Stránka 1 z 1

Preventivni kontrola desktop Pc

Napsal: 05 zář 2016 17:27
od s16strnadova
Ahoj kamarádi,

ve svém pc jsem postřehla v posledních dnech nesprávnou funkčnost prohlížení internetu (pomalá odezva, jednou za čas vyskočí pop up okno s nevyžádanou reklamou). Prosím mohli by jste mi zkontrolovat co mám v pc v nepořádku? Velice děkuji za Vaši pomoc.
Logfile of random's system information tool 1.10 (written by random/random)
Run by micha at 2016-09-05 18:18:27
Microsoft Windows 10 Home
System drive C: has 54 GB (47%) free of 114 GB
Total RAM: 8120 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:18:34, on 05.09.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0545)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\micha\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\micha.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [PowerDVD15Agent] "C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\micha\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
O4 - HKCU\..\Run: [iCloudPhotos] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\micha\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\micha\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\Program Files\Microsoft Office\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Poslat do On&eNotu - res://C:\Program Files\Microsoft Office\Office16\ONBttnIE.dll/105
O9 - Extra button: Poslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Poslat do On&eNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: @%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430 - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: @%CommonProgramFiles%\Microsoft Shared\Office16\oregres.dll,-430 - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - CyberLink - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wondershare Driver Install Service (WsDrvInst) - Wondershare - C:\Program Files (x86)\Wondershare\TunesGo Retro\DriverInstall.exe

--
End of file - 12291 bytes

======Listing Processes======







C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-88b2e4fb-4736-4b4f-88e3-b863bd853573 -SystemEventPortName:HostProcess-a4be7a6f-36f7-45fc-aaaa-b6f3baa76e01 -IoCancelEventPortName:HostProcess-c989c9c1-4fc8-4ce9-a276-fed5e4607464 -NonStateChangingEventPortName:HostProcess-71a8798c-cd0d-42e4-93bb-85cdf52f63ba -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f6a2b6ef-7d10-4da6-b1d3-02a0db05ff26 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k appmodel
dashost.exe {bf10e8b8-582a-4c21-8023fde855c80ce8}
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"dwm.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
taskhostw.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Users\micha\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe"
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding
"C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE16\CSISYN~1.EXE" -Embedding
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe -Embedding
"C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"fontdrvhost.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" -Embedding
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
PowerDVD15Agent.exe agent
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.23941.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
"C:\Program Files\WindowsApps\SupportingComputersInc.Fhotoroom_15.1.31.0_x64__pxc4cxt3rds1p\Fhotoroom.exe" -ServerName:App.AppXak7ma83pvf7k24vdvjwd46j4bf8vf69t.mca
"C:\Users\micha\AppData\Local\JDownloader v2.0\JDownloader2.exe"
"C:\Program Files\WindowsApps\Microsoft.ZuneMusic_3.6.23981.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca
"C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1608.2213.0_x64__8wekyb3d8bbwe\Calculator.exe" -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca

"C:\WINDOWS\system32\notepad.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\micha\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=53.0.2785.89 --handshake-handle=0x1ac
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5844.0.2041803885\907420006" --mojo-application-channel-token=9AEB7C8912C684F89D3761FE36FD4E1B --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/MonthlyPrompt/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_02/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,14,17,30,55,69 --gpu-vendor-id=0x10de --gpu-device-id=0x1187 --gpu-driver-vendor=NVIDIA --gpu-driver-version=21.21.13.7270 --gpu-driver-date=8-25-2016 --mojo-platform-channel-handle=1392 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/MonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_02/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/ --primordial-pipe-token=5367D224C1700B6056463B5276DA7587 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=3C067EFA401C577F87619B361C8E7D98 --mojo-application-channel-token=5367D224C1700B6056463B5276DA7587 --channel="5844.5.781544017\1088495623" --mojo-platform-channel-handle=4996 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe348_ Global\UsGthrCtrlFltPipeMssGthrPipe348 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 632 644 652 8192 648
"C:\Users\micha\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\DriverToolkit Autorun.job - C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe --autorun
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31 226984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL [2015-07-31 2165976]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31 161448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL [2015-07-31 1512152]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-01-26 8781568]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-06-14 2397120]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-06-14 1767944]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2016-07-26 176952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\micha\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-08-16 633024]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-08-17 29538432]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
"iCloudServices"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [2016-07-08 67384]
"iCloudDrive"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [2016-07-08 110392]
"iCloudPhotos"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [2016-07-08 356664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\micha\AppData\Local\Microsoft\OneDrive\17.3.6301.0127_1\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-07-11 8900328]
"PowerDVD15Agent"=C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe [2015-06-07 949960]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2016-07-05 67384]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2016-06-20 2131344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"aux"=wdmaud.drv
"vidc.pDAD"=prodad-codec.dll
"msacm.l3codecp"=l3codecp.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-09-05 18:18:27 ----D---- C:\rsit
2016-09-05 18:18:27 ----D---- C:\Program Files\trend micro
2016-09-05 13:51:54 ----HD---- C:\OneDriveTemp
2016-09-04 21:23:16 ----D---- C:\ShadowPlay
2016-09-04 20:27:39 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2016-09-04 20:27:36 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2016-09-04 20:27:35 ----D---- C:\Program Files (x86)\VulkanRT
2016-09-04 20:27:08 ----D---- C:\WINDOWS\LastGood
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFTH264.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvDecMFTMjpeg.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvumdshimx.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvinitx.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvEncMFTH264.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvdispgenco6437270.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvdispco6437270.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-09-04 20:26:12 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-09-04 20:26:11 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-09-04 20:26:11 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2016-08-11 12:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryBroker.dll
2016-08-11 12:40:03 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2016-08-11 12:40:03 ----A---- C:\WINDOWS\system32\MusNotification.exe
2016-08-11 12:40:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2016-08-11 12:40:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2016-08-11 12:40:02 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2016-08-11 12:40:02 ----A---- C:\WINDOWS\system32\rdpudd.dll
2016-08-11 12:40:02 ----A---- C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-08-11 12:40:01 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-08-11 12:40:01 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-08-11 12:40:01 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2016-08-11 12:40:00 ----A---- C:\WINDOWS\system32\wmp.dll
2016-08-11 12:40:00 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-08-11 12:39:59 ----A---- C:\WINDOWS\SYSWOW64\wldp.dll
2016-08-11 12:39:59 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-08-11 12:39:59 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-08-11 12:39:59 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2016-08-11 12:39:59 ----A---- C:\WINDOWS\system32\dbgeng.dll
2016-08-11 12:39:58 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-08-11 12:39:58 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-08-11 12:39:57 ----A---- C:\WINDOWS\system32\wevtutil.exe
2016-08-11 12:39:57 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-08-11 12:39:56 ----A---- C:\WINDOWS\SYSWOW64\SensorsNativeApi.dll
2016-08-11 12:39:55 ----A---- C:\WINDOWS\system32\usocore.dll
2016-08-11 12:39:55 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-08-11 12:39:55 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-08-11 12:39:55 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-08-11 12:39:55 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2016-08-11 12:39:55 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-08-11 12:39:54 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-08-11 12:39:54 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-08-11 12:39:54 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-08-11 12:39:54 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2016-08-11 12:39:53 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-08-11 12:39:53 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-08-11 12:39:53 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-08-11 12:39:52 ----A---- C:\WINDOWS\SYSWOW64\VEEventDispatcher.dll
