Stránka 1 z 1

Preventivka notebooku

Napsal: 05 zář 2016 18:05
od maty207
Dobrý den,

Rád bych poprosil o preventivku mého laptopu. Děkuji


Logfile of random's system information tool 1.10 (written by random/random)
Run by Ondra at 2016-09-05 18:54:52
Microsoft Windows 10 Home
System drive C: has 437 GB (48%) free of 911 GB
Total RAM: 8084 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:54:59, on 5. 9. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal

Running processes:
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Games\World_of_Warships\WoWSLauncher.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Ondra.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkI ... id=UE01DHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll
O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Overwolf] "C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe" -overwolfsilent
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3996182392-1031933315-1381193400-1001\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3996182392-1031933315-1381193400-1001\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'UpdatusUser')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: HandyAndy.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{156a1112-b8cb-4067-8a2b-43d31fdd6754}: NameServer = 62.204.224.2,62.204.224.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{156a1112-b8cb-4067-8a2b-43d31fdd6754}: NameServer = 62.204.224.2,62.204.224.3
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file)
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CCSDK - Unknown owner - C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @oem85.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\system32\ibtsiva (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Maxthon Core Update Service (MaxthonUpdateSvc) - Maxthon - C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
O23 - Service: McAfee AP Service (McAPExe) - McAfee, Inc. - C:\Program Files\McAfee\MSC\McAPExe.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe
O23 - Service: McAfee Boot Delay Start Service (McBootDelayStartSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee CSP Service (mccspsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: Intel Security PEF Service (PEFService) - Intel Security, Inc. - C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\SysWOW64\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\SysWOW64\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14949 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
winlogon.exe
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f378d328-9541-4f4a-a68a-dbb4e93c3073 -SystemEventPortName:HostProcess-d2b63479-0482-4ed9-ae02-2c6c6ff96a43 -IoCancelEventPortName:HostProcess-1ed88e26-c5f2-416a-ad32-aef3c9e82eca -NonStateChangingEventPortName:HostProcess-25214c54-7e25-4eb3-ae68-8ba15ca101c8 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a22474b5-d667-4566-89a1-bb00916c67c7 -DeviceGroupId:WudfDefaultDevicePool
"C:\WINDOWS\system32\nvvsvc.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
dashost.exe {a2ea4722-49da-40b4-91fdc3a5a5fea026}
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\windows\system32\CxAudMsg64.exe
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
"C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe"
"C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe"

C:\WINDOWS\system32\ibtsiva
C:\WINDOWS\SysWOW64\vmnetdhcp.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe"
C:\WINDOWS\SysWOW64\vmnat.exe
C:\WINDOWS\SysWoW64\SAsrv.exe
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"fontdrvhost.exe"
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
taskhostw.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.23941.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
C:\WINDOWS\system32\nvvsvc.exe -session -first
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -scheduled
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.7.113.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\WINDOWS\system32\rundll32.exe" -localserver 22d8c27b-47a1-48d1-ad08-7da7abd79617
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" "-cachedir=C:\Users\Ondra\AppData\Local\Steam\htmlcache" "-steampid=14964" "-buildid=1471977975" "-steamid=0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="C:\Program Files (x86)\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="10752.0.131092407\1718187364" --font-cache-shared-handle=1468 /prefetch:1
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="C:\Program Files (x86)\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="10752.1.1846632104\1513195668" --font-cache-shared-handle=1832 /prefetch:1
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --enable-pinch --lang=en-US --lang=en-US --log-file="C:\Program Files (x86)\Steam\bin\debug.log" --product-version="Valve Steam Client" --disable-spell-checking --enable-system-flash --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-gpu-compositing --channel="10752.2.2025548751\1690433540" --font-cache-shared-handle=2604 /prefetch:1
"C:\WINDOWS\System32\Taskmgr.exe" /2
C:\WINDOWS\system32\AUDIODG.EXE 0x424
"C:\Games\World_of_Warships\WoWSLauncher.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe468_ Global\UsGthrCtrlFltPipeMssGthrPipe468 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 620 624 632 8192 628
"C:\Users\Ondra\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Ondra\AppData\Roaming\Mozilla\Firefox\Profiles\zsqirdlr.default

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 22.0.0.209 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.91.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.91.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 22.0.0.209 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-07-19 229072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-22 901600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-15 462400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-22 678656]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2016-07-12 1741104]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-15 173120]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2015-06-16 5060864]
"Nvtmru"=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [2013-10-18 1028384]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2014-02-26 36352]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-09-04 907480]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-09-15 4196432]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2012-06-13 1647616]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2016-06-01 176952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-08-23 2857248]
"OneDrive"=C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-08-27 633024]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2016-01-15 4177784]
"Overwolf"=C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [2016-08-29 247344]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-06-01 8722136]
"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2016-09-01 3639280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]
"Uninstall C:\Users\Ondra\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer_For_P2G8"=C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [2014-09-09 110344]
"CLVirtualDrive"=C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [2014-09-09 492808]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-03-23 7139256]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-04-01 596504]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HandyAndy.lnk - C:\Program Files\Andy\HandyAndy.exe

