Problém s kradením účtů
Napsal: 14 říj 2016 17:56
Zdravím,
Poslední dobou se mi opakovaně někdo dobývá na nejrůznější účty od eBay přes Microsoft Live až po Instagram. Rád bych se vyhnul tomu, aby to priste byl PayPal nebo muj bankovni ucet, takze prosim o pomoc a nize zasilam log.
Kvuli omezeni v poctu znaku delim log do dvou postu.
PART 1
Logfile of random's system information tool 1.10 (written by random/random)
Run by jakub_000 at 2016-10-14 18:45:34
Microsoft Windows 10 Home
System drive C: has 195 GB (45%) free of 435 GB
Total RAM: 3979 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:45:44, on 14.10.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal
Running processes:
C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Program Files\WindowsApps\Microsoft.BingNews_4.16.18.0_x86__8wekyb3d8bbwe\Microsoft.Msn.News.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\jakub_000.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com/?fr=vmn&type=vmn_ ... 0721__yaie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Web Companion] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
O4 - HKCU\..\RunOnce: [Application Restart #1] C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem46.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\system32\ibtsiva (file missing)
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LavasoftTcpService - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Update service - Popcorn Time - C:\Program Files (x86)\Popcorn Time\Updater.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: WC Assistant (WCAssistantService) - Unknown owner - C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10458 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-51c7568e-ae54-4607-b2e0-874934e7240b -SystemEventPortName:HostProcess-46f4c2a0-166d-4cd7-b71a-e6dd5dcb3dae -IoCancelEventPortName:HostProcess-5d1964b2-6243-4b57-9fd8-61ed07b49fb2 -NonStateChangingEventPortName:HostProcess-61b3f90e-08f7-45cd-8bd8-4897eec17b74 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:661186c8-f8dc-4e37-a68b-4ef53ba44adf -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
dashost.exe {fed9b398-2348-4548-bd9738aded41f108}
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
C:\windows\system32\CxAudMsg64.exe
C:\WINDOWS\system32\ibtsiva
"C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\SysWoW64\SAsrv.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe"
"C:\Program Files (x86)\Popcorn Time\Updater.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe" /LOGON
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
igfxEM.exe
igfxHK.exe
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
igfxTray.exe
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe"
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.190.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Windows\RTFTrack.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe" --minimize
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\system32\wbem\wmiprvse.exe
"fontdrvhost.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/8/OneClickSignIn/BlueOnWhite/Prefetch/ContentPrefetchPrefetchOff/Prerender/Prerender15minTTL/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_81/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="3836.1.1024443234\776324117" /prefetch:3
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceStartMenuIndexer.exe"
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.BingNews_4.16.18.0_x86__8wekyb3d8bbwe\Microsoft.Msn.News.exe" -ServerName:AppexNews.AppX3vz52bd72d0ycrnwe6jysfgn7k1qcv00.mca
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\jakub_000\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=53.0.2785.116 --handshake-handle=0x258
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4992.0.44525305\1416093626" --mojo-application-channel-token=321C2DBD0BD2987A68CD4BC9B84D6D25 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,14,18,31,48,56 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.4276 --gpu-driver-date=8-17-2015 --mojo-platform-channel-handle=1504 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --primordial-pipe-token=5A24CA4906246D3F8973122C6D4C0C50 --lang=en-US --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=1A660821C4E03F47B5149900732F0148 --mojo-application-channel-token=5A24CA4906246D3F8973122C6D4C0C50 --channel="4992.3.111495788\1536492731" --mojo-platform-channel-handle=2848 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --primordial-pipe-token=EBCB50502C59B4D12882DED46D5ED7DF --lang=en-US --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=80D6A6C0C56EF95E898276B3A1CF2886 --mojo-application-channel-token=EBCB50502C59B4D12882DED46D5ED7DF --channel="4992.4.1526305422\987827380" --mojo-platform-channel-handle=2868 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=1343C0856C2F0F40B401082719A1D7F6 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=305F12738677E652C257E52E03855DA8 --mojo-application-channel-token=1343C0856C2F0F40B401082719A1D7F6 --channel="4992.6.385123217\1506753078" --mojo-platform-channel-handle=5948 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/*EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/*PluginPowerSaverTiny/Control/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=2921F4E6CBB41841FB67F0D5C25579A1 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=B6877D2A1ABFB83B069CC4CDFD108D7B --mojo-application-channel-token=2921F4E6CBB41841FB67F0D5C25579A1 --channel="4992.9.130941466\1490554698" --mojo-platform-channel-handle=3472 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/*EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/*PluginPowerSaverTiny/Control/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=84C4A97C6D66104EDA93A90C5BB404D1 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=B1A5ECDC7FBCEA22D74305E83BE6ABFB --mojo-application-channel-token=84C4A97C6D66104EDA93A90C5BB404D1 --channel="4992.10.610404179\1070442513" --mojo-platform-channel-handle=7484 /prefetch:1
C:\WINDOWS\system32\AUDIODG.EXE 0x3b0
C:\Windows\System32\smartscreen.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 620 648 656 8192 652
"C:\Users\jakub_000\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2014-02-27 6340312]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-09-05 907480]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2012-06-13 1647616]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2014-09-20 16094704]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2014-09-20 10841584]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-07-27 3945672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-09-25 633024]
"Web Companion"=C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [2016-10-08 1790616]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]
"Application Restart #1"=C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [2016-09-18 7874024]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-08-08 8900328]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-10-14 18:45:34 ----D---- C:\rsit
2016-10-14 18:45:34 ----D---- C:\Program Files\trend micro
2016-10-13 20:43:43 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\dsreg.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\dsreg.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2016-10-13 20:43:38 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-10-13 20:43:37 ----A---- C:\WINDOWS\system32\netshell.dll
2016-10-13 20:43:37 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-10-13 20:43:37 ----A---- C:\WINDOWS\system32\msdtctm.dll
2016-10-13 20:43:36 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2016-10-13 20:43:35 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-10-13 20:43:33 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-10-13 20:43:33 ----A---- C:\WINDOWS\system32\wpncore.dll
