Při spuštění počítače se spouští PowerShell okno
Napsal: 28 lis 2016 17:20
Zdravím. Při spuštění počítače se mi spouští okno PowerShellu, které chvíli na mě bliká textovým kurzorem, nejde do něj psát, po pár minutách se zase zavře. Mám podezření ma virus, Eset Online Scanner jich našel 6 (mezi instalačkama, pravděpodobně PUP). Ten ale před koncem skenu neočekávaně spadl
Co může toto okno PowerShellu vyvolávat? Předtím se neukazovalo.
Logfile of random's system information tool 1.10 (written by random/random)
Run by nimrod at 2016-11-28 17:14:48
Microsoft Windows 10 Home
System drive C: has 622 GB (66%) free of 937 GB
Total RAM: 3288 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:15:07, on 28. 11. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe
C:\Users\nimrod\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\nimrod\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Users\nimrod\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Users\nimrod\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\nimrod.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com/?pc=ACJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: ::1 wp-dev
O1 - Hosts: ::1 utilities
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
O4 - HKLM\..\Run: [PlaysTV] "C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe" --startup
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=av
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKCU\..\Run: [OneDrive] "C:\Users\nimrod\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_D666053EBBCBECDDF302E5B8C0D21F88] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [Xvid] powershell.exe -nologo -WindowStyle hidden -Noninteractive -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files (x86)\Xvid\CheckUpdate.ps1"
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgamps.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
O23 - Service: Xamarin Bonjour Service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Xamarin\Bonjour\mDNSResponder.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater40.3.6 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.6\ToolbarUpdater.exe
O23 - Service: wampapache64 - Apache Software Foundation - c:\wamp64\bin\apache\apache2.4.23\bin\httpd.exe
O23 - Service: wampmysqld64 - Unknown owner - c:\wamp64\bin\mysql\mysql5.7.14\bin\mysqld.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
--
End of file - 11267 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AVG Driver Updater Scan.job - C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe scheduled
C:\WINDOWS\tasks\AVG Driver Updater Startup.job - C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe -boot
C:\WINDOWS\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-09-13 163528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Web TuneUp - C:\Program Files (x86)\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll [2016-09-30 2260040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2016-10-11 1743664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22 755392]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvgUi"=C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [2016-09-13 218896]
"vProt"=C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2016-09-30 2180680]
"PlaysTV"=C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [2016-08-09 71440]
"AVG_UI"=C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [2016-09-13 218896]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2016-11-07 25673776]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\nimrod\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-09-30 633024]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-11-15 9105112]
"GoogleChromeAutoLaunch_D666053EBBCBECDDF302E5B8C0D21F88"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2016-09-14 967496]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2016-10-12 23818712]
"Xvid"=powershell.exe -nologo -WindowStyle hidden -Noninteractive -NoProfile -ExecutionPolicy Bypass -File C:\Program Files (x86)\Xvid\CheckUpdate.ps1 []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\abdocs.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acerportal.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\carecenter.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\epowerui.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\playstv_launcher.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\quickaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setting.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=l3codecp.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.cvid"=iccvid.dll
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.zmbv"=zmbv.dll
"vidc.ffds"=C:\Program Files (x86)\ffdshow\ffdshow.ax
"vidc.XVID"=xvidvfw.dll
"vidc.x264"=x264vfw.dll
======File associations======
.inf - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
.inf - install -
.ini - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
.js - edit -
.js - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
======List of files/folders created in the last 1 month======
2016-11-28 17:14:50 ----D---- C:\Program Files (x86)\trend micro
2016-11-28 17:14:48 ----D---- C:\rsit
2016-11-26 11:07:10 ----D---- C:\WINDOWS\Panther
2016-11-19 14:31:33 ----D---- C:\ProgramData\Avg_Update_1116sp
2016-11-18 10:53:10 ----D---- C:\ProgramData\Avg_Update_1116tb
2016-11-17 12:05:38 ----D---- C:\Program Files (x86)\x264vfw
2016-11-16 14:52:06 ----A---- C:\WINDOWS\SysWoW64\xvidvfw.dll
2016-11-16 14:52:06 ----A---- C:\WINDOWS\SysWoW64\xvidcore.dll
2016-11-16 14:52:01 ----AD---- C:\Program Files (x86)\Xvid
2016-11-15 21:16:17 ----D---- C:\Program Files (x86)\VirtualDub
2016-11-15 20:53:34 ----D---- C:\videodvdmaker
2016-11-15 20:53:34 ----D---- C:\Users\nimrod\AppData\Roaming\Video DVD Maker FREE
2016-11-14 15:43:28 ----D---- C:\Users\nimrod\AppData\Roaming\vlc
2016-11-14 15:27:02 ----D---- C:\Program Files (x86)\VideoLAN
2016-11-14 15:20:05 ----D---- C:\Program Files (x86)\ffdshow