C:\Users\Ondra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
PowerReg Scheduler V3.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-09-05 18:54:53 ----D---- C:\Program Files\trend micro
2016-09-05 18:54:52 ----D---- C:\rsit
2016-09-02 03:17:58 ----HD---- C:\Program Files\Common Files\EAInstaller
2016-09-01 11:44:33 ----D---- C:\Program Files (x86)\Origin Games
2016-09-01 11:37:46 ----D---- C:\Users\Ondra\AppData\Roaming\Origin
2016-09-01 11:16:45 ----D---- C:\ProgramData\Origin
2016-09-01 11:16:42 ----D---- C:\ProgramData\Electronic Arts
2016-09-01 11:14:55 ----AD---- C:\Program Files (x86)\Origin
2016-08-28 11:31:18 ----D---- C:\Users\Ondra\AppData\Roaming\ROCKETSROCKETSROCKETS
2016-08-24 16:40:14 ----D---- C:\Users\Ondra\AppData\Roaming\Mozilla
2016-08-24 16:40:01 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-23 22:39:31 ----A---- C:\WINDOWS\SYSWOW64\tsmf.dll
2016-08-23 22:39:31 ----A---- C:\WINDOWS\SYSWOW64\sppc.dll
2016-08-23 22:39:31 ----A---- C:\WINDOWS\SYSWOW64\slc.dll
2016-08-23 22:39:31 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncPolicy.dll
2016-08-23 22:39:31 ----A---- C:\WINDOWS\SYSWOW64\pidgenx.dll
2016-08-23 22:39:31 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2016-08-23 22:39:30 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-08-23 22:39:30 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2016-08-23 22:39:30 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-08-23 22:39:30 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-08-23 22:39:30 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2016-08-23 22:39:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.UXRes.dll
2016-08-23 22:39:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2016-08-23 22:39:28 ----A---- C:\WINDOWS\SYSWOW64\ClipboardServer.dll
2016-08-23 22:39:26 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2016-08-23 22:39:26 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2016-08-23 22:39:26 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2016-08-23 22:39:26 ----A---- C:\WINDOWS\SYSWOW64\smphost.dll
2016-08-23 22:39:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\tcpipcfg.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\netiougc.exe
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2016-08-23 22:39:25 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-08-23 22:39:24 ----A---- C:\WINDOWS\SYSWOW64\sppcext.dll
2016-08-23 22:39:24 ----A---- C:\WINDOWS\SYSWOW64\slcext.dll
2016-08-23 22:39:24 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-08-23 22:39:24 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2016-08-23 22:39:24 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2016-08-23 22:39:24 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2016-08-23 22:39:24 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\wmploc.DLL
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\wlanhlp.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\spwmp.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-08-23 22:39:23 ----A---- C:\WINDOWS\SYSWOW64\deviceassociation.dll
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-08-23 22:39:22 ----A---- C:\WINDOWS\SYSWOW64\dxmasf.dll
2016-08-23 22:39:20 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-08-23 22:39:20 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2016-08-23 22:39:20 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2016-08-23 22:39:20 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2016-08-23 22:39:20 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-08-23 22:39:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2016-08-23 22:39:19 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-08-23 22:39:19 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-08-23 22:39:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-08-23 22:39:18 ----A---- C:\WINDOWS\SYSWOW64\samlib.dll
2016-08-23 22:39:18 ----A---- C:\WINDOWS\SYSWOW64\offlinesam.dll
2016-08-23 22:39:18 ----A---- C:\WINDOWS\SYSWOW64\container.dll
2016-08-23 22:39:18 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll
2016-08-23 22:39:17 ----A---- C:\WINDOWS\SYSWOW64\MSAJApi.dll
2016-08-23 22:37:54 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-08-23 22:37:54 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-08-23 22:37:54 ----A---- C:\WINDOWS\system32\ClipboardServer.dll
2016-08-23 22:37:53 ----A---- C:\WINDOWS\system32\drivers\stornvme.sys
2016-08-23 22:37:52 ----A---- C:\WINDOWS\system32\DscCore.dll
2016-08-23 22:37:47 ----A---- C:\WINDOWS\system32\wsp_health.dll
2016-08-23 22:37:47 ----A---- C:\WINDOWS\system32\smphost.dll
2016-08-23 22:37:47 ----A---- C:\WINDOWS\system32\mispace.dll
2016-08-23 22:37:46 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2016-08-23 22:37:46 ----A---- C:\WINDOWS\system32\winmde.dll
2016-08-23 22:37:46 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-08-23 22:37:44 ----A---- C:\WINDOWS\system32\wuuhext.dll
2016-08-23 22:37:44 ----A---- C:\WINDOWS\system32\wups2.dll
2016-08-23 22:37:44 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-08-23 22:37:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-08-23 22:37:44 ----A---- C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-08-23 22:37:44 ----A---- C:\WINDOWS\system32\WinBioDataModel.dll
2016-08-23 22:37:43 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-08-23 22:37:43 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-08-23 22:37:43 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-08-23 22:37:42 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-08-23 22:37:41 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\w32time.dll
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\twinui.dll
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\tsmf.dll
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\tcpipcfg.dll
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\systemreset.exe
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\SysResetErr.exe
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\ResetEngine.exe
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\reseteng.dll
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\netiougc.exe
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2016-08-23 22:37:40 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2016-08-23 22:37:39 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-08-23 22:37:39 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-08-23 22:37:39 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-08-23 22:37:39 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2016-08-23 22:37:39 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-08-23 22:37:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2016-08-23 22:37:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2016-08-23 22:37:38 ----A---- C:\WINDOWS\system32\shell32.dll