2016-10-13 20:43:32 ----A---- C:\WINDOWS\system32\wpx.dll
2016-10-13 20:43:32 ----A---- C:\WINDOWS\system32\ncsi.dll
2016-10-13 20:43:32 ----A---- C:\WINDOWS\system32\inetcomm.dll
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\nlasvc.dll
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\credprovs.dll
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\bcdedit.exe
2016-10-13 20:43:30 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-10-13 20:43:30 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-10-13 20:43:30 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-10-13 20:43:29 ----A---- C:\WINDOWS\system32\wininet.dll
2016-10-13 20:43:29 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2016-10-13 20:43:28 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-10-13 20:43:28 ----A---- C:\WINDOWS\system32\DWrite.dll
2016-10-13 20:43:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-10-13 20:43:25 ----A---- C:\WINDOWS\system32\shell32.dll
2016-10-13 20:43:24 ----A---- C:\WINDOWS\SYSWOW64\dialclient.dll
2016-10-13 20:43:23 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2016-10-13 20:43:23 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-10-13 20:43:19 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-10-13 20:43:18 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-10-13 20:43:17 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2016-10-13 20:43:17 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-10-13 20:43:16 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2016-10-13 20:43:15 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-10-13 20:43:15 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-10-13 20:43:14 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-10-13 20:43:14 ----A---- C:\WINDOWS\system32\aadtb.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-10-13 20:43:12 ----A---- C:\WINDOWS\system32\smartscreen.exe
2016-10-13 20:43:12 ----A---- C:\WINDOWS\system32\drivers\MegaSas2i.sys
2016-10-13 20:43:11 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-10-13 20:43:10 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-10-13 20:43:10 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-10-13 20:43:09 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2016-10-13 20:43:09 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2016-10-13 20:43:08 ----A---- C:\WINDOWS\SYSWOW64\offreg.dll
2016-10-13 20:43:08 ----A---- C:\WINDOWS\SYSWOW64\credprovs.dll
2016-10-13 20:43:08 ----A---- C:\WINDOWS\system32\adsmsext.dll
2016-10-13 20:43:06 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\efswrt.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\dialclient.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-13 20:43:04 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-10-13 20:43:04 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-10-13 20:43:04 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-13 20:43:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-10-13 20:43:02 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-13 20:43:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-10-13 20:43:01 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-10-13 20:43:01 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2016-10-13 20:42:56 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-13 20:42:56 ----A---- C:\WINDOWS\system32\wc_storage.dll
2016-10-13 20:42:56 ----A---- C:\WINDOWS\system32\daxexec.dll
2016-10-13 20:42:54 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-10-13 20:42:50 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-10-13 20:42:48 ----A---- C:\WINDOWS\system32\wbiosrvc.dll
2016-10-13 20:42:47 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-10-13 20:42:47 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-10-13 20:42:43 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2016-10-13 20:42:43 ----A---- C:\WINDOWS\system32\mfsensorgroup.dll
2016-10-13 20:42:42 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-10-13 20:42:42 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-10-13 20:42:42 ----A---- C:\WINDOWS\system32\FrameServer.dll
2016-10-13 20:42:41 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-10-13 20:42:40 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-10-13 20:42:39 ----A---- C:\WINDOWS\system32\wmp.dll
2016-10-13 20:42:38 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-10-13 20:42:38 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2016-10-13 20:42:37 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-10-13 20:42:34 ----A---- C:\WINDOWS\system32\winresume.exe
2016-10-13 20:42:34 ----A---- C:\WINDOWS\system32\winload.exe
2016-10-13 20:42:33 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\GamePanel.exe
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\apprepsync.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\apprepapi.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-10-13 20:42:30 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2016-10-13 20:42:30 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-13 20:42:29 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2016-10-13 20:42:29 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2016-10-13 20:42:28 ----A---- C:\WINDOWS\SYSWOW64\MSVidCtl.dll
2016-10-13 20:42:28 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-10-13 20:42:28 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2016-10-13 20:42:27 ----A---- C:\WINDOWS\SYSWOW64\ConfigureExpandedStorage.dll
2016-10-13 20:42:27 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2016-10-13 20:42:27 ----A---- C:\WINDOWS\system32\offreg.dll
2016-10-13 20:42:27 ----A---- C:\WINDOWS\system32\drivers\tm.sys
2016-10-13 20:42:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2016-10-13 20:42:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2016-10-13 20:42:26 ----A---- C:\WINDOWS\system32\msi.dll
2016-10-13 20:42:26 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-10-13 20:42:25 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-10-13 20:42:24 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\ChatApis.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\EmailApis.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\SYSWOW64\mfsensorgroup.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\ContactApis.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-10-13 20:42:21 ----A---- C:\WINDOWS\system32\mspaint.exe
2016-10-13 20:42:20 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-13 20:42:20 ----A---- C:\WINDOWS\system32\win32spl.dll
2016-10-13 20:42:19 ----A---- C:\WINDOWS\system32\FntCache.dll
2016-10-13 20:42:18 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-13 20:42:18 ----A---- C:\WINDOWS\system32\ShareHost.dll
2016-10-13 20:42:17 ----A---- C:\WINDOWS\system32\twinui.dll
2016-10-13 20:42:13 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-13 20:42:12 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-10-13 20:42:12 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-10-13 20:42:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2016-10-13 20:42:07 ----A---- C:\WINDOWS\system32\mos.dll
2016-10-13 20:42:06 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-10-13 20:42:06 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-10-13 20:42:05 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-10-13 20:42:05 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-10-13 20:42:04 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2016-10-13 20:42:04 ----A---- C:\WINDOWS\system32\cloudAP.dll
2016-10-13 20:42:03 ----A---- C:\WINDOWS\SYSWOW64\adsmsext.dll
2016-10-13 20:42:03 ----A---- C:\WINDOWS\system32\mfps.dll
2016-10-13 20:42:03 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-10-13 20:42:02 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2016-10-05 18:24:47 ----AD---- C:\Program Files (x86)\Mozilla Thunderbird