2016-11-14 15:08:33 ----D---- C:\Users\nimrod\AppData\Roaming\Subtitle Edit
2016-11-14 15:08:33 ----AD---- C:\Program Files (x86)\Subtitle Edit
2016-11-14 13:37:33 ----D---- C:\Users\nimrod\AppData\Roaming\FontForge
2016-11-14 13:35:56 ----AD---- C:\Program Files (x86)\FontForgeBuilds
2016-11-14 13:29:18 ----HD---- C:\Program Files (x86)\InstallJammer Registry
2016-11-14 13:28:32 ----AD---- C:\Program Files (x86)\MidiEditor
2016-11-12 14:53:19 ----D---- C:\Users\nimrod\AppData\Roaming\Brief
2016-11-12 14:47:57 ----AD---- C:\Program Files (x86)\Brief
2016-11-10 17:41:27 ----A---- C:\WINDOWS\SysWoW64\openglv5.dll
2016-11-10 17:41:26 ----A---- C:\WINDOWS\SysWoW64\openglv3.dll
2016-11-09 22:11:14 ----AD---- C:\Program Files (x86)\Lame For Audacity
2016-11-09 22:10:55 ----AD---- C:\Program Files (x86)\FFmpeg for Audacity
2016-11-09 22:02:52 ----AD---- C:\Program Files (x86)\Audacity
2016-11-09 11:54:07 ----A---- C:\WINDOWS\SysWoW64\usercpl.dll
2016-11-09 11:54:07 ----A---- C:\WINDOWS\SysWoW64\themecpl.dll
2016-11-09 11:54:07 ----A---- C:\WINDOWS\SysWoW64\input.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\TSpkg.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\sud.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\stobject.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\mstscax.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\msctf.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\comctl32.dll
2016-11-09 11:54:03 ----A---- C:\WINDOWS\SysWoW64\olepro32.dll
2016-11-09 11:54:03 ----A---- C:\WINDOWS\SysWoW64\asycfilt.dll
2016-11-09 11:54:00 ----A---- C:\WINDOWS\SysWoW64\inetcomm.dll
2016-11-09 11:53:56 ----A---- C:\WINDOWS\SysWoW64\iertutil.dll
2016-11-09 11:53:55 ----A---- C:\WINDOWS\SysWoW64\ieproxy.dll
2016-11-09 11:53:55 ----A---- C:\WINDOWS\SysWoW64\ieapfltr.dll
2016-11-09 11:53:54 ----A---- C:\WINDOWS\SysWoW64\wininet.dll
2016-11-09 11:53:50 ----A---- C:\WINDOWS\SysWoW64\wininetlui.dll
2016-11-09 11:53:50 ----A---- C:\WINDOWS\SysWoW64\urlmon.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\VSD3DWARPDebug.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\hgcpl.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\ddraw.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\d3d9.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\d3d8.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\d3d12warp.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\ActionCenterCPL.dll
2016-11-09 11:53:48 ----A---- C:\WINDOWS\SysWoW64\VSD3DWARP12Debug.dll
2016-11-09 11:53:48 ----A---- C:\WINDOWS\SysWoW64\DevicePairing.dll
2016-11-09 11:53:45 ----A---- C:\WINDOWS\SysWoW64\comdlg32.dll
2016-11-09 11:53:42 ----A---- C:\WINDOWS\SysWoW64\AuthExt.dll
2016-11-09 11:53:39 ----A---- C:\WINDOWS\SysWoW64\authui.dll
2016-11-09 11:53:38 ----A---- C:\WINDOWS\SysWoW64\Windows.Media.Protection.PlayReady.dll
2016-11-09 11:53:35 ----A---- C:\WINDOWS\SysWoW64\zipfldr.dll
2016-11-09 11:53:33 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Immersive.dll
2016-11-09 11:53:32 ----A---- C:\WINDOWS\SysWoW64\win32kfull.sys
2016-11-09 11:53:32 ----A---- C:\WINDOWS\SysWoW64\win32k.sys
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\UIAnimation.dll
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\StoreAgent.dll
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\MSVidCtl.dll
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\InstallAgentUserBroker.exe
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\InstallAgent.exe
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Search.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Logon.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Cred.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.BlockedShutdown.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.BioFeedback.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.Shell.Search.UriHandler.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\twinui.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\LaunchWinApp.exe
2016-11-09 11:53:27 ----A---- C:\WINDOWS\SysWoW64\twinapi.dll
2016-11-09 11:53:27 ----A---- C:\WINDOWS\SysWoW64\rdpcore.dll
2016-11-09 11:53:27 ----A---- C:\WINDOWS\SysWoW64\mstsc.exe
2016-11-09 11:53:26 ----A---- C:\WINDOWS\SysWoW64\shell32.dll
2016-11-09 11:53:26 ----A---- C:\WINDOWS\SysWoW64\msv1_0.dll
2016-11-09 11:53:26 ----A---- C:\WINDOWS\SysWoW64\jscript9diag.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\Windows.Security.Authentication.OnlineId.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\jscript9.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\Chakradiag.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\Chakra.dll
2016-11-09 11:53:19 ----A---- C:\WINDOWS\SysWoW64\oleaut32.dll
2016-11-09 11:53:19 ----A---- C:\WINDOWS\SysWoW64\ntshrui.dll
2016-11-09 11:53:19 ----A---- C:\WINDOWS\SysWoW64\ntdll.dll
2016-11-09 11:53:16 ----A---- C:\WINDOWS\SysWoW64\NetSetupEngine.dll
2016-11-09 11:53:16 ----A---- C:\WINDOWS\SysWoW64\NetSetupApi.dll
2016-11-09 11:53:14 ----A---- C:\WINDOWS\SysWoW64\NPSM.dll
2016-11-09 11:53:13 ----A---- C:\WINDOWS\SysWoW64\msinfo32.exe
2016-11-09 11:53:13 ----A---- C:\WINDOWS\SysWoW64\mfcore.dll
2016-11-09 11:53:12 ----A---- C:\WINDOWS\SysWoW64\wmp.dll
2016-11-09 11:53:11 ----A---- C:\WINDOWS\SysWoW64\mfsvr.dll
2016-11-09 11:53:11 ----A---- C:\WINDOWS\SysWoW64\mfsensorgroup.dll
2016-11-09 11:53:10 ----A---- C:\WINDOWS\SysWoW64\MFMediaEngine.dll
2016-11-09 11:53:10 ----A---- C:\WINDOWS\SysWoW64\FSClient.dll
2016-11-09 11:53:09 ----A---- C:\WINDOWS\SysWoW64\LockAppBroker.dll
2016-11-09 11:53:04 ----A---- C:\WINDOWS\SysWoW64\ieframe.dll
2016-11-09 11:53:01 ----A---- C:\WINDOWS\SysWoW64\indexeddbserver.dll
2016-11-09 11:53:00 ----A---- C:\WINDOWS\SysWoW64\mshtmled.dll
2016-11-09 11:53:00 ----A---- C:\WINDOWS\SysWoW64\edgehtml.dll
2016-11-09 11:53:00 ----A---- C:\WINDOWS\SysWoW64\dxtrans.dll
2016-11-09 11:52:59 ----A---- C:\WINDOWS\SysWoW64\iepeers.dll
2016-11-09 11:52:58 ----A---- C:\WINDOWS\SysWoW64\mshtml.dll
2016-11-09 11:52:51 ----A---- C:\WINDOWS\SysWoW64\Windows.Globalization.dll
2016-11-09 11:52:51 ----A---- C:\WINDOWS\SysWoW64\GlobCollationHost.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\gdi32full.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\gameux.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\fontdrvhost.exe
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\atmlib.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\atmfd.dll
2016-11-09 11:52:49 ----A---- C:\WINDOWS\SysWoW64\fontext.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\weretw.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\wer.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\ExplorerFrame.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\explorer.exe
2016-11-09 11:52:47 ----A---- C:\WINDOWS\SysWoW64\efsext.dll
2016-11-09 11:52:46 ----A---- C:\WINDOWS\SysWoW64\d3d10warp.dll
2016-11-09 11:52:45 ----A---- C:\WINDOWS\SysWoW64\Windows.Devices.HumanInterfaceDevice.dll
2016-11-09 11:52:43 ----A---- C:\WINDOWS\SysWoW64\ole32.dll
2016-11-09 11:52:43 ----A---- C:\WINDOWS\SysWoW64\chartv.dll
2016-11-09 11:52:43 ----A---- C:\WINDOWS\SysWoW64\cdp.dll
2016-11-09 11:52:42 ----A---- C:\WINDOWS\SysWoW64\AudioSes.dll
2016-11-09 11:52:41 ----A---- C:\WINDOWS\SysWoW64\Windows.ApplicationModel.LockScreen.dll
2016-11-09 11:52:40 ----A---- C:\WINDOWS\SysWoW64\BcastDVRHelper.dll
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\ErrorDetailsUpdate.dll
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\ErrorDetails.dll
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\bcastdvr.exe
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\AppCapture.dll
2016-11-09 11:43:33 ----A---- C:\WINDOWS\explorer.exe
2016-11-08 13:49:21 ----D---- C:\Games
2016-11-08 13:46:03 ----D---- C:\GameDev
2016-11-07 18:07:25 ----D---- C:\Users\nimrod\AppData\Roaming\obs-studio
2016-11-07 18:00:27 ----D---- C:\Program Files (x86)\obs-studio
2016-11-06 15:38:25 ----A---- C:\Users\nimrod\AppData\Roaming\mclip.dat
2016-11-06 15:38:25 ----A---- C:\Users\nimrod\AppData\Roaming\hexplorer.dat
2016-11-06 15:35:49 ----D---- C:\Program Files (x86)\hexplorer
2016-11-01 18:41:34 ----D---- C:\Users\nimrod\AppData\Roaming\inkscape
2016-11-01 18:27:43 ----AD---- C:\Program Files (x86)\Inkscape
2016-10-31 17:23:45 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2016-10-31 17:23:43 ----D---- C:\ProgramData\Adobe
2016-10-31 17:23:43 ----D---- C:\Program Files (x86)\Common Files\Adobe
2016-10-31 16:51:38 ----D---- C:\Users\nimrod\AppData\Roaming\Poedit
2016-10-31 16:51:15 ----AD---- C:\Program Files (x86)\Poedit
2016-10-30 11:14:07 ----D---- C:\ONION
2016-10-30 09:14:27 ----D---- C:\Program Files (x86)\Adobe Photoshop
======List of files/folders modified in the last 1 month======
2016-11-28 17:14:52 ----D---- C:\WINDOWS\Prefetch
2016-11-28 17:14:50 ----RD---- C:\Program Files (x86)
2016-11-28 17:10:35 ----D---- C:\WINDOWS\Temp
2016-11-28 11:52:33 ----D---- C:\WINDOWS\System32
2016-11-27 11:34:55 ----D---- C:\ProgramData\MFAData
2016-11-27 10:43:58 ----RD---- C:\WINDOWS\Microsoft.NET
2016-11-27 10:40:21 ----SHD---- C:\System Volume Information
2016-11-26 11:27:22 ----SHD---- C:\WINDOWS\Installer
2016-11-26 11:07:10 ----D---- C:\Windows
2016-11-25 23:58:34 ----D---- C:\Users\nimrod\AppData\Roaming\Audacity
2016-11-24 16:10:09 ----D---- C:\WINDOWS\INF
2016-11-24 16:09:47 ----RD---- C:\Program Files
2016-11-24 16:07:32 ----D---- C:\WINDOWS\AppReadiness
2016-11-22 10:04:10 ----D---- C:\WINDOWS\debug
2016-11-20 18:44:38 ----SD---- C:\Users\nimrod\AppData\Roaming\Microsoft
2016-11-20 18:28:26 ----RSD---- C:\WINDOWS\Fonts
2016-11-19 14:31:33 ----HD---- C:\ProgramData
2016-11-17 12:20:56 ----D---- C:\WINDOWS\SoftwareDistribution
2016-11-17 12:05:38 ----D---- C:\WINDOWS\SysWOW64
2016-11-13 13:49:22 ----D---- C:\WINDOWS\rescache
2016-11-12 15:35:01 ----D---- C:\WINDOWS\WinSxS
2016-11-12 11:04:17 ----RD---- C:\WINDOWS\assembly
2016-11-12 06:16:51 ----D---- C:\Program Files (x86)\Dropbox
2016-11-11 19:01:36 ----D---- C:\ProgramData\Package Cache
2016-11-10 17:52:48 ----D---- C:\WINDOWS\CbsTemp
2016-11-10 09:07:19 ----D---- C:\WINDOWS\LiveKernelReports
2016-11-10 01:15:26 ----D---- C:\WINDOWS\SysWoW64\migration
2016-11-10 01:15:11 ----D---- C:\WINDOWS\SysWoW64\cs-CZ
2016-11-10 01:14:14 ----D---- C:\WINDOWS\ShellExperiences
2016-11-10 01:14:12 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-11-10 01:14:11 ----D---- C:\WINDOWS\bcastdvr
2016-11-10 01:14:11 ----D---- C:\WINDOWS\AppPatch
2016-11-09 16:35:59 ----D---- C:\ProgramData\Microsoft Help
2016-11-09 16:25:33 ----A---- C:\WINDOWS\win.ini
2016-11-01 08:49:54 ----D---- C:\Program Files (x86)\Google
2016-10-31 19:00:04 ----D---- C:\WWW
2016-10-31 17:28:36 ----D---- C:\Users\nimrod\AppData\Roaming\Adobe
2016-10-31 17:23:43 ----D---- C:\Program Files (x86)\Common Files
2016-10-30 09:13:47 ----D---- C:\DOSBOX
2016-10-29 00:56:11 ----A---- C:\WINDOWS\SysWoW64\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;@oem29.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmpfd.sys []
R0 amdpsp;@oem32.inf,%amdpsp.SVCDESC%;AMD PSP Service; C:\WINDOWS\system32\DRIVERS\amdpsp.sys []
R0 AVGIDSHA;AVGIDSHA; C:\WINDOWS\system32\DRIVERS\avgidsha.sys []
R0 Avgloga;AVG Logging Driver; C:\WINDOWS\system32\DRIVERS\avgloga.sys []
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx64.sys []
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx64.sys []
R0 Avguniva;AVG Universal Driver; C:\WINDOWS\system32\DRIVERS\avguniva.sys []
R0 BTATH_BUS;@oem15.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys []
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys []
R1 Avgdiska;AVG Disk Driver; C:\WINDOWS\system32\DRIVERS\avgdiska.sys []
R1 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdrivera.sys []
R1 Avgldx64;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx64.sys []
R1 Avgwfpa;AVG Firewall Driver; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys []
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys []
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys []
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys []
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys []
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys []
R3 amdkmdag;amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmdag.sys [2016-10-01 26559504]
R3 amdkmdap;amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmpag.sys [2016-10-01 527264]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\System32\drivers\athw8x.sys []
R3 AtiHDAudioService;@oem30.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys []
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys []
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys []
R3 LMDriver;@oem18.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys []
R3 RadioShim;@oem18.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys []
R3 rt640x64;@oem13.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys []
R3 RTSPER;@oem9.inf,%Rts5227PER%;Realtek PCIE Card Reader - PER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys []
R3 SensorsSimulatorDriver;@oem26.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys []
R3 SynRMIHID;@oem6.inf,%SynRMIHID.SVCDESC%;Synaptics HID Service; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys []
S0 amdkmafd;@oem27.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys []
S0 Avgboota;AVG Early Launch Anti-Malware Driver; C:\WINDOWS\system32\DRIVERS\avgboota.sys []
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys []
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys []
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys []
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys []
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys []
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys []
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys []
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys []
S3 amdkmcsp;@oem32.inf,%amdkmcsp.SVCDESC%;AMD Kernel Mode CSP Service; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys []
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys []
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys []
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys []
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys []
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys []
S3 dbx;dbx; C:\WINDOWS\system32\DRIVERS\dbx.sys []
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys []
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys []
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys []
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys []
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys []
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys []
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys []
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys []
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys []
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys []
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys []
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys []
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys []
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys []
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys []
S3 ReFSv1;ReFSv1; C:\WINDOWS\SysWoW64\drivers\ReFSv1.sys []
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys []
S3 scvad_simple;@oem34.inf,%scvad_simple.SvcDesc%;SplitCam Virtual Microphone (WDM); C:\WINDOWS\system32\drivers\SplitCamAudio.sys []
S3 splitcam_hd_driver;@oem33.inf,%splitcam_hd_driver.DeviceDesc%;SplitCam Virtual Video Driver; C:\WINDOWS\system32\DRIVERS\splitcam_hd_driver.sys []
S3 SWDUMon;SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe []
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [2016-11-02 5337696]
R2 avgsvc;AVG Service; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [2016-09-13 1149712]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [2016-11-02 727512]
R2 Bonjour Service;Xamarin Bonjour Service; C:\Program Files (x86)\Xamarin\Bonjour\mDNSResponder.exe [2015-07-15 394752]
R2 CDPUserSvc_1fd2d75;CDPUserSvc_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R2 DbxSvc;DbxSvc; C:\WINDOWS\system32\DbxSvc.exe []
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc); C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [2015-02-05 22744]
R2 OneSyncSvc_1fd2d75;Hostitel synchronizace_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2012-04-24 254512]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2016-04-30 131776]
R2 tbaseprovisioning;tbaseprovisioning; C:\WINDOWS\SysWOW64\tbaseprovisioning.exe [2016-08-23 51224]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
R3 PimIndexMaintenanceSvc_1fd2d75;Data kontaktů_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-10-17 143144]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S3 AvgAMPS;AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [2016-11-02 647864]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-10-17 143144]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe []
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-02-19 142336]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 MessagingService_1fd2d75;Služba zasílání zpráv_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe []
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe []
S4 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2016-07-14 2267352]
S4 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2014-06-12 2573032]
S4 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2015-12-22 349728]
S4 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2015-12-22 209952]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-23 153752]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-23 153752]
S4 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2014-06-10 466664]
S4 PlaysService;Plays.tv Update Service; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [2016-08-09 32528]
S4 QASvc;Quick Access Service; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [2014-06-26 458984]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
-----------------EOF-----------------

Logfile of random's system information tool 1.10 (written by random/random)
Run by nimrod at 2016-11-28 17:14:48
Microsoft Windows 10 Home
System drive C: has 622 GB (66%) free of 937 GB
Total RAM: 3288 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:15:07, on 28. 11. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe
C:\Users\nimrod\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\nimrod\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Users\nimrod\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
C:\Users\nimrod\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\nimrod.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com/?pc=ACJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: ::1 wp-dev
O1 - Hosts: ::1 utilities
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
O4 - HKLM\..\Run: [PlaysTV] "C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe" --startup
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=av
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKCU\..\Run: [OneDrive] "C:\Users\nimrod\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_D666053EBBCBECDDF302E5B8C0D21F88] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [Xvid] powershell.exe -nologo -WindowStyle hidden -Noninteractive -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files (x86)\Xvid\CheckUpdate.ps1"
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgamps.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
O23 - Service: Xamarin Bonjour Service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Xamarin\Bonjour\mDNSResponder.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater40.3.6 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.6\ToolbarUpdater.exe
O23 - Service: wampapache64 - Apache Software Foundation - c:\wamp64\bin\apache\apache2.4.23\bin\httpd.exe
O23 - Service: wampmysqld64 - Unknown owner - c:\wamp64\bin\mysql\mysql5.7.14\bin\mysqld.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
--
End of file - 11267 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AVG Driver Updater Scan.job - C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe scheduled
C:\WINDOWS\tasks\AVG Driver Updater Startup.job - C:\Program Files (x86)\AVG Driver Updater\AVG Driver Updater.exe -boot
C:\WINDOWS\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-09-13 163528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Web TuneUp - C:\Program Files (x86)\AVG Web TuneUp\4.3.6.255\AVG Web TuneUp.dll [2016-09-30 2260040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2016-10-11 1743664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22 755392]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvgUi"=C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [2016-09-13 218896]
"vProt"=C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2016-09-30 2180680]
"PlaysTV"=C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [2016-08-09 71440]
"AVG_UI"=C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [2016-09-13 218896]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2016-11-07 25673776]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\nimrod\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-09-30 633024]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-11-15 9105112]
"GoogleChromeAutoLaunch_D666053EBBCBECDDF302E5B8C0D21F88"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2016-09-14 967496]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2016-10-12 23818712]
"Xvid"=powershell.exe -nologo -WindowStyle hidden -Noninteractive -NoProfile -ExecutionPolicy Bypass -File C:\Program Files (x86)\Xvid\CheckUpdate.ps1 []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\abdocs.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acerportal.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\carecenter.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\epowerui.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\playstv_launcher.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\quickaccess.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setting.exe]
"Debugger=""C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=l3codecp.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.cvid"=iccvid.dll
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.zmbv"=zmbv.dll
"vidc.ffds"=C:\Program Files (x86)\ffdshow\ffdshow.ax
"vidc.XVID"=xvidvfw.dll
"vidc.x264"=x264vfw.dll
======File associations======
.inf - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
.inf - install -
.ini - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
.js - edit -
.js - open - "C:\Program Files\Notepad++\notepad++.exe" "%1"
======List of files/folders created in the last 1 month======
2016-11-28 17:14:50 ----D---- C:\Program Files (x86)\trend micro
2016-11-28 17:14:48 ----D---- C:\rsit
2016-11-26 11:07:10 ----D---- C:\WINDOWS\Panther
2016-11-19 14:31:33 ----D---- C:\ProgramData\Avg_Update_1116sp
2016-11-18 10:53:10 ----D---- C:\ProgramData\Avg_Update_1116tb
2016-11-17 12:05:38 ----D---- C:\Program Files (x86)\x264vfw
2016-11-16 14:52:06 ----A---- C:\WINDOWS\SysWoW64\xvidvfw.dll
2016-11-16 14:52:06 ----A---- C:\WINDOWS\SysWoW64\xvidcore.dll
2016-11-16 14:52:01 ----AD---- C:\Program Files (x86)\Xvid
2016-11-15 21:16:17 ----D---- C:\Program Files (x86)\VirtualDub
2016-11-15 20:53:34 ----D---- C:\videodvdmaker
2016-11-15 20:53:34 ----D---- C:\Users\nimrod\AppData\Roaming\Video DVD Maker FREE
2016-11-14 15:43:28 ----D---- C:\Users\nimrod\AppData\Roaming\vlc
2016-11-14 15:27:02 ----D---- C:\Program Files (x86)\VideoLAN
2016-11-14 15:20:05 ----D---- C:\Program Files (x86)\ffdshow
2016-11-14 15:08:33 ----D---- C:\Users\nimrod\AppData\Roaming\Subtitle Edit
2016-11-14 15:08:33 ----AD---- C:\Program Files (x86)\Subtitle Edit
2016-11-14 13:37:33 ----D---- C:\Users\nimrod\AppData\Roaming\FontForge
2016-11-14 13:35:56 ----AD---- C:\Program Files (x86)\FontForgeBuilds
2016-11-14 13:29:18 ----HD---- C:\Program Files (x86)\InstallJammer Registry
2016-11-14 13:28:32 ----AD---- C:\Program Files (x86)\MidiEditor
2016-11-12 14:53:19 ----D---- C:\Users\nimrod\AppData\Roaming\Brief
2016-11-12 14:47:57 ----AD---- C:\Program Files (x86)\Brief
2016-11-10 17:41:27 ----A---- C:\WINDOWS\SysWoW64\openglv5.dll
2016-11-10 17:41:26 ----A---- C:\WINDOWS\SysWoW64\openglv3.dll
2016-11-09 22:11:14 ----AD---- C:\Program Files (x86)\Lame For Audacity
2016-11-09 22:10:55 ----AD---- C:\Program Files (x86)\FFmpeg for Audacity
2016-11-09 22:02:52 ----AD---- C:\Program Files (x86)\Audacity
2016-11-09 11:54:07 ----A---- C:\WINDOWS\SysWoW64\usercpl.dll
2016-11-09 11:54:07 ----A---- C:\WINDOWS\SysWoW64\themecpl.dll
2016-11-09 11:54:07 ----A---- C:\WINDOWS\SysWoW64\input.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\TSpkg.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\sud.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\stobject.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\mstscax.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\msctf.dll
2016-11-09 11:54:06 ----A---- C:\WINDOWS\SysWoW64\comctl32.dll
2016-11-09 11:54:03 ----A---- C:\WINDOWS\SysWoW64\olepro32.dll
2016-11-09 11:54:03 ----A---- C:\WINDOWS\SysWoW64\asycfilt.dll
2016-11-09 11:54:00 ----A---- C:\WINDOWS\SysWoW64\inetcomm.dll
2016-11-09 11:53:56 ----A---- C:\WINDOWS\SysWoW64\iertutil.dll
2016-11-09 11:53:55 ----A---- C:\WINDOWS\SysWoW64\ieproxy.dll
2016-11-09 11:53:55 ----A---- C:\WINDOWS\SysWoW64\ieapfltr.dll
2016-11-09 11:53:54 ----A---- C:\WINDOWS\SysWoW64\wininet.dll
2016-11-09 11:53:50 ----A---- C:\WINDOWS\SysWoW64\wininetlui.dll
2016-11-09 11:53:50 ----A---- C:\WINDOWS\SysWoW64\urlmon.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\VSD3DWARPDebug.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\hgcpl.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\ddraw.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\d3d9.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\d3d8.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\d3d12warp.dll
2016-11-09 11:53:49 ----A---- C:\WINDOWS\SysWoW64\ActionCenterCPL.dll
2016-11-09 11:53:48 ----A---- C:\WINDOWS\SysWoW64\VSD3DWARP12Debug.dll
2016-11-09 11:53:48 ----A---- C:\WINDOWS\SysWoW64\DevicePairing.dll
2016-11-09 11:53:45 ----A---- C:\WINDOWS\SysWoW64\comdlg32.dll
2016-11-09 11:53:42 ----A---- C:\WINDOWS\SysWoW64\AuthExt.dll
2016-11-09 11:53:39 ----A---- C:\WINDOWS\SysWoW64\authui.dll
2016-11-09 11:53:38 ----A---- C:\WINDOWS\SysWoW64\Windows.Media.Protection.PlayReady.dll
2016-11-09 11:53:35 ----A---- C:\WINDOWS\SysWoW64\zipfldr.dll
2016-11-09 11:53:33 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Immersive.dll
2016-11-09 11:53:32 ----A---- C:\WINDOWS\SysWoW64\win32kfull.sys
2016-11-09 11:53:32 ----A---- C:\WINDOWS\SysWoW64\win32k.sys
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\UIAnimation.dll
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\StoreAgent.dll
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\MSVidCtl.dll
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\InstallAgentUserBroker.exe
2016-11-09 11:53:29 ----A---- C:\WINDOWS\SysWoW64\InstallAgent.exe
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Search.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Logon.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.Cred.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.BlockedShutdown.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.UI.BioFeedback.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\Windows.Shell.Search.UriHandler.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\twinui.dll
2016-11-09 11:53:28 ----A---- C:\WINDOWS\SysWoW64\LaunchWinApp.exe
2016-11-09 11:53:27 ----A---- C:\WINDOWS\SysWoW64\twinapi.dll
2016-11-09 11:53:27 ----A---- C:\WINDOWS\SysWoW64\rdpcore.dll
2016-11-09 11:53:27 ----A---- C:\WINDOWS\SysWoW64\mstsc.exe
2016-11-09 11:53:26 ----A---- C:\WINDOWS\SysWoW64\shell32.dll
2016-11-09 11:53:26 ----A---- C:\WINDOWS\SysWoW64\msv1_0.dll
2016-11-09 11:53:26 ----A---- C:\WINDOWS\SysWoW64\jscript9diag.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\Windows.Security.Authentication.OnlineId.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\jscript9.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\Chakradiag.dll
2016-11-09 11:53:25 ----A---- C:\WINDOWS\SysWoW64\Chakra.dll
2016-11-09 11:53:19 ----A---- C:\WINDOWS\SysWoW64\oleaut32.dll
2016-11-09 11:53:19 ----A---- C:\WINDOWS\SysWoW64\ntshrui.dll
2016-11-09 11:53:19 ----A---- C:\WINDOWS\SysWoW64\ntdll.dll
2016-11-09 11:53:16 ----A---- C:\WINDOWS\SysWoW64\NetSetupEngine.dll
2016-11-09 11:53:16 ----A---- C:\WINDOWS\SysWoW64\NetSetupApi.dll
2016-11-09 11:53:14 ----A---- C:\WINDOWS\SysWoW64\NPSM.dll
2016-11-09 11:53:13 ----A---- C:\WINDOWS\SysWoW64\msinfo32.exe
2016-11-09 11:53:13 ----A---- C:\WINDOWS\SysWoW64\mfcore.dll
2016-11-09 11:53:12 ----A---- C:\WINDOWS\SysWoW64\wmp.dll
2016-11-09 11:53:11 ----A---- C:\WINDOWS\SysWoW64\mfsvr.dll
2016-11-09 11:53:11 ----A---- C:\WINDOWS\SysWoW64\mfsensorgroup.dll
2016-11-09 11:53:10 ----A---- C:\WINDOWS\SysWoW64\MFMediaEngine.dll
2016-11-09 11:53:10 ----A---- C:\WINDOWS\SysWoW64\FSClient.dll
2016-11-09 11:53:09 ----A---- C:\WINDOWS\SysWoW64\LockAppBroker.dll
2016-11-09 11:53:04 ----A---- C:\WINDOWS\SysWoW64\ieframe.dll
2016-11-09 11:53:01 ----A---- C:\WINDOWS\SysWoW64\indexeddbserver.dll
2016-11-09 11:53:00 ----A---- C:\WINDOWS\SysWoW64\mshtmled.dll
2016-11-09 11:53:00 ----A---- C:\WINDOWS\SysWoW64\edgehtml.dll
2016-11-09 11:53:00 ----A---- C:\WINDOWS\SysWoW64\dxtrans.dll
2016-11-09 11:52:59 ----A---- C:\WINDOWS\SysWoW64\iepeers.dll
2016-11-09 11:52:58 ----A---- C:\WINDOWS\SysWoW64\mshtml.dll
2016-11-09 11:52:51 ----A---- C:\WINDOWS\SysWoW64\Windows.Globalization.dll
2016-11-09 11:52:51 ----A---- C:\WINDOWS\SysWoW64\GlobCollationHost.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\gdi32full.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\gameux.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\fontdrvhost.exe
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\atmlib.dll
2016-11-09 11:52:50 ----A---- C:\WINDOWS\SysWoW64\atmfd.dll
2016-11-09 11:52:49 ----A---- C:\WINDOWS\SysWoW64\fontext.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\weretw.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\wer.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\ExplorerFrame.dll
2016-11-09 11:52:48 ----A---- C:\WINDOWS\SysWoW64\explorer.exe
2016-11-09 11:52:47 ----A---- C:\WINDOWS\SysWoW64\efsext.dll
2016-11-09 11:52:46 ----A---- C:\WINDOWS\SysWoW64\d3d10warp.dll
2016-11-09 11:52:45 ----A---- C:\WINDOWS\SysWoW64\Windows.Devices.HumanInterfaceDevice.dll
2016-11-09 11:52:43 ----A---- C:\WINDOWS\SysWoW64\ole32.dll
2016-11-09 11:52:43 ----A---- C:\WINDOWS\SysWoW64\chartv.dll
2016-11-09 11:52:43 ----A---- C:\WINDOWS\SysWoW64\cdp.dll
2016-11-09 11:52:42 ----A---- C:\WINDOWS\SysWoW64\AudioSes.dll
2016-11-09 11:52:41 ----A---- C:\WINDOWS\SysWoW64\Windows.ApplicationModel.LockScreen.dll
2016-11-09 11:52:40 ----A---- C:\WINDOWS\SysWoW64\BcastDVRHelper.dll
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\ErrorDetailsUpdate.dll
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\ErrorDetails.dll
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\bcastdvr.exe
2016-11-09 11:52:39 ----A---- C:\WINDOWS\SysWoW64\AppCapture.dll
2016-11-09 11:43:33 ----A---- C:\WINDOWS\explorer.exe
2016-11-08 13:49:21 ----D---- C:\Games
2016-11-08 13:46:03 ----D---- C:\GameDev
2016-11-07 18:07:25 ----D---- C:\Users\nimrod\AppData\Roaming\obs-studio
2016-11-07 18:00:27 ----D---- C:\Program Files (x86)\obs-studio
2016-11-06 15:38:25 ----A---- C:\Users\nimrod\AppData\Roaming\mclip.dat
2016-11-06 15:38:25 ----A---- C:\Users\nimrod\AppData\Roaming\hexplorer.dat
2016-11-06 15:35:49 ----D---- C:\Program Files (x86)\hexplorer
2016-11-01 18:41:34 ----D---- C:\Users\nimrod\AppData\Roaming\inkscape
2016-11-01 18:27:43 ----AD---- C:\Program Files (x86)\Inkscape
2016-10-31 17:23:45 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2016-10-31 17:23:43 ----D---- C:\ProgramData\Adobe
2016-10-31 17:23:43 ----D---- C:\Program Files (x86)\Common Files\Adobe
2016-10-31 16:51:38 ----D---- C:\Users\nimrod\AppData\Roaming\Poedit
2016-10-31 16:51:15 ----AD---- C:\Program Files (x86)\Poedit
2016-10-30 11:14:07 ----D---- C:\ONION
2016-10-30 09:14:27 ----D---- C:\Program Files (x86)\Adobe Photoshop
======List of files/folders modified in the last 1 month======
2016-11-28 17:14:52 ----D---- C:\WINDOWS\Prefetch
2016-11-28 17:14:50 ----RD---- C:\Program Files (x86)
2016-11-28 17:10:35 ----D---- C:\WINDOWS\Temp
2016-11-28 11:52:33 ----D---- C:\WINDOWS\System32
2016-11-27 11:34:55 ----D---- C:\ProgramData\MFAData
2016-11-27 10:43:58 ----RD---- C:\WINDOWS\Microsoft.NET
2016-11-27 10:40:21 ----SHD---- C:\System Volume Information
2016-11-26 11:27:22 ----SHD---- C:\WINDOWS\Installer
2016-11-26 11:07:10 ----D---- C:\Windows
2016-11-25 23:58:34 ----D---- C:\Users\nimrod\AppData\Roaming\Audacity
2016-11-24 16:10:09 ----D---- C:\WINDOWS\INF
2016-11-24 16:09:47 ----RD---- C:\Program Files
2016-11-24 16:07:32 ----D---- C:\WINDOWS\AppReadiness
2016-11-22 10:04:10 ----D---- C:\WINDOWS\debug
2016-11-20 18:44:38 ----SD---- C:\Users\nimrod\AppData\Roaming\Microsoft
2016-11-20 18:28:26 ----RSD---- C:\WINDOWS\Fonts
2016-11-19 14:31:33 ----HD---- C:\ProgramData
2016-11-17 12:20:56 ----D---- C:\WINDOWS\SoftwareDistribution
2016-11-17 12:05:38 ----D---- C:\WINDOWS\SysWOW64
2016-11-13 13:49:22 ----D---- C:\WINDOWS\rescache
2016-11-12 15:35:01 ----D---- C:\WINDOWS\WinSxS
2016-11-12 11:04:17 ----RD---- C:\WINDOWS\assembly
2016-11-12 06:16:51 ----D---- C:\Program Files (x86)\Dropbox
2016-11-11 19:01:36 ----D---- C:\ProgramData\Package Cache
2016-11-10 17:52:48 ----D---- C:\WINDOWS\CbsTemp
2016-11-10 09:07:19 ----D---- C:\WINDOWS\LiveKernelReports
2016-11-10 01:15:26 ----D---- C:\WINDOWS\SysWoW64\migration
2016-11-10 01:15:11 ----D---- C:\WINDOWS\SysWoW64\cs-CZ
2016-11-10 01:14:14 ----D---- C:\WINDOWS\ShellExperiences
2016-11-10 01:14:12 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-11-10 01:14:11 ----D---- C:\WINDOWS\bcastdvr
2016-11-10 01:14:11 ----D---- C:\WINDOWS\AppPatch
2016-11-09 16:35:59 ----D---- C:\ProgramData\Microsoft Help
2016-11-09 16:25:33 ----A---- C:\WINDOWS\win.ini
2016-11-01 08:49:54 ----D---- C:\Program Files (x86)\Google
2016-10-31 19:00:04 ----D---- C:\WWW
2016-10-31 17:28:36 ----D---- C:\Users\nimrod\AppData\Roaming\Adobe
2016-10-31 17:23:43 ----D---- C:\Program Files (x86)\Common Files
2016-10-30 09:13:47 ----D---- C:\DOSBOX
2016-10-29 00:56:11 ----A---- C:\WINDOWS\SysWoW64\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;@oem29.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmpfd.sys []
R0 amdpsp;@oem32.inf,%amdpsp.SVCDESC%;AMD PSP Service; C:\WINDOWS\system32\DRIVERS\amdpsp.sys []
R0 AVGIDSHA;AVGIDSHA; C:\WINDOWS\system32\DRIVERS\avgidsha.sys []
R0 Avgloga;AVG Logging Driver; C:\WINDOWS\system32\DRIVERS\avgloga.sys []
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx64.sys []
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx64.sys []
R0 Avguniva;AVG Universal Driver; C:\WINDOWS\system32\DRIVERS\avguniva.sys []
R0 BTATH_BUS;@oem15.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys []
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys []
R1 Avgdiska;AVG Disk Driver; C:\WINDOWS\system32\DRIVERS\avgdiska.sys []
R1 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\avgidsdrivera.sys []
R1 Avgldx64;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx64.sys []
R1 Avgwfpa;AVG Firewall Driver; C:\WINDOWS\system32\DRIVERS\avgwfpa.sys []
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys []
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys []
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys []
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys []
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys []
R3 amdkmdag;amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmdag.sys [2016-10-01 26559504]
R3 amdkmdap;amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0307329.inf_amd64_55b6bd3e40065979\atikmpag.sys [2016-10-01 527264]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\System32\drivers\athw8x.sys []
R3 AtiHDAudioService;@oem30.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys []
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys []
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys []
R3 LMDriver;@oem18.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys []
R3 RadioShim;@oem18.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys []
R3 rt640x64;@oem13.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys []
R3 RTSPER;@oem9.inf,%Rts5227PER%;Realtek PCIE Card Reader - PER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys []
R3 SensorsSimulatorDriver;@oem26.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys []
R3 SynRMIHID;@oem6.inf,%SynRMIHID.SVCDESC%;Synaptics HID Service; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys []
S0 amdkmafd;@oem27.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys []
S0 Avgboota;AVG Early Launch Anti-Malware Driver; C:\WINDOWS\system32\DRIVERS\avgboota.sys []
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys []
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys []
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys []
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys []
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys []
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys []
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys []
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys []
S3 amdkmcsp;@oem32.inf,%amdkmcsp.SVCDESC%;AMD Kernel Mode CSP Service; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys []
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys []
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys []
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys []
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys []
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys []
S3 dbx;dbx; C:\WINDOWS\system32\DRIVERS\dbx.sys []
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys []
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys []
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys []
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys []
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys []
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys []
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys []
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys []
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys []
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys []
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys []
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys []
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys []
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys []
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys []
S3 ReFSv1;ReFSv1; C:\WINDOWS\SysWoW64\drivers\ReFSv1.sys []
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys []
S3 scvad_simple;@oem34.inf,%scvad_simple.SvcDesc%;SplitCam Virtual Microphone (WDM); C:\WINDOWS\system32\drivers\SplitCamAudio.sys []
S3 splitcam_hd_driver;@oem33.inf,%splitcam_hd_driver.DeviceDesc%;SplitCam Virtual Video Driver; C:\WINDOWS\system32\DRIVERS\splitcam_hd_driver.sys []
S3 SWDUMon;SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe []
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [2016-11-02 5337696]
R2 avgsvc;AVG Service; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [2016-09-13 1149712]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [2016-11-02 727512]
R2 Bonjour Service;Xamarin Bonjour Service; C:\Program Files (x86)\Xamarin\Bonjour\mDNSResponder.exe [2015-07-15 394752]
R2 CDPUserSvc_1fd2d75;CDPUserSvc_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R2 DbxSvc;DbxSvc; C:\WINDOWS\system32\DbxSvc.exe []
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc); C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [2015-02-05 22744]
R2 OneSyncSvc_1fd2d75;Hostitel synchronizace_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2012-04-24 254512]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2016-04-30 131776]
R2 tbaseprovisioning;tbaseprovisioning; C:\WINDOWS\SysWOW64\tbaseprovisioning.exe [2016-08-23 51224]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
R3 PimIndexMaintenanceSvc_1fd2d75;Data kontaktů_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-10-17 143144]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S3 AvgAMPS;AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [2016-11-02 647864]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-10-17 143144]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe []
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-02-19 142336]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 MessagingService_1fd2d75;Služba zasílání zpráv_1fd2d75; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe []
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2016-07-16 38792]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe []
S4 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2016-07-14 2267352]
S4 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2014-06-12 2573032]
S4 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2015-12-22 349728]
S4 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2015-12-22 209952]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-23 153752]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-23 153752]
S4 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2014-06-10 466664]
S4 PlaysService;Plays.tv Update Service; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [2016-08-09 32528]
S4 QASvc;Quick Access Service; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [2014-06-26 458984]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 38792]
-----------------EOF-----------------