2016-08-23 22:37:38 ----A---- C:\WINDOWS\system32\SettingSyncPolicy.dll
2016-08-23 22:37:38 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2016-08-23 22:37:38 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2016-08-23 22:37:37 ----A---- C:\WINDOWS\system32\sppsvc.exe
2016-08-23 22:37:37 ----A---- C:\WINDOWS\system32\sppcext.dll
2016-08-23 22:37:37 ----A---- C:\WINDOWS\system32\sppc.dll
2016-08-23 22:37:37 ----A---- C:\WINDOWS\system32\slc.dll
2016-08-23 22:37:37 ----A---- C:\WINDOWS\system32\pidgenx.dll
2016-08-23 22:37:37 ----A---- C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-08-23 22:37:37 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-08-23 22:37:36 ----A---- C:\WINDOWS\system32\slcext.dll
2016-08-23 22:37:36 ----A---- C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-08-23 22:37:36 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-08-23 22:37:36 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-08-23 22:37:36 ----A---- C:\WINDOWS\system32\GenValObj.exe
2016-08-23 22:37:35 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2016-08-23 22:37:35 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2016-08-23 22:37:34 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\wpninprc.dll
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\wlansvc.dll
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\wlansec.dll
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\wlanhlp.dll
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-08-23 22:37:33 ----A---- C:\WINDOWS\system32\drivers\wof.sys
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\wlanapi.dll
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\WiFiConfigSP.dll
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\wfdprov.dll
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\deviceassociation.dll
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\dasHost.exe
2016-08-23 22:37:32 ----A---- C:\WINDOWS\system32\das.dll
2016-08-23 22:37:30 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-08-23 22:37:30 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-08-23 22:37:30 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-08-23 22:37:29 ----A---- C:\WINDOWS\system32\wmploc.DLL
2016-08-23 22:37:29 ----A---- C:\WINDOWS\system32\wmp.dll
2016-08-23 22:37:29 ----A---- C:\WINDOWS\system32\spwmp.dll
2016-08-23 22:37:29 ----A---- C:\WINDOWS\system32\mfpmp.exe
2016-08-23 22:37:29 ----A---- C:\WINDOWS\system32\dxmasf.dll
2016-08-23 22:37:28 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2016-08-23 22:37:28 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-08-23 22:37:28 ----A---- C:\WINDOWS\system32\mf.dll
2016-08-23 22:37:28 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2016-08-23 22:37:28 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-08-23 22:37:28 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-08-23 22:37:27 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2016-08-23 22:37:27 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-08-23 22:37:27 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-08-23 22:37:25 ----A---- C:\WINDOWS\system32\iesetup.dll
2016-08-23 22:37:25 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-08-23 22:37:25 ----A---- C:\WINDOWS\system32\iernonce.dll
2016-08-23 22:37:25 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2016-08-23 22:37:24 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-08-23 22:37:24 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2016-08-23 22:37:24 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-08-23 22:37:23 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-08-23 22:37:23 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2016-08-23 22:37:21 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-08-23 22:37:18 ----A---- C:\WINDOWS\system32\resutils.dll
2016-08-23 22:37:18 ----A---- C:\WINDOWS\system32\clusapi.dll
2016-08-23 22:37:14 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2016-08-23 22:37:14 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-08-23 22:37:14 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-08-23 22:37:14 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-08-23 22:37:12 ----A---- C:\WINDOWS\system32\samsrv.dll
2016-08-23 22:37:12 ----A---- C:\WINDOWS\system32\samlib.dll
2016-08-23 22:37:12 ----A---- C:\WINDOWS\system32\offlinesam.dll
2016-08-23 22:37:12 ----A---- C:\WINDOWS\system32\dosvc.dll
2016-08-23 22:37:12 ----A---- C:\WINDOWS\system32\domgmt.dll
2016-08-23 22:37:12 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-08-23 22:37:11 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-08-23 22:37:11 ----A---- C:\WINDOWS\system32\dafpos.dll
2016-08-23 22:37:11 ----A---- C:\WINDOWS\system32\container.dll
2016-08-23 22:37:11 ----A---- C:\WINDOWS\system32\ConsoleLogon.dll
2016-08-23 22:37:11 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-08-23 22:37:11 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-08-23 22:37:10 ----A---- C:\WINDOWS\system32\CastLaunch.dll
2016-08-23 22:36:54 ----A---- C:\WINDOWS\system32\winresume.exe
2016-08-23 22:36:54 ----A---- C:\WINDOWS\system32\winload.exe
2016-08-23 22:36:54 ----A---- C:\WINDOWS\system32\qmgr.dll
2016-08-23 22:36:54 ----A---- C:\WINDOWS\system32\CloudBackupSettings.dll
2016-08-23 22:36:42 ----A---- C:\WINDOWS\system32\MSAJApi.dll
2016-08-23 22:36:41 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-08-23 22:36:37 ----A---- C:\WINDOWS\system32\kdhvcom.dll
2016-08-23 22:36:37 ----A---- C:\WINDOWS\system32\hvloader.exe
2016-08-23 22:36:37 ----A---- C:\WINDOWS\system32\hvix64.exe
2016-08-23 22:36:37 ----A---- C:\WINDOWS\system32\hvax64.exe
2016-08-23 22:36:37 ----A---- C:\WINDOWS\system32\drivers\hvservice.sys
2016-08-23 22:36:33 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys
2016-08-23 22:36:33 ----A---- C:\WINDOWS\system32\drivers\hidparse.sys
2016-08-23 22:36:33 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys
2016-08-10 20:30:19 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-08-10 20:24:57 ----D---- C:\WINDOWS\PCHEALTH
2016-08-10 20:22:16 ----A---- C:\WINDOWS\system32\win32u.dll
2016-08-10 20:22:16 ----A---- C:\WINDOWS\system32\win32k.sys
2016-08-10 20:22:14 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-08-10 20:22:13 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2016-08-10 20:21:58 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2016-08-10 20:21:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2016-08-10 20:21:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2016-08-10 20:21:55 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-08-10 20:21:54 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-08-10 20:21:46 ----A---- C:\WINDOWS\SYSWOW64\Chakrathunk.dll
2016-08-10 20:21:45 ----A---- C:\WINDOWS\SYSWOW64\win32u.dll
