Logfile of random's system information tool 1.14 (written by random/random)
Run by Honza at 2016-12-23 16:45:07
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 875 GB (93%) free of 941 GB
Total RAM: 8111 MB (56% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:45:14, on 23.12.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
C:\Program Files (x86)\IObit\Driver Booster\4.1.0\Scheduler.exe
C:\Program Files\trend micro\Honza_RSITx64 (1).exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [Sound Blaster Cinema] "C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Killer Network Manager.lnk = ?
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Droid4XService - Unknown owner - C:\Program Files (x86)\Droid4X\Droid4XService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Unknown owner - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (file missing)
O23 - Service: Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\Windows\system32\ibtsiva (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Micro Star SCM - Micro-Star International Co., Ltd. - C:\Windows\SysWOW64\MSIService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: uTorrent Server - Unknown owner - C:\uTorrent\nssm.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 8320 bytes
======Enumerating Processes======
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\WLANExt.exe 17682528
\??\C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Droid4X\Droid4XService.exe"
"C:\Program Files\Elantech\ETDService.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
C:\Windows\system32\ibtsiva.exe
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\taskeng.exe
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\Windows\SysWOW64\MSIService.exe
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\uTorrent\nssm.exe
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
C:\uTorrent\utorrent.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\igfxHK.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\rundll32.exe" C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe" -minimize
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\MSI\Dragon Gaming Center\Dragon Gaming Center.exe"
"C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe" /r
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files (x86)\IObit\Driver Booster\4.1.0\Scheduler.exe" /scheduler
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Honza\AppData\Local\Google\Chrome\User Data" --url=
https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=55.0.2883.87 --handshake-handle=0xc0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=5112 --on-initialized-event-handle=332 --parent-handle=336 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,*PreferHtmlOverPlugins<Html5ByDefault,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Disabled/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/Html5ByDefault/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/*SiteIsolationExtensions/Control/StrictSecureCookies/Default/SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Control/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group2/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_70/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_17/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=6,16,17,18,21,37,54,65 --gpu-vendor-id=0x8086 --gpu-device-id=0x0416 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.14.4264 --gpu-driver-date=8-4-2015 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x1391 --service-request-channel-token=5B391ED74F2D56DCF2A785BA59F46833 --mojo-platform-channel-handle=1064 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,*PreferHtmlOverPlugins<Html5ByDefault,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Disabled/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/Html5ByDefault/Default/*InstanceID/Enabled/MaterialDesignDownloads/Enabled/*MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/*SiteIsolationExtensions/Control/StrictSecureCookies/Default/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Control/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group2/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_70/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_17/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --primordial-pipe-token=623C7646F5931EC4C980C8DC081D82B1 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=623C7646F5931EC4C980C8DC081D82B1 --mojo-platform-channel-handle=2456 /prefetch:1
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,*PreferHtmlOverPlugins<Html5ByDefault,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Disabled/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/*Html5ByDefault/Default/*InstanceID/Enabled/MaterialDesignDownloads/Enabled/*MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/*SiteIsolationExtensions/Control/*StrictSecureCookies/Default/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Control/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group2/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_70/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_17/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=8F5C90DF405AB0F5FF9376FE41749159 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=8F5C90DF405AB0F5FF9376FE41749159 --mojo-platform-channel-handle=2076 /prefetch:1
C:\Windows\servicing\TrustedInstaller.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
"C:\Users\Honza\Downloads\RSITx64 (1).exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Driver Booster Scheduler - C:\Program Files (x86)\IObit\Driver Booster\4.1.0\Scheduler.exe /scheduler
C:\Windows\system32\tasks\Driver Booster SkipUAC (Honza) - C:\Program Files (x86)\IObit\Driver Booster\4.1.0\DriverBooster.exe /skipuac
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\MSI_Dragon Gaming Center - C:\Program Files (x86)\MSI\Dragon Gaming Center\mDispatch.exe C:\Program Files (x86)\MSI\Dragon Gaming Center\Dragon Gaming Center.exe
C:\Windows\system32\tasks\Norton Anti-Theft\Norton Error Analyzer - C:\Program Files (x86)\Norton Anti-Theft\Engine\1.9.0.14\SymErr.exe /analyze
C:\Windows\system32\tasks\Norton Anti-Theft\Norton Error Processor - C:\Program Files (x86)\Norton Anti-Theft\Engine\1.9.0.14\SymErr.exe /submit
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\Setup\EOSNotify - %windir%\system32\EOSNotify.exe
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan - c:\Program Files\Microsoft Security Client\\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges
C:\Windows\system32\tasks\Microsoft\Microsoft Antimalware\MpIdleTask - c:\Program Files\Microsoft Security Client\\MpCmdRun.exe -IdleTask -TaskName MpIdleTask
=========Google Chrome=========
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension hjnhcgkngeeahimbfhejeaiijecekhba 1 ClixAddon 0.86
Extension ibmlkgieigeddcedpbijnpojheoddido 1 Arcane Legends 1.5.5.3
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.1
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5516.1005.0.3
Homepage:
http://www.myfreezoo.cz/game/
default_search_provider.search_url:
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-01-20 2234144]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-08-23 2893104]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1353680]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2016-12-23 16776192]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 60 []
"MBCfg64"=C:\Windows\system32\MBCfg64.dll [2013-08-29 40576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2016-12-20 2876704]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-12-20 292848]
"Sound Blaster Cinema"=C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [2013-08-16 711680]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{4E08CC97-912D-458B-8705-9A14C325532F}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-12-23 16:38:27 ----N---- C:\Windows\Updreg.EXE
2016-12-23 16:38:23 ----N---- C:\Windows\SYSWOW64\ResDefA.exe
2016-12-23 16:38:23 ----N---- C:\Windows\SYSWOW64\MBCfgUninstall32.ini
2016-12-23 16:38:23 ----N---- C:\Windows\SYSWOW64\MBCfg32.ini
2016-12-23 16:38:23 ----N---- C:\Windows\SYSWOW64\MBCfg32.exe
2016-12-23 16:38:23 ----N---- C:\Windows\SYSWOW64\MBCfg32.dll
2016-12-23 16:38:23 ----N---- C:\Windows\SYSWOW64\ChezSC32.DLL
2016-12-23 16:38:23 ----N---- C:\Windows\system32\MBCfgUninstall64.ini
2016-12-23 16:38:23 ----N---- C:\Windows\system32\MBCfg64.ini
2016-12-23 16:38:23 ----N---- C:\Windows\system32\MBCfg64.exe
2016-12-23 16:38:22 ----N---- C:\Windows\system32\MBCfg64.dll
2016-12-23 16:38:22 ----N---- C:\Windows\system32\ChezSC64.DLL
2016-12-23 16:38:22 ----N---- C:\Windows\MBCfg_SP_APOIM.ini
2016-12-23 16:38:22 ----N---- C:\Windows\MBCfg_HP_APOIM.ini
2016-12-23 16:38:22 ----N---- C:\Windows\MBCfg_APOIM.ini
2016-12-23 16:38:22 ----D---- C:\ProgramData\Creative
2016-12-23 16:38:21 ----A---- C:\Windows\SYSWOW64\CmdRtr.DLL
2016-12-23 16:38:21 ----A---- C:\Windows\SYSWOW64\APOMngr.DLL
2016-12-23 16:38:21 ----A---- C:\Windows\system32\CmdRtr64.DLL
2016-12-23 16:38:21 ----A---- C:\Windows\system32\APOMgr64.DLL
2016-12-23 16:37:46 ----D---- C:\Program Files (x86)\Creative
2016-12-23 14:23:46 ----D---- C:\80fde98dde49a4fd8a
2016-12-23 14:23:30 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2016-12-23 14:23:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2016-12-23 14:23:30 ----A---- C:\Windows\system32\XAudio2_7.dll
2016-12-23 14:23:30 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2016-12-23 14:23:28 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2016-12-23 14:23:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2016-12-23 14:23:28 ----A---- C:\Windows\system32\xactengine3_7.dll
2016-12-23 14:23:28 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2016-12-23 14:23:27 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2016-12-23 14:23:27 ----A---- C:\Windows\system32\d3dcsx_43.dll
2016-12-23 14:23:26 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2016-12-23 14:23:26 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2016-12-23 14:23:26 ----A---- C:\Windows\system32\d3dx11_43.dll
2016-12-23 14:23:26 ----A---- C:\Windows\system32\d3dx10_43.dll
2016-12-23 14:23:25 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2016-12-23 14:23:25 ----A---- C:\Windows\system32\D3DX9_43.dll
2016-12-23 14:23:24 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2016-12-23 14:23:24 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2016-12-23 14:23:24 ----A---- C:\Windows\system32\XAudio2_6.dll
2016-12-23 14:23:24 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2016-12-23 14:23:23 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2016-12-23 14:23:23 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2016-12-23 14:23:23 ----A---- C:\Windows\system32\xactengine3_6.dll
2016-12-23 14:23:23 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2016-12-23 14:23:22 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2016-12-23 14:23:22 ----A---- C:\Windows\system32\XAudio2_5.dll
2016-12-23 14:23:21 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2016-12-23 14:23:21 ----A---- C:\Windows\system32\xactengine3_5.dll
2016-12-23 14:23:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2016-12-23 14:23:20 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2016-12-23 14:23:18 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2016-12-23 14:23:18 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2016-12-23 14:23:18 ----A---- C:\Windows\system32\d3dx11_42.dll
2016-12-23 14:23:18 ----A---- C:\Windows\system32\d3dcsx_42.dll
2016-12-23 14:23:17 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2016-12-23 14:23:17 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2016-12-23 14:23:17 ----A---- C:\Windows\system32\D3DX9_42.dll
2016-12-23 14:23:17 ----A---- C:\Windows\system32\d3dx10_42.dll
2016-12-23 14:23:16 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2016-12-23 14:23:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2016-12-23 14:23:16 ----A---- C:\Windows\system32\d3dx10_41.dll
2016-12-23 14:23:16 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2016-12-23 14:23:15 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2016-12-23 14:23:15 ----A---- C:\Windows\system32\D3DX9_41.dll
2016-12-23 14:23:14 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2016-12-23 14:23:14 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2016-12-23 14:23:14 ----A---- C:\Windows\system32\XAudio2_4.dll
2016-12-23 14:23:14 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2016-12-23 14:23:13 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2016-12-23 14:23:13 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2016-12-23 14:23:13 ----A---- C:\Windows\system32\xactengine3_4.dll
2016-12-23 14:23:13 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2016-12-23 14:23:12 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2016-12-23 14:23:12 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2016-12-23 14:23:12 ----A---- C:\Windows\system32\d3dx10_40.dll
2016-12-23 14:23:12 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2016-12-23 14:23:11 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2016-12-23 14:23:11 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2016-12-23 14:23:11 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2016-12-23 14:23:11 ----A---- C:\Windows\system32\XAudio2_3.dll
2016-12-23 14:23:11 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2016-12-23 14:23:11 ----A---- C:\Windows\system32\D3DX9_40.dll
2016-12-23 14:23:10 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2016-12-23 14:23:10 ----A---- C:\Windows\system32\xactengine3_3.dll
2016-12-23 14:23:09 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2016-12-23 14:23:09 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2016-12-23 14:23:08 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2016-12-23 14:23:08 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2016-12-23 14:23:08 ----A---- C:\Windows\system32\XAudio2_2.dll
2016-12-23 14:23:08 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2016-12-23 14:23:07 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2016-12-23 14:23:07 ----A---- C:\Windows\system32\xactengine3_2.dll
2016-12-23 14:23:06 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2016-12-23 14:23:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2016-12-23 14:23:06 ----A---- C:\Windows\system32\d3dx10_39.dll
2016-12-23 14:23:06 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2016-12-23 14:23:04 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2016-12-23 14:23:04 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2016-12-23 14:23:04 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2016-12-23 14:23:04 ----A---- C:\Windows\system32\D3DX9_39.dll
2016-12-23 14:23:03 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2016-12-23 14:23:03 ----A---- C:\Windows\system32\XAudio2_1.dll
2016-12-23 14:23:02 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2016-12-23 14:23:02 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2016-12-23 14:23:02 ----A---- C:\Windows\system32\xactengine3_1.dll
2016-12-23 14:23:02 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2016-12-23 14:23:00 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2016-12-23 14:23:00 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2016-12-23 14:23:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2016-12-23 14:23:00 ----A---- C:\Windows\system32\D3DX9_38.dll
2016-12-23 14:23:00 ----A---- C:\Windows\system32\d3dx10_38.dll
2016-12-23 14:23:00 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2016-12-23 14:22:59 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2016-12-23 14:22:59 ----A---- C:\Windows\system32\XAudio2_0.dll
2016-12-23 14:22:58 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2016-12-23 14:22:58 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2016-12-23 14:22:58 ----A---- C:\Windows\system32\xactengine3_0.dll
2016-12-23 14:22:58 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2016-12-23 14:22:57 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2016-12-23 14:22:57 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2016-12-23 14:22:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2016-12-23 14:22:57 ----A---- C:\Windows\system32\D3DX9_37.dll
2016-12-23 14:22:57 ----A---- C:\Windows\system32\d3dx10_37.dll
2016-12-23 14:22:57 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2016-12-23 14:22:56 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2016-12-23 14:22:56 ----A---- C:\Windows\system32\xactengine2_10.dll
2016-12-23 14:22:54 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2016-12-23 14:22:54 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2016-12-23 14:22:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2016-12-23 14:22:54 ----A---- C:\Windows\system32\d3dx9_36.dll
2016-12-23 14:22:54 ----A---- C:\Windows\system32\d3dx10_36.dll
2016-12-23 14:22:54 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2016-12-23 14:22:52 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2016-12-23 14:22:52 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2016-12-23 14:22:52 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2016-12-23 14:22:52 ----A---- C:\Windows\system32\xactengine2_9.dll
2016-12-23 14:22:52 ----A---- C:\Windows\system32\d3dx10_35.dll
2016-12-23 14:22:52 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2016-12-23 14:22:51 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2016-12-23 14:22:51 ----A---- C:\Windows\system32\d3dx9_35.dll
2016-12-23 14:22:50 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2016-12-23 14:22:50 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2016-12-23 14:22:50 ----A---- C:\Windows\system32\xactengine2_8.dll
2016-12-23 14:22:50 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2016-12-23 14:22:49 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2016-12-23 14:22:49 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2016-12-23 14:22:49 ----A---- C:\Windows\system32\d3dx10_34.dll
2016-12-23 14:22:49 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2016-12-23 14:22:48 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2016-12-23 14:22:48 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2016-12-23 14:22:48 ----A---- C:\Windows\system32\xinput1_3.dll
2016-12-23 14:22:48 ----A---- C:\Windows\system32\d3dx9_34.dll
2016-12-23 14:22:47 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2016-12-23 14:22:47 ----A---- C:\Windows\system32\xactengine2_7.dll
2016-12-23 14:22:46 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2016-12-23 14:22:46 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2016-12-23 14:22:46 ----A---- C:\Windows\system32\d3dx10_33.dll
2016-12-23 14:22:46 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2016-12-23 14:22:45 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2016-12-23 14:22:45 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2016-12-23 14:22:45 ----A---- C:\Windows\system32\xactengine2_6.dll
2016-12-23 14:22:45 ----A---- C:\Windows\system32\d3dx9_33.dll
2016-12-23 14:22:44 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2016-12-23 14:22:44 ----A---- C:\Windows\system32\xactengine2_5.dll
2016-12-23 14:22:43 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2016-12-23 14:22:43 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2016-12-23 14:22:43 ----A---- C:\Windows\system32\d3dx9_32.dll
2016-12-23 14:22:43 ----A---- C:\Windows\system32\d3dx10.dll
2016-12-23 14:22:42 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2016-12-23 14:22:42 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2016-12-23 14:22:42 ----A---- C:\Windows\system32\xactengine2_4.dll
2016-12-23 14:22:42 ----A---- C:\Windows\system32\x3daudio1_1.dll
2016-12-23 14:22:39 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2016-12-23 14:22:39 ----A---- C:\Windows\system32\d3dx9_31.dll
2016-12-23 14:22:37 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2016-12-23 14:22:37 ----A---- C:\Windows\system32\xactengine2_3.dll
2016-12-23 14:22:36 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2016-12-23 14:22:36 ----A---- C:\Windows\system32\xinput1_2.dll
2016-12-23 14:22:35 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2016-12-23 14:22:35 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2016-12-23 14:22:35 ----A---- C:\Windows\system32\xinput1_1.dll
2016-12-23 14:22:35 ----A---- C:\Windows\system32\xactengine2_2.dll
2016-12-23 14:22:34 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2016-12-23 14:22:34 ----A---- C:\Windows\system32\xactengine2_1.dll
2016-12-23 14:22:22 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2016-12-23 14:22:22 ----A---- C:\Windows\system32\d3dx9_30.dll
2016-12-23 14:22:21 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2016-12-23 14:22:21 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2016-12-23 14:22:21 ----A---- C:\Windows\system32\xactengine2_0.dll
2016-12-23 14:22:21 ----A---- C:\Windows\system32\x3daudio1_0.dll
2016-12-23 14:22:20 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2016-12-23 14:22:20 ----A---- C:\Windows\system32\d3dx9_29.dll
2016-12-23 14:22:19 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2016-12-23 14:22:19 ----A---- C:\Windows\system32\d3dx9_28.dll
2016-12-23 14:22:17 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2016-12-23 14:22:17 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2016-12-23 14:22:17 ----A---- C:\Windows\system32\d3dx9_27.dll
2016-12-23 14:22:17 ----A---- C:\Windows\system32\d3dx9_26.dll
2016-12-23 14:22:14 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2016-12-23 14:22:14 ----A---- C:\Windows\system32\d3dx9_25.dll
2016-12-23 14:22:13 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2016-12-23 14:22:13 ----A---- C:\Windows\system32\d3dx9_24.dll
2016-12-23 14:21:12 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-12-23 14:21:04 ----D---- C:\Windows\system32\Macromed
2016-12-23 14:21:00 ----D---- C:\Windows\SYSWOW64\Macromed
2016-12-23 14:10:07 ----A---- C:\Windows\system32\drivers\Netwsw02.sys
2016-12-23 14:10:06 ----A---- C:\Windows\system32\drivers\Netwfw02.dat
2016-12-23 14:09:54 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2016-12-23 14:09:54 ----A---- C:\Windows\system32\nvaudcap64v.dll
2016-12-23 14:09:54 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2016-12-23 14:09:43 ----A---- C:\Windows\system32\drivers\TeeDriverx64.sys
2016-12-23 14:07:59 ----D---- C:\Windows\IObit
2016-12-23 14:02:05 ----A---- C:\Windows\system32\SRSWOW64.dll
2016-12-23 14:02:05 ----A---- C:\Windows\system32\SRSTSX64.dll
2016-12-23 14:02:05 ----A---- C:\Windows\system32\SRSTSH64.dll
2016-12-23 14:02:05 ----A---- C:\Windows\system32\SRSHP64.dll
2016-12-23 14:02:02 ----A---- C:\Windows\system32\RtPgEx64.dll
2016-12-23 14:02:01 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2016-12-23 14:02:00 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2016-12-23 14:02:00 ----A---- C:\Windows\system32\RtkCfg64.dll
2016-12-23 14:02:00 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2016-12-23 14:01:59 ----A---- C:\Windows\system32\RtkApi64.dll
2016-12-23 14:01:59 ----A---- C:\Windows\system32\RTEEP64A.dll
2016-12-23 14:01:59 ----A---- C:\Windows\system32\RTEEL64A.dll
2016-12-23 14:01:59 ----A---- C:\Windows\system32\RTEEG64A.dll
2016-12-23 14:01:59 ----A---- C:\Windows\system32\RTEED64A.dll
2016-12-23 14:01:59 ----A---- C:\Windows\system32\RtDataProc64.dll
2016-12-23 14:01:58 ----A---- C:\Windows\system32\RTCOM64.dll
2016-12-23 14:01:58 ----A---- C:\Windows\system32\RP3DHT64.dll
2016-12-23 14:01:58 ----A---- C:\Windows\system32\RP3DAA64.dll
2016-12-23 14:01:58 ----A---- C:\Windows\system32\RltkAPO64.dll
2016-12-23 14:01:58 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2016-12-23 14:01:57 ----A---- C:\Windows\system32\RCoInstII64.dll
2016-12-23 14:01:55 ----A---- C:\Windows\system32\MBWrp64.dll
2016-12-23 14:01:55 ----A---- C:\Windows\system32\drivers\MBfilt64.sys
2016-12-23 14:01:54 ----A---- C:\Windows\SYSWOW64\MBAPO232.dll
2016-12-23 14:01:54 ----A---- C:\Windows\system32\MBAPO264.dll
2016-12-23 14:01:51 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2016-12-23 14:01:49 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-12-23 14:01:47 ----A---- C:\Windows\system32\FMAPO64.dll
2016-12-23 14:01:45 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-12-23 14:01:42 ----A---- C:\Windows\system32\AERTAR64.dll
2016-12-23 14:01:42 ----A---- C:\Windows\system32\AERTAC64.dll
2016-12-23 14:01:27 ----A---- C:\Windows\system32\ibtsiva.exe
2016-12-23 14:01:27 ----A---- C:\Windows\system32\ibtproppage.dll
2016-12-23 14:01:27 ----A---- C:\Windows\system32\drivers\ibtusb.sys
2016-12-23 14:01:16 ----A---- C:\Windows\system32\drivers\iusb3xhc.sys
2016-12-23 14:01:01 ----A---- C:\Windows\SYSWOW64\RsCRIcon.dll
2016-12-23 14:01:01 ----A---- C:\Windows\system32\RtCRX64.dll
2016-12-23 14:01:01 ----A---- C:\Windows\system32\drivers\RtsPer.sys
2016-12-23 14:01:01 ----A---- C:\Windows\RtCRU64.exe
2016-12-23 14:00:31 ----A---- C:\Windows\system32\drivers\IntcDAud.sys
2016-12-23 13:59:45 ----A---- C:\Windows\system32\drivers\iaStorF.sys
2016-12-23 13:59:45 ----A---- C:\Windows\system32\drivers\iaStorA.sys
2016-12-23 13:59:33 ----A---- C:\Windows\system32\drivers\e2xw7x64.sys
2016-12-23 13:52:02 ----D---- C:\ProgramData\ProductData
2016-12-23 13:48:05 ----D---- C:\ProgramData\IObit
2016-12-23 13:48:04 ----A---- C:\Windows\SYSWOW64\drivers\HWiNFO64A.SYS
2016-12-23 13:48:01 ----D---- C:\Users\Honza\AppData\Roaming\IObit
2016-12-23 13:47:47 ----D---- C:\Program Files (x86)\IObit
2016-12-23 13:46:38 ----D---- C:\Torrents
2016-12-23 13:31:26 ----D---- C:\uTorrent
2016-12-23 13:30:07 ----D---- C:\Users\Honza\AppData\Roaming\uTorrent
2016-12-23 13:05:49 ----D---- C:\Program Files\Droid4Xext
2016-12-23 13:05:23 ----DC---- C:\Windows\system32\DRVSTORE
2016-12-23 13:05:23 ----A---- C:\Windows\system32\drivers\VBoxDrv.sys
2016-12-23 13:05:22 ----D---- C:\Program Files\Oracle
2016-12-23 13:04:49 ----A---- C:\hsrv.txt
2016-12-23 13:04:29 ----D---- C:\Program Files (x86)\Droid4X
2016-12-23 12:59:32 ----D---- C:\ProgramData\Thunder Network
2016-12-23 12:59:31 ----D---- C:\Users\Honza\AppData\Roaming\HaiYuInst
2016-12-23 12:32:38 ----D---- C:\Program Files (x86)\Steam
2016-12-23 11:57:10 ----D---- C:\rsit
2016-12-23 11:57:10 ----D---- C:\Program Files\trend micro
2016-12-23 11:50:26 ----A---- C:\Windows\system32\wups2.dll
2016-12-23 11:50:26 ----A---- C:\Windows\system32\wucltux.dll
2016-12-23 11:50:26 ----A---- C:\Windows\system32\wuaueng.dll
2016-12-23 11:50:26 ----A---- C:\Windows\system32\wuauclt.exe
2016-12-23 11:49:52 ----A---- C:\Windows\SYSWOW64\wups.dll
2016-12-23 11:49:52 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2016-12-23 11:49:52 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-12-23 11:49:52 ----A---- C:\Windows\system32\wups.dll
2016-12-23 11:49:52 ----A---- C:\Windows\system32\wudriver.dll
2016-12-23 11:49:52 ----A---- C:\Windows\system32\wuapi.dll
2016-12-23 11:49:41 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2016-12-23 11:49:41 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2016-12-23 11:49:41 ----A---- C:\Windows\system32\wuwebv.dll
2016-12-23 11:49:41 ----A---- C:\Windows\system32\wuapp.exe
2016-12-23 11:35:45 ----D---- C:\Windows\system32\SPReview
2016-12-23 11:35:24 ----D---- C:\Windows\system32\EventProviders
2016-12-23 11:33:47 ----A---- C:\Windows\system32\netfxperf.dll
2016-12-23 11:33:47 ----A---- C:\Windows\system32\mshtml.dll
2016-12-23 11:33:47 ----A---- C:\Windows\system32\dfshim.dll
2016-12-23 11:33:45 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2016-12-23 11:33:41 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2016-12-23 11:33:41 ----A---- C:\Windows\system32\mstscax.dll
2016-12-23 11:33:41 ----A---- C:\Windows\system32\ieframe.dll
2016-12-23 11:33:41 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2016-12-23 11:33:41 ----A---- C:\Windows\system32\d3d10warp.dll
2016-12-23 11:33:40 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-12-23 11:33:39 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-12-23 11:33:39 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2016-12-23 11:33:39 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2016-12-23 11:33:39 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2016-12-23 11:33:38 ----A---- C:\Windows\system32\sysmain.dll
2016-12-23 11:33:38 ----A---- C:\Windows\system32\drivers\tcpip.sys
2016-12-23 11:33:37 ----A---- C:\Windows\system32\XpsPrint.dll
2016-12-23 11:33:37 ----A---- C:\Windows\system32\wmp.dll
2016-12-23 11:33:37 ----A---- C:\Windows\system32\tquery.dll
2016-12-23 11:33:37 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-12-23 11:33:35 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2016-12-23 11:33:35 ----A---- C:\Windows\system32\secproc_isv.dll
2016-12-23 11:33:35 ----A---- C:\Windows\system32\ntdll.dll
2016-12-23 11:33:35 ----A---- C:\Windows\system32\mssrch.dll
2016-12-23 11:33:35 ----A---- C:\Windows\system32\mscoree.dll
2016-12-23 11:33:35 ----A---- C:\Windows\system32\mmcndmgr.dll
2016-12-23 11:33:35 ----A---- C:\Windows\system32\mf.dll
2016-12-23 11:33:35 ----A---- C:\Windows\system32\d2d1.dll
2016-12-23 11:33:34 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2016-12-23 11:33:34 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2016-12-23 11:33:34 ----A---- C:\Windows\system32\xpsservices.dll
2016-12-23 11:33:34 ----A---- C:\Windows\system32\secproc.dll
2016-12-23 11:33:34 ----A---- C:\Windows\system32\RMActivate_isv.exe
2016-12-23 11:33:34 ----A---- C:\Windows\system32\RMActivate.exe
2016-12-23 11:33:33 ----A---- C:\Windows\SYSWOW64\secproc.dll
2016-12-23 11:33:33 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2016-12-23 11:33:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-12-23 11:33:33 ----A---- C:\Windows\system32\rpcrt4.dll
2016-12-23 11:33:33 ----A---- C:\Windows\system32\jscript.dll
2016-12-23 11:33:32 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2016-12-23 11:33:32 ----A---- C:\Windows\system32\schedsvc.dll
2016-12-23 11:33:31 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\wininet.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\wevtsvc.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\urlmon.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\taskschd.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\spwizui.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\RacEngn.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\ole32.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\iertutil.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\esent.dll
2016-12-23 11:33:31 ----A---- C:\Windows\system32\drivers\ntfs.sys
2016-12-23 11:33:31 ----A---- C:\Windows\system32\diagperf.dll
2016-12-23 11:33:30 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-12-23 11:33:30 ----A---- C:\Windows\system32\vssapi.dll
2016-12-23 11:33:30 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-12-23 11:33:29 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-12-23 11:33:29 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2016-12-23 11:33:29 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-12-23 11:33:29 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2016-12-23 11:33:29 ----A---- C:\Windows\system32\UIRibbon.dll
2016-12-23 11:33:29 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2016-12-23 11:33:29 ----A---- C:\Windows\system32\msxml3.dll
2016-12-23 11:33:29 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2016-12-23 11:33:29 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2016-12-23 11:33:29 ----A---- C:\Windows\explorer.exe
2016-12-23 11:33:28 ----A---- C:\Windows\system32\win32k.sys
2016-12-23 11:33:27 ----A---- C:\Windows\SYSWOW64\esent.dll
2016-12-23 11:33:27 ----A---- C:\Windows\system32\WsmSvc.dll
2016-12-23 11:33:26 ----A---- C:\Windows\system32\WMVCORE.DLL
2016-12-23 11:33:25 ----A---- C:\Windows\SYSWOW64\tquery.dll
2016-12-23 11:33:25 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2016-12-23 11:33:25 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2016-12-23 11:33:25 ----A---- C:\Windows\system32\WMVDECOD.DLL
2016-12-23 11:33:25 ----A---- C:\Windows\system32\WinSAT.exe
2016-12-23 11:33:25 ----A---- C:\Windows\system32\spreview.exe
2016-12-23 11:33:25 ----A---- C:\Windows\system32\spinstall.exe
2016-12-23 11:33:25 ----A---- C:\Windows\system32\rdpdd.dll
2016-12-23 11:33:25 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2016-12-23 11:33:25 ----A---- C:\Windows\system32\PresentationHost.exe
2016-12-23 11:33:25 ----A---- C:\Windows\system32\MPSSVC.dll
2016-12-23 11:33:25 ----A---- C:\Windows\system32\DWrite.dll
2016-12-23 11:33:25 ----A---- C:\Windows\system32\CPFilters.dll
2016-12-23 11:33:25 ----A---- C:\Windows\system32\CertEnroll.dll
2016-12-23 11:33:24 ----A---- C:\Windows\system32\d3d9.dll
2016-12-23 11:33:23 ----A---- C:\Windows\SYSWOW64\RacEngn.dll
2016-12-23 11:33:23 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2016-12-23 11:33:23 ----A---- C:\Windows\system32\SearchFolder.dll
2016-12-23 11:33:23 ----A---- C:\Windows\system32\msxml6.dll
2016-12-23 11:33:23 ----A---- C:\Windows\system32\kerberos.dll
2016-12-23 11:33:23 ----A---- C:\Windows\system32\IKEEXT.DLL
2016-12-23 11:33:23 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2016-12-23 11:33:22 ----A---- C:\Windows\system32\VSSVC.exe
2016-12-23 11:33:22 ----A---- C:\Windows\system32\kernel32.dll
2016-12-23 11:33:22 ----A---- C:\Windows\system32\gpsvc.dll
2016-12-23 11:33:22 ----A---- C:\Windows\system32\FntCache.dll
2016-12-23 11:33:21 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-12-23 11:33:21 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-12-23 11:33:21 ----A---- C:\Windows\system32\mstime.dll
2016-12-23 11:33:21 ----A---- C:\Windows\system32\dwmcore.dll
2016-12-23 11:33:21 ----A---- C:\Windows\system32\drivers\ndis.sys
2016-12-23 11:33:21 ----A---- C:\Windows\system32\drivers\http.sys
2016-12-23 11:33:21 ----A---- C:\Windows\system32\drivers\afd.sys
2016-12-23 11:33:21 ----A---- C:\Windows\system32\dbgeng.dll
2016-12-23 11:33:21 ----A---- C:\Windows\system32\crypt32.dll
2016-12-23 11:33:21 ----A---- C:\Windows\system32\actxprxy.dll
2016-12-23 11:33:20 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-12-23 11:33:19 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\TSWorkspace.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\termsrv.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\sqmapi.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\schannel.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\qmgr.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\mstsc.exe
2016-12-23 11:33:19 ----A---- C:\Windows\system32\lsasrv.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\KernelBase.dll
2016-12-23 11:33:19 ----A---- C:\Windows\system32\drivers\srv2.sys
2016-12-23 11:33:19 ----A---- C:\Windows\system32\drivers\srv.sys
2016-12-23 11:33:19 ----A---- C:\Windows\system32\audiosrv.dll
2016-12-23 11:33:18 ----A---- C:\Windows\SYSWOW64\vssapi.dll
2016-12-23 11:33:18 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2016-12-23 11:33:18 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-12-23 11:33:18 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-12-23 11:33:18 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2016-12-23 11:33:18 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2016-12-23 11:33:18 ----A---- C:\Windows\system32\winhttp.dll
2016-12-23 11:33:18 ----A---- C:\Windows\system32\QAGENTRT.DLL
2016-12-23 11:33:18 ----A---- C:\Windows\system32\propsys.dll
2016-12-23 11:33:18 ----A---- C:\Windows\system32\netlogon.dll
2016-12-23 11:33:18 ----A---- C:\Windows\system32\msv1_0.dll