Pomalý PC, neustále vytěžuje Antimalware
Napsal: 13 srp 2016 06:47
Dobrý den, poslední dobou mi dělá, že proces Antimalware Service Executable mi disk zatíží na 100% a počítač se stává nepoužitelným. Proces ukončit nejde, tak prosím o pomoc, radu. Děkuji za Váš čas i um.
Přikládám log z RSIT
omalLogfile of random's system information tool 1.10 (written by random/random)
Run by stsam at 2016-08-13 07:34:49
Microsoft Windows 10 Pro
System drive C: has 81 GB (36%) free of 228 GB
Total RAM: 8136 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:38:57, on 13.08.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0545)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
C:\Windows\SysWOW64\muachost.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
C:\Program Files (x86)\MuralPix\MpAgent.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Windows\SysWOW64\mshta.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\stsam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=Vic ... gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [MuralPixAgent] C:\Program Files (x86)\MuralPix\MpAgent.exe /r
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [DriverPack Notifier] C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe --run startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKCU\..\Run: [OneDrive] "C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [VideoViewer] C:\Program Files (x86)\VideoViewer\VideoViewer.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {53049A9A-1122-4673-B8D4-12F545AE3285} (CV781Object Object) - http://192.168.2.167:88/AVC_AX_764.cab
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
O23 - Service: GamingHotkey_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_ActiveX_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
O23 - Service: MSI Live Update Service (MSI_LiveUpdate_Service) - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - @ByELDI - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12644 bytes
======Listing Processes======
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\system32\svchost.exe -k appmodel
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\KMSpico\Service_KMS.exe"
C:\Windows\system32\locator.exe
"C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
C:\Windows\system32\wbem\WmiApSrv.exe
dashost.exe {f29b50ff-5e19-49a5-b96293e28b726f7e}
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey F3E936E2-7DA4-282B-59F6-8DF65DF92D48 -Reinvoke
C:\Windows\System32\WinLogon.exe -SpecialSession
"dwm.exe"
atieclxx
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe"
C:\Windows\SysWOW64\muachost.exe
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe"
"C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe" scan upload
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
KHALMNPR.EXE /API
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\MuralPix\MpAgent.exe" /r
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Windows\System32\mshta.exe" "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\bin\Tools\run.hta" "--relaunch" "true" "--run" "startup"
"C:\Windows\System32\cmd.exe" /C powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression" > "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stdout.log" 2> "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stderr.log"
\??\C:\Windows\system32\conhost.exe 0x4
powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression"
C:\Windows\System32\svchost.exe -k UnistackSvcGroup
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\system32\compattelrunner.exe
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"fontdrvhost.exe"
"C:\Windows\System32\Taskmgr.exe" /3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=52.0.2743.116 --handshake-handle=0x1a8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="8124.0.1249233551\2077789560" --mojo-application-channel-token=4C9C3347F88DE3ED5A5AC6AF44178535 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,13,27,55 --gpu-vendor-id=0x1002 --gpu-device-id=0x67df --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=16.300.0.0 --gpu-driver-date=6-28-2016 --mojo-platform-channel-handle=1252 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8C85144625CBBC6A43D4F0A8D662C520 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=4A11360B9A616B99C86859AD85EA7E26 --mojo-application-channel-token=E3D21900503249DB050C3E550396B40B --channel="8124.1.851544708\271718450" --mojo-platform-channel-handle=2300 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4043DA56AE328F5B28158319D606BB99 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=73A91C7171BBCB6CB79AE829E7EE9460 --mojo-application-channel-token=A4E8F60DA7BE25D142220E90ABE5C406 --channel="8124.2.999908557\476529172" --mojo-platform-channel-handle=2360 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=02C7F62EE586097A824BD762B08488CF --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=C88306070C12463BC522BC6A2C16621D --mojo-application-channel-token=F54653761001648A97BD6F2B3A004717 --channel="8124.4.109337816\1038838931" --mojo-platform-channel-handle=2852 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4E77192C7A2A60640E84DF815352B0EE --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=2D8F7758716730A90FB6D9114D19C24B --mojo-application-channel-token=551E7BEBBC7DECC3E002809E339B90CD --channel="8124.5.1904356563\358751761" --mojo-platform-channel-handle=2856 /prefetch:1
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$308CE,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
"C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$208E0,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
C:\Windows\system32\DeviceCensus.exe -cv:T3yKlP98OEOWJnjQ.4
"C:\Users\stsam\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=017128FA7225A853CC443198E9F4B795 --lang=cs --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=468FC8E89E058427F50926EB3E166896 --mojo-application-channel-token=5D58BFDF807FB820C5AC8D33644D7E1C --channel="8124.8.1453647312\1240125929" --mojo-platform-channel-handle=4968 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8D5F062C0B7B3EB2CB0ADFEDED3AF79B --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=60BB871A0CAC383459120B55396F8573 --mojo-application-channel-token=6388244A2EC53327F63A75D5995B5E92 --channel="8124.10.794626780\683474137" --mojo-platform-channel-handle=2336 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="8124.11.1238816108\1743907658" --ppapi-flash-args --lang=cs --device-scale-factor=1 --mojo-platform-channel-handle=4864 --ignored=" --type=renderer " /prefetch:3
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-30 213192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 209504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26 435320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-30 2101040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-30 154832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26 366200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-30 1523504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 6141528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-07-18 8842496]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2015-08-26 3113592]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-07-08 6638472]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-05-18 554184]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-06-29 26424960]
