064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-10 18:55 - 2016-08-03 06:34 - 00400896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 06:33 - 18677760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-08-10 18:55 - 2016-08-03 06:33 - 02050048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-10 18:55 - 2016-08-03 06:33 - 00687616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-10 18:55 - 2016-08-03 06:32 - 12585984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-08-10 18:55 - 2016-08-03 06:32 - 01467392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2016-08-10 18:55 - 2016-08-03 06:32 - 00434688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2016-08-10 18:55 - 2016-08-03 06:31 - 06743040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2016-08-10 18:55 - 2016-08-03 06:31 - 00705536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2016-08-10 18:55 - 2016-08-03 06:29 - 12133376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-10 18:55 - 2016-08-03 06:28 - 03663360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-10 18:55 - 2016-08-03 06:25 - 05323776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2016-08-10 18:55 - 2016-08-03 06:25 - 04078080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2016-08-10 18:55 - 2016-08-03 06:23 - 05660672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-08-10 18:55 - 2016-08-03 06:23 - 01799680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2016-08-10 18:55 - 2016-08-03 06:22 - 02501120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-10 18:55 - 2016-08-03 06:22 - 01502208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-10 18:55 - 2016-08-03 06:21 - 01708032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActiveSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 06:19 - 02180096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2016-08-10 18:54 - 2016-08-03 12:22 - 01322760 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-08-10 18:54 - 2016-08-03 12:22 - 00058408 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.dll
2016-08-10 18:54 - 2016-08-03 12:21 - 22561256 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-08-10 18:54 - 2016-08-03 12:11 - 00422744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2016-08-10 18:54 - 2016-08-03 11:46 - 22384128 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-08-10 18:54 - 2016-08-03 11:40 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll
2016-08-10 18:54 - 2016-08-03 11:38 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2016-08-10 18:54 - 2016-08-03 11:36 - 00221696 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-10 18:54 - 2016-08-03 11:35 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-08-10 18:54 - 2016-08-03 11:34 - 00383488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-08-10 18:54 - 2016-08-03 11:33 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2016-08-10 18:54 - 2016-08-03 11:31 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2016-08-10 18:54 - 2016-08-03 11:30 - 24613888 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-10 18:54 - 2016-08-03 11:30 - 00970752 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-10 18:54 - 2016-08-03 11:28 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2016-08-10 18:54 - 2016-08-03 11:27 - 01752576 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-10 18:54 - 2016-08-03 11:27 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2016-08-10 18:54 - 2016-08-03 11:20 - 13390336 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-10 18:54 - 2016-08-03 11:15 - 07833088 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-08-10 18:54 - 2016-08-03 06:37 - 00335872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-08-10 18:54 - 2016-08-03 06:35 - 00286208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2016-08-10 18:54 - 2016-08-03 06:32 - 01526272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-09 22:13 - 2016-08-09 22:13 - 00003448 _____ C:\Windows\System32\Tasks\{F85AB10B-D146-4EC6-904C-8CC654092F00}
2016-08-06 17:19 - 2016-08-06 17:19 - 00226252 _____ C:\Windows\Minidump\080616-8812-01.dmp
2016-08-01 08:34 - 2016-08-01 08:34 - 00000000 ___HD C:\ProgramData\CanonIJScan
2016-07-30 12:41 - 2016-07-30 12:41 - 00190116 _____ C:\Windows\Minidump\073016-9343-01.dmp
2016-07-29 14:55 - 2016-07-29 14:56 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Mozilla
2016-07-29 14:55 - 2016-07-29 14:55 - 00000000 ____D C:\Users\stsam\AppData\Local\Mozilla
2016-07-29 14:26 - 2016-07-29 14:26 - 00000000 ____D C:\ProgramData\ATI
2016-07-29 14:23 - 2016-07-29 14:23 - 00000000 ____D C:\Users\stsam\AppData\Roaming\library_dir
2016-07-29 14:23 - 2016-07-29 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2016-07-29 14:23 - 2016-07-29 14:23 - 00000000 ____D C:\Program Files (x86)\Raptr Inc
2016-07-29 14:11 - 2016-07-29 14:11 - 00000000 ____D C:\Users\stsam\AppData\Roaming\DRPNPS
2016-07-29 14:08 - 2014-09-10 18:14 - 00163480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00660120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomct2.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00617896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00444328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MShflxgd.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00416408 _____ (Microsoft Corporation ) C:\Windows\SysWOW64\comct332.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00279192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatgrd.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00259736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msflxgrd.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00253080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatlst.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00222360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tabctl32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00219288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00218776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00212112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mci32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00179352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmask32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00170920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comct232.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00131728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00130712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msstdfmt.dll
2016-07-29 14:08 - 2013-11-25 15:27 - 00127640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswinsck.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00119960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomm32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00108696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTKPRP.DLL
2016-07-29 14:08 - 2013-11-25 15:27 - 00104088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\picclp32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00084624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysinfo.ocx