2016-08-10 20:21:45 ----A---- C:\WINDOWS\SYSWOW64\win32k.sys
2016-08-10 20:21:41 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2016-08-10 20:21:40 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2016-08-10 20:21:37 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-08-10 20:21:37 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-08-10 20:21:37 ----A---- C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-08-10 20:21:36 ----A---- C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-08-10 20:21:36 ----A---- C:\WINDOWS\system32\Chakrathunk.dll
2016-08-10 20:21:36 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2016-08-10 20:21:35 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2016-08-10 20:21:34 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-08-10 20:21:33 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-08-10 20:21:32 ----A---- C:\WINDOWS\system32\mspaint.exe
2016-08-10 20:21:32 ----A---- C:\WINDOWS\system32\DataSenseHandlers.dll
2016-08-10 20:21:31 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2016-08-10 20:21:30 ----A---- C:\WINDOWS\system32\shutdownux.dll
2016-08-10 20:21:26 ----A---- C:\WINDOWS\system32\aclui.dll
2016-08-09 21:29:22 ----SHD---- C:\Recovery
2016-08-09 21:29:16 ----DC---- C:\WINDOWS\Panther
2016-08-09 21:26:34 ----D---- C:\ProgramData\Microsoft OneDrive
2016-08-09 21:25:05 ----A---- C:\WINDOWS\SYSWOW64\wevtapi.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\wevtapi.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\user32.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\msctf.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\cdd.dll
2016-08-09 21:25:05 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsRemoteEngine.exe
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsProxyStub.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsExperiment.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsDesktopEngine.exe
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsCapture.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\VSD3DWARPDebug.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\VSD3DWARP12Debug.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\perf_gputiming.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DXToolsReporting.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DxToolsReportGenerator.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DXToolsOfflineAnalysis.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DXToolsMonitor.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DXGIDebug.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DXCpl.exe
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DXCaptureReplay.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\DXCap.exe
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\d3d12warp.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\d3d12SDKLayers.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\d3d11_3SDKLayers.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\SYSWOW64\d2d1debug3.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\VsGraphicsExperiment.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\VsGraphicsCapture.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\VSD3DWARPDebug.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\DXToolsReporting.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\DXToolsMonitor.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\DXGIDebug.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\DXCpl.exe
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\DXCaptureReplay.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\DXCap.exe
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\d3d12warp.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\d3d12SDKLayers.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2016-08-09 21:23:46 ----A---- C:\WINDOWS\system32\d2d1debug3.dll
2016-08-09 21:23:45 ----A---- C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2016-08-09 21:23:45 ----A---- C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2016-08-09 21:23:45 ----A---- C:\WINDOWS\system32\perf_gputiming.dll
2016-08-09 21:23:45 ----A---- C:\WINDOWS\system32\DxToolsReportGenerator.dll
2016-08-09 21:22:59 ----D---- C:\ProgramData\USOShared
2016-08-09 21:15:57 ----D---- C:\WINDOWS\system32\Microsoft
2016-08-09 21:13:02 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2016-08-09 21:13:02 ----D---- C:\Program Files\Reference Assemblies
2016-08-09 21:13:02 ----D---- C:\Program Files\MSBuild
2016-08-09 21:13:02 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-08-09 21:13:02 ----AD---- C:\Program Files (x86)\MSBuild
2016-08-09 21:12:25 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2016-08-09 21:12:25 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2016-08-09 21:12:25 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-08-09 21:12:17 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2016-08-09 21:12:17 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-08-09 21:12:17 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-08-09 20:57:52 ----ASH---- C:\hiberfil.sys
2016-08-09 20:39:22 ----SD---- C:\Users\Ondra\AppData\Roaming\Microsoft
2016-08-09 20:38:46 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-08-09 20:38:42 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2016-08-09 20:35:47 ----D---- C:\WINDOWS\SYSWOW64\sda
2016-08-09 20:35:25 ----A---- C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-08-09 20:35:25 ----A---- C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-08-09 20:35:23 ----D---- C:\ProgramData\Conexant
2016-08-09 20:35:20 ----D---- C:\Program Files\CONEXANT
2016-08-09 20:35:18 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.DLL
2016-08-09 20:35:18 ----A---- C:\WINDOWS\system32\OpenCL.DLL
2016-08-09 20:35:12 ----AD---- C:\Program Files\Intel
2016-08-09 20:34:50 ----D---- C:\Program Files\Synaptics
2016-08-09 20:34:32 ----D---- C:\ProgramData\NVIDIA
2016-08-09 20:34:25 ----A---- C:\WINDOWS\SYSWOW64\oemdspif.dll
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-08-09 20:34:25 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-08-09 20:34:22 ----HD---- C:\Program Files (x86)\Uninstall Information
2016-08-09 20:34:11 ----D---- C:\ProgramData\NVIDIA Corporation
2016-08-09 20:34:01 ----D---- C:\Program Files\NVIDIA Corporation
2016-08-09 20:33:38 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-08-09 20:32:02 ----AS---- C:\WINDOWS\bootstat.dat
2016-08-09 20:31:13 ----D---- C:\WINDOWS\Prefetch
2016-08-09 20:30:36 ----D---- C:\WINDOWS\system32\SleepStudy
2016-08-09 20:30:36 ----D---- C:\WINDOWS\ServiceProfiles
2016-08-09 20:30:23 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-08-07 00:35:07 ----D---- C:\Users\Ondra\AppData\Roaming\The Creative Assembly