"VideoViewer"=C:\Program Files (x86)\VideoViewer\VideoViewer.exe [2015-07-03 286720]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MuralPixAgent"=C:\Program Files (x86)\MuralPix\MpAgent.exe [2006-12-30 102400]
"CanonQuickMenu"=C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [2016-03-11 1314432]
"DriverPack Notifier"=C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [2015-12-18 258560]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2016-07-19 11340752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2015-07-02 65992]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=lvcod64.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-08-13 07:34:49 ----D---- C:\rsit
2016-08-13 07:34:49 ----D---- C:\Program Files\trend micro
2016-08-13 06:58:07 ----HD---- C:\OneDriveTemp
2016-08-12 17:51:22 ----D---- C:\Windows\SYSWOW64\LiveUpdate
2016-08-12 17:51:22 ----A---- C:\Windows\SYSWOW64\ReleaseNote.txt
2016-08-12 15:57:58 ----D---- C:\Program Files\MSI Kombustor 3
2016-08-12 15:57:53 ----A---- C:\Windows\acpimof.dll
2016-08-12 15:57:41 ----D---- C:\Intel
2016-08-12 15:57:24 ----SHD---- C:\Config.Msi
2016-08-12 15:57:09 ----A---- C:\Windows\SYSWOW64\muachost.exe
2016-08-12 15:57:05 ----A---- C:\Windows\system32\FintekIcon1.dll
2016-08-12 15:57:05 ----A---- C:\Windows\system32\drivers\I2cHkBurn.sys
2016-08-12 15:56:54 ----D---- C:\Program Files (x86)\MSI
2016-08-12 15:56:54 ----D---- C:\MSI
2016-08-12 15:56:39 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-08-12 15:56:38 ----A---- C:\Windows\system32\vulkan-1.dll
2016-08-12 15:56:35 ----D---- C:\Program Files (x86)\VulkanRT
2016-08-12 15:55:47 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\coinst_16.30.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_vi_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_FJ_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_el_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_cz_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\amdocl12cl64.dll
2016-08-12 15:55:45 ----A---- C:\Windows\SYSWOW64\amdoclvp9lib32.dll
2016-08-12 15:55:45 ----A---- C:\Windows\system32\amdoclvp9lib64.dll
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativvaxy_cik.dat
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativce03.dat
2016-08-12 15:55:43 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_vi.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_FJ.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativce02.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdocl64.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdmcl64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\clinfo.exe
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_stn_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_cik_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amfrt64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34b.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34a.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde31a.dat
2016-08-12 15:52:10 ----D---- C:\Windows\LastGood.Tmp
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryClient.dll
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\rdpudd.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotificationUx.exe
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotification.exe
2016-08-10 18:55:37 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2016-08-10 18:55:37 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-08-10 18:55:37 ----A---- C:\Windows\system32\rdpcorets.dll
2016-08-10 18:55:36 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-08-10 18:55:36 ----A---- C:\Windows\system32\WWAHost.exe
2016-08-10 18:55:35 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\wldp.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupEngine.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupApi.dll
2016-08-10 18:55:34 ----A---- C:\Windows\system32\wmp.dll
2016-08-10 18:55:33 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2016-08-10 18:55:33 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-08-10 18:55:33 ----A---- C:\Windows\system32\dbgeng.dll
2016-08-10 18:55:32 ----A---- C:\Windows\system32\drivers\cng.sys
2016-08-10 18:55:31 ----A---- C:\Windows\system32\wevtutil.exe
2016-08-10 18:55:31 ----A---- C:\Windows\system32\lsasrv.dll
2016-08-10 18:55:30 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\NetSetupApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\musdialoghandlers.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\win32kbase.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\NetSetupEngine.dll
2016-08-10 18:55:28 ----A---- C:\Windows\system32\cdd.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\usocore.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\NetSetupSvc.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2016-08-10 18:55:26 ----A---- C:\Windows\system32\win32kfull.sys
2016-08-10 18:55:25 ----A---- C:\Windows\system32\TpmTasks.dll
2016-08-10 18:55:24 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-08-10 18:55:22 ----A---- C:\Windows\system32\mstscax.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\tdlrecover.exe
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\wwansvc.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\WUDFPlatform.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\winsrv.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\RecoveryDrive.exe
2016-08-10 18:55:19 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\GdiPlus.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\drivers\pdc.sys
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-08-10 18:55:17 ----A---- C:\Windows\system32\sppwinob.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuaueng.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuauclt.exe
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wininet.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\urlmon.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\sppobjs.dll
2016-08-10 18:55:15 ----A---- C:\Windows\SYSWOW64\wevtutil.exe
2016-08-10 18:55:15 ----A---- C:\Windows\system32\iertutil.dll
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\storport.sys
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\pci.sys
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wuapi.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wshbth.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-08-10 18:55:14 ----A---- C:\Windows\system32\BluetoothApis.dll
2016-08-10 18:55:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\tileobjserver.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\appraiser.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\acmigration.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\wldp.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\tdlrecover.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\LockAppHost.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\IdCtrls.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-08-10 18:55:07 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\ActiveSyncProvider.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\IdCtrls.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2016-08-10 18:55:02 ----A---- C:\Windows\system32\msfeeds.dll
2016-08-10 18:55:01 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-08-10 18:55:01 ----A---- C:\Windows\system32\jscript9.dll
2016-08-10 18:54:59 ----A---- C:\Windows\system32\Chakra.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\ieframe.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\Chakradiag.dll
2016-08-10 18:54:57 ----A---- C:\Windows\system32\edgehtml.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\wuuhext.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\mshtml.dll
2016-08-10 18:54:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\LogonController.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\ieapfltr.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\shell32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\ole32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2016-08-10 18:54:50 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2016-08-10 18:54:50 ----A---- C:\Windows\system32\SensorsApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorsNativeApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorService.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\kerberos.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\drivers\rdbss.sys
2016-08-10 18:54:49 ----A---- C:\Windows\system32\bthserv.dll
2016-08-10 18:54:48 ----A---- C:\Windows\system32\ie4uinit.exe
2016-08-01 08:34:43 ----HD---- C:\ProgramData\CanonIJScan
2016-07-29 14:55:44 ----D---- C:\Users\stsam\AppData\Roaming\Mozilla
2016-07-29 14:26:06 ----D---- C:\ProgramData\ATI
2016-07-29 14:23:37 ----D---- C:\Users\stsam\AppData\Roaming\library_dir
2016-07-29 14:23:33 ----D---- C:\Program Files (x86)\Raptr Inc
2016-07-29 14:11:28 ----D---- C:\Users\stsam\AppData\Roaming\DRPNPS
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\Vb40032.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcrt10.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcr70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSVCP70.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvci70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvbvm50.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSSTKPRP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msstdfmt.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71KOR.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71JPN.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ITA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHT.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHS.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71FRA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ESP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ENU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71DEU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70kor.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70jpn.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70ita.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70cht.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70chs.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70fra.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70esp.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70enu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70deu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl71.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl70.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaeapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\toseaeapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE3.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE2.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\WavesGUILib64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosasfapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosade.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tepeqapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tbb_waves.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo264.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\SRSWOW64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sltech64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slprp64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slcnt64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sl3apo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\audioLibVc.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SECOMN32.DLL
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSX64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSH64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSHP64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRRPTR64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFSS_APO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFNHK64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEHDRA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SECOMN64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtPgEx64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEP64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEL64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEG64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEED64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtDataProc64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DHT64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DAA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RCoInstII64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2016-07-29 14:07:26 ----A---- C:\Windows\system32\RCoRes64.dat
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEP64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEL64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEG64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EED64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEA64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MISS_APO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\KAAPORT64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMUI.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMLimiter.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMHVS.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMClariFi.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\FMAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64F3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CX64APO.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CAF64APO2.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\Caf64api.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAR64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAC64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2016-07-29 14:06:56 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 14:06:55 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-07-29 14:06:46 ----D---- C:\Users\stsam\AppData\Roaming\Opera Software