2016-07-29 14:08 - 2011-01-12 21:36 - 01054208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71u.dll
2016-07-29 14:08 - 2011-01-12 21:25 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71DEU.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71ITA.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71FRA.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71ESP.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71ENU.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71KOR.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71JPN.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71CHT.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71CHS.DLL
2016-07-29 14:08 - 2011-01-12 20:53 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl71.dll
2016-07-29 14:08 - 2008-04-15 14:00 - 01355776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvbvm50.dll
2016-07-29 14:08 - 2007-01-30 18:04 - 00339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
2016-07-29 14:08 - 2006-08-25 22:28 - 01017344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70u.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ita.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70fra.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70esp.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70deu.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70enu.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70kor.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70jpn.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70cht.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70chs.dll
2016-07-29 14:08 - 2006-08-25 22:07 - 01024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70.dll
2016-07-29 14:08 - 2006-08-25 21:17 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl70.dll
2016-07-29 14:08 - 2006-04-10 22:41 - 01066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL32.OCX
2016-07-29 14:08 - 2005-01-20 17:25 - 00054784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvci70.dll
2016-07-29 14:08 - 2002-01-05 03:40 - 00487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVCP70.DLL
2016-07-29 14:08 - 1996-01-12 02:00 - 00935632 _____ (Microsoft Corporation) C:\Windows\system\Vb40016.dll
2016-07-29 14:08 - 1996-01-12 02:00 - 00722192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Vb40032.dll
2016-07-29 14:08 - 1994-11-17 23:00 - 00210944 _____ C:\Windows\SysWOW64\msvcrt10.dll
2016-07-29 14:08 - 1993-05-11 19:00 - 00398416 _____ (Microsoft Corporation) C:\Windows\system\Vbrun300.dll
2016-07-29 14:08 - 1992-10-21 00:00 - 00356992 _____ (Microsoft Corporation) C:\Windows\system\vbrun200.dll
2016-07-29 14:08 - 1991-05-10 01:00 - 00271264 _____ C:\Windows\system\vbrun100.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 72520720 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2016-07-29 14:07 - 2016-07-18 11:56 - 24404664 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRenderAVX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 24314816 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRender64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 17370496 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioCapture64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 15202040 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 14057256 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 13122584 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 12988352 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO4064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 10512456 _____ (Intel Corporation) C:\Windows\system32\IntelSSTAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 07172920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 07096192 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 06566325 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2016-07-29 14:07 - 2016-07-18 11:56 - 06358552 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV3apo.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 06264640 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 05793528 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 05593624 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 05339560 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 03299832 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 03282544 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 03199744 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02895104 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2016-07-29 14:07 - 2016-07-18 11:56 - 02825112 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO7064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02732600 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02706872 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02437760 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02203752 _____ (DTS, Inc.) C:\Windows\system32\slcnt64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02190992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02110592 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02071296 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02050176 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01965816 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01959608 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01780624 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01608128 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64APO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01591064 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01508936 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01435152 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01422936 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01382240 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01360528 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01336624 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaeapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01334384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01213664 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01186824 _____ (Intel Corporation) C:\Windows\system32\IntelSstCApoPropPage.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01166168 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01061120 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01041744 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01003864 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00999864 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00965032 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00962136 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tosasfapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00931624 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00927424 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00923752 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00873472 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00743968 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00727440 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00716112 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00708320 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00689888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00678192 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00677672 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00618192 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00589080 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.DLL