2016-08-11 12:39:52 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-08-11 12:39:52 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-08-11 12:39:52 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-08-11 12:39:51 ----A---- C:\WINDOWS\SYSWOW64\tdlrecover.exe
2016-08-11 12:39:51 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2016-08-11 12:39:51 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-08-11 12:39:51 ----A---- C:\WINDOWS\system32\WUDFPlatform.dll
2016-08-11 12:39:51 ----A---- C:\WINDOWS\system32\winsrv.dll
2016-08-11 12:39:51 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-08-11 12:39:51 ----A---- C:\WINDOWS\system32\RecoveryDrive.exe
2016-08-11 12:39:50 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-08-11 12:39:50 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-08-11 12:39:50 ----A---- C:\WINDOWS\system32\cdd.dll
2016-08-11 12:39:49 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2016-08-11 12:39:49 ----A---- C:\WINDOWS\SYSWOW64\wshbth.dll
2016-08-11 12:39:49 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2016-08-11 12:39:49 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2016-08-11 12:39:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-08-11 12:39:48 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2016-08-11 12:39:48 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-08-11 12:39:48 ----A---- C:\WINDOWS\system32\sppwinob.dll
2016-08-11 12:39:48 ----A---- C:\WINDOWS\system32\sppobjs.dll
2016-08-11 12:39:47 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-08-11 12:39:47 ----A---- C:\WINDOWS\system32\wininet.dll
2016-08-11 12:39:47 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-08-11 12:39:47 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-08-11 12:39:46 ----A---- C:\WINDOWS\SYSWOW64\wevtutil.exe
2016-08-11 12:39:46 ----A---- C:\WINDOWS\system32\wuapi.dll
2016-08-11 12:39:46 ----A---- C:\WINDOWS\system32\wshbth.dll
2016-08-11 12:39:46 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2016-08-11 12:39:46 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2016-08-11 12:39:46 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2016-08-11 12:39:45 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-08-11 12:39:44 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-08-11 12:39:44 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-08-11 12:39:44 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2016-08-11 12:39:43 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-08-11 12:39:43 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2016-08-11 12:39:43 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-08-11 12:39:43 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-08-11 12:39:42 ----A---- C:\WINDOWS\system32\VEEventDispatcher.dll
2016-08-11 12:39:42 ----A---- C:\WINDOWS\system32\tileobjserver.dll
2016-08-11 12:39:42 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-08-11 12:39:42 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-08-11 12:39:42 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-08-11 12:39:41 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-08-11 12:39:41 ----A---- C:\WINDOWS\system32\wldp.dll
2016-08-11 12:39:41 ----A---- C:\WINDOWS\system32\tdlrecover.exe
2016-08-11 12:39:41 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2016-08-11 12:39:41 ----A---- C:\WINDOWS\system32\IdCtrls.dll
2016-08-11 12:39:40 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-08-11 12:39:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-08-11 12:39:40 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2016-08-11 12:39:40 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2016-08-11 12:39:40 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2016-08-11 12:39:40 ----A---- C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-08-11 12:39:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2016-08-11 12:39:39 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-08-11 12:39:39 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-08-11 12:39:38 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-08-11 12:39:38 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-08-11 12:39:38 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-08-11 12:39:38 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-08-11 12:39:37 ----A---- C:\WINDOWS\SYSWOW64\IdCtrls.dll
2016-08-11 12:39:37 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-08-11 12:39:37 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-08-11 12:39:36 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-08-11 12:39:36 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-08-11 12:39:35 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-08-11 12:39:35 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-08-11 12:39:35 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-08-11 12:39:34 ----A---- C:\WINDOWS\system32\wuuhext.dll
2016-08-11 12:39:34 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-08-11 12:39:33 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2016-08-11 12:39:33 ----A---- C:\WINDOWS\system32\ole32.dll
2016-08-11 12:39:33 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-08-11 12:39:33 ----A---- C:\WINDOWS\system32\LogonController.dll
2016-08-11 12:39:33 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2016-08-11 12:39:32 ----A---- C:\WINDOWS\system32\shell32.dll
2016-08-11 12:39:32 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-08-11 12:39:29 ----A---- C:\WINDOWS\SYSWOW64\SensorsApi.dll
2016-08-11 12:39:29 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2016-08-11 12:39:28 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-08-11 12:39:28 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2016-08-11 12:39:28 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-08-11 12:39:28 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-08-11 12:39:28 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2016-08-11 12:39:28 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2016-08-11 12:39:28 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2016-08-11 12:39:28 ----A---- C:\WINDOWS\system32\bthserv.dll
2016-08-07 16:13:27 ----D---- C:\ProgramData\DigiDNA
2016-08-07 15:21:34 ----D---- C:\Users\micha\AppData\Roaming\JAM Software
2016-08-07 15:06:37 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2016-08-07 15:06:37 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2016-08-07 15:06:37 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2016-08-07 15:05:31 ----A---- C:\WINDOWS\SYSWOW64\SETBD74.tmp
2016-08-07 15:05:31 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2016-08-07 15:05:30 ----A---- C:\WINDOWS\system32\nvdispgenco6436881.dll
2016-08-07 15:05:30 ----A---- C:\WINDOWS\system32\nvdispco6436881.dll
2016-08-07 10:43:59 ----D---- C:\Program Files\iPod
2016-08-07 10:43:59 ----D---- C:\Program Files (x86)\iTunes
2016-08-07 10:43:59 ----AD---- C:\Program Files\iTunes