2016-07-29 14:06:40 ----AD---- C:\Program Files (x86)\Opera
2016-07-29 14:06:28 ----AD---- C:\Users\stsam\AppData\Roaming\DriverPack Notifier
2016-07-29 14:06:27 ----D---- C:\Program Files (x86)\DriverPack Notifier
2016-07-29 14:06:27 ----AD---- C:\Program Files (x86)\WinRAR
2016-07-29 14:06:03 ----D---- C:\Users\stsam\AppData\Roaming\DRPSu
2016-07-27 12:39:36 ----AD---- C:\Program Files (x86)\AMD
2016-07-27 12:19:20 ----D---- C:\Program Files (x86)\Geeks3D
2016-07-27 12:18:34 ----D---- C:\Users\stsam\AppData\Roaming\AMD
2016-07-16 17:57:06 ----ASH---- C:\pagefile.sys
2016-07-15 22:20:36 ----D---- C:\Font
2016-07-14 18:26:03 ----ASH---- C:\swapfile.sys
======List of files/folders modified in the last 1 month======
2016-08-13 07:38:50 ----D---- C:\Windows\Temp
2016-08-13 07:34:49 ----RD---- C:\Program Files
2016-08-13 07:34:49 ----D---- C:\Windows\Prefetch
2016-08-13 07:26:09 ----D---- C:\Users\stsam\AppData\Roaming\Skype
2016-08-13 07:00:59 ----HD---- C:\Program Files\WindowsApps
2016-08-13 07:00:58 ----D---- C:\Windows\AppReadiness
2016-08-13 06:57:38 ----D---- C:\Windows\system32\sru
2016-08-12 21:27:32 ----D---- C:\Program Files (x86)\VideoViewer
2016-08-12 19:02:42 ----D---- C:\Windows\System32
2016-08-12 19:02:42 ----D---- C:\Windows\INF
2016-08-12 19:02:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-08-12 18:29:45 ----AD---- C:\Windows\SysWOW64
2016-08-12 18:07:26 ----D---- C:\Windows\Microsoft.NET
2016-08-12 15:58:50 ----D---- C:\Windows
2016-08-12 15:58:29 ----D---- C:\Windows\system32\CatRoot
2016-08-12 15:57:39 ----D---- C:\Windows\system32\drivers
2016-08-12 15:57:38 ----D---- C:\Windows\system32\Tasks
2016-08-12 15:57:38 ----D---- C:\Windows\system32\DriverStore
2016-08-12 15:57:37 ----D---- C:\ProgramData\Package Cache
2016-08-12 15:57:36 ----SHD---- C:\Windows\Installer
2016-08-12 15:57:24 ----SHD---- C:\System Volume Information
2016-08-12 15:56:54 ----RD---- C:\Program Files (x86)
2016-08-12 15:56:18 ----AD---- C:\Program Files\AMD
2016-08-12 07:02:23 ----D---- C:\ProgramData\CanonIJPLM
2016-08-11 20:36:13 ----D---- C:\Windows\system32\config
2016-08-11 19:09:47 ----D---- C:\Windows\WinSxS
2016-08-11 19:09:21 ----D---- C:\Windows\system32\catroot2
2016-08-11 19:07:41 ----D---- C:\Windows\rescache
2016-08-10 22:32:24 ----RD---- C:\Windows\ImmersiveControlPanel
2016-08-10 22:32:24 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\en-US
2016-08-10 22:32:24 ----D---- C:\Windows\system32\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\appraiser
2016-08-10 22:32:23 ----D---- C:\Program Files\Windows Journal
2016-08-10 22:32:23 ----D---- C:\Program Files\Internet Explorer
2016-08-10 22:32:23 ----D---- C:\Program Files (x86)\Internet Explorer
2016-08-10 21:04:27 ----D---- C:\Windows\system32\SecureBootUpdates
2016-08-10 21:04:27 ----D---- C:\Windows\CbsTemp
2016-08-10 21:04:25 ----D---- C:\Windows\system32\MRT
2016-08-10 21:00:14 ----AC---- C:\Windows\system32\MRT.exe
2016-08-06 17:19:10 ----D---- C:\Windows\Minidump
2016-08-05 11:00:11 ----D---- C:\AMD
2016-08-05 09:06:47 ----AD---- C:\Program Files (x86)\DVDFab 9
2016-08-05 07:47:16 ----D---- C:\Users\stsam\AppData\Roaming\vlc
2016-08-04 14:31:45 ----D---- C:\Windows\system32\NDF
2016-08-01 08:34:43 ----HD---- C:\ProgramData
2016-07-30 12:42:22 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-07-30 12:42:11 ----D---- C:\Program Files (x86)\Common Files
2016-07-30 12:41:35 ----AD---- C:\Program Files (x86)\Microsoft Office
2016-07-29 14:22:59 ----D---- C:\ProgramData\AMD
2016-07-29 14:08:47 ----D---- C:\Windows\system32\wbem
2016-07-29 14:08:06 ----AD---- C:\Windows\System
2016-07-29 14:07:56 ----D---- C:\Windows\system32\DAX2
2016-07-29 14:07:46 ----D---- C:\Windows\SYSWOW64\RTCOM
2016-07-29 09:11:18 ----D---- C:\Windows\Tasks
2016-07-29 08:25:52 ----RSD---- C:\Windows\assembly
2016-07-29 08:25:52 ----D---- C:\Windows\SYSWOW64\directx
2016-07-29 08:25:31 ----D---- C:\Games
2016-07-27 21:25:34 ----N---- C:\Windows\system32\MpSigStub.exe
2016-07-27 11:55:26 ----SHD---- C:\$Recycle.Bin
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCfg64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkApi64.dll
2016-07-18 11:56:32 ----A---- C:\Windows\system32\RltkAPO64.dll
2016-07-15 10:09:34 ----SD---- C:\Users\stsam\AppData\Roaming\Microsoft
2016-07-15 10:09:34 ----SD---- C:\ProgramData\Microsoft
2016-07-15 09:05:07 ----D---- C:\ProgramData\Skype
2016-07-15 09:05:05 ----RD---- C:\Program Files (x86)\Skype
2016-07-14 14:45:00 ----D---- C:\Users\stsam\AppData\Roaming\Seznam.cz
2016-07-14 14:44:56 ----D---- C:\Program Files (x86)\Seznam.cz
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-08-03 84640]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-08-03 263296]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-08-03 197288]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-08-03 208552]
R1 EpfwLWF;@oem24.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-08-03 61608]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2016-08-03 153248]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-10-30 47616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-06-29 26689024]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-06-29 500736]
R3 AtiHDAudioService;@oem13.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWT6.sys [2016-04-26 110096]
R3 I2cHkBurn;I2cHkBurn; C:\Windows\system32\drivers\I2cHkBurn.sys [2015-07-27 41760]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-07-18 5193736]
R3 LEqdUsb;@oem29.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2015-06-18 87696]
R3 LHidEqd;@oem30.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2015-06-18 23184]
R3 LHidFilt;@oem35.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2015-06-18 86672]
R3 LMouFilt;@oem35.inf,%LMouFilt.SvcDesc%;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2015-06-18 69264]
S0 amdkmafd;@oem3.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2015-07-28 40720]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2016-08-03 15488]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-10-30 58720]
S3 athur;@oem25.inf,%ATHR.Service.DispName%;Atheros AR9271 Wireless Network Adapter Service; C:\Windows\System32\drivers\athurx.sys [2010-01-05 1847296]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\Windows\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2016-02-13 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Users\stsam\AppData\Local\Temp\HWiNFO64A.SYS [2016-07-26 27552]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\Windows\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 LVRS64;@oem16.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-10-26 351520]
S3 LVUVC64;@oem15.inf,%PID_0825_DD%(UVC);Logitech HD Webcam C270(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-10-26 4758176]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 MSICDSetup;MSICDSetup; \??\W:\CDriver64.sys [2009-08-12 28984]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\W:\NTIOLib_X64.sys [2011-06-29 11888]
Přikládám log z RSIT
omalLogfile of random's system information tool 1.10 (written by random/random)
Run by stsam at 2016-08-13 07:34:49
Microsoft Windows 10 Pro
System drive C: has 81 GB (36%) free of 228 GB
Total RAM: 8136 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:38:57, on 13.08.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0545)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
C:\Windows\SysWOW64\muachost.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
C:\Program Files (x86)\MuralPix\MpAgent.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Windows\SysWOW64\mshta.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\stsam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=Vic ... gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [MuralPixAgent] C:\Program Files (x86)\MuralPix\MpAgent.exe /r
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [DriverPack Notifier] C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe --run startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKCU\..\Run: [OneDrive] "C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [VideoViewer] C:\Program Files (x86)\VideoViewer\VideoViewer.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {53049A9A-1122-4673-B8D4-12F545AE3285} (CV781Object Object) - http://192.168.2.167:88/AVC_AX_764.cab
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
O23 - Service: GamingHotkey_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_ActiveX_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
O23 - Service: MSI Live Update Service (MSI_LiveUpdate_Service) - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - @ByELDI - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12644 bytes
======Listing Processes======
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\system32\svchost.exe -k appmodel
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\KMSpico\Service_KMS.exe"
C:\Windows\system32\locator.exe
"C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
C:\Windows\system32\wbem\WmiApSrv.exe
dashost.exe {f29b50ff-5e19-49a5-b96293e28b726f7e}
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey F3E936E2-7DA4-282B-59F6-8DF65DF92D48 -Reinvoke
C:\Windows\System32\WinLogon.exe -SpecialSession
"dwm.exe"
atieclxx
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe"
C:\Windows\SysWOW64\muachost.exe
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe"
"C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe" scan upload
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
KHALMNPR.EXE /API
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\MuralPix\MpAgent.exe" /r
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Windows\System32\mshta.exe" "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\bin\Tools\run.hta" "--relaunch" "true" "--run" "startup"
"C:\Windows\System32\cmd.exe" /C powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression" > "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stdout.log" 2> "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stderr.log"
\??\C:\Windows\system32\conhost.exe 0x4
powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression"
C:\Windows\System32\svchost.exe -k UnistackSvcGroup
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\system32\compattelrunner.exe
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"fontdrvhost.exe"
"C:\Windows\System32\Taskmgr.exe" /3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=52.0.2743.116 --handshake-handle=0x1a8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="8124.0.1249233551\2077789560" --mojo-application-channel-token=4C9C3347F88DE3ED5A5AC6AF44178535 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,13,27,55 --gpu-vendor-id=0x1002 --gpu-device-id=0x67df --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=16.300.0.0 --gpu-driver-date=6-28-2016 --mojo-platform-channel-handle=1252 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8C85144625CBBC6A43D4F0A8D662C520 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=4A11360B9A616B99C86859AD85EA7E26 --mojo-application-channel-token=E3D21900503249DB050C3E550396B40B --channel="8124.1.851544708\271718450" --mojo-platform-channel-handle=2300 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4043DA56AE328F5B28158319D606BB99 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=73A91C7171BBCB6CB79AE829E7EE9460 --mojo-application-channel-token=A4E8F60DA7BE25D142220E90ABE5C406 --channel="8124.2.999908557\476529172" --mojo-platform-channel-handle=2360 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=02C7F62EE586097A824BD762B08488CF --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=C88306070C12463BC522BC6A2C16621D --mojo-application-channel-token=F54653761001648A97BD6F2B3A004717 --channel="8124.4.109337816\1038838931" --mojo-platform-channel-handle=2852 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4E77192C7A2A60640E84DF815352B0EE --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=2D8F7758716730A90FB6D9114D19C24B --mojo-application-channel-token=551E7BEBBC7DECC3E002809E339B90CD --channel="8124.5.1904356563\358751761" --mojo-platform-channel-handle=2856 /prefetch:1
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$308CE,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
"C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$208E0,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
C:\Windows\system32\DeviceCensus.exe -cv:T3yKlP98OEOWJnjQ.4
"C:\Users\stsam\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=017128FA7225A853CC443198E9F4B795 --lang=cs --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=468FC8E89E058427F50926EB3E166896 --mojo-application-channel-token=5D58BFDF807FB820C5AC8D33644D7E1C --channel="8124.8.1453647312\1240125929" --mojo-platform-channel-handle=4968 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8D5F062C0B7B3EB2CB0ADFEDED3AF79B --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=60BB871A0CAC383459120B55396F8573 --mojo-application-channel-token=6388244A2EC53327F63A75D5995B5E92 --channel="8124.10.794626780\683474137" --mojo-platform-channel-handle=2336 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="8124.11.1238816108\1743907658" --ppapi-flash-args --lang=cs --device-scale-factor=1 --mojo-platform-channel-handle=4864 --ignored=" --type=renderer " /prefetch:3
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-30 213192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 209504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26 435320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-30 2101040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-30 154832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26 366200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-30 1523504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 6141528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-07-18 8842496]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2015-08-26 3113592]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-07-08 6638472]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-05-18 554184]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-06-29 26424960]
"VideoViewer"=C:\Program Files (x86)\VideoViewer\VideoViewer.exe [2015-07-03 286720]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MuralPixAgent"=C:\Program Files (x86)\MuralPix\MpAgent.exe [2006-12-30 102400]
"CanonQuickMenu"=C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [2016-03-11 1314432]
"DriverPack Notifier"=C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [2015-12-18 258560]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2016-07-19 11340752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2015-07-02 65992]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=lvcod64.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-08-13 07:34:49 ----D---- C:\rsit
2016-08-13 07:34:49 ----D---- C:\Program Files\trend micro
2016-08-13 06:58:07 ----HD---- C:\OneDriveTemp
2016-08-12 17:51:22 ----D---- C:\Windows\SYSWOW64\LiveUpdate
2016-08-12 17:51:22 ----A---- C:\Windows\SYSWOW64\ReleaseNote.txt
2016-08-12 15:57:58 ----D---- C:\Program Files\MSI Kombustor 3
2016-08-12 15:57:53 ----A---- C:\Windows\acpimof.dll
2016-08-12 15:57:41 ----D---- C:\Intel
2016-08-12 15:57:24 ----SHD---- C:\Config.Msi
2016-08-12 15:57:09 ----A---- C:\Windows\SYSWOW64\muachost.exe
2016-08-12 15:57:05 ----A---- C:\Windows\system32\FintekIcon1.dll
2016-08-12 15:57:05 ----A---- C:\Windows\system32\drivers\I2cHkBurn.sys
2016-08-12 15:56:54 ----D---- C:\Program Files (x86)\MSI
2016-08-12 15:56:54 ----D---- C:\MSI
2016-08-12 15:56:39 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-08-12 15:56:38 ----A---- C:\Windows\system32\vulkan-1.dll
2016-08-12 15:56:35 ----D---- C:\Program Files (x86)\VulkanRT
2016-08-12 15:55:47 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\coinst_16.30.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_vi_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_FJ_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_el_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_cz_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\amdocl12cl64.dll
2016-08-12 15:55:45 ----A---- C:\Windows\SYSWOW64\amdoclvp9lib32.dll
2016-08-12 15:55:45 ----A---- C:\Windows\system32\amdoclvp9lib64.dll
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativvaxy_cik.dat
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativce03.dat
2016-08-12 15:55:43 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_vi.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_FJ.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativce02.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdocl64.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdmcl64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\clinfo.exe
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_stn_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_cik_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amfrt64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34b.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34a.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde31a.dat
2016-08-12 15:52:10 ----D---- C:\Windows\LastGood.Tmp
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryClient.dll
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\rdpudd.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotificationUx.exe
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotification.exe
2016-08-10 18:55:37 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2016-08-10 18:55:37 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-08-10 18:55:37 ----A---- C:\Windows\system32\rdpcorets.dll
2016-08-10 18:55:36 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-08-10 18:55:36 ----A---- C:\Windows\system32\WWAHost.exe
2016-08-10 18:55:35 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\wldp.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupEngine.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupApi.dll
2016-08-10 18:55:34 ----A---- C:\Windows\system32\wmp.dll
2016-08-10 18:55:33 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2016-08-10 18:55:33 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-08-10 18:55:33 ----A---- C:\Windows\system32\dbgeng.dll
2016-08-10 18:55:32 ----A---- C:\Windows\system32\drivers\cng.sys
2016-08-10 18:55:31 ----A---- C:\Windows\system32\wevtutil.exe
2016-08-10 18:55:31 ----A---- C:\Windows\system32\lsasrv.dll
2016-08-10 18:55:30 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\NetSetupApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\musdialoghandlers.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\win32kbase.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\NetSetupEngine.dll
2016-08-10 18:55:28 ----A---- C:\Windows\system32\cdd.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\usocore.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\NetSetupSvc.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2016-08-10 18:55:26 ----A---- C:\Windows\system32\win32kfull.sys
2016-08-10 18:55:25 ----A---- C:\Windows\system32\TpmTasks.dll
2016-08-10 18:55:24 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-08-10 18:55:22 ----A---- C:\Windows\system32\mstscax.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\tdlrecover.exe
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\wwansvc.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\WUDFPlatform.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\winsrv.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\RecoveryDrive.exe
2016-08-10 18:55:19 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\GdiPlus.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\drivers\pdc.sys
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-08-10 18:55:17 ----A---- C:\Windows\system32\sppwinob.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuaueng.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuauclt.exe
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wininet.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\urlmon.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\sppobjs.dll
2016-08-10 18:55:15 ----A---- C:\Windows\SYSWOW64\wevtutil.exe
2016-08-10 18:55:15 ----A---- C:\Windows\system32\iertutil.dll
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\storport.sys
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\pci.sys
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wuapi.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wshbth.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-08-10 18:55:14 ----A---- C:\Windows\system32\BluetoothApis.dll
2016-08-10 18:55:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\tileobjserver.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\appraiser.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\acmigration.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\wldp.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\tdlrecover.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\LockAppHost.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\IdCtrls.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-08-10 18:55:07 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\ActiveSyncProvider.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\IdCtrls.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2016-08-10 18:55:02 ----A---- C:\Windows\system32\msfeeds.dll
2016-08-10 18:55:01 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-08-10 18:55:01 ----A---- C:\Windows\system32\jscript9.dll
2016-08-10 18:54:59 ----A---- C:\Windows\system32\Chakra.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\ieframe.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\Chakradiag.dll
2016-08-10 18:54:57 ----A---- C:\Windows\system32\edgehtml.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\wuuhext.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\mshtml.dll
2016-08-10 18:54:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\LogonController.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\ieapfltr.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\shell32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\ole32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2016-08-10 18:54:50 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2016-08-10 18:54:50 ----A---- C:\Windows\system32\SensorsApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorsNativeApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorService.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\kerberos.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\drivers\rdbss.sys
2016-08-10 18:54:49 ----A---- C:\Windows\system32\bthserv.dll
2016-08-10 18:54:48 ----A---- C:\Windows\system32\ie4uinit.exe
2016-08-01 08:34:43 ----HD---- C:\ProgramData\CanonIJScan
2016-07-29 14:55:44 ----D---- C:\Users\stsam\AppData\Roaming\Mozilla
2016-07-29 14:26:06 ----D---- C:\ProgramData\ATI
2016-07-29 14:23:37 ----D---- C:\Users\stsam\AppData\Roaming\library_dir
2016-07-29 14:23:33 ----D---- C:\Program Files (x86)\Raptr Inc
2016-07-29 14:11:28 ----D---- C:\Users\stsam\AppData\Roaming\DRPNPS
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\Vb40032.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcrt10.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcr70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSVCP70.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvci70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvbvm50.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSSTKPRP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msstdfmt.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71KOR.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71JPN.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ITA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHT.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHS.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71FRA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ESP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ENU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71DEU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70kor.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70jpn.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70ita.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70cht.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70chs.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70fra.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70esp.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70enu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70deu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl71.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl70.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaeapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\toseaeapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE3.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE2.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\WavesGUILib64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosasfapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosade.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tepeqapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tbb_waves.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo264.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\SRSWOW64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sltech64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slprp64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slcnt64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sl3apo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\audioLibVc.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SECOMN32.DLL
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSX64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSH64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSHP64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRRPTR64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFSS_APO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFNHK64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEHDRA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SECOMN64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtPgEx64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEP64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEL64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEG64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEED64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtDataProc64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DHT64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DAA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RCoInstII64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2016-07-29 14:07:26 ----A---- C:\Windows\system32\RCoRes64.dat
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEP64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEL64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEG64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EED64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEA64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MISS_APO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\KAAPORT64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMUI.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMLimiter.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMHVS.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMClariFi.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\FMAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64F3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CX64APO.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CAF64APO2.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\Caf64api.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAR64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAC64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2016-07-29 14:06:56 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 14:06:55 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-07-29 14:06:46 ----D---- C:\Users\stsam\AppData\Roaming\Opera Software
2016-07-29 14:06:40 ----AD---- C:\Program Files (x86)\Opera
2016-07-29 14:06:28 ----AD---- C:\Users\stsam\AppData\Roaming\DriverPack Notifier
2016-07-29 14:06:27 ----D---- C:\Program Files (x86)\DriverPack Notifier
2016-07-29 14:06:27 ----AD---- C:\Program Files (x86)\WinRAR
2016-07-29 14:06:03 ----D---- C:\Users\stsam\AppData\Roaming\DRPSu
2016-07-27 12:39:36 ----AD---- C:\Program Files (x86)\AMD
2016-07-27 12:19:20 ----D---- C:\Program Files (x86)\Geeks3D
2016-07-27 12:18:34 ----D---- C:\Users\stsam\AppData\Roaming\AMD
2016-07-16 17:57:06 ----ASH---- C:\pagefile.sys
2016-07-15 22:20:36 ----D---- C:\Font
2016-07-14 18:26:03 ----ASH---- C:\swapfile.sys
======List of files/folders modified in the last 1 month======
2016-08-13 07:38:50 ----D---- C:\Windows\Temp
2016-08-13 07:34:49 ----RD---- C:\Program Files
2016-08-13 07:34:49 ----D---- C:\Windows\Prefetch
2016-08-13 07:26:09 ----D---- C:\Users\stsam\AppData\Roaming\Skype
2016-08-13 07:00:59 ----HD---- C:\Program Files\WindowsApps
2016-08-13 07:00:58 ----D---- C:\Windows\AppReadiness
2016-08-13 06:57:38 ----D---- C:\Windows\system32\sru
2016-08-12 21:27:32 ----D---- C:\Program Files (x86)\VideoViewer
2016-08-12 19:02:42 ----D---- C:\Windows\System32
2016-08-12 19:02:42 ----D---- C:\Windows\INF
2016-08-12 19:02:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-08-12 18:29:45 ----AD---- C:\Windows\SysWOW64
2016-08-12 18:07:26 ----D---- C:\Windows\Microsoft.NET
2016-08-12 15:58:50 ----D---- C:\Windows
2016-08-12 15:58:29 ----D---- C:\Windows\system32\CatRoot
2016-08-12 15:57:39 ----D---- C:\Windows\system32\drivers
2016-08-12 15:57:38 ----D---- C:\Windows\system32\Tasks
2016-08-12 15:57:38 ----D---- C:\Windows\system32\DriverStore
2016-08-12 15:57:37 ----D---- C:\ProgramData\Package Cache
2016-08-12 15:57:36 ----SHD---- C:\Windows\Installer
2016-08-12 15:57:24 ----SHD---- C:\System Volume Information
2016-08-12 15:56:54 ----RD---- C:\Program Files (x86)
2016-08-12 15:56:18 ----AD---- C:\Program Files\AMD
2016-08-12 07:02:23 ----D---- C:\ProgramData\CanonIJPLM
2016-08-11 20:36:13 ----D---- C:\Windows\system32\config
2016-08-11 19:09:47 ----D---- C:\Windows\WinSxS
2016-08-11 19:09:21 ----D---- C:\Windows\system32\catroot2
2016-08-11 19:07:41 ----D---- C:\Windows\rescache
2016-08-10 22:32:24 ----RD---- C:\Windows\ImmersiveControlPanel
2016-08-10 22:32:24 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\en-US
2016-08-10 22:32:24 ----D---- C:\Windows\system32\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\appraiser
2016-08-10 22:32:23 ----D---- C:\Program Files\Windows Journal
2016-08-10 22:32:23 ----D---- C:\Program Files\Internet Explorer
2016-08-10 22:32:23 ----D---- C:\Program Files (x86)\Internet Explorer
2016-08-10 21:04:27 ----D---- C:\Windows\system32\SecureBootUpdates
2016-08-10 21:04:27 ----D---- C:\Windows\CbsTemp
2016-08-10 21:04:25 ----D---- C:\Windows\system32\MRT
2016-08-10 21:00:14 ----AC---- C:\Windows\system32\MRT.exe
2016-08-06 17:19:10 ----D---- C:\Windows\Minidump
2016-08-05 11:00:11 ----D---- C:\AMD
2016-08-05 09:06:47 ----AD---- C:\Program Files (x86)\DVDFab 9
2016-08-05 07:47:16 ----D---- C:\Users\stsam\AppData\Roaming\vlc
2016-08-04 14:31:45 ----D---- C:\Windows\system32\NDF
2016-08-01 08:34:43 ----HD---- C:\ProgramData
2016-07-30 12:42:22 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-07-30 12:42:11 ----D---- C:\Program Files (x86)\Common Files
2016-07-30 12:41:35 ----AD---- C:\Program Files (x86)\Microsoft Office
2016-07-29 14:22:59 ----D---- C:\ProgramData\AMD
2016-07-29 14:08:47 ----D---- C:\Windows\system32\wbem
2016-07-29 14:08:06 ----AD---- C:\Windows\System
2016-07-29 14:07:56 ----D---- C:\Windows\system32\DAX2
2016-07-29 14:07:46 ----D---- C:\Windows\SYSWOW64\RTCOM
2016-07-29 09:11:18 ----D---- C:\Windows\Tasks
2016-07-29 08:25:52 ----RSD---- C:\Windows\assembly
2016-07-29 08:25:52 ----D---- C:\Windows\SYSWOW64\directx
2016-07-29 08:25:31 ----D---- C:\Games
2016-07-27 21:25:34 ----N---- C:\Windows\system32\MpSigStub.exe
2016-07-27 11:55:26 ----SHD---- C:\$Recycle.Bin
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCfg64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkApi64.dll
2016-07-18 11:56:32 ----A---- C:\Windows\system32\RltkAPO64.dll
2016-07-15 10:09:34 ----SD---- C:\Users\stsam\AppData\Roaming\Microsoft
2016-07-15 10:09:34 ----SD---- C:\ProgramData\Microsoft
2016-07-15 09:05:07 ----D---- C:\ProgramData\Skype
2016-07-15 09:05:05 ----RD---- C:\Program Files (x86)\Skype
2016-07-14 14:45:00 ----D---- C:\Users\stsam\AppData\Roaming\Seznam.cz
2016-07-14 14:44:56 ----D---- C:\Program Files (x86)\Seznam.cz
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-08-03 84640]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-08-03 263296]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-08-03 197288]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-08-03 208552]
R1 EpfwLWF;@oem24.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-08-03 61608]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2016-08-03 153248]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-10-30 47616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-06-29 26689024]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-06-29 500736]
R3 AtiHDAudioService;@oem13.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWT6.sys [2016-04-26 110096]
R3 I2cHkBurn;I2cHkBurn; C:\Windows\system32\drivers\I2cHkBurn.sys [2015-07-27 41760]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-07-18 5193736]
R3 LEqdUsb;@oem29.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2015-06-18 87696]
R3 LHidEqd;@oem30.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2015-06-18 23184]
R3 LHidFilt;@oem35.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2015-06-18 86672]
R3 LMouFilt;@oem35.inf,%LMouFilt.SvcDesc%;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2015-06-18 69264]
S0 amdkmafd;@oem3.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2015-07-28 40720]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2016-08-03 15488]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-10-30 58720]
S3 athur;@oem25.inf,%ATHR.Service.DispName%;Atheros AR9271 Wireless Network Adapter Service; C:\Windows\System32\drivers\athurx.sys [2010-01-05 1847296]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\Windows\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2016-02-13 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Users\stsam\AppData\Local\Temp\HWiNFO64A.SYS [2016-07-26 27552]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\Windows\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 LVRS64;@oem16.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-10-26 351520]
S3 LVUVC64;@oem15.inf,%PID_0825_DD%(UVC);Logitech HD Webcam C270(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-10-26 4758176]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 MSICDSetup;MSICDSetup; \??\W:\CDriver64.sys [2009-08-12 28984]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\W:\NTIOLib_X64.sys [2011-06-29 11888]