2016-10-02 14:34:39 ----A---- C:\WINDOWS\SYSWOW64\LicenseManagerApi.dll
2016-10-02 14:34:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2016-10-02 14:34:38 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-10-02 14:34:37 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2016-10-02 14:34:37 ----A---- C:\WINDOWS\system32\mssrch.dll
2016-10-02 14:34:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.UXRes.dll
2016-10-02 14:34:34 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2016-10-02 14:34:34 ----A---- C:\WINDOWS\system32\tquery.dll
2016-10-02 14:34:33 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2016-10-02 14:34:33 ----A---- C:\WINDOWS\system32\ConsoleLogon.dll
2016-10-02 14:34:32 ----A---- C:\WINDOWS\system32\nettrace.dll
2016-10-02 14:34:31 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-10-02 14:34:31 ----A---- C:\WINDOWS\system32\usbmon.dll
2016-10-02 14:34:31 ----A---- C:\WINDOWS\system32\samsrv.dll
2016-10-02 14:34:30 ----A---- C:\WINDOWS\SYSWOW64\TempSignedLicenseExchangeTask.dll
2016-10-02 14:34:30 ----A---- C:\WINDOWS\system32\SpeechPal.dll
2016-10-02 14:34:30 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2016-10-02 14:34:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.CredDialogController.dll
2016-10-02 14:34:29 ----A---- C:\WINDOWS\system32\ci.dll
2016-10-02 14:34:28 ----A---- C:\WINDOWS\SYSWOW64\WSManHTTPConfig.exe
2016-10-02 14:34:28 ----A---- C:\WINDOWS\system32\mprdim.dll
2016-10-02 14:34:28 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2016-10-02 14:34:27 ----A---- C:\WINDOWS\SYSWOW64\mfksproxy.dll
2016-10-02 14:34:27 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-10-02 14:34:27 ----A---- C:\WINDOWS\system32\SessEnv.dll
2016-10-02 14:34:27 ----A---- C:\WINDOWS\system32\hal.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\wkssvc.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\offlinesam.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\LogonController.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\wmpps.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\webio.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2016-10-02 14:34:24 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2016-10-02 14:34:24 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2016-10-02 14:34:23 ----A---- C:\WINDOWS\system32\drivers\wcifs.sys
2016-10-02 14:34:22 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\SYSWOW64\devenum.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-10-02 14:34:21 ----A---- C:\WINDOWS\SYSWOW64\DolbyDecMFT.dll
2016-10-02 14:34:21 ----A---- C:\WINDOWS\system32\nshwfp.dll
2016-10-02 14:34:20 ----A---- C:\WINDOWS\system32\securekernel.exe
2016-10-02 14:34:20 ----A---- C:\WINDOWS\system32\rdpudd.dll
2016-10-02 14:34:20 ----A---- C:\WINDOWS\system32\profsvc.dll
2016-10-02 14:34:19 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2016-10-02 14:34:19 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2016-10-02 14:34:19 ----A---- C:\WINDOWS\system32\RDXService.dll
2016-10-02 14:34:17 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2016-10-02 14:34:17 ----A---- C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-10-02 14:34:16 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2016-10-02 14:34:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\system32\mssprxy.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\system32\lsm.dll
2016-10-02 14:34:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2016-10-02 14:34:12 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2016-10-02 14:34:12 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2016-10-02 14:34:11 ----A---- C:\WINDOWS\system32\puiobj.dll
2016-10-02 14:34:11 ----A---- C:\WINDOWS\system32\NetworkUXBroker.dll
2016-10-02 14:34:11 ----A---- C:\WINDOWS\system32\CastLaunch.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\imapi2.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\credprovslegacy.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\system32\Windows.Devices.Printers.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\system32\fhcfg.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\system32\credprovslegacy.dll
2016-10-02 14:34:09 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2016-10-02 14:34:09 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2016-10-02 14:34:08 ----A---- C:\WINDOWS\system32\sppsvc.exe
2016-10-02 14:33:56 ----A---- C:\WINDOWS\system32\sppobjs.dll
2016-10-02 14:33:56 ----A---- C:\WINDOWS\system32\MSAudDecMFT.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\reseteng.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-10-02 14:33:54 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-10-02 14:33:54 ----A---- C:\WINDOWS\system32\ClipUp.exe
2016-10-02 14:33:53 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-10-02 14:33:52 ----A---- C:\WINDOWS\system32\cdp.dll
2016-10-02 14:33:50 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-10-02 14:33:50 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-10-02 14:33:49 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2016-10-02 14:33:48 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2016-10-02 14:33:48 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2016-10-02 14:33:48 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-10-02 14:33:47 ----A---- C:\WINDOWS\system32\wsp_health.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\sppwinob.dll
2016-10-02 14:33:45 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-10-02 14:33:45 ----A---- C:\WINDOWS\system32\tdh.dll
2016-10-02 14:33:45 ----A---- C:\WINDOWS\system32\gpsvc.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\cdpsvc.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\bdesvc.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\NotificationController.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\devinv.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\cdpusersvc.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\resutils.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\localspl.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\SYSWOW64\pdh.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\sppcext.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\pdh.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\manage-bde.exe
2016-10-02 14:33:40 ----A---- C:\WINDOWS\SYSWOW64\mprdim.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\icsvc.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\discan.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\BootMenuUX.dll
2016-10-02 14:33:39 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-10-02 14:33:39 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2016-10-02 14:33:39 ----A---- C:\WINDOWS\system32\systemreset.exe
2016-10-02 14:33:39 ----A---- C:\WINDOWS\system32\ReAgent.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\system32\NfcRadioMedia.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\system32\AppContracts.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\SYSWOW64\offlinesam.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\system32\Sens.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\system32\fveui.dll
2016-10-02 14:33:35 ----A---- C:\WINDOWS\SYSWOW64\SndVolSSO.dll
2016-10-02 14:33:35 ----A---- C:\WINDOWS\system32\cmintegrator.dll
2016-10-02 14:33:35 ----A---- C:\WINDOWS\splwow64.exe
2016-10-02 14:33:34 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2016-10-02 14:33:34 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-10-02 14:33:34 ----A---- C:\WINDOWS\system32\VPNv2CSP.dll
2016-10-02 14:33:33 ----A---- C:\WINDOWS\SYSWOW64\wlancfg.dll
2016-10-02 14:33:33 ----A---- C:\WINDOWS\system32\fvenotify.exe
2016-10-02 14:33:33 ----A---- C:\WINDOWS\system32\bdeui.dll