======List of files/folders modified in the last 1 month======

2016-09-05 18:18:27 ----RD---- C:\Program Files
2016-09-05 18:15:09 ----D---- C:\WINDOWS\Temp
2016-09-05 17:51:00 ----D---- C:\WINDOWS\system32\sru
2016-09-05 17:36:13 ----D---- C:\WINDOWS\Prefetch
2016-09-05 15:36:06 ----D---- C:\WINDOWS\debug
2016-09-05 15:02:58 ----D---- C:\Users\micha\AppData\Roaming\MPC-HC
2016-09-05 15:01:31 ----D---- C:\WINDOWS\SoftwareDistribution
2016-09-05 15:01:31 ----D---- C:\WINDOWS\INF
2016-09-05 15:01:31 ----D---- C:\Windows
2016-09-04 23:07:29 ----D---- C:\WINDOWS\Microsoft.NET
2016-09-04 20:29:47 ----D---- C:\WINDOWS\system32\config
2016-09-04 20:27:57 ----D---- C:\WINDOWS\SysWOW64
2016-09-04 20:27:57 ----D---- C:\WINDOWS\System32
2016-09-04 20:27:57 ----D---- C:\ProgramData\NVIDIA Corporation
2016-09-04 20:27:50 ----D---- C:\ProgramData\NVIDIA
2016-09-04 20:27:38 ----D---- C:\WINDOWS\system32\DriverStore
2016-09-04 20:27:37 ----D---- C:\WINDOWS\system32\drivers
2016-09-04 20:27:35 ----RD---- C:\Program Files (x86)
2016-09-04 20:24:23 ----D---- C:\Users\micha\AppData\Roaming\Skype
2016-09-04 19:57:35 ----D---- C:\WINDOWS\system32\appraiser
2016-09-04 19:57:35 ----D---- C:\WINDOWS\CbsTemp
2016-09-04 19:50:26 ----RD---- C:\WINDOWS\assembly
2016-09-04 19:48:04 ----D---- C:\WINDOWS\AppReadiness
2016-09-04 19:48:03 ----HD---- C:\Program Files\WindowsApps
2016-09-04 19:42:19 ----SHDC---- C:\WINDOWS\Installer
2016-09-04 19:42:18 ----RD---- C:\Program Files (x86)\Skype
2016-09-04 19:37:39 ----D---- C:\WINDOWS\WinSxS
2016-08-26 01:27:49 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2016-08-26 01:27:49 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-08-26 01:27:49 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2016-08-26 01:27:49 ----A---- C:\WINDOWS\system32\nvhdagenco6420103.dll
2016-08-26 01:27:49 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-08-25 23:12:08 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-08-25 23:12:08 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-08-25 23:12:07 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-08-25 23:12:07 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-08-25 23:12:07 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-08-25 23:12:07 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-08-25 23:12:07 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-08-25 23:12:07 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-08-24 11:29:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-08-16 15:57:29 ----D---- C:\WINDOWS\system32\Tasks
2016-08-15 17:04:19 ----D---- C:\WINDOWS\rescache
2016-08-15 16:47:03 ----D---- C:\WINDOWS\system32\catroot2
2016-08-15 00:10:48 ----SHD---- C:\Boot
2016-08-14 21:30:48 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-08-14 21:30:48 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-08-14 21:30:48 ----D---- C:\WINDOWS\system32\en-US
2016-08-14 21:30:48 ----D---- C:\WINDOWS\system32\cs-CZ
2016-08-14 21:30:48 ----D---- C:\Program Files\Windows Journal
2016-08-14 21:30:48 ----D---- C:\Program Files\Internet Explorer
2016-08-14 21:30:48 ----D---- C:\Program Files (x86)\Internet Explorer
2016-08-14 16:10:36 ----HD---- C:\ProgramData
2016-08-14 15:40:24 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2016-08-14 15:40:24 ----D---- C:\WINDOWS\system32\MRT
2016-08-14 15:38:12 ----AC---- C:\WINDOWS\system32\MRT.exe
2016-08-07 15:07:05 ----D---- C:\Program Files\NVIDIA Corporation
2016-08-07 15:06:41 ----D---- C:\ProgramData\Package Cache
2016-08-07 15:03:25 ----D---- C:\Users\micha\AppData\Roaming\uTorrent
2016-08-07 10:43:59 ----D---- C:\Program Files\Common Files\Apple