2016-07-29 14:07 - 2016-07-18 11:56 - 00582096 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaemaxapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00574760 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00570096 _____ (Intel Corporation) C:\Windows\system32\tbb_waves.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00532384 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00514528 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00504312 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00500560 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00472312 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00467168 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00450128 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00447728 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00447184 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\toseaeapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00445408 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00441272 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00437168 _____ (Conexant Systems, Inc.) C:\Windows\system32\CAF64APO2.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00428232 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00416512 _____ (Harman) C:\Windows\system32\HMUI.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00387320 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00381416 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00371456 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00366128 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HMAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00362064 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00360352 _____ (Harman) C:\Windows\system32\HMClariFi.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00343712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00341152 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00341152 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00330568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00327456 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00310424 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00272720 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00258864 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00253904 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00253872 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00252880 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00231920 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00221976 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00214840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00209536 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00203848 _____ (Harman) C:\Windows\system32\HMHVS.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ_Voice.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00179600 _____ (Harman) C:\Windows\system32\HMLimiter.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00166208 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00158704 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00154368 _____ (Harman) C:\Windows\system32\HarmanAudioInterface.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00151792 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00134208 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00122328 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00118600 _____ C:\Windows\system32\AcpiServiceVnA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00118600 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00112504 _____ (Conexant Systems, Inc.) C:\Windows\system32\Caf64api.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00110992 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00105312 _____ C:\Windows\system32\audioLibVc.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00090920 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00088352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00088328 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00084624 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00075544 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00005604 _____ C:\Windows\system32\cxapo.lncs
2016-07-29 14:07 - 2016-07-18 11:56 - 00000736 _____ C:\Windows\system32\cxapo.prop
2016-07-29 14:06 - 2016-08-05 09:03 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Opera Software
2016-07-29 14:06 - 2016-08-05 09:03 - 00000000 ____D C:\Users\stsam\AppData\Local\Opera Software
2016-07-29 14:06 - 2016-08-05 09:03 - 00000000 ____D C:\Program Files (x86)\Opera
2016-07-29 14:06 - 2016-07-29 14:08 - 00000000 ____D C:\Users\stsam\AppData\Roaming\DRPSu
2016-07-29 14:06 - 2016-07-29 14:07 - 00000000 ____D C:\Users\stsam\AppData\Roaming\DriverPack Notifier
2016-07-29 14:06 - 2016-07-29 14:06 - 00003526 _____ C:\Windows\System32\Tasks\DriverPack Notifier
2016-07-29 14:06 - 2016-07-29 14:06 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\WinRAR
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\DriverPack Notifier
2016-07-29 08:25 - 2016-08-11 19:27 - 00000810 _____ C:\Users\Public\Desktop\World of Tanks.lnk
2016-07-29 08:25 - 2016-08-11 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2016-07-29 07:43 - 2016-07-29 07:43 - 00177140 _____ C:\Windows\Minidump\072916-6984-01.dmp
2016-07-27 20:53 - 2016-07-27 20:53 - 00120180 _____ C:\Windows\Minidump\072716-6609-01.dmp
2016-07-27 20:44 - 2016-07-27 20:44 - 00007625 _____ C:\Users\stsam\AppData\Local\Resmon.ResmonCfg
2016-07-27 17:55 - 2016-07-27 17:55 - 00125508 _____ C:\Windows\Minidump\072716-6875-01.dmp
2016-07-27 17:47 - 2016-08-06 17:19 - 869743340 _____ C:\Windows\MEMORY.DMP
2016-07-27 17:47 - 2016-07-27 17:47 - 00121684 _____ C:\Windows\Minidump\072716-7578-01.dmp
2016-07-27 12:39 - 2016-07-29 14:22 - 00000000 ____D C:\Program Files (x86)\AMD
2016-07-27 12:39 - 2016-07-27 12:39 - 00004296 _____ C:\Windows\System32\Tasks\AMD Updater
2016-07-27 12:39 - 2016-07-27 12:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2016-07-27 12:39 - 2016-07-27 12:39 - 00000000 _____ C:\Windows\ativpsrm.bin
2016-07-27 12:19 - 2016-07-27 12:19 - 00001335 _____ C:\Users\stsam\Desktop\FurMark.lnk
2016-07-27 12:19 - 2016-07-27 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D
2016-07-27 12:19 - 2016-07-27 12:19 - 00000000 ____D C:\Program Files (x86)\Geeks3D
2016-07-27 12:18 - 2016-07-27 12:18 - 00000000 ____D C:\Users\stsam\AppData\Roaming\AMD
2016-07-26 08:43 - 2016-07-26 08:43 - 00000000 ____D C:\Users\stsam\Desktop\HWiNFO64
2016-07-21 15:51 - 2016-07-21 15:51 - 00105857 _____ C:\Users\stsam\Desktop\ticket-BGHEHD.pdf
2016-07-21 15:51 - 2016-07-21 15:51 - 00105419 _____ C:\Users\stsam\Desktop\ticket-L56BD5.pdf
2016-07-15 22:20 - 2016-07-15 22:20 - 00000000 ____D C:\Font

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-13 20:16 - 2016-04-16 13:01 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-13 19:59 - 2016-04-16 12:18 - 01771468 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-13 19:59 - 2016-02-13 14:50 - 00750030 _____ C:\Windows\system32\perfh005.dat
2016-08-13 19:59 - 2016-02-13 14:50 - 00150654 _____ C:\Windows\system32\perfc005.dat
2016-08-13 19:59 - 2015-10-30 09:21 - 00000000 ____D C:\Windows\INF
2016-08-13 19:56 - 2016-04-17 12:13 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Skype
2016-08-13 19:56 - 2016-04-16 12:16 - 00000000 ___RD C:\Users\stsam\OneDrive
2016-08-13 19:55 - 2016-04-16 13:01 - 00000968 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-13 19:55 - 2016-02-13 15:10 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-13 19:54 - 2016-04-18 19:20 - 00001136 _____ C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\VideoViewer.lnk
2016-08-13 19:54 - 2015-10-30 08:28 - 00524288 ___SH C:\Windows\system32\config\BBI
2016-08-13 19:53 - 2016-04-18 22:36 - 00000000 ____D C:\Users\stsam\Desktop\avech kamera
2016-08-13 19:53 - 2016-04-18 19:19 - 00017408 _____ (Microsoft Corporation) C:\psapi.dll
2016-08-13 19:33 - 2016-06-27 18:51 - 00004190 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C2495B7A-D459-4449-A5F1-2B2CA37527E2}
2016-08-13 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\AppReadiness
2016-08-13 07:00 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-08-12 15:57 - 2016-04-16 12:27 - 00000000 ____D C:\ProgramData\Package Cache
2016-08-12 15:56 - 2016-04-16 12:26 - 00000000 ____D C:\Program Files\AMD
2016-08-12 15:52 - 2016-04-16 18:26 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2016-08-12 07:10 - 2016-05-01 18:40 - 00000000 ___RD C:\Users\stsam\Documents\Scanned Documents
2016-08-12 07:02 - 2016-06-14 08:19 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-08-11 19:07 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\rescache
2016-08-11 07:22 - 2016-02-13 15:14 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-08-10 22:32 - 2016-02-13 15:01 - 00000000 ____D C:\Program Files\Windows Journal
2016-08-10 22:32 - 2015-10-30 09:24 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2016-08-10 22:32 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\system32\appraiser
2016-08-10 21:04 - 2016-04-16 12:31 - 00000000 ____D C:\Windows\system32\MRT
2016-08-10 21:04 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\system32\SecureBootUpdates
2016-08-10 21:04 - 2015-10-30 09:11 - 00000000 ____D C:\Windows\CbsTemp
2016-08-10 21:00 - 2016-04-16 12:31 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-08-10 07:50 - 2016-04-18 17:50 - 00000000 ____D C:\Users\stsam\Documents\FinePrint
2016-08-09 22:16 - 2016-04-21 21:39 - 00000000 ____D C:\Users\stsam\AppData\Local\ElevatedDiagnostics
2016-08-09 15:38 - 2016-04-16 12:15 - 00000000 ____D C:\Users\stsam
2016-08-09 11:54 - 2016-04-16 13:04 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-06 17:19 - 2016-06-29 16:12 - 00000000 ____D C:\Windows\Minidump
2016-08-05 12:46 - 2016-04-18 22:36 - 03524096 ___SH C:\Users\stsam\Desktop\Thumbs.db
2016-08-05 11:02 - 2016-04-16 12:26 - 00000000 ____D C:\AMD
2016-08-05 09:06 - 2016-07-13 10:24 - 00000000 ____D C:\Program Files (x86)\DVDFab 9
2016-08-05 07:47 - 2016-05-17 06:43 - 00000000 ____D C:\Users\stsam\AppData\Roaming\vlc
2016-08-04 14:31 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\system32\NDF
2016-08-03 10:24 - 2016-02-09 08:27 - 00263296 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00208552 _____ (ESET) C:\Windows\system32\Drivers\epfw.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00197288 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00153248 _____ (ESET) C:\Windows\system32\Drivers\ekbdflt.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00084640 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00061608 _____ (ESET) C:\Windows\system32\Drivers\epfwlwf.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00015488 _____ (ESET) C:\Windows\system32\Drivers\eelam.sys
2016-08-03 08:39 - 2016-05-08 06:53 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-01 13:04 - 2016-05-01 18:52 - 00000000 ____D C:\Users\stsam\Documents\Recepty
2016-08-01 10:23 - 2016-05-02 17:57 - 00000000 ____D C:\Users\stsam\AppData\Local\AutoPlan
2016-08-01 10:23 - 2016-05-01 18:49 - 00000000 ____D C:\Users\stsam\Documents\AutoPlan
2016-07-30 12:42 - 2015-10-30 09:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-07-30 12:41 - 2016-04-16 16:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-07-29 14:22 - 2016-04-16 12:27 - 00000000 ____D C:\ProgramData\AMD
2016-07-29 14:08 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\System
2016-07-29 14:07 - 2016-04-16 18:27 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2016-07-29 14:07 - 2016-04-16 18:27 - 00000000 ____D C:\Windows\system32\DAX2
2016-07-29 14:06 - 2016-04-16 17:45 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-29 14:06 - 2016-04-16 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-29 09:11 - 2016-04-16 13:01 - 00004030 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-29 09:11 - 2016-04-16 13:01 - 00003798 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-29 08:25 - 2016-04-16 14:08 - 00000000 ____D C:\Windows\SysWOW64\directx
2016-07-29 08:25 - 2016-04-16 13:09 - 00000000 ____D C:\Games
2016-07-27 21:25 - 2016-04-16 12:33 - 00504488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-07-27 12:39 - 2016-04-16 12:53 - 00000000 ____D C:\Users\stsam\AppData\Local\AMD
2016-07-19 11:38 - 2016-06-19 21:10 - 00000000 ____D C:\Users\stsam\Desktop\Jana-Foto
2016-07-18 11:56 - 2016-04-16 18:26 - 05193736 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2016-07-18 11:56 - 2016-04-16 18:26 - 03283248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2016-07-18 11:56 - 2016-04-16 18:26 - 03090544 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2016-07-18 11:56 - 2016-04-16 18:26 - 00192992 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2016-07-18 11:56 - 2016-04-16 18:26 - 00023704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2016-07-18 09:40 - 2016-05-06 06:29 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-07-15 09:05 - 2016-04-17 12:13 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-07-15 09:05 - 2016-04-17 12:13 - 00000000 ____D C:\ProgramData\Skype
2016-07-14 14:45 - 2016-07-13 10:32 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Seznam.cz
2016-07-14 14:44 - 2016-07-13 10:33 - 00000000 ____D C:\Program Files (x86)\Seznam.cz

==================== Files in the root of some directories =======

2016-07-27 20:44 - 2016-07-27 20:44 - 0007625 _____ () C:\Users\stsam\AppData\Local\Resmon.ResmonCfg
2016-04-16 18:27 - 2016-04-16 18:27 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\stsam\AppData\Local\Temp\libeay32.dll
C:\Users\stsam\AppData\Local\Temp\msvcm80.dll
C:\Users\stsam\AppData\Local\Temp\msvcp80.dll
C:\Users\stsam\AppData\Local\Temp\msvcr120.dll
C:\Users\stsam\AppData\Local\Temp\msvcr80.dll
C:\Users\stsam\AppData\Local\Temp\playstv_patch.exe
C:\Users\stsam\AppData\Local\Temp\raptrpatch.exe
C:\Users\stsam\AppData\Local\Temp\raptr_stub.exe
C:\Users\stsam\AppData\Local\Temp\sqlite3.dll
C:\Users\stsam\AppData\Local\Temp\vlc-2.2.4-win32.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-07 20:15

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:223.08 GB) (Free:112.57 GB) NTFS
Drive w: (G71-VAT1029) (CDROM) (Total:1.22 GB) (Free:0 GB) CDFS
Drive z: (Zaloha) (Fixed) (Total:1863.01 GB) (Free:497.74 GB) NTFS

Available physical RAM: 3919.59 MB
Total physical RAM: 8136.32 MB
Percentage of memory in use: 51%

==================== MBR and Partition Table ==================

Light Image Resizer 4.7.7.0 (HKLM-x32\...\{EBE030DD-D404-4D92-85E9-8C3624820808}_is1) (Version: 4.7.7.0 - ObviousIdea)
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: F4D3C445)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.1 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 77A3847A)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

==================== Security Center ==================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 9.0.395.2 (Disabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personální firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\stsam\Desktop" je 1773 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000001


==================== End Of Log ==============================

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 13 srp 2016 21:48
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\MountPoints2: {65edbeaf-03bb-11e6-bd67-806e6f6e6963} - "W:\DVDSetup.exe"
CHR StartupUrls: Default -> "hxxp://www.google.cz/","hxxp://wiki.wargaming. ... AMX_50_120"
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\ProgramData\DP45977C.lfl
C:\Users\stsam\AppData\Local\Temp
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Z logu:
Velikost slozky "C:\Users\stsam\Desktop" je 1773 MB.
To je příliš mnoho a může to zpomalovat start systému. Vytvořte v C:\Users\stsam novou složku, do níž přesuňte všechna data z plochy (kromě zástupců). Na plochu si pak pro snazší přístup dejte zástupce té složky.

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 14 srp 2016 19:54
od stsam
Díky, zdá se že je problém vyřešen, každopádně je výrazně svižnější, ještě jednou moc děkuju.

Re: Pomalý PC, neustále vytěžuje Antimalware

Napsal: 14 srp 2016 20:10
od Rudy
To jsem rád a nemáte zač! :)