2016-10-02 14:33:32 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2016-10-02 14:33:32 ----A---- C:\WINDOWS\SYSWOW64\CPFilters.dll
2016-10-02 14:33:32 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2016-10-02 14:33:31 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2016-10-02 14:33:31 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\SYSWOW64\sppcext.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\credprovhost.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\clusapi.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2016-10-02 14:33:28 ----A---- C:\WINDOWS\system32\Windows.Media.Ocr.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\system32\PrintWSDAHost.dll
2016-10-02 14:33:26 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-10-02 14:33:26 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-10-02 14:33:25 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2016-10-02 14:33:25 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2016-10-02 14:33:25 ----A---- C:\WINDOWS\system32\MSVPXENC.dll
2016-10-02 14:33:25 ----A---- C:\WINDOWS\system32\ffbroker.dll
2016-10-02 14:33:24 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2016-10-02 14:33:02 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-10-02 14:32:58 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-10-02 14:32:54 ----A---- C:\WINDOWS\system32\spaceman.exe
2016-10-02 14:32:54 ----A---- C:\WINDOWS\system32\mispace.dll
2016-10-02 14:32:53 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-10-02 14:32:53 ----A---- C:\WINDOWS\system32\storagewmi.dll
2016-10-02 14:32:53 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-10-02 14:32:53 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2016-10-02 14:32:52 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-10-02 14:32:52 ----A---- C:\WINDOWS\system32\qmgr.dll
2016-10-02 14:32:51 ----A---- C:\WINDOWS\SYSWOW64\MSAC3ENC.DLL
2016-10-02 14:32:51 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-10-02 14:32:51 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2016-10-02 14:32:50 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2016-10-02 14:32:50 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-10-02 14:32:49 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2016-10-02 14:32:49 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-10-02 14:32:48 ----A---- C:\WINDOWS\explorer.exe
2016-10-02 14:32:47 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-10-02 14:32:47 ----A---- C:\WINDOWS\system32\dsregcmd.exe
2016-10-02 14:32:46 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-10-02 14:32:45 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-10-02 14:32:43 ----A---- C:\WINDOWS\system32\rascustom.dll
2016-10-02 14:32:42 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2016-10-02 14:32:41 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2016-10-02 14:32:41 ----A---- C:\WINDOWS\system32\mfksproxy.dll
2016-10-02 14:32:41 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-10-02 14:32:41 ----A---- C:\WINDOWS\system32\drivers\stornvme.sys
2016-10-02 14:32:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\RMapi.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\dnsapi.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\system32\wintrust.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\system32\mprapi.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\system32\BthRadioMedia.dll
2016-10-02 14:32:37 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2016-10-02 14:32:37 ----A---- C:\WINDOWS\system32\LsaIso.exe
2016-10-02 14:32:37 ----A---- C:\WINDOWS\system32\drivers\cmimcext.sys
2016-10-02 14:32:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2016-10-02 14:32:36 ----A---- C:\WINDOWS\SYSWOW64\tsmf.dll
2016-10-02 14:32:36 ----A---- C:\WINDOWS\SYSWOW64\biwinrt.dll
2016-10-02 14:32:36 ----A---- C:\WINDOWS\system32\drivers\storahci.sys
2016-10-02 14:32:36 ----A---- C:\WINDOWS\system32\drivers\http.sys
2016-10-02 14:32:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2016-10-02 14:32:35 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2016-10-02 14:32:35 ----A---- C:\WINDOWS\system32\wpnapps.dll
2016-10-02 14:32:35 ----A---- C:\WINDOWS\system32\nltest.exe
2016-10-02 14:32:35 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-10-02 14:32:34 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2016-10-02 14:32:34 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-10-02 14:32:34 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\devenum.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\DataExchange.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\RelPost.exe
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\rasmans.dll
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\ieproxy.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\SYSWOW64\DataExchange.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\system32\drivers\winhvr.sys
2016-10-02 14:32:30 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\ngccredprov.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\BackgroundMediaPolicy.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\system32\setupugc.exe
2016-10-02 14:32:29 ----A---- C:\WINDOWS\system32\OneBackupHandler.dll
2016-10-02 14:32:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-10-02 14:32:28 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2016-10-02 14:32:28 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-10-02 14:32:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-10-02 14:32:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2016-10-02 14:32:27 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\easwrt.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\SYSWOW64\dlnashext.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\system32\bootux.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-10-02 14:32:22 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2016-10-02 14:32:22 ----A---- C:\WINDOWS\SYSWOW64\ngccredprov.dll
2016-10-02 14:32:22 ----A---- C:\WINDOWS\system32\AccountsRt.dll
2016-10-02 14:32:21 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-10-02 14:32:21 ----A---- C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2016-10-02 14:32:21 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\system32\NgcCtnr.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\system32\Family.Client.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\system32\imapi2.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\system32\Family.Authentication.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.UserDeviceAssociation.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.Energy.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\smphost.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\appinfo.dll
2016-10-02 14:32:16 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-10-02 14:32:16 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-10-02 14:32:11 ----A---- C:\WINDOWS\system32\windows.storage.dll
2016-10-02 14:32:09 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2016-10-02 14:32:06 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-10-02 14:32:04 ----A---- C:\WINDOWS\system32\d2d1.dll
2016-10-02 14:32:04 ----A---- C:\WINDOWS\system32\comsvcs.dll
2016-10-02 14:32:03 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2016-10-02 14:32:03 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2016-10-02 14:32:02 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2016-10-02 14:32:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
Predem moc dekuju.
Jakub
Poslední dobou se mi opakovaně někdo dobývá na nejrůznější účty od eBay přes Microsoft Live až po Instagram. Rád bych se vyhnul tomu, aby to priste byl PayPal nebo muj bankovni ucet, takze prosim o pomoc a nize zasilam log.
Kvuli omezeni v poctu znaku delim log do dvou postu.