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-07-05 74544]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-08-07 292704]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2016-07-05 37144]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2016-07-05 103064]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-07-05 1070904]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-07-13 473592]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-07-05 37656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-07-05 108304]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2016-07-05 162904]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2016-01-26 4686592]
R3 MBfilt;MBfilt; C:\WINDOWS\system32\drivers\MBfilt64.sys [2016-01-26 41088]
R3 MEIx64;@oem21.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [2016-01-26 202032]
R3 NVHDA;@oem12.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2016-08-26 223304]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-08-27 14216760]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-06-14 26560]
R3 nvvad_WaveExtensible;@oem5.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2016-04-14 56384]
R3 rt640x64;@oem6.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2016-01-26 889584]
R3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2015-10-30 131584]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2015-10-30 221184]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-02-07 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2016-04-23 63488]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2016-05-28 258912]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-04-23 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]
S3 USBAAPL64;@oem10.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl64.sys [2015-06-17 54784]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\WINDOWS\System32\drivers\usbser.sys [2016-04-23 67072]
S3 vhf;@%SystemRoot%\system32\drivers\vhf.sys,-100; C:\WINDOWS\System32\drivers\vhf.sys [2015-10-30 31744]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-03-02 83768]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-07-05 197128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-06-14 1163712]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [2016-08-15 29728]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2015-07-07 785904]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-06-14 1879488]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-06-14 2521024]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2016-08-25 1362368]
R2 OneSyncSvc_12035dda;Hostitel synchronizace_12035dda; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2014-10-20 614664]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [2016-08-25 426040]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 UserManager;@%systemroot%\system32\usermgr.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-07-26 651576]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-06-14 3632576]
R3 PimIndexMaintenanceSvc_12035dda;Data kontaktů_12035dda; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 UnistoreSvc_12035dda;Úložiště uživatelských dat_12035dda; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 UserDataSvc_12035dda;Přístup k uživatelským datům_12035dda; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-26 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-26 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_12035dda;Služba zasílání zpráv_12035dda; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 242864]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UserDataSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-14001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 UsoSvc;@%systemroot%\system32\usocore.dll,-102; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Re: Preventivni kontrola desktop Pc

Napsal: 05 zář 2016 18:57
od Roli
Zdravím, stáhni a spusť AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.


Pak použij Mbam z mého podpisu a také mi sem z něj dej log.

Re: Preventivni kontrola desktop Pc

Napsal: 05 zář 2016 20:01
od s16strnadova
Ahojky,

děkuji za rady, zde přikládám log z AdwCleaner:
# AdwCleaner v6.010 - Log soubor vytvořen 05/09/2016 na 20:26:36
# Aktualizováno dne 12/08/2016 z ToolsLib
# Databáze : 2016-09-05.1 [Server]
# Operační systém : Windows 10 Home (X64)
# Uživatelské jméno : micha - MISA_WIN10
# Beží od : C:\Users\micha\Downloads\adwcleaner_6.010.exe
# Mod: Čištění
# Podpora : https://toolslib.net/forum



***** [ Služby ] *****



***** [ Adresáře ] *****

[-] Adresář smazán:C:\Users\micha\AppData\Local\DriverToolkit
[-] Adresář smazán:C:\Users\micha\AppData\Roaming\RPEng
[-] Adresář smazán:C:\Program Files (x86)\DriverToolkit


***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKU\S-1-5-21-2976775506-2560316150-966240833-1001\Software\Classes\AppXrh6feys59dqfzsv9p3s9p6aep0hwtb23
[#] Klíč smazán po restartování:HKCU\Software\Classes\AppXrh6feys59dqfzsv9p3s9p6aep0hwtb23
[-] Klíč smazán:HKLM\SOFTWARE\Classes\OCComSDK.ComSDK
[-] Klíč smazán:HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] Klíč smazán:HKU\S-1-5-21-2976775506-2560316150-966240833-1001\Software\DriverToolkit
[-] Klíč smazán:HKU\S-1-5-21-2976775506-2560316150-966240833-1001\Software\PRODUCTSETUP
[#] Klíč smazán po restartování:HKCU\Software\DriverToolkit
[#] Klíč smazán po restartování:HKCU\Software\PRODUCTSETUP
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\jdownloader-free.en.softonic.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\jdownloader.softonic.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\jdownloader-free.en.softonic.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\jdownloader.softonic.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com