======List of files/folders modified in the last 1 month======

2016-09-05 18:54:53 ----RD---- C:\Program Files
2016-09-05 18:51:04 ----D---- C:\WINDOWS\Temp
2016-09-05 18:19:00 ----D---- C:\WINDOWS\system32\sru
2016-09-05 17:51:04 ----D---- C:\Program Files (x86)\Steam
2016-09-04 22:46:44 ----RD---- C:\WINDOWS\Microsoft.NET
2016-09-04 22:38:30 ----D---- C:\Users\Ondra\AppData\Roaming\TS3Client
2016-09-04 20:24:34 ----D---- C:\WINDOWS\system32\drivers
2016-09-04 07:56:03 ----D---- C:\WINDOWS\AppReadiness
2016-09-03 14:09:45 ----D---- C:\WINDOWS\system32\config
2016-09-03 11:52:16 ----D---- C:\WINDOWS\CbsTemp
2016-09-03 11:52:12 ----D---- C:\WINDOWS\WinSxS
2016-09-03 11:52:12 ----D---- C:\WINDOWS\SysWOW64
2016-09-03 11:51:49 ----D---- C:\WINDOWS\system32\catroot2
2016-09-03 07:34:06 ----HD---- C:\Program Files\WindowsApps
2016-09-02 23:44:31 ----AD---- C:\KMPlayer
2016-09-02 17:49:15 ----SHD---- C:\System Volume Information
2016-09-02 03:17:58 ----D---- C:\Program Files\Common Files
2016-09-01 11:44:33 ----RD---- C:\Program Files (x86)
2016-09-01 11:16:45 ----HD---- C:\ProgramData
2016-09-01 11:16:08 ----SHD---- C:\WINDOWS\Installer
2016-09-01 11:16:08 ----SHD---- C:\Config.Msi
2016-08-31 18:36:47 ----AD---- C:\Program Files (x86)\Overwolf
2016-08-31 18:35:27 ----D---- C:\Users\Ondra\AppData\Roaming\Skype
2016-08-30 14:41:27 ----RD---- C:\Program Files (x86)\Skype
2016-08-27 21:43:26 ----D---- C:\WINDOWS\system32\Tasks
2016-08-26 07:43:07 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-08-25 18:29:12 ----D---- C:\WINDOWS\rescache
2016-08-25 06:24:25 ----D---- C:\WINDOWS\system32\DriverStore
2016-08-24 18:01:05 ----D---- C:\Users\Ondra\AppData\Roaming\Unity
2016-08-24 03:06:35 ----D---- C:\WINDOWS\INF
2016-08-24 02:56:32 ----D---- C:\WINDOWS\System32
2016-08-24 02:49:45 ----AD---- C:\ProgramData\VMware
2016-08-24 02:41:31 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-08-24 02:41:31 ----D---- C:\WINDOWS\SYSWOW64\en-US
2016-08-24 02:41:31 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-08-24 02:41:26 ----SD---- C:\WINDOWS\system32\dsc
2016-08-24 02:41:26 ----D---- C:\WINDOWS\system32\wbem
2016-08-24 02:41:26 ----D---- C:\WINDOWS\system32\migration
2016-08-24 02:41:26 ----D---- C:\WINDOWS\system32\en-US
2016-08-24 02:41:26 ----D---- C:\WINDOWS\system32\cs-CZ
2016-08-24 02:41:26 ----D---- C:\WINDOWS\system32\Boot
2016-08-24 02:41:26 ----D---- C:\WINDOWS\system32\appraiser
2016-08-24 02:41:21 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-08-24 02:41:21 ----D---- C:\WINDOWS\ShellExperiences
2016-08-24 02:41:18 ----D---- C:\WINDOWS\AppPatch
2016-08-24 02:41:18 ----D---- C:\Program Files\Windows Media Player
2016-08-24 02:41:18 ----D---- C:\Program Files (x86)\Windows Media Player
2016-08-23 23:26:07 ----D---- C:\ProgramData\Microsoft Help
2016-08-23 23:24:36 ----RSD---- C:\WINDOWS\assembly
2016-08-22 22:44:28 ----D---- C:\WINDOWS\system32\NDF
2016-08-16 20:09:50 ----D---- C:\WINDOWS\Logs
2016-08-12 21:49:46 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-08-12 04:44:13 ----D---- C:\WINDOWS\system32\LogFiles
2016-08-11 05:41:32 ----D---- C:\WINDOWS\system32\WDI
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\zh-TW
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\zh-HK
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\zh-CN
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\uk-UA
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\tr-TR
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\th-TH
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\sv-SE
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\sl-SI
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\sk-SK
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\ru-RU
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\ro-RO
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\pt-PT
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\pt-BR
2016-08-11 05:27:17 ----D---- C:\WINDOWS\system32\pl-PL
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\nl-NL
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\nb-NO
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\lv-LV
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\lt-LT
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\ko-KR
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\ja-jp
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\it-IT
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\hu-HU
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\hr-HR
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\he-IL
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\fr-FR
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\fr-CA
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\fi-FI
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\et-EE
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\es-MX
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\es-ES
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\en-GB
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\el-GR
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\de-DE
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\da-DK
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\bg-BG
2016-08-11 05:27:16 ----D---- C:\WINDOWS\system32\ar-SA
2016-08-11 05:27:14 ----D---- C:\Program Files (x86)\Windows Mail
2016-08-11 05:27:13 ----D---- C:\Program Files\Windows Mail
2016-08-10 20:42:51 ----D---- C:\WINDOWS\system32\MRT
2016-08-10 20:31:29 ----D---- C:\WINDOWS\debug
2016-08-10 20:30:54 ----AC---- C:\WINDOWS\system32\MRT.exe
2016-08-10 20:24:57 ----D---- C:\Windows
2016-08-10 20:22:40 ----D---- C:\WINDOWS\system32\restore
2016-08-10 04:58:14 ----D---- C:\WINDOWS\appcompat
2016-08-09 21:23:11 ----SD---- C:\WINDOWS\SYSWOW64\F12
2016-08-09 21:23:11 ----D---- C:\WINDOWS\SYSWOW64\winrm
2016-08-09 21:23:11 ----D---- C:\WINDOWS\SYSWOW64\WCN
2016-08-09 21:23:11 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2016-08-09 21:23:08 ----SD---- C:\WINDOWS\SYSWOW64\DiagSvcs
2016-08-09 21:23:08 ----SD---- C:\WINDOWS\system32\F12
2016-08-09 21:23:08 ----D---- C:\WINDOWS\SYSWOW64\en
2016-08-09 21:23:08 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-US
2016-08-09 21:23:08 ----D---- C:\WINDOWS\system32\winrm
2016-08-09 21:23:08 ----D---- C:\WINDOWS\system32\WCN
2016-08-09 21:23:08 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-08-09 21:23:08 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2016-08-09 21:23:08 ----D---- C:\WINDOWS\system32\migwiz
2016-08-09 21:23:07 ----SD---- C:\WINDOWS\system32\DiagSvcs
2016-08-09 21:23:07 ----RD---- C:\Program Files\Windows Defender
2016-08-09 21:23:07 ----D---- C:\WINDOWS\system32\en
2016-08-09 21:23:07 ----D---- C:\WINDOWS\system32\drivers\en-US
2016-08-09 21:23:07 ----D---- C:\WINDOWS\servicing
2016-08-09 21:23:07 ----D---- C:\WINDOWS\en-US
2016-08-09 21:23:07 ----D---- C:\Program Files\Windows Photo Viewer
2016-08-09 21:23:07 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2016-08-09 21:23:07 ----D---- C:\Program Files (x86)\Windows Defender
2016-08-09 21:23:04 ----D---- C:\ProgramData\USOPrivate
2016-08-09 21:22:45 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 12.0
2016-08-09 21:22:45 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 11.0
2016-08-09 21:22:45 ----AD---- C:\Program Files (x86)\Microsoft Visual Studio 14.0
2016-08-09 21:21:18 ----D---- C:\Program Files\Windows NT
2016-08-09 21:20:45 ----D---- C:\WINDOWS\SoftwareDistribution
2016-08-09 21:18:12 ----D---- C:\WINDOWS\Registration
2016-08-09 21:18:04 ----RSD---- C:\WINDOWS\Fonts
2016-08-09 21:18:04 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-08-09 21:18:04 ----D---- C:\WINDOWS\system32\Tasks_Migrated
2016-08-09 21:13:02 ----D---- C:\WINDOWS\SYSWOW64\MUI
2016-08-09 21:13:02 ----D---- C:\WINDOWS\system32\MUI
2016-08-09 21:12:58 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2016-08-09 21:12:58 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2016-08-09 21:12:58 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2016-08-09 21:12:58 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2016-08-09 21:12:55 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2016-08-09 21:12:55 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2016-08-09 21:12:55 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2016-08-09 21:12:55 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2016-08-09 21:12:55 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2016-08-09 21:12:55 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2016-08-09 21:12:55 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2016-08-09 21:12:51 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2016-08-09 21:12:51 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2016-08-09 21:12:51 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2016-08-09 21:12:51 ----A---- C:\WINDOWS\system32\dpnet.dll
2016-08-09 21:12:51 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2016-08-09 21:12:51 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2016-08-09 21:12:50 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2016-08-09 21:08:20 ----D---- C:\WINDOWS\Tasks
2016-08-09 21:07:47 ----SD---- C:\ProgramData\Microsoft
2016-08-09 21:07:38 ----D---- C:\WINDOWS\system32\drivers\etc
2016-08-09 21:01:58 ----D---- C:\WINDOWS\system32\CatRoot
2016-08-09 20:57:21 ----D---- C:\WINDOWS\system32\FxsTmp
2016-08-09 20:57:09 ----D---- C:\WINDOWS\SYSWOW64\drivers
2016-08-09 20:57:09 ----D---- C:\WINDOWS\SYSWOW64\1033
2016-08-09 20:57:08 ----D---- C:\WINDOWS\system32\1033
2016-08-09 20:57:07 ----D---- C:\WINDOWS\ShellNew
2016-08-09 20:56:59 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-08-09 20:47:25 ----D---- C:\WINDOWS\SYSWOW64\zh-TW
2016-08-09 20:47:25 ----D---- C:\WINDOWS\SYSWOW64\zh-HK
2016-08-09 20:47:25 ----D---- C:\WINDOWS\SYSWOW64\zh-CN
2016-08-09 20:47:24 ----D---- C:\WINDOWS\SYSWOW64\uk-UA
2016-08-09 20:47:24 ----D---- C:\WINDOWS\SYSWOW64\tr-TR
2016-08-09 20:47:24 ----D---- C:\WINDOWS\SYSWOW64\th-TH
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\sv-SE
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-RS
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\sl-SI
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\ru-RU
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\ro-RO
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\pt-PT
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\pt-BR
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\nl-NL
2016-08-09 20:47:23 ----D---- C:\WINDOWS\SYSWOW64\nb-NO
2016-08-09 20:47:22 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2016-08-09 20:47:22 ----D---- C:\WINDOWS\SYSWOW64\lv-LV
2016-08-09 20:47:22 ----D---- C:\WINDOWS\SYSWOW64\lt-LT
2016-08-09 20:47:22 ----D---- C:\WINDOWS\SYSWOW64\ko-KR
2016-08-09 20:47:22 ----D---- C:\WINDOWS\SYSWOW64\ja-JP
2016-08-09 20:47:22 ----D---- C:\WINDOWS\SYSWOW64\it-IT
2016-08-09 20:47:21 ----D---- C:\WINDOWS\SYSWOW64\hu-HU
2016-08-09 20:47:21 ----D---- C:\WINDOWS\SYSWOW64\hr-HR
2016-08-09 20:47:21 ----D---- C:\WINDOWS\SYSWOW64\he-IL
2016-08-09 20:47:21 ----D---- C:\WINDOWS\SYSWOW64\fr-FR
2016-08-09 20:47:21 ----D---- C:\WINDOWS\SYSWOW64\fi-FI
2016-08-09 20:47:20 ----D---- C:\WINDOWS\SYSWOW64\et-EE
2016-08-09 20:47:20 ----D---- C:\WINDOWS\SYSWOW64\es-ES
2016-08-09 20:47:19 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2016-08-09 20:47:19 ----D---- C:\WINDOWS\SYSWOW64\el-GR
2016-08-09 20:47:19 ----D---- C:\WINDOWS\SYSWOW64\de-DE
2016-08-09 20:47:19 ----D---- C:\WINDOWS\SYSWOW64\da-DK
2016-08-09 20:47:18 ----D---- C:\WINDOWS\SYSWOW64\bg-BG
2016-08-09 20:47:18 ----D---- C:\WINDOWS\SYSWOW64\ar-SA
2016-08-09 20:47:13 ----HD---- C:\WINDOWS\system32\WLANProfiles
2016-08-09 20:47:10 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2016-08-09 20:47:10 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2016-08-09 20:47:09 ----D---- C:\WINDOWS\system32\spool
2016-08-09 20:47:08 ----D---- C:\WINDOWS\system32\slmgr
2016-08-09 20:47:07 ----D---- C:\WINDOWS\system32\oobe
2016-08-09 20:47:05 ----D---- C:\WINDOWS\system32\Macromed
2016-08-09 20:47:05 ----D---- C:\WINDOWS\system32\InputMethod
2016-08-09 20:47:02 ----DC---- C:\WINDOWS\system32\DRVSTORE
2016-08-09 20:46:00 ----D---- C:\WINDOWS\LiveKernelReports
2016-08-09 20:45:49 ----D---- C:\WINDOWS\InputMethod
2016-08-09 20:45:14 ----RD---- C:\Users
2016-08-09 20:44:53 ----AD---- C:\Program Files (x86)\Microsoft.NET
2016-08-09 20:44:51 ----D---- C:\Program Files (x86)\Common Files
2016-08-09 20:44:45 ----D---- C:\Program Files\Microsoft.NET
2016-08-09 20:44:43 ----AD---- C:\Program Files\Common Files\microsoft shared
2016-08-09 20:42:33 ----D---- C:\WINDOWS\system32\Recovery
2016-08-09 20:40:37 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-08-09 20:38:25 ----D---- C:\WINDOWS\system32\Sysprep
2016-08-09 20:36:12 ----RD---- C:\WINDOWS\PrintDialog
2016-08-09 20:36:11 ----RD---- C:\WINDOWS\MiracastView
2016-08-09 20:35:48 ----D---- C:\WINDOWS\twain_32
2016-08-09 20:34:24 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2016-02-22 74544]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2016-08-05 292704]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2014-02-26 645992]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-07-16 45920]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2016-03-22 37144]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2016-02-22 103064]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2016-03-09 1070904]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2016-02-23 463744]
R1 CLVirtualDrive;CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-07-16 88576]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-07-16 8192]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2016-02-22 37656]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2016-03-09 107792]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2016-02-22 165344]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 hcmon;VMware hcmon; \??\C:\WINDOWS\system32\drivers\hcmon.sys [2015-11-06 57536]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2016-07-16 48128]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2016-07-16 78336]
R3 ACPIVPC;@oem10.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2015-06-04 42328]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\system32\DRIVERS\BTHUSB.sys [2016-07-16 84992]
R3 CnxtHdAudService;@oem63.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2015-05-19 1543912]
R3 dtlitescsibus;@oem44.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2016-01-31 30264]
R3 dtliteusbbus;@oem55.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [2016-01-31 47672]
R3 ibtusb;@oem85.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R); C:\WINDOWS\system32\DRIVERS\ibtusb.sys [2016-07-12 349960]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2016-05-27 7936600]
R3 mcdevice;mcdevice; C:\WINDOWS\system32\DRIVERS\mcdevice.sys [2011-05-19 334400]
R3 MEIx64;@oem80.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2013-09-16 99288]
R3 NETwNb64;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\WINDOWS\System32\drivers\Netwbw02.sys [2016-07-16 3485696]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2015-07-23 11142984]
R3 rt640x64;@oem66.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-06-18 895256]
R3 RTSUER;@oem64.inf,%RtsUER%;Realtek USB Card Reader - UER; C:\WINDOWS\system32\Drivers\RtsUer.sys [2015-07-03 410880]
R3 rtsuvc;@oem48.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2015-06-16 3068160]
R3 SensorsSimulatorDriver;@oem14.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [2016-07-16 216064]
R3 SynTP;@oem78.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2016-06-01 642168]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-07-16 105824]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-07-16 101216]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2016-07-16 58720]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2016-07-16 61792]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2016-07-16 32096]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2016-07-16 9728]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\system32\DRIVERS\BTHport.sys [2016-07-16 965120]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-07-16 38912]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-07-16 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-07-16 20480]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-07-16 50016]
S3 HipShieldK;McAfee Inc. HipShieldK; C:\WINDOWS\system32\drivers\HipShieldK.sys [2015-05-19 207208]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-08-06 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2016-07-16 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-07-16 176384]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2016-07-16 526176]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 IntcDAud;@oem77.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2014-08-20 453872]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 mfeaack;McAfee Inc. mfeaack; C:\WINDOWS\system32\drivers\mfeaack.sys [2015-11-25 419624]
S3 mfencrk;McAfee Inc. mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [2015-11-20 109480]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-07-16 842584]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2016-07-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2016-07-16 928608]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2015-06-03 42696]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-03-02 83768]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-02-22 237096]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CCSDK;CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [2014-07-10 592880]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 CDPUserSvc_106b5c;CDPUserSvc_106b5c; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 CxAudMsg;Conexant Audio Message Service; C:\windows\system32\CxAudMsg64.exe [2013-07-25 206552]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-02-26 16232]
R2 ibtsiva;@oem85.inf,%SERVICE_NAME%;Intel Bluetooth Service; C:\WINDOWS\system32\ibtsiva []
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2016-05-27 374360]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-16 169432]
R2 Lenovo System Agent Service;Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [2015-12-14 584664]
R2 LenovoWiFiHotspotSvr;Lenovo WiFiHotspot Service; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [2015-03-24 198192]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-16 390616]
R2 MaxthonUpdateSvc;Maxthon Core Update Service; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [2016-07-12 2451880]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2015-07-23 937800]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-10-18 1914656]
R2 OneSyncSvc_106b5c;Hostitel synchronizace_106b5c; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 PEFService;Intel Security PEF Service; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [2015-12-14 902112]
R2 SAService;Conexant SmartAudio service; C:\WINDOWS\syswow64\SAsrv.exe [2011-09-01 447104]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2016-06-01 255608]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2016-01-15 1369464]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2016-06-01 651576]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R3 PimIndexMaintenanceSvc_106b5c;Data kontaktů_106b5c; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-23 1465120]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-29 144200]
S2 HomeNetSvc;McAfee Home Network; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S2 McAPExe;McAfee AP Service; C:\Program Files\McAfee\MSC\McAPExe.exe [2016-01-08 863448]
S2 McBootDelayStartSvc;McAfee Boot Delay Start Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
S2 mccspsvc;McAfee CSP Service; C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe [2015-12-02 1694152]
S2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
S2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-13 270016]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2016-05-27 302176]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-07-16 93184]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-29 144200]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 Lenovo EasyPlus Hotspot;Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [2014-09-23 561408]
S3 McAWFwk;McAfee Activation Service; C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [2014-03-12 332528]
S3 McODS;McAfee Scanner; C:\Program Files\mcafee\VirusScan\mcods.exe [2016-01-08 681680]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService_106b5c;Služba zasílání zpráv_106b5c; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-09-05 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-09-01 2122248]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-08-29 1310448]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2016-07-16 1312768]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S4 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]

-----------------EOF-----------------

Re: Preventivka notebooku

Napsal: 05 zář 2016 19:01
od Roli
Zdravím, přes Odebrat programy odinstaluj vše od McAfee.


Stáhni a spusť AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.

Re: Preventivka notebooku

Napsal: 05 zář 2016 20:03
od maty207
Tak po vymazání log, zaráží mě tam několik věcí, co prý nešlo smazat

# AdwCleaner v6.010 - Log soubor vytvořen 05/09/2016 na 20:32:22
# Aktualizováno dne 12/08/2016 z ToolsLib
# Databáze : 2016-09-05.1 [Server]
# Operační systém : Windows 10 Home (X64)
# Uživatelské jméno : Ondra - LENOVO-PC
# Beží od : C:\Users\Ondra\Downloads\adwcleaner_6.010.exe
# Mod: Čištění
# Podpora : https://toolslib.net/forum



***** [ Služby ] *****



***** [ Adresáře ] *****

[-] Adresář smazán:C:\Users\Ondra\AppData\Local\pokki
[-] Adresář smazán:C:\Users\Ondra\AppData\Local\UpdateAdmin
[#] Adresář nelze smazat:C:\Users\Ondra\AppData\Local\Pokki
[-] Adresář smazán:C:\ProgramData\pokki
[#] Adresář nelze smazat:C:\ProgramData\Pokki
[-] Adresář smazán:C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
[-] Adresář smazán:C:\Program Files (x86)\Amazon\Amazon1ButtonApp
[-] Adresář smazán:C:\Users\Default User\AppData\Local\Pokki
[#] Adresář nelze smazat:C:\Users\Default\AppData\Local\Pokki


***** [ Soubory ] *****

[-] Soubor smazán:C:\END


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKCU\Software\43f23bafe11f4262babb817ba180dfeb
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_Start_Menu
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AmazonAppIE.AppGateway
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AmazonAppIE.GadgetGateway
[-] Klíč smazán:HKLM\SOFTWARE\Classes\OCComSDK.ComSDK
[-] Klíč smazán:HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Klíč smazán:HKU\S-1-5-21-3996182392-1031933315-1381193400-1002\Software\DownloadAdmin
[-] Klíč smazán:HKU\S-1-5-21-3996182392-1031933315-1381193400-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
[#] Klíč smazán po restartování:HKCU\Software\DownloadAdmin
[#] Klíč smazán po restartování:HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{81F17B54-5D57-485E-88CC-F6D20D66B5E0}
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45B71F1875D5E58488CC6F2DD0665B0E
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\Installer\Products\45B71F1875D5E58488CC6F2DD0665B0E
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Installer\Features\45B71F1875D5E58488CC6F2DD0665B0E
[#] Klíč smazán po restartování:HKLM\SOFTWARE\Classes\Installer\Products\45B71F1875D5E58488CC6F2DD0665B0E
[-] Data obnovena:HKU\S-1-5-21-3996182392-1031933315-1381193400-1002\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages]
[-] Data obnovena:HKU\S-1-5-21-3996182392-1031933315-1381193400-1002\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
[-] Data obnovena:HKCU\Software\Microsoft\Internet Explorer\Main [Secondary Start Pages]
[-] Data obnovena:HKCU\Software\Microsoft\Internet Explorer\Main [Default_Secondary_Page_URL]
[-] Klíč smazán:HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Klíč smazán:HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[-] Hodnota smazána:HKU\S-1-5-21-3996182392-1031933315-1381193400-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Pokki]
[-] Klíč smazán:HKCU\Software\Classes\Directory\shell\pokki
[-] Klíč smazán:HKCU\Software\Classes\lnkfile\shell\pokki


***** [ Prohlížeče ] *****

[-] [gadgetbox] [Search Provider] Smazání:gadgetbox
[-] [search.mywebsearch.com] [Search Provider] Smazání:search.mywebsearch.com
[-] [ask.com] [Search Provider] Smazání:ask.com
[-] [C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Smazání:hxxp://search.gboxapp.com/


*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [5102 Bajtů] - [05/09/2016 20:32:22]
C:\AdwCleaner\AdwCleaner[S0].txt - [5585 Bajtů] - [05/09/2016 20:27:43]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5250 Bajtů] ##########

Re: Preventivka notebooku

Napsal: 07 zář 2016 18:45
od Roli
maty207 píše:Tak po vymazání log, zaráží mě tam několik věcí, co prý nešlo smazat
Nejde smazat pouze Pokki, což až takový průšvih není, hlavně že odmazal ty brebery.


Spusť skener Cure It podle TOHOTO návodu

po skončení skenu mi sem nakopíruj výsledky - stačí konec logu se souhrnem.

(Upozornění je úchylně pomalý a je zapotřebí ho sledovat občas se na něco ptá)

Re: Preventivka notebooku

Napsal: 08 zář 2016 05:10
od maty207
Nic nenašel, log to nevypsalo, jen mi stejně přijde divný ta spotřeba RAMky, za klidu 2 GB

Re: Preventivka notebooku

Napsal: 12 zář 2016 17:20
od Roli
maty207 píše:Nic nenašel, log to nevypsalo
Log by vyhodit měl, ale když nic nenašel je to v pořádku.
maty207 píše:jen mi stejně přijde divný ta spotřeba RAMky, za klidu 2 GB
Celkem normální stav.


Pokud tedy s PC není žadný problém je to z mé strany vše.