PART 1
Logfile of random's system information tool 1.10 (written by random/random)
Run by jakub_000 at 2016-10-14 18:45:34
Microsoft Windows 10 Home
System drive C: has 195 GB (45%) free of 435 GB
Total RAM: 3979 MB (42% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:45:44, on 14.10.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal
Running processes:
C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Program Files\WindowsApps\Microsoft.BingNews_4.16.18.0_x86__8wekyb3d8bbwe\Microsoft.Msn.News.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\jakub_000.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com/?fr=vmn&type=vmn_ ... 0721__yaie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Web Companion] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
O4 - HKCU\..\RunOnce: [Application Restart #1] C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lavasofttcpservice.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem46.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\system32\ibtsiva (file missing)
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LavasoftTcpService - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Update service - Popcorn Time - C:\Program Files (x86)\Popcorn Time\Updater.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: WC Assistant (WCAssistantService) - Unknown owner - C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10458 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-51c7568e-ae54-4607-b2e0-874934e7240b -SystemEventPortName:HostProcess-46f4c2a0-166d-4cd7-b71a-e6dd5dcb3dae -IoCancelEventPortName:HostProcess-5d1964b2-6243-4b57-9fd8-61ed07b49fb2 -NonStateChangingEventPortName:HostProcess-61b3f90e-08f7-45cd-8bd8-4897eec17b74 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:661186c8-f8dc-4e37-a68b-4ef53ba44adf -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
dashost.exe {fed9b398-2348-4548-bd9738aded41f108}
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
C:\windows\system32\CxAudMsg64.exe
C:\WINDOWS\system32\ibtsiva
"C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\SysWoW64\SAsrv.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe"
"C:\Program Files (x86)\Popcorn Time\Updater.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe" /LOGON
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
igfxEM.exe
igfxHK.exe
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
igfxTray.exe
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe"
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.190.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Windows\RTFTrack.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe" --minimize
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\system32\wbem\wmiprvse.exe
"fontdrvhost.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/8/OneClickSignIn/BlueOnWhite/Prefetch/ContentPrefetchPrefetchOff/Prerender/Prerender15minTTL/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_81/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warm_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="3836.1.1024443234\776324117" /prefetch:3
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceStartMenuIndexer.exe"
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.BingNews_4.16.18.0_x86__8wekyb3d8bbwe\Microsoft.Msn.News.exe" -ServerName:AppexNews.AppX3vz52bd72d0ycrnwe6jysfgn7k1qcv00.mca
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\jakub_000\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=53.0.2785.116 --handshake-handle=0x258
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4992.0.44525305\1416093626" --mojo-application-channel-token=321C2DBD0BD2987A68CD4BC9B84D6D25 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,14,18,31,48,56 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.4276 --gpu-driver-date=8-17-2015 --mojo-platform-channel-handle=1504 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --primordial-pipe-token=5A24CA4906246D3F8973122C6D4C0C50 --lang=en-US --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=1A660821C4E03F47B5149900732F0148 --mojo-application-channel-token=5A24CA4906246D3F8973122C6D4C0C50 --channel="4992.3.111495788\1536492731" --mojo-platform-channel-handle=2848 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --primordial-pipe-token=EBCB50502C59B4D12882DED46D5ED7DF --lang=en-US --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=80D6A6C0C56EF95E898276B3A1CF2886 --mojo-application-channel-token=EBCB50502C59B4D12882DED46D5ED7DF --channel="4992.4.1526305422\987827380" --mojo-platform-channel-handle=2868 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Control/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=1343C0856C2F0F40B401082719A1D7F6 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=305F12738677E652C257E52E03855DA8 --mojo-application-channel-token=1343C0856C2F0F40B401082719A1D7F6 --channel="4992.6.385123217\1506753078" --mojo-platform-channel-handle=5948 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/*EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/*PluginPowerSaverTiny/Control/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=2921F4E6CBB41841FB67F0D5C25579A1 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=B6877D2A1ABFB83B069CC4CDFD108D7B --mojo-application-channel-token=2921F4E6CBB41841FB67F0D5C25579A1 --channel="4992.9.130941466\1490554698" --mojo-platform-channel-handle=3472 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=BlockSmallPluginContent<PluginPowerSaverTiny,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/*EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Control/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/*PluginPowerSaverTiny/Control/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_02/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=84C4A97C6D66104EDA93A90C5BB404D1 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=B1A5ECDC7FBCEA22D74305E83BE6ABFB --mojo-application-channel-token=84C4A97C6D66104EDA93A90C5BB404D1 --channel="4992.10.610404179\1070442513" --mojo-platform-channel-handle=7484 /prefetch:1
C:\WINDOWS\system32\AUDIODG.EXE 0x3b0
C:\Windows\System32\smartscreen.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 620 648 656 8192 652
"C:\Users\jakub_000\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2014-02-27 6340312]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-09-05 907480]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2012-06-13 1647616]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2014-09-20 16094704]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2014-09-20 10841584]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-07-27 3945672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-09-25 633024]
"Web Companion"=C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [2016-10-08 1790616]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\jakub_000\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"=C:\WINDOWS\system32\cmd.exe [2016-07-16 232960]
"Application Restart #1"=C:\Users\jakub_000\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [2016-09-18 7874024]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-08-08 8900328]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-10-14 18:45:34 ----D---- C:\rsit
2016-10-14 18:45:34 ----D---- C:\Program Files\trend micro
2016-10-13 20:43:43 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2016-10-13 20:43:42 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2016-10-13 20:43:41 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\dsreg.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-13 20:43:40 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\dsreg.dll
2016-10-13 20:43:39 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2016-10-13 20:43:38 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-10-13 20:43:37 ----A---- C:\WINDOWS\system32\netshell.dll
2016-10-13 20:43:37 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-10-13 20:43:37 ----A---- C:\WINDOWS\system32\msdtctm.dll
2016-10-13 20:43:36 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2016-10-13 20:43:35 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-10-13 20:43:33 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-10-13 20:43:33 ----A---- C:\WINDOWS\system32\wpncore.dll
2016-10-13 20:43:32 ----A---- C:\WINDOWS\system32\wpx.dll
2016-10-13 20:43:32 ----A---- C:\WINDOWS\system32\ncsi.dll
2016-10-13 20:43:32 ----A---- C:\WINDOWS\system32\inetcomm.dll
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\nlasvc.dll
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\credprovs.dll
2016-10-13 20:43:31 ----A---- C:\WINDOWS\system32\bcdedit.exe
2016-10-13 20:43:30 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-10-13 20:43:30 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-10-13 20:43:30 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-10-13 20:43:29 ----A---- C:\WINDOWS\system32\wininet.dll
2016-10-13 20:43:29 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2016-10-13 20:43:28 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-10-13 20:43:28 ----A---- C:\WINDOWS\system32\DWrite.dll
2016-10-13 20:43:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-10-13 20:43:25 ----A---- C:\WINDOWS\system32\shell32.dll
2016-10-13 20:43:24 ----A---- C:\WINDOWS\SYSWOW64\dialclient.dll
2016-10-13 20:43:23 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2016-10-13 20:43:23 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-10-13 20:43:19 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-10-13 20:43:18 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-10-13 20:43:17 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2016-10-13 20:43:17 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-10-13 20:43:16 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2016-10-13 20:43:15 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-10-13 20:43:15 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-10-13 20:43:14 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-10-13 20:43:14 ----A---- C:\WINDOWS\system32\aadtb.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2016-10-13 20:43:13 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-10-13 20:43:12 ----A---- C:\WINDOWS\system32\smartscreen.exe
2016-10-13 20:43:12 ----A---- C:\WINDOWS\system32\drivers\MegaSas2i.sys
2016-10-13 20:43:11 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-10-13 20:43:10 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-10-13 20:43:10 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-10-13 20:43:09 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2016-10-13 20:43:09 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2016-10-13 20:43:08 ----A---- C:\WINDOWS\SYSWOW64\offreg.dll
2016-10-13 20:43:08 ----A---- C:\WINDOWS\SYSWOW64\credprovs.dll
2016-10-13 20:43:08 ----A---- C:\WINDOWS\system32\adsmsext.dll
2016-10-13 20:43:06 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\efswrt.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\dialclient.dll
2016-10-13 20:43:05 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-13 20:43:04 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-10-13 20:43:04 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-10-13 20:43:04 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2016-10-13 20:43:03 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-13 20:43:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-10-13 20:43:02 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-13 20:43:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-10-13 20:43:01 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-10-13 20:43:01 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2016-10-13 20:42:56 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-13 20:42:56 ----A---- C:\WINDOWS\system32\wc_storage.dll
2016-10-13 20:42:56 ----A---- C:\WINDOWS\system32\daxexec.dll
2016-10-13 20:42:54 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-10-13 20:42:50 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-10-13 20:42:48 ----A---- C:\WINDOWS\system32\wbiosrvc.dll
2016-10-13 20:42:47 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-10-13 20:42:47 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-10-13 20:42:43 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2016-10-13 20:42:43 ----A---- C:\WINDOWS\system32\mfsensorgroup.dll
2016-10-13 20:42:42 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-10-13 20:42:42 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-10-13 20:42:42 ----A---- C:\WINDOWS\system32\FrameServer.dll
2016-10-13 20:42:41 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-10-13 20:42:40 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-10-13 20:42:39 ----A---- C:\WINDOWS\system32\wmp.dll
2016-10-13 20:42:38 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-10-13 20:42:38 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2016-10-13 20:42:37 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2016-10-13 20:42:36 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2016-10-13 20:42:35 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-10-13 20:42:34 ----A---- C:\WINDOWS\system32\winresume.exe
2016-10-13 20:42:34 ----A---- C:\WINDOWS\system32\winload.exe
2016-10-13 20:42:33 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\GamePanel.exe
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\apprepsync.dll
2016-10-13 20:42:32 ----A---- C:\WINDOWS\system32\apprepapi.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-10-13 20:42:31 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-10-13 20:42:30 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2016-10-13 20:42:30 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-13 20:42:29 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2016-10-13 20:42:29 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2016-10-13 20:42:28 ----A---- C:\WINDOWS\SYSWOW64\MSVidCtl.dll
2016-10-13 20:42:28 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-10-13 20:42:28 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2016-10-13 20:42:27 ----A---- C:\WINDOWS\SYSWOW64\ConfigureExpandedStorage.dll
2016-10-13 20:42:27 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2016-10-13 20:42:27 ----A---- C:\WINDOWS\system32\offreg.dll
2016-10-13 20:42:27 ----A---- C:\WINDOWS\system32\drivers\tm.sys
2016-10-13 20:42:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2016-10-13 20:42:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2016-10-13 20:42:26 ----A---- C:\WINDOWS\system32\msi.dll
2016-10-13 20:42:26 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-10-13 20:42:25 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-10-13 20:42:24 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\ChatApis.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\EmailApis.dll
2016-10-13 20:42:23 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\SYSWOW64\mfsensorgroup.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\ContactApis.dll
2016-10-13 20:42:22 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-10-13 20:42:21 ----A---- C:\WINDOWS\system32\mspaint.exe
2016-10-13 20:42:20 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-13 20:42:20 ----A---- C:\WINDOWS\system32\win32spl.dll
2016-10-13 20:42:19 ----A---- C:\WINDOWS\system32\FntCache.dll
2016-10-13 20:42:18 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-13 20:42:18 ----A---- C:\WINDOWS\system32\ShareHost.dll
2016-10-13 20:42:17 ----A---- C:\WINDOWS\system32\twinui.dll
2016-10-13 20:42:13 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-13 20:42:12 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-10-13 20:42:12 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-10-13 20:42:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2016-10-13 20:42:07 ----A---- C:\WINDOWS\system32\mos.dll
2016-10-13 20:42:06 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-10-13 20:42:06 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-10-13 20:42:05 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-10-13 20:42:05 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-10-13 20:42:04 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2016-10-13 20:42:04 ----A---- C:\WINDOWS\system32\cloudAP.dll
2016-10-13 20:42:03 ----A---- C:\WINDOWS\SYSWOW64\adsmsext.dll
2016-10-13 20:42:03 ----A---- C:\WINDOWS\system32\mfps.dll
2016-10-13 20:42:03 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-10-13 20:42:02 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2016-10-05 18:24:47 ----AD---- C:\Program Files (x86)\Mozilla Thunderbird
2016-10-02 14:34:39 ----A---- C:\WINDOWS\SYSWOW64\LicenseManagerApi.dll
2016-10-02 14:34:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2016-10-02 14:34:38 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-10-02 14:34:37 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2016-10-02 14:34:37 ----A---- C:\WINDOWS\system32\mssrch.dll
2016-10-02 14:34:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.UXRes.dll
2016-10-02 14:34:34 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2016-10-02 14:34:34 ----A---- C:\WINDOWS\system32\tquery.dll
2016-10-02 14:34:33 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2016-10-02 14:34:33 ----A---- C:\WINDOWS\system32\ConsoleLogon.dll
2016-10-02 14:34:32 ----A---- C:\WINDOWS\system32\nettrace.dll
2016-10-02 14:34:31 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-10-02 14:34:31 ----A---- C:\WINDOWS\system32\usbmon.dll
2016-10-02 14:34:31 ----A---- C:\WINDOWS\system32\samsrv.dll
2016-10-02 14:34:30 ----A---- C:\WINDOWS\SYSWOW64\TempSignedLicenseExchangeTask.dll
2016-10-02 14:34:30 ----A---- C:\WINDOWS\system32\SpeechPal.dll
2016-10-02 14:34:30 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2016-10-02 14:34:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.CredDialogController.dll
2016-10-02 14:34:29 ----A---- C:\WINDOWS\system32\ci.dll
2016-10-02 14:34:28 ----A---- C:\WINDOWS\SYSWOW64\WSManHTTPConfig.exe
2016-10-02 14:34:28 ----A---- C:\WINDOWS\system32\mprdim.dll
2016-10-02 14:34:28 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2016-10-02 14:34:27 ----A---- C:\WINDOWS\SYSWOW64\mfksproxy.dll
2016-10-02 14:34:27 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-10-02 14:34:27 ----A---- C:\WINDOWS\system32\SessEnv.dll
2016-10-02 14:34:27 ----A---- C:\WINDOWS\system32\hal.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\wkssvc.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\offlinesam.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\LogonController.dll
2016-10-02 14:34:26 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\wmpps.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\webio.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-10-02 14:34:25 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2016-10-02 14:34:24 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2016-10-02 14:34:24 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2016-10-02 14:34:23 ----A---- C:\WINDOWS\system32\drivers\wcifs.sys
2016-10-02 14:34:22 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\SYSWOW64\devenum.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2016-10-02 14:34:22 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-10-02 14:34:21 ----A---- C:\WINDOWS\SYSWOW64\DolbyDecMFT.dll
2016-10-02 14:34:21 ----A---- C:\WINDOWS\system32\nshwfp.dll
2016-10-02 14:34:20 ----A---- C:\WINDOWS\system32\securekernel.exe
2016-10-02 14:34:20 ----A---- C:\WINDOWS\system32\rdpudd.dll
2016-10-02 14:34:20 ----A---- C:\WINDOWS\system32\profsvc.dll
2016-10-02 14:34:19 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2016-10-02 14:34:19 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2016-10-02 14:34:19 ----A---- C:\WINDOWS\system32\RDXService.dll
2016-10-02 14:34:17 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2016-10-02 14:34:17 ----A---- C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-10-02 14:34:16 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2016-10-02 14:34:15 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2016-10-02 14:34:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\system32\mssprxy.dll
2016-10-02 14:34:14 ----A---- C:\WINDOWS\system32\lsm.dll
2016-10-02 14:34:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2016-10-02 14:34:12 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2016-10-02 14:34:12 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2016-10-02 14:34:11 ----A---- C:\WINDOWS\system32\puiobj.dll
2016-10-02 14:34:11 ----A---- C:\WINDOWS\system32\NetworkUXBroker.dll
2016-10-02 14:34:11 ----A---- C:\WINDOWS\system32\CastLaunch.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\imapi2.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\credprovslegacy.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\system32\Windows.Devices.Printers.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\system32\fhcfg.dll
2016-10-02 14:34:10 ----A---- C:\WINDOWS\system32\credprovslegacy.dll
2016-10-02 14:34:09 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2016-10-02 14:34:09 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2016-10-02 14:34:08 ----A---- C:\WINDOWS\system32\sppsvc.exe
2016-10-02 14:33:56 ----A---- C:\WINDOWS\system32\sppobjs.dll
2016-10-02 14:33:56 ----A---- C:\WINDOWS\system32\MSAudDecMFT.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\reseteng.dll
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-02 14:33:55 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-10-02 14:33:54 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-10-02 14:33:54 ----A---- C:\WINDOWS\system32\ClipUp.exe
2016-10-02 14:33:53 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-10-02 14:33:52 ----A---- C:\WINDOWS\system32\cdp.dll
2016-10-02 14:33:50 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-10-02 14:33:50 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-10-02 14:33:49 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2016-10-02 14:33:48 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2016-10-02 14:33:48 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2016-10-02 14:33:48 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-10-02 14:33:47 ----A---- C:\WINDOWS\system32\wsp_health.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2016-10-02 14:33:46 ----A---- C:\WINDOWS\system32\sppwinob.dll
2016-10-02 14:33:45 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-10-02 14:33:45 ----A---- C:\WINDOWS\system32\tdh.dll
2016-10-02 14:33:45 ----A---- C:\WINDOWS\system32\gpsvc.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\cdpsvc.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\bdesvc.dll
2016-10-02 14:33:44 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\NotificationController.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\devinv.dll
2016-10-02 14:33:43 ----A---- C:\WINDOWS\system32\cdpusersvc.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\resutils.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-10-02 14:33:42 ----A---- C:\WINDOWS\system32\localspl.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\SYSWOW64\pdh.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\sppcext.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\pdh.dll
2016-10-02 14:33:41 ----A---- C:\WINDOWS\system32\manage-bde.exe
2016-10-02 14:33:40 ----A---- C:\WINDOWS\SYSWOW64\mprdim.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\icsvc.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\discan.dll
2016-10-02 14:33:40 ----A---- C:\WINDOWS\system32\BootMenuUX.dll
2016-10-02 14:33:39 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-10-02 14:33:39 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2016-10-02 14:33:39 ----A---- C:\WINDOWS\system32\systemreset.exe
2016-10-02 14:33:39 ----A---- C:\WINDOWS\system32\ReAgent.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\system32\NfcRadioMedia.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\system32\AppContracts.dll
2016-10-02 14:33:38 ----A---- C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\SYSWOW64\offlinesam.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2016-10-02 14:33:37 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\system32\Sens.dll
2016-10-02 14:33:36 ----A---- C:\WINDOWS\system32\fveui.dll
2016-10-02 14:33:35 ----A---- C:\WINDOWS\SYSWOW64\SndVolSSO.dll
2016-10-02 14:33:35 ----A---- C:\WINDOWS\system32\cmintegrator.dll
2016-10-02 14:33:35 ----A---- C:\WINDOWS\splwow64.exe
2016-10-02 14:33:34 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2016-10-02 14:33:34 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-10-02 14:33:34 ----A---- C:\WINDOWS\system32\VPNv2CSP.dll
2016-10-02 14:33:33 ----A---- C:\WINDOWS\SYSWOW64\wlancfg.dll
2016-10-02 14:33:33 ----A---- C:\WINDOWS\system32\fvenotify.exe
2016-10-02 14:33:33 ----A---- C:\WINDOWS\system32\bdeui.dll
2016-10-02 14:33:32 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2016-10-02 14:33:32 ----A---- C:\WINDOWS\SYSWOW64\CPFilters.dll
2016-10-02 14:33:32 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2016-10-02 14:33:31 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2016-10-02 14:33:31 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\SYSWOW64\sppcext.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2016-10-02 14:33:30 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\credprovhost.dll
2016-10-02 14:33:29 ----A---- C:\WINDOWS\system32\clusapi.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2016-10-02 14:33:28 ----A---- C:\WINDOWS\system32\Windows.Media.Ocr.dll
2016-10-02 14:33:28 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-10-02 14:33:27 ----A---- C:\WINDOWS\system32\PrintWSDAHost.dll
2016-10-02 14:33:26 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-10-02 14:33:26 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-10-02 14:33:25 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2016-10-02 14:33:25 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2016-10-02 14:33:25 ----A---- C:\WINDOWS\system32\MSVPXENC.dll
2016-10-02 14:33:25 ----A---- C:\WINDOWS\system32\ffbroker.dll
2016-10-02 14:33:24 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2016-10-02 14:33:02 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-10-02 14:32:58 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-10-02 14:32:54 ----A---- C:\WINDOWS\system32\spaceman.exe
2016-10-02 14:32:54 ----A---- C:\WINDOWS\system32\mispace.dll
2016-10-02 14:32:53 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-10-02 14:32:53 ----A---- C:\WINDOWS\system32\storagewmi.dll
2016-10-02 14:32:53 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-10-02 14:32:53 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2016-10-02 14:32:52 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-10-02 14:32:52 ----A---- C:\WINDOWS\system32\qmgr.dll
2016-10-02 14:32:51 ----A---- C:\WINDOWS\SYSWOW64\MSAC3ENC.DLL
2016-10-02 14:32:51 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2016-10-02 14:32:51 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2016-10-02 14:32:50 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2016-10-02 14:32:50 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-10-02 14:32:49 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2016-10-02 14:32:49 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-10-02 14:32:48 ----A---- C:\WINDOWS\explorer.exe
2016-10-02 14:32:47 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-10-02 14:32:47 ----A---- C:\WINDOWS\system32\dsregcmd.exe
2016-10-02 14:32:46 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-10-02 14:32:45 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-10-02 14:32:43 ----A---- C:\WINDOWS\system32\rascustom.dll
2016-10-02 14:32:42 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2016-10-02 14:32:41 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2016-10-02 14:32:41 ----A---- C:\WINDOWS\system32\mfksproxy.dll
2016-10-02 14:32:41 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-10-02 14:32:41 ----A---- C:\WINDOWS\system32\drivers\stornvme.sys
2016-10-02 14:32:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\RMapi.dll
2016-10-02 14:32:40 ----A---- C:\WINDOWS\system32\dnsapi.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\system32\wintrust.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-10-02 14:32:39 ----A---- C:\WINDOWS\system32\mprapi.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-10-02 14:32:38 ----A---- C:\WINDOWS\system32\BthRadioMedia.dll
2016-10-02 14:32:37 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2016-10-02 14:32:37 ----A---- C:\WINDOWS\system32\LsaIso.exe
2016-10-02 14:32:37 ----A---- C:\WINDOWS\system32\drivers\cmimcext.sys
2016-10-02 14:32:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2016-10-02 14:32:36 ----A---- C:\WINDOWS\SYSWOW64\tsmf.dll
2016-10-02 14:32:36 ----A---- C:\WINDOWS\SYSWOW64\biwinrt.dll
2016-10-02 14:32:36 ----A---- C:\WINDOWS\system32\drivers\storahci.sys
2016-10-02 14:32:36 ----A---- C:\WINDOWS\system32\drivers\http.sys
2016-10-02 14:32:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2016-10-02 14:32:35 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2016-10-02 14:32:35 ----A---- C:\WINDOWS\system32\wpnapps.dll
2016-10-02 14:32:35 ----A---- C:\WINDOWS\system32\nltest.exe
2016-10-02 14:32:35 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-10-02 14:32:34 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2016-10-02 14:32:34 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-10-02 14:32:34 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\devenum.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\DataExchange.dll
2016-10-02 14:32:33 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\RelPost.exe
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\rasmans.dll
2016-10-02 14:32:32 ----A---- C:\WINDOWS\system32\ieproxy.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\SYSWOW64\DataExchange.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2016-10-02 14:32:31 ----A---- C:\WINDOWS\system32\drivers\winhvr.sys
2016-10-02 14:32:30 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\ngccredprov.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2016-10-02 14:32:30 ----A---- C:\WINDOWS\system32\BackgroundMediaPolicy.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2016-10-02 14:32:29 ----A---- C:\WINDOWS\system32\setupugc.exe
2016-10-02 14:32:29 ----A---- C:\WINDOWS\system32\OneBackupHandler.dll
2016-10-02 14:32:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-10-02 14:32:28 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2016-10-02 14:32:28 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-10-02 14:32:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-10-02 14:32:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2016-10-02 14:32:27 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2016-10-02 14:32:26 ----A---- C:\WINDOWS\system32\easwrt.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-10-02 14:32:25 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\SYSWOW64\dlnashext.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2016-10-02 14:32:24 ----A---- C:\WINDOWS\system32\bootux.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2016-10-02 14:32:23 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-10-02 14:32:22 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2016-10-02 14:32:22 ----A---- C:\WINDOWS\SYSWOW64\ngccredprov.dll
2016-10-02 14:32:22 ----A---- C:\WINDOWS\system32\AccountsRt.dll
2016-10-02 14:32:21 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-10-02 14:32:21 ----A---- C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2016-10-02 14:32:21 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\system32\NgcCtnr.dll
2016-10-02 14:32:20 ----A---- C:\WINDOWS\system32\Family.Client.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\system32\imapi2.dll
2016-10-02 14:32:19 ----A---- C:\WINDOWS\system32\Family.Authentication.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.UserDeviceAssociation.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.Energy.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\smphost.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-10-02 14:32:18 ----A---- C:\WINDOWS\system32\appinfo.dll
2016-10-02 14:32:16 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-10-02 14:32:16 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-10-02 14:32:11 ----A---- C:\WINDOWS\system32\windows.storage.dll
2016-10-02 14:32:09 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2016-10-02 14:32:06 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-10-02 14:32:04 ----A---- C:\WINDOWS\system32\d2d1.dll
2016-10-02 14:32:04 ----A---- C:\WINDOWS\system32\comsvcs.dll
2016-10-02 14:32:03 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2016-10-02 14:32:03 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2016-10-02 14:32:02 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2016-10-02 14:32:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
Predem moc dekuju.
Jakub