***** [ Prohlížeče ] *****

[-] [C:\Users\micha\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Smazání:hxxp://search.conduit.com/?ctid=CT3307181&SearchSource=48&CUI=UN14584351682968440&UM=2&sspv=TB_CNI3


*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [3713 Bajtů] - [05/09/2016 20:26:36]
C:\AdwCleaner\AdwCleaner[S0].txt - [3992 Bajtů] - [05/09/2016 20:25:09]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3861 Bajtů] ##########

Re: Preventivni kontrola desktop Pc

Napsal: 05 zář 2016 21:07
od s16strnadova
Zde prikladam MB Log:

Malwarebytes Anti-Malware
http://www.malwarebytes.org

Datum skenování: 05.09.2016
Čas skenování: 20:31
Protokol: mblog.txt
Správce: Ano

Verze: 2.2.1.1043
Databáze malwaru: v2016.09.05.08
Databáze rootkitů: v2016.08.15.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 10
CPU: x64
Souborový systém: NTFS
Uživatel: micha

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 708776
Uplynulý čas: 43 min, 50 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 4
CrackTool.Agent, E:\Programs\Photo,Video\Adobe Photoshop CS6 13.0 Final CZ\patch - PainteR\adobe.photoshop.cs6-patch.exe, , [2e5e7df18119a88e83e7dd6b6b962ad6],
RiskWare.Tool.HCK, E:\Programs\Photo,Video\Video\Cyberlink\PowerDirector-14.0.2019.0-Ultimate\PowerDirector 14.0.2019.0 Ultimate\Keygen-CORE\keygen.exe, , [602c83eb2d6d9d99c59848b454ac5ea2],
RiskWare.Tool.CK, E:\Programs\Photo,Video\Video\Xilisoft.Video.Converter.Ultimate.v7.7.2.20130217.Incl.Keygen-BRD\Keygen.exe, , [0d7fe28c6f2b23136fd3896c7d83da26],
PUP.Optional.APNToolBar, E:\Programs\Stahování z Netu\aTubeCatcher.exe, , [cdbf0569b4e62115fcc647e254ad619f],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Re: Preventivni kontrola desktop Pc

Napsal: 07 zář 2016 18:41
od Roli
Vše co Mbam našel nech smazat.


Spusť skener Cure It podle TOHOTO návodu

po skončení skenu mi sem nakopíruj výsledky - stačí konec logu se souhrnem.

(Upozornění je úchylně pomalý a je zapotřebí ho sledovat občas se na něco ptá)

Re: Preventivni kontrola desktop Pc

Napsal: 11 zář 2016 11:01
od s16strnadova
Ahojky, zasílám konec logu se sournem :)
Total 9964104617 bytes in 29090 files scanned (33225 objects)
Total 29054 files (33182 objects) are clean
Total 1 file are suspicious
Total 42 files are raised error condition
Scan time is 00:02:49.105

Change language: "Czech (Český)"
-----------------------------------------------------------------------------
Start curing
-----------------------------------------------------------------------------

C:\WINDOWS\system32\drivers\etc\hosts - cured

Total 9964104617 bytes in 29090 files scanned (33225 objects)
Total 29054 files (33182 objects) are clean
Total 1 file are suspicious
Total 1 file are neutralized
Total 42 files are raised error condition
Scan time is 00:02:49.105

Re: Preventivni kontrola desktop Pc

Napsal: 12 zář 2016 17:22
od Roli
Bezva a jak se PC chová ?

Re: Preventivni kontrola desktop Pc

Napsal: 19 zář 2016 15:20
od s16strnadova
Zdravím,

omlouvám se, že píši po takové době. Pc funguje nyní bez problémů. Velice děkuji za Vaši pomoc.

Přeji hezký den.

Míša.

Re: Preventivni kontrola desktop Pc

Napsal: 20 zář 2016 17:21
od Roli
Ahoj princezno, není proč se omlouvat PC se musí řádně testnout :)

Jinak není zač a :closed: