Jeden den poo přeinstalování počítače mám v procesech havěť
Napsal: 08 led 2017 12:04
Prosím o radu a případně pomoc..
jeden den po přeinstalování notebooku mi v procesech řádí prográmky
atieclxx.exe
csrss.exe
winlogon.exe.
Počítač je jak kdyby měl chřipku a vleče se.. procesor počítá jak nikdy.
Děkuji moc za případnou pomoc a nebo třeba i radu v čem dělám při instalaci chybu, nebo jaký Antivir případně Firewall.. AMD Catalyst control center stažen ze stránek Lenovo.
díííky
P. S. Nejsem si jist, ale myslím, že se to tam objevilo po istalaci
Tady Log
Logfile of random's system information tool 1.10 (written by random/random)
Run by Defeld at 2017-01-08 11:55:06
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 208 GB (82%) free of 254 GB
Total RAM: 7132 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:55:14, on 8.1.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17041)
Boot mode: Normal
Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Users\Defeld\AppData\Local\Viber\Viber.exe
C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\trend micro\Defeld.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Viber] "C:\Users\Defeld\AppData\Local\Viber\Viber.exe" StartMinimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\Windows\SysWOW64\tbaseprovisioning.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6858 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\SysWOW64\tbaseprovisioning.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\Elantech\ETDService.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe"
"C:\Users\Defeld\AppData\Local\Viber\Viber.exe" StartMinimized
"C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Stardock\ObjectDockPlus2\Dock64.exe"
"C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDockTray.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Elantech\ETDIntelligent.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
taskmgr.exe /3
"C:\Program Files\Mozilla Firefox\firefox.exe"
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\notepad.exe"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Defeld\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS.exe
C:\Windows\tasks\AutoKMSDaily.job - C:\Windows\AutoKMS.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Defeld\AppData\Roaming\Mozilla\Firefox\Profiles\6yl39iso.default-1483843057778
prefs.js - "browser.startup.homepage" - "http://seznam.cz/"
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 24.0.0.186 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 24.0.0.186 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14 81024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-01-06 790552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-01-06 664848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\Windows\RTFTrack.exe [2017-01-06 5158144]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2015-01-13 3315896]
"Malwarebytes TrayApp"=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2016-12-14 2776528]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Viber"=C:\Users\Defeld\AppData\Local\Viber\Viber.exe [2016-04-13 69268048]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2017-01-06 9080768]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-02-02 767176]
C:\Users\Defeld\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Stardock ObjectDock.lnk - C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files (x86)\Stardock\ObjectDockPlus2\ODMenu64.dll [2010-03-24 633200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-01-08 11:55:07 ----D---- C:\Program Files\trend micro
2017-01-08 11:55:06 ----D---- C:\rsit
2017-01-08 10:08:50 ----D---- C:\Users\Defeld\AppData\Roaming\VS Revo Group
2017-01-08 04:42:04 ----D---- C:\Users\Defeld\AppData\Roaming\Macromedia
2017-01-08 03:32:44 ----D---- C:\Users\Defeld\AppData\Roaming\ATI
2017-01-08 03:32:44 ----D---- C:\ProgramData\ATI
2017-01-08 02:52:10 ----A---- C:\Windows\system32\drivers\MBAMChameleon.sys
2017-01-08 02:51:55 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-01-08 02:51:55 ----A---- C:\Windows\system32\drivers\farflt.sys
2017-01-08 02:51:47 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-01-08 02:51:38 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-01-08 02:51:19 ----A---- C:\Windows\system32\drivers\mbae64.sys
2017-01-08 02:51:11 ----D---- C:\ProgramData\Malwarebytes
2017-01-08 02:51:11 ----D---- C:\Program Files\Malwarebytes
2017-01-08 02:13:30 ----D---- C:\Program Files (x86)\AMD AVT
2017-01-08 02:12:51 ----D---- C:\ProgramData\AMD
2017-01-08 02:11:20 ----D---- C:\Program Files (x86)\AMD
2017-01-07 23:48:39 ----D---- C:\Program Files (x86)\Adobe
2017-01-07 23:47:42 ----A---- C:\Windows\IsUninst.exe
2017-01-07 22:43:03 ----D---- C:\AdwCleaner
2017-01-07 01:44:09 ----D---- C:\ProgramData\Synology
2017-01-07 01:44:07 ----D---- C:\Program Files (x86)\Synology
2017-01-06 21:53:24 ----HD---- C:\ProgramData\CanonBJ
2017-01-06 21:52:46 ----A---- C:\Windows\system32\CNMLMBL.DLL
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNHMCA6.dll
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNC_BLL.dll
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNC_BLI.dll
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNC_BLC.dll
2017-01-06 21:52:25 ----HD---- C:\ProgramData\CanonIJFAX
2017-01-06 21:52:19 ----A---- C:\Windows\system32\CNCALBL.DLL
2017-01-06 20:19:48 ----D---- C:\Users\Defeld\AppData\Roaming\WinRAR
2017-01-06 19:13:46 ----A---- C:\Windows\AutoKMS.ini
2017-01-06 18:58:42 ----D---- C:\Program Files\Common Files\DESIGNER
2017-01-06 18:58:23 ----D---- C:\Windows\PCHEALTH
2017-01-06 18:56:42 ----D---- C:\Program Files\Microsoft Analysis Services
2017-01-06 18:56:42 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2017-01-06 18:56:32 ----D---- C:\Program Files (x86)\Microsoft Office
2017-01-06 18:56:31 ----D---- C:\ProgramData\Microsoft Help
2017-01-06 18:56:31 ----D---- C:\Program Files\Microsoft Office
2017-01-06 18:56:20 ----RHD---- C:\MSOCache
2017-01-06 18:45:14 ----D---- C:\Users\Defeld\AppData\Roaming\Stardock
2017-01-06 18:44:52 ----HDC---- C:\ProgramData\{0F4A7EFE-5950-4389-BF36-1E625D72456B}
2017-01-06 18:44:51 ----D---- C:\ProgramData\Stardock
2017-01-06 18:44:49 ----D---- C:\Program Files (x86)\Stardock
2017-01-06 18:13:15 ----A---- C:\Windows\SYSWOW64\detoured.dll
2017-01-06 18:13:15 ----A---- C:\Windows\SYSWOW64\atieah32.exe
2017-01-06 18:13:15 ----A---- C:\Windows\system32\detoured.dll
2017-01-06 18:13:15 ----A---- C:\Windows\system32\atieah64.exe
2017-01-06 18:13:07 ----A---- C:\Windows\SYSWOW64\amdgfxinfo32.dll
2017-01-06 18:13:07 ----A---- C:\Windows\system32\ativvaxy_FJ_nd.dat
2017-01-06 18:13:07 ----A---- C:\Windows\system32\ativvaxy_FJ.dat
2017-01-06 18:13:07 ----A---- C:\Windows\system32\amdgfxinfo64.dll
2017-01-06 18:04:27 ----D---- C:\Program Files\Elantech
2017-01-06 18:03:55 ----D---- C:\drivers
2017-01-06 17:19:26 ----D---- C:\Users\Defeld\AppData\Roaming\TeamViewer
2017-01-06 17:14:21 ----D---- C:\Program Files (x86)\TeamViewer
2017-01-06 16:36:53 ----D---- C:\Windows\SYSWOW64\sda
2017-01-06 15:42:37 ----D---- C:\Users\Defeld\AppData\Roaming\AMD
2017-01-06 15:42:33 ----D---- C:\Users\Defeld\AppData\Roaming\ViberPC
2017-01-06 15:38:41 ----D---- C:\Users\Defeld\AppData\Roaming\ACD Systems
2017-01-06 15:36:47 ----D---- C:\ProgramData\ACD Systems
2017-01-06 15:36:42 ----D---- C:\Program Files\Common Files\ACD Systems
2017-01-06 15:36:42 ----D---- C:\Program Files\ACD Systems
2017-01-06 15:32:07 ----D---- C:\Windows\IObit
2017-01-06 15:31:41 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-01-06 15:28:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-01-06 15:27:58 ----D---- C:\Windows\system32\Macromed
2017-01-06 15:27:55 ----D---- C:\Windows\SYSWOW64\Macromed
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\XAudio2_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\xactengine3_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\system32\d3dx11_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\system32\d3dx10_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\system32\d3dcsx_43.dll
2017-01-06 15:27:41 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2017-01-06 15:27:41 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2017-01-06 15:27:41 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2017-01-06 15:27:41 ----A---- C:\Windows\system32\XAudio2_6.dll
2017-01-06 15:27:41 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2017-01-06 15:27:41 ----A---- C:\Windows\system32\D3DX9_43.dll
2017-01-06 15:27:40 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2017-01-06 15:27:40 ----A---- C:\Windows\system32\xactengine3_6.dll
2017-01-06 15:27:39 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2017-01-06 15:27:39 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2017-01-06 15:27:38 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2017-01-06 15:27:38 ----A---- C:\Windows\system32\XAudio2_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\system32\xactengine3_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\system32\d3dx11_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\system32\d3dcsx_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2017-01-06 15:27:36 ----A---- C:\Windows\system32\D3DX9_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\system32\d3dx10_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\system32\D3DX9_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\system32\d3dx10_41.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\XAudio2_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\xactengine3_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2017-01-06 15:27:33 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\system32\D3DX9_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\system32\d3dx10_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2017-01-06 15:27:32 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2017-01-06 15:27:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2017-01-06 15:27:32 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2017-01-06 15:27:32 ----A---- C:\Windows\system32\XAudio2_3.dll
2017-01-06 15:27:32 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2017-01-06 15:27:32 ----A---- C:\Windows\system32\xactengine3_3.dll
2017-01-06 15:27:31 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2017-01-06 15:27:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2017-01-06 15:27:31 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2017-01-06 15:27:31 ----A---- C:\Windows\system32\XAudio2_2.dll
2017-01-06 15:27:31 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2017-01-06 15:27:31 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2017-01-06 15:27:30 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2017-01-06 15:27:30 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2017-01-06 15:27:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2017-01-06 15:27:30 ----A---- C:\Windows\system32\xactengine3_2.dll
2017-01-06 15:27:30 ----A---- C:\Windows\system32\d3dx10_39.dll
2017-01-06 15:27:30 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2017-01-06 15:27:29 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2017-01-06 15:27:29 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2017-01-06 15:27:29 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2017-01-06 15:27:29 ----A---- C:\Windows\system32\XAudio2_1.dll
2017-01-06 15:27:29 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2017-01-06 15:27:29 ----A---- C:\Windows\system32\D3DX9_39.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\xactengine3_1.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\d3dx10_38.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2017-01-06 15:27:27 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2017-01-06 15:27:27 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2017-01-06 15:27:27 ----A---- C:\Windows\system32\XAudio2_0.dll
2017-01-06 15:27:27 ----A---- C:\Windows\system32\D3DX9_38.dll
2017-01-06 15:27:26 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2017-01-06 15:27:26 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2017-01-06 15:27:26 ----A---- C:\Windows\system32\xactengine3_0.dll
2017-01-06 15:27:26 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2017-01-06 15:27:25 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\system32\d3dx10_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2017-01-06 15:27:24 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2017-01-06 15:27:24 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2017-01-06 15:27:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2017-01-06 15:27:24 ----A---- C:\Windows\system32\xactengine2_10.dll
2017-01-06 15:27:24 ----A---- C:\Windows\system32\d3dx10_36.dll
2017-01-06 15:27:24 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2017-01-06 15:27:23 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2017-01-06 15:27:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2017-01-06 15:27:22 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2017-01-06 15:27:22 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2017-01-06 15:27:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2017-01-06 15:27:22 ----A---- C:\Windows\system32\xactengine2_9.dll
2017-01-06 15:27:22 ----A---- C:\Windows\system32\d3dx10_35.dll
2017-01-06 15:27:22 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2017-01-06 15:27:21 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2017-01-06 15:27:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2017-01-06 15:27:21 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2017-01-06 15:27:21 ----A---- C:\Windows\system32\xactengine2_8.dll
2017-01-06 15:27:21 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2017-01-06 15:27:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2017-01-06 15:27:20 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\system32\d3dx10_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\xinput1_3.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\xactengine2_7.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2017-01-06 15:27:18 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2017-01-06 15:27:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2017-01-06 15:27:17 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2017-01-06 15:27:17 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2017-01-06 15:27:17 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2017-01-06 15:27:17 ----A---- C:\Windows\system32\xactengine2_6.dll
2017-01-06 15:27:17 ----A---- C:\Windows\system32\xactengine2_5.dll
2017-01-06 15:27:17 ----A---- C:\Windows\system32\d3dx10.dll
2017-01-06 15:27:16 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2017-01-06 15:27:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2017-01-06 15:27:16 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2017-01-06 15:27:16 ----A---- C:\Windows\system32\xactengine2_4.dll
2017-01-06 15:27:16 ----A---- C:\Windows\system32\x3daudio1_1.dll
2017-01-06 15:27:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2017-01-06 15:27:15 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2017-01-06 15:27:15 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2017-01-06 15:27:15 ----A---- C:\Windows\system32\xactengine2_3.dll
2017-01-06 15:27:15 ----A---- C:\Windows\system32\d3dx9_31.dll
2017-01-06 15:27:14 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2017-01-06 15:27:14 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2017-01-06 15:27:14 ----A---- C:\Windows\system32\xinput1_2.dll
2017-01-06 15:27:14 ----A---- C:\Windows\system32\xactengine2_2.dll
2017-01-06 15:27:13 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2017-01-06 15:27:13 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2017-01-06 15:27:13 ----A---- C:\Windows\system32\xinput1_1.dll
2017-01-06 15:27:13 ----A---- C:\Windows\system32\xactengine2_1.dll
2017-01-06 15:27:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2017-01-06 15:27:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2017-01-06 15:27:09 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2017-01-06 15:27:09 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2017-01-06 15:27:09 ----A---- C:\Windows\system32\xactengine2_0.dll
2017-01-06 15:27:09 ----A---- C:\Windows\system32\x3daudio1_0.dll
2017-01-06 15:27:08 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2017-01-06 15:27:08 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2017-01-06 15:27:08 ----A---- C:\Windows\system32\d3dx9_29.dll
2017-01-06 15:27:08 ----A---- C:\Windows\system32\d3dx9_28.dll
2017-01-06 15:27:07 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2017-01-06 15:27:07 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2017-01-06 15:27:07 ----A---- C:\Windows\system32\d3dx9_27.dll
2017-01-06 15:27:07 ----A---- C:\Windows\system32\d3dx9_26.dll
2017-01-06 15:27:06 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2017-01-06 15:27:06 ----A---- C:\Windows\system32\d3dx9_25.dll
2017-01-06 15:27:05 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2017-01-06 15:27:05 ----A---- C:\Windows\system32\d3dx9_24.dll
2017-01-06 15:25:38 ----D---- C:\ProgramData\Package Cache
2017-01-06 15:22:44 ----A---- C:\Windows\system32\RtNicProp64.dll
2017-01-06 15:22:44 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2017-01-06 15:22:20 ----A---- C:\Windows\SYSWOW64\RsCRIcon.dll
2017-01-06 15:22:20 ----A---- C:\Windows\system32\RtCRX64.dll
2017-01-06 15:22:20 ----A---- C:\Windows\system32\drivers\RtsUer.sys
2017-01-06 15:22:20 ----A---- C:\Windows\RtCRU64.exe
2017-01-06 15:21:51 ----A---- C:\Windows\system32\drivers\rtsuvc.sys
2017-01-06 15:21:50 ----A---- C:\Windows\SYSWOW64\RtCamP.dll
2017-01-06 15:21:50 ----A---- C:\Windows\SYSWOW64\RsDecode.dll
2017-01-06 15:21:50 ----A---- C:\Windows\system32\RtCamP64.dll
2017-01-06 15:21:50 ----A---- C:\Windows\system32\RtCamO64.dll
2017-01-06 15:21:50 ----A---- C:\Windows\RTFTrack.exe
2017-01-06 15:21:23 ----A---- C:\Windows\system32\drivers\athrx.sys
2017-01-06 15:20:51 ----D---- C:\Program Files\Common Files\Atheros
2017-01-06 15:20:05 ----A---- C:\Windows\system32\drivers\btfilter.sys
2017-01-06 15:20:05 ----A---- C:\Windows\system32\BtContextMenu.dll
2017-01-06 15:20:05 ----A---- C:\Windows\system32\btcoinst.dll
2017-01-06 15:19:40 ----D---- C:\ProgramData\Conexant
2017-01-06 15:19:39 ----D---- C:\Program Files\CONEXANT
2017-01-06 15:19:30 ----A---- C:\Windows\system32\UCI64A52.DLL
2017-01-06 15:19:30 ----A---- C:\Windows\system32\FMAPO64.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEP64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEL64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEG64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EED64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEA64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\drivers\Mixer.ini
2017-01-06 15:19:30 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CxPageMaster64.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CX64BP07.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CX64AP86.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CSpkExt64.dll
2017-01-06 14:57:23 ----D---- C:\Program Files\Mozilla Firefox
2017-01-06 14:39:23 ----D---- C:\Users\Defeld\AppData\Roaming\Thunderbird
2017-01-06 14:38:36 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2017-01-06 14:33:19 ----D---- C:\Program Files\WinRAR
2017-01-06 14:22:31 ----D---- C:\Users\Defeld\AppData\Roaming\Mozilla
2017-01-06 14:22:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-06 14:17:14 ----D---- C:\Users\Defeld\AppData\Roaming\AVAST Software
2017-01-06 14:16:51 ----D---- C:\Program Files\Common Files\AV
2017-01-06 14:16:44 ----A---- C:\Windows\system32\drivers\aswvmm.sys
2017-01-06 14:16:44 ----A---- C:\Windows\system32\drivers\aswStm.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswsp.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswsnx.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-01-06 14:16:38 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2017-01-06 14:16:38 ----A---- C:\Windows\system32\aswBoot.exe
2017-01-06 14:16:37 ----A---- C:\Windows\system32\ucrtbase.dll
2017-01-06 14:16:32 ----A---- C:\Windows\avastSS.scr
2017-01-06 14:15:10 ----D---- C:\Program Files\AVAST Software
2017-01-06 14:14:31 ----D---- C:\ProgramData\AVAST Software
2017-01-06 14:12:53 ----D---- C:\ProgramData\VS Revo Group
2017-01-06 14:12:52 ----A---- C:\Windows\system32\drivers\revoflt.sys
2017-01-06 14:12:51 ----D---- C:\Program Files\VS Revo Group
2017-01-06 13:33:59 ----D---- C:\Windows\tbaseregistry
2017-01-06 13:33:59 ----A---- C:\Windows\SYSWOW64\IEShims.dll
2017-01-06 13:28:50 ----D---- C:\ProgramData\ProductData
2017-01-06 13:28:22 ----D---- C:\Users\Defeld\AppData\Roaming\IObit
2017-01-06 13:28:22 ----D---- C:\ProgramData\IObit
2017-01-06 13:28:22 ----A---- C:\Windows\SYSWOW64\drivers\HWiNFO64A.SYS
2017-01-06 13:28:18 ----D---- C:\Program Files (x86)\IObit
2017-01-06 13:22:56 ----D---- C:\Users\Defeld\AppData\Roaming\Adobe
2017-01-06 13:22:45 ----D---- C:\Users\Defeld\AppData\Roaming\Identities
2017-01-06 13:08:33 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-01-06 13:06:46 ----D---- C:\Program Files (x86)\Microsoft.NET
2017-01-06 13:06:45 ----D---- C:\Windows\Migration
2017-01-06 13:06:25 ----SHD---- C:\Windows\Installer
2017-01-06 13:04:05 ----D---- C:\Program Files\Common Files\ATI Technologies
2017-01-06 13:03:46 ----D---- C:\Program Files\AMD
2017-01-06 13:02:36 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2017-01-06 13:02:36 ----A---- C:\Windows\system32\poqexec.exe
2017-01-06 13:02:32 ----DC---- C:\Windows\system32\DRVSTORE
2017-01-06 13:01:38 ----SD---- C:\Users\Defeld\AppData\Roaming\Microsoft
2017-01-06 13:01:38 ----D---- C:\Users\Defeld\AppData\Roaming\Media Center Programs
2017-01-06 13:01:28 ----SHD---- C:\Recovery
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Šablony
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Plocha
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Oblíbené položky
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Nabídka Start
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Dokumenty
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Data aplikací
2017-01-06 12:53:33 ----D---- C:\Windows\SoftwareDistribution
2017-01-06 12:51:24 ----D---- C:\Windows\Prefetch
2017-01-06 12:50:31 ----ASH---- C:\pagefile.sys
2017-01-06 12:50:31 ----ASH---- C:\hiberfil.sys
2017-01-06 12:39:54 ----SHD---- C:\System Volume Information
2017-01-06 12:39:22 ----D---- C:\Windows\Panther
======List of files/folders modified in the last 1 month======
2017-01-08 11:55:07 ----RD---- C:\Program Files
2017-01-08 11:41:09 ----D---- C:\Windows\system32\config
2017-01-08 11:40:39 ----D---- C:\Windows\system32\Tasks
2017-01-08 11:27:34 ----D---- C:\Windows\system32\wdi
2017-01-08 11:24:57 ----D---- C:\Windows\Temp
2017-01-08 11:05:00 ----D---- C:\Windows\system32\drivers
2017-01-08 10:17:16 ----D---- C:\Windows
2017-01-08 10:00:34 ----D---- C:\Windows\Microsoft.NET
2017-01-08 05:59:43 ----D---- C:\Windows\Tasks
2017-01-08 03:32:44 ----HD---- C:\ProgramData
2017-01-08 03:22:56 ----D---- C:\Windows\System32
2017-01-08 03:22:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-01-08 03:22:55 ----D---- C:\Windows\inf
2017-01-08 02:15:16 ----D---- C:\Windows\SysWOW64
2017-01-08 02:14:48 ----D---- C:\Windows\system32\catroot
2017-01-08 02:13:45 ----D---- C:\Windows\system32\DriverStore
2017-01-08 02:13:30 ----RD---- C:\Program Files (x86)
2017-01-08 02:13:30 ----D---- C:\Program Files (x86)\Common Files
2017-01-08 02:11:14 ----D---- C:\Windows\system32\catroot2
2017-01-06 22:57:04 ----SD---- C:\ProgramData\Microsoft
2017-01-06 19:51:52 ----D---- C:\Windows\Logs
2017-01-06 18:59:37 ----RSD---- C:\Windows\assembly
2017-01-06 18:59:36 ----D---- C:\Windows\winsxs
2017-01-06 18:58:47 ----RSD---- C:\Windows\Fonts
2017-01-06 18:58:42 ----D---- C:\Program Files\Common Files
2017-01-06 18:58:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2017-01-06 18:56:50 ----D---- C:\Windows\ShellNew
2017-01-06 17:13:25 ----D---- C:\Windows\system32\LogFiles
2017-01-06 15:22:44 ----A---- C:\Windows\system32\RTNUninst64.dll
2017-01-06 13:28:22 ----D---- C:\Windows\SYSWOW64\drivers
2017-01-06 13:22:43 ----SHD---- C:\$Recycle.Bin
2017-01-06 13:07:58 ----D---- C:\Windows\twain_32
2017-01-06 13:07:51 ----D---- C:\Windows\system32\CodeIntegrity
2017-01-06 13:06:48 ----D---- C:\Windows\SYSWOW64\en-US
2017-01-06 13:06:48 ----D---- C:\Windows\system32\en-US
2017-01-06 13:02:03 ----D---- C:\Windows\system32\restore
2017-01-06 13:01:38 ----RD---- C:\Users
2017-01-06 13:01:28 ----D---- C:\Windows\system32\Recovery
2017-01-06 13:01:28 ----D---- C:\Program Files\Windows NT
2017-01-06 13:00:37 ----D---- C:\Windows\rescache
2017-01-06 13:00:22 ----D---- C:\Windows\debug
2017-01-06 12:54:51 ----D---- C:\Windows\system32\drivers\UMDF
2017-01-06 12:54:30 ----D---- C:\Windows\system32\sysprep
2017-01-06 12:51:19 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2014-09-24 83656]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2014-09-24 43720]
R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2014-10-28 62152]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2017-01-06 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2017-01-06 293352]
R0 MBAMSwissArmy;MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [2017-01-08 250816]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2014-06-08 213848]
R1 amdpsp;AMD PSP 1.0 Service; C:\Windows\system32\DRIVERS\amdpsp.sys [2014-02-24 233672]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-01-06 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-01-06 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-01-06 969184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-01-06 513632]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2014-06-08 516096]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Windows\system32\drivers\mbae64.sys [2016-12-14 77416]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2017-01-06 26528]
R1 MBAMChameleon;MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [2017-01-08 176064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-06-08 60416]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-01-06 108816]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-01-06 163416]
R3 amdhub30;AMD USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\amdhub30.sys [2015-01-21 108256]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-02-02 18977792]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-02-02 591872]
R3 amdxhc;AMD USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\amdxhc.sys [2015-01-21 229088]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2017-01-06 4172536]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-12-21 94720]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2017-01-06 609992]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2014-06-08 80384]
R3 busenum;Synology Virtual USB Hub; C:\Windows\system32\DRIVERS\busenum.sys [2012-08-03 55776]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2017-01-06 1700568]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2015-01-13 443064]
R3 MBAMFarflt;MBAMFarflt; \??\C:\Windows\system32\drivers\farflt.sys [2017-01-08 102856]
R3 MBAMProtection;MBAMProtection; \??\C:\Windows\system32\drivers\mbam.sys [2017-01-08 43968]
R3 MBAMWebProtection;MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [2017-01-08 81696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2017-01-06 1037832]
R3 RTSUER;Realtek USB Card Reader - UER; C:\Windows\system32\Drivers\RtsUer.sys [2017-01-06 418784]
R3 rtsuvc;EasyCamera; C:\Windows\system32\DRIVERS\rtsuvc.sys [2017-01-06 3127552]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S2 APXACC;AppEx Networks Accelerator LWF; C:\Windows\system32\DRIVERS\appexDrv.sys []
S3 amdkmcsp;AMD Kernel Mode CSP Service; C:\Windows\system32\DRIVERS\amdkmcsp.sys [2014-02-24 81096]
S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2017-01-06 37656]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2014-06-08 552960]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-06-08 19456]
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 31800]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2014-02-27 331992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2014-06-08 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-06-08 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-06-08 29696]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2014-06-08 42496]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-02-02 246272]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-01-06 197128]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2014-06-08 27136]
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2015-01-13 102072]
R2 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2016-12-14 4317648]
R2 tbaseprovisioning;tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [2014-02-24 51712]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2015-04-09 5261584]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2014-06-08 27136]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-08 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-01-06 198088]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2014-06-08 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2014-06-08 27136]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-02-02 344064]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 UsbClientService;UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [2016-03-18 248840]
-----------------EOF-----------------
jeden den po přeinstalování notebooku mi v procesech řádí prográmky
atieclxx.exe
csrss.exe
winlogon.exe.
Počítač je jak kdyby měl chřipku a vleče se.. procesor počítá jak nikdy.
Děkuji moc za případnou pomoc a nebo třeba i radu v čem dělám při instalaci chybu, nebo jaký Antivir případně Firewall.. AMD Catalyst control center stažen ze stránek Lenovo.
díííky
P. S. Nejsem si jist, ale myslím, že se to tam objevilo po istalaci
Tady Log
Logfile of random's system information tool 1.10 (written by random/random)
Run by Defeld at 2017-01-08 11:55:06
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 208 GB (82%) free of 254 GB
Total RAM: 7132 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:55:14, on 8.1.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17041)
Boot mode: Normal
Running processes:
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Users\Defeld\AppData\Local\Viber\Viber.exe
C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\trend micro\Defeld.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Viber] "C:\Users\Defeld\AppData\Local\Viber\Viber.exe" StartMinimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\Windows\SysWOW64\tbaseprovisioning.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6858 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\SysWOW64\tbaseprovisioning.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\Elantech\ETDService.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe"
"C:\Users\Defeld\AppData\Local\Viber\Viber.exe" StartMinimized
"C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Stardock\ObjectDockPlus2\Dock64.exe"
"C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDockTray.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Elantech\ETDIntelligent.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
taskmgr.exe /3
"C:\Program Files\Mozilla Firefox\firefox.exe"
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\notepad.exe"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Defeld\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job - C:\Windows\AutoKMS.exe
C:\Windows\tasks\AutoKMSDaily.job - C:\Windows\AutoKMS.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Defeld\AppData\Roaming\Mozilla\Firefox\Profiles\6yl39iso.default-1483843057778
prefs.js - "browser.startup.homepage" - "http://seznam.cz/"
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 24.0.0.186 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 24.0.0.186 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14 81024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-01-06 790552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-01-06 664848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\Windows\RTFTrack.exe [2017-01-06 5158144]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2015-01-13 3315896]
"Malwarebytes TrayApp"=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2016-12-14 2776528]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Viber"=C:\Users\Defeld\AppData\Local\Viber\Viber.exe [2016-04-13 69268048]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2017-01-06 9080768]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-02-02 767176]
C:\Users\Defeld\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Stardock ObjectDock.lnk - C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program Files (x86)\Stardock\ObjectDockPlus2\ODMenu64.dll [2010-03-24 633200]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-01-08 11:55:07 ----D---- C:\Program Files\trend micro
2017-01-08 11:55:06 ----D---- C:\rsit
2017-01-08 10:08:50 ----D---- C:\Users\Defeld\AppData\Roaming\VS Revo Group
2017-01-08 04:42:04 ----D---- C:\Users\Defeld\AppData\Roaming\Macromedia
2017-01-08 03:32:44 ----D---- C:\Users\Defeld\AppData\Roaming\ATI
2017-01-08 03:32:44 ----D---- C:\ProgramData\ATI
2017-01-08 02:52:10 ----A---- C:\Windows\system32\drivers\MBAMChameleon.sys
2017-01-08 02:51:55 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-01-08 02:51:55 ----A---- C:\Windows\system32\drivers\farflt.sys
2017-01-08 02:51:47 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-01-08 02:51:38 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-01-08 02:51:19 ----A---- C:\Windows\system32\drivers\mbae64.sys
2017-01-08 02:51:11 ----D---- C:\ProgramData\Malwarebytes
2017-01-08 02:51:11 ----D---- C:\Program Files\Malwarebytes
2017-01-08 02:13:30 ----D---- C:\Program Files (x86)\AMD AVT
2017-01-08 02:12:51 ----D---- C:\ProgramData\AMD
2017-01-08 02:11:20 ----D---- C:\Program Files (x86)\AMD
2017-01-07 23:48:39 ----D---- C:\Program Files (x86)\Adobe
2017-01-07 23:47:42 ----A---- C:\Windows\IsUninst.exe
2017-01-07 22:43:03 ----D---- C:\AdwCleaner
2017-01-07 01:44:09 ----D---- C:\ProgramData\Synology
2017-01-07 01:44:07 ----D---- C:\Program Files (x86)\Synology
2017-01-06 21:53:24 ----HD---- C:\ProgramData\CanonBJ
2017-01-06 21:52:46 ----A---- C:\Windows\system32\CNMLMBL.DLL
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNHMCA6.dll
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNC_BLL.dll
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNC_BLI.dll
2017-01-06 21:52:29 ----A---- C:\Windows\system32\CNC_BLC.dll
2017-01-06 21:52:25 ----HD---- C:\ProgramData\CanonIJFAX
2017-01-06 21:52:19 ----A---- C:\Windows\system32\CNCALBL.DLL
2017-01-06 20:19:48 ----D---- C:\Users\Defeld\AppData\Roaming\WinRAR
2017-01-06 19:13:46 ----A---- C:\Windows\AutoKMS.ini
2017-01-06 18:58:42 ----D---- C:\Program Files\Common Files\DESIGNER
2017-01-06 18:58:23 ----D---- C:\Windows\PCHEALTH
2017-01-06 18:56:42 ----D---- C:\Program Files\Microsoft Analysis Services
2017-01-06 18:56:42 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2017-01-06 18:56:32 ----D---- C:\Program Files (x86)\Microsoft Office
2017-01-06 18:56:31 ----D---- C:\ProgramData\Microsoft Help
2017-01-06 18:56:31 ----D---- C:\Program Files\Microsoft Office
2017-01-06 18:56:20 ----RHD---- C:\MSOCache
2017-01-06 18:45:14 ----D---- C:\Users\Defeld\AppData\Roaming\Stardock
2017-01-06 18:44:52 ----HDC---- C:\ProgramData\{0F4A7EFE-5950-4389-BF36-1E625D72456B}
2017-01-06 18:44:51 ----D---- C:\ProgramData\Stardock
2017-01-06 18:44:49 ----D---- C:\Program Files (x86)\Stardock
2017-01-06 18:13:15 ----A---- C:\Windows\SYSWOW64\detoured.dll
2017-01-06 18:13:15 ----A---- C:\Windows\SYSWOW64\atieah32.exe
2017-01-06 18:13:15 ----A---- C:\Windows\system32\detoured.dll
2017-01-06 18:13:15 ----A---- C:\Windows\system32\atieah64.exe
2017-01-06 18:13:07 ----A---- C:\Windows\SYSWOW64\amdgfxinfo32.dll
2017-01-06 18:13:07 ----A---- C:\Windows\system32\ativvaxy_FJ_nd.dat
2017-01-06 18:13:07 ----A---- C:\Windows\system32\ativvaxy_FJ.dat
2017-01-06 18:13:07 ----A---- C:\Windows\system32\amdgfxinfo64.dll
2017-01-06 18:04:27 ----D---- C:\Program Files\Elantech
2017-01-06 18:03:55 ----D---- C:\drivers
2017-01-06 17:19:26 ----D---- C:\Users\Defeld\AppData\Roaming\TeamViewer
2017-01-06 17:14:21 ----D---- C:\Program Files (x86)\TeamViewer
2017-01-06 16:36:53 ----D---- C:\Windows\SYSWOW64\sda
2017-01-06 15:42:37 ----D---- C:\Users\Defeld\AppData\Roaming\AMD
2017-01-06 15:42:33 ----D---- C:\Users\Defeld\AppData\Roaming\ViberPC
2017-01-06 15:38:41 ----D---- C:\Users\Defeld\AppData\Roaming\ACD Systems
2017-01-06 15:36:47 ----D---- C:\ProgramData\ACD Systems
2017-01-06 15:36:42 ----D---- C:\Program Files\Common Files\ACD Systems
2017-01-06 15:36:42 ----D---- C:\Program Files\ACD Systems
2017-01-06 15:32:07 ----D---- C:\Windows\IObit
2017-01-06 15:31:41 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-01-06 15:28:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-01-06 15:27:58 ----D---- C:\Windows\system32\Macromed
2017-01-06 15:27:55 ----D---- C:\Windows\SYSWOW64\Macromed
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\XAudio2_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\xactengine3_7.dll
2017-01-06 15:27:43 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\system32\d3dx11_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\system32\d3dx10_43.dll
2017-01-06 15:27:42 ----A---- C:\Windows\system32\d3dcsx_43.dll
2017-01-06 15:27:41 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2017-01-06 15:27:41 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2017-01-06 15:27:41 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2017-01-06 15:27:41 ----A---- C:\Windows\system32\XAudio2_6.dll
2017-01-06 15:27:41 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2017-01-06 15:27:41 ----A---- C:\Windows\system32\D3DX9_43.dll
2017-01-06 15:27:40 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2017-01-06 15:27:40 ----A---- C:\Windows\system32\xactengine3_6.dll
2017-01-06 15:27:39 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2017-01-06 15:27:39 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2017-01-06 15:27:38 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2017-01-06 15:27:38 ----A---- C:\Windows\system32\XAudio2_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\system32\xactengine3_5.dll
2017-01-06 15:27:38 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\system32\d3dx11_42.dll
2017-01-06 15:27:37 ----A---- C:\Windows\system32\d3dcsx_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2017-01-06 15:27:36 ----A---- C:\Windows\system32\D3DX9_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\system32\d3dx10_42.dll
2017-01-06 15:27:36 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\system32\D3DX9_41.dll
2017-01-06 15:27:35 ----A---- C:\Windows\system32\d3dx10_41.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\XAudio2_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\xactengine3_4.dll
2017-01-06 15:27:34 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2017-01-06 15:27:33 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\system32\D3DX9_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\system32\d3dx10_40.dll
2017-01-06 15:27:33 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2017-01-06 15:27:32 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2017-01-06 15:27:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2017-01-06 15:27:32 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2017-01-06 15:27:32 ----A---- C:\Windows\system32\XAudio2_3.dll
2017-01-06 15:27:32 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2017-01-06 15:27:32 ----A---- C:\Windows\system32\xactengine3_3.dll
2017-01-06 15:27:31 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2017-01-06 15:27:31 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2017-01-06 15:27:31 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2017-01-06 15:27:31 ----A---- C:\Windows\system32\XAudio2_2.dll
2017-01-06 15:27:31 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2017-01-06 15:27:31 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2017-01-06 15:27:30 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2017-01-06 15:27:30 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2017-01-06 15:27:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2017-01-06 15:27:30 ----A---- C:\Windows\system32\xactengine3_2.dll
2017-01-06 15:27:30 ----A---- C:\Windows\system32\d3dx10_39.dll
2017-01-06 15:27:30 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2017-01-06 15:27:29 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2017-01-06 15:27:29 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2017-01-06 15:27:29 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2017-01-06 15:27:29 ----A---- C:\Windows\system32\XAudio2_1.dll
2017-01-06 15:27:29 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2017-01-06 15:27:29 ----A---- C:\Windows\system32\D3DX9_39.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2017-01-06 15:27:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\xactengine3_1.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\d3dx10_38.dll
2017-01-06 15:27:28 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2017-01-06 15:27:27 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2017-01-06 15:27:27 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2017-01-06 15:27:27 ----A---- C:\Windows\system32\XAudio2_0.dll
2017-01-06 15:27:27 ----A---- C:\Windows\system32\D3DX9_38.dll
2017-01-06 15:27:26 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2017-01-06 15:27:26 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2017-01-06 15:27:26 ----A---- C:\Windows\system32\xactengine3_0.dll
2017-01-06 15:27:26 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2017-01-06 15:27:25 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\system32\d3dx10_37.dll
2017-01-06 15:27:25 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2017-01-06 15:27:24 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2017-01-06 15:27:24 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2017-01-06 15:27:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2017-01-06 15:27:24 ----A---- C:\Windows\system32\xactengine2_10.dll
2017-01-06 15:27:24 ----A---- C:\Windows\system32\d3dx10_36.dll
2017-01-06 15:27:24 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2017-01-06 15:27:23 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2017-01-06 15:27:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2017-01-06 15:27:22 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2017-01-06 15:27:22 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2017-01-06 15:27:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2017-01-06 15:27:22 ----A---- C:\Windows\system32\xactengine2_9.dll
2017-01-06 15:27:22 ----A---- C:\Windows\system32\d3dx10_35.dll
2017-01-06 15:27:22 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2017-01-06 15:27:21 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2017-01-06 15:27:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2017-01-06 15:27:21 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2017-01-06 15:27:21 ----A---- C:\Windows\system32\xactengine2_8.dll
2017-01-06 15:27:21 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2017-01-06 15:27:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2017-01-06 15:27:20 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\system32\d3dx10_34.dll
2017-01-06 15:27:20 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2017-01-06 15:27:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\xinput1_3.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\xactengine2_7.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2017-01-06 15:27:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2017-01-06 15:27:18 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2017-01-06 15:27:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2017-01-06 15:27:17 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2017-01-06 15:27:17 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2017-01-06 15:27:17 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2017-01-06 15:27:17 ----A---- C:\Windows\system32\xactengine2_6.dll
2017-01-06 15:27:17 ----A---- C:\Windows\system32\xactengine2_5.dll
2017-01-06 15:27:17 ----A---- C:\Windows\system32\d3dx10.dll
2017-01-06 15:27:16 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2017-01-06 15:27:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2017-01-06 15:27:16 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2017-01-06 15:27:16 ----A---- C:\Windows\system32\xactengine2_4.dll
2017-01-06 15:27:16 ----A---- C:\Windows\system32\x3daudio1_1.dll
2017-01-06 15:27:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2017-01-06 15:27:15 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2017-01-06 15:27:15 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2017-01-06 15:27:15 ----A---- C:\Windows\system32\xactengine2_3.dll
2017-01-06 15:27:15 ----A---- C:\Windows\system32\d3dx9_31.dll
2017-01-06 15:27:14 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2017-01-06 15:27:14 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2017-01-06 15:27:14 ----A---- C:\Windows\system32\xinput1_2.dll
2017-01-06 15:27:14 ----A---- C:\Windows\system32\xactengine2_2.dll
2017-01-06 15:27:13 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2017-01-06 15:27:13 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2017-01-06 15:27:13 ----A---- C:\Windows\system32\xinput1_1.dll
2017-01-06 15:27:13 ----A---- C:\Windows\system32\xactengine2_1.dll
2017-01-06 15:27:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2017-01-06 15:27:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2017-01-06 15:27:09 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2017-01-06 15:27:09 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2017-01-06 15:27:09 ----A---- C:\Windows\system32\xactengine2_0.dll
2017-01-06 15:27:09 ----A---- C:\Windows\system32\x3daudio1_0.dll
2017-01-06 15:27:08 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2017-01-06 15:27:08 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2017-01-06 15:27:08 ----A---- C:\Windows\system32\d3dx9_29.dll
2017-01-06 15:27:08 ----A---- C:\Windows\system32\d3dx9_28.dll
2017-01-06 15:27:07 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2017-01-06 15:27:07 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2017-01-06 15:27:07 ----A---- C:\Windows\system32\d3dx9_27.dll
2017-01-06 15:27:07 ----A---- C:\Windows\system32\d3dx9_26.dll
2017-01-06 15:27:06 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2017-01-06 15:27:06 ----A---- C:\Windows\system32\d3dx9_25.dll
2017-01-06 15:27:05 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2017-01-06 15:27:05 ----A---- C:\Windows\system32\d3dx9_24.dll
2017-01-06 15:25:38 ----D---- C:\ProgramData\Package Cache
2017-01-06 15:22:44 ----A---- C:\Windows\system32\RtNicProp64.dll
2017-01-06 15:22:44 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2017-01-06 15:22:20 ----A---- C:\Windows\SYSWOW64\RsCRIcon.dll
2017-01-06 15:22:20 ----A---- C:\Windows\system32\RtCRX64.dll
2017-01-06 15:22:20 ----A---- C:\Windows\system32\drivers\RtsUer.sys
2017-01-06 15:22:20 ----A---- C:\Windows\RtCRU64.exe
2017-01-06 15:21:51 ----A---- C:\Windows\system32\drivers\rtsuvc.sys
2017-01-06 15:21:50 ----A---- C:\Windows\SYSWOW64\RtCamP.dll
2017-01-06 15:21:50 ----A---- C:\Windows\SYSWOW64\RsDecode.dll
2017-01-06 15:21:50 ----A---- C:\Windows\system32\RtCamP64.dll
2017-01-06 15:21:50 ----A---- C:\Windows\system32\RtCamO64.dll
2017-01-06 15:21:50 ----A---- C:\Windows\RTFTrack.exe
2017-01-06 15:21:23 ----A---- C:\Windows\system32\drivers\athrx.sys
2017-01-06 15:20:51 ----D---- C:\Program Files\Common Files\Atheros
2017-01-06 15:20:05 ----A---- C:\Windows\system32\drivers\btfilter.sys
2017-01-06 15:20:05 ----A---- C:\Windows\system32\BtContextMenu.dll
2017-01-06 15:20:05 ----A---- C:\Windows\system32\btcoinst.dll
2017-01-06 15:19:40 ----D---- C:\ProgramData\Conexant
2017-01-06 15:19:39 ----D---- C:\Program Files\CONEXANT
2017-01-06 15:19:30 ----A---- C:\Windows\system32\UCI64A52.DLL
2017-01-06 15:19:30 ----A---- C:\Windows\system32\FMAPO64.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEP64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEL64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEG64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EED64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\EEA64A.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\drivers\Mixer.ini
2017-01-06 15:19:30 ----A---- C:\Windows\system32\drivers\CHDRT64.sys
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CxPageMaster64.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CX64BP07.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CX64AP86.dll
2017-01-06 15:19:30 ----A---- C:\Windows\system32\CSpkExt64.dll
2017-01-06 14:57:23 ----D---- C:\Program Files\Mozilla Firefox
2017-01-06 14:39:23 ----D---- C:\Users\Defeld\AppData\Roaming\Thunderbird
2017-01-06 14:38:36 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2017-01-06 14:33:19 ----D---- C:\Program Files\WinRAR
2017-01-06 14:22:31 ----D---- C:\Users\Defeld\AppData\Roaming\Mozilla
2017-01-06 14:22:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-06 14:17:14 ----D---- C:\Users\Defeld\AppData\Roaming\AVAST Software
2017-01-06 14:16:51 ----D---- C:\Program Files\Common Files\AV
2017-01-06 14:16:44 ----A---- C:\Windows\system32\drivers\aswvmm.sys
2017-01-06 14:16:44 ----A---- C:\Windows\system32\drivers\aswStm.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswsp.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswsnx.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-01-06 14:16:43 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-01-06 14:16:38 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2017-01-06 14:16:38 ----A---- C:\Windows\system32\aswBoot.exe
2017-01-06 14:16:37 ----A---- C:\Windows\system32\ucrtbase.dll
2017-01-06 14:16:32 ----A---- C:\Windows\avastSS.scr
2017-01-06 14:15:10 ----D---- C:\Program Files\AVAST Software
2017-01-06 14:14:31 ----D---- C:\ProgramData\AVAST Software
2017-01-06 14:12:53 ----D---- C:\ProgramData\VS Revo Group
2017-01-06 14:12:52 ----A---- C:\Windows\system32\drivers\revoflt.sys
2017-01-06 14:12:51 ----D---- C:\Program Files\VS Revo Group
2017-01-06 13:33:59 ----D---- C:\Windows\tbaseregistry
2017-01-06 13:33:59 ----A---- C:\Windows\SYSWOW64\IEShims.dll
2017-01-06 13:28:50 ----D---- C:\ProgramData\ProductData
2017-01-06 13:28:22 ----D---- C:\Users\Defeld\AppData\Roaming\IObit
2017-01-06 13:28:22 ----D---- C:\ProgramData\IObit
2017-01-06 13:28:22 ----A---- C:\Windows\SYSWOW64\drivers\HWiNFO64A.SYS
2017-01-06 13:28:18 ----D---- C:\Program Files (x86)\IObit
2017-01-06 13:22:56 ----D---- C:\Users\Defeld\AppData\Roaming\Adobe
2017-01-06 13:22:45 ----D---- C:\Users\Defeld\AppData\Roaming\Identities
2017-01-06 13:08:33 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-01-06 13:06:46 ----D---- C:\Program Files (x86)\Microsoft.NET
2017-01-06 13:06:45 ----D---- C:\Windows\Migration
2017-01-06 13:06:25 ----SHD---- C:\Windows\Installer
2017-01-06 13:04:05 ----D---- C:\Program Files\Common Files\ATI Technologies
2017-01-06 13:03:46 ----D---- C:\Program Files\AMD
2017-01-06 13:02:36 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2017-01-06 13:02:36 ----A---- C:\Windows\system32\poqexec.exe
2017-01-06 13:02:32 ----DC---- C:\Windows\system32\DRVSTORE
2017-01-06 13:01:38 ----SD---- C:\Users\Defeld\AppData\Roaming\Microsoft
2017-01-06 13:01:38 ----D---- C:\Users\Defeld\AppData\Roaming\Media Center Programs
2017-01-06 13:01:28 ----SHD---- C:\Recovery
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Šablony
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Plocha
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Oblíbené položky
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Nabídka Start
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Dokumenty
2017-01-06 13:01:28 ----SHD---- C:\ProgramData\Data aplikací
2017-01-06 12:53:33 ----D---- C:\Windows\SoftwareDistribution
2017-01-06 12:51:24 ----D---- C:\Windows\Prefetch
2017-01-06 12:50:31 ----ASH---- C:\pagefile.sys
2017-01-06 12:50:31 ----ASH---- C:\hiberfil.sys
2017-01-06 12:39:54 ----SHD---- C:\System Volume Information
2017-01-06 12:39:22 ----D---- C:\Windows\Panther
======List of files/folders modified in the last 1 month======
2017-01-08 11:55:07 ----RD---- C:\Program Files
2017-01-08 11:41:09 ----D---- C:\Windows\system32\config
2017-01-08 11:40:39 ----D---- C:\Windows\system32\Tasks
2017-01-08 11:27:34 ----D---- C:\Windows\system32\wdi
2017-01-08 11:24:57 ----D---- C:\Windows\Temp
2017-01-08 11:05:00 ----D---- C:\Windows\system32\drivers
2017-01-08 10:17:16 ----D---- C:\Windows
2017-01-08 10:00:34 ----D---- C:\Windows\Microsoft.NET
2017-01-08 05:59:43 ----D---- C:\Windows\Tasks
2017-01-08 03:32:44 ----HD---- C:\ProgramData
2017-01-08 03:22:56 ----D---- C:\Windows\System32
2017-01-08 03:22:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-01-08 03:22:55 ----D---- C:\Windows\inf
2017-01-08 02:15:16 ----D---- C:\Windows\SysWOW64
2017-01-08 02:14:48 ----D---- C:\Windows\system32\catroot
2017-01-08 02:13:45 ----D---- C:\Windows\system32\DriverStore
2017-01-08 02:13:30 ----RD---- C:\Program Files (x86)
2017-01-08 02:13:30 ----D---- C:\Program Files (x86)\Common Files
2017-01-08 02:11:14 ----D---- C:\Windows\system32\catroot2
2017-01-06 22:57:04 ----SD---- C:\ProgramData\Microsoft
2017-01-06 19:51:52 ----D---- C:\Windows\Logs
2017-01-06 18:59:37 ----RSD---- C:\Windows\assembly
2017-01-06 18:59:36 ----D---- C:\Windows\winsxs
2017-01-06 18:58:47 ----RSD---- C:\Windows\Fonts
2017-01-06 18:58:42 ----D---- C:\Program Files\Common Files
2017-01-06 18:58:31 ----D---- C:\Program Files\Common Files\Microsoft Shared
2017-01-06 18:56:50 ----D---- C:\Windows\ShellNew
2017-01-06 17:13:25 ----D---- C:\Windows\system32\LogFiles
2017-01-06 15:22:44 ----A---- C:\Windows\system32\RTNUninst64.dll
2017-01-06 13:28:22 ----D---- C:\Windows\SYSWOW64\drivers
2017-01-06 13:22:43 ----SHD---- C:\$Recycle.Bin
2017-01-06 13:07:58 ----D---- C:\Windows\twain_32
2017-01-06 13:07:51 ----D---- C:\Windows\system32\CodeIntegrity
2017-01-06 13:06:48 ----D---- C:\Windows\SYSWOW64\en-US
2017-01-06 13:06:48 ----D---- C:\Windows\system32\en-US
2017-01-06 13:02:03 ----D---- C:\Windows\system32\restore
2017-01-06 13:01:38 ----RD---- C:\Users
2017-01-06 13:01:28 ----D---- C:\Windows\system32\Recovery
2017-01-06 13:01:28 ----D---- C:\Program Files\Windows NT
2017-01-06 13:00:37 ----D---- C:\Windows\rescache
2017-01-06 13:00:22 ----D---- C:\Windows\debug
2017-01-06 12:54:51 ----D---- C:\Windows\system32\drivers\UMDF
2017-01-06 12:54:30 ----D---- C:\Windows\system32\sysprep
2017-01-06 12:51:19 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2014-09-24 83656]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2014-09-24 43720]
R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2014-10-28 62152]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2017-01-06 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2017-01-06 293352]
R0 MBAMSwissArmy;MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [2017-01-08 250816]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2014-06-08 213848]
R1 amdpsp;AMD PSP 1.0 Service; C:\Windows\system32\DRIVERS\amdpsp.sys [2014-02-24 233672]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-01-06 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-01-06 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-01-06 969184]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-01-06 513632]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2014-06-08 516096]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Windows\system32\drivers\mbae64.sys [2016-12-14 77416]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2017-01-06 26528]
R1 MBAMChameleon;MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [2017-01-08 176064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-06-08 60416]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-01-06 108816]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-01-06 163416]
R3 amdhub30;AMD USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\amdhub30.sys [2015-01-21 108256]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2015-02-02 18977792]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2015-02-02 591872]
R3 amdxhc;AMD USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\amdxhc.sys [2015-01-21 229088]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2017-01-06 4172536]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-12-21 94720]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2017-01-06 609992]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2014-06-08 80384]
R3 busenum;Synology Virtual USB Hub; C:\Windows\system32\DRIVERS\busenum.sys [2012-08-03 55776]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2017-01-06 1700568]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2015-01-13 443064]
R3 MBAMFarflt;MBAMFarflt; \??\C:\Windows\system32\drivers\farflt.sys [2017-01-08 102856]
R3 MBAMProtection;MBAMProtection; \??\C:\Windows\system32\drivers\mbam.sys [2017-01-08 43968]
R3 MBAMWebProtection;MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [2017-01-08 81696]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2017-01-06 1037832]
R3 RTSUER;Realtek USB Card Reader - UER; C:\Windows\system32\Drivers\RtsUer.sys [2017-01-06 418784]
R3 rtsuvc;EasyCamera; C:\Windows\system32\DRIVERS\rtsuvc.sys [2017-01-06 3127552]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S2 APXACC;AppEx Networks Accelerator LWF; C:\Windows\system32\DRIVERS\appexDrv.sys []
S3 amdkmcsp;AMD Kernel Mode CSP Service; C:\Windows\system32\DRIVERS\amdkmcsp.sys [2014-02-24 81096]
S3 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2017-01-06 37656]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2014-06-08 552960]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-06-08 19456]
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 31800]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2014-02-27 331992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2014-06-08 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-06-08 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-06-08 29696]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2014-06-08 42496]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2015-02-02 246272]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-01-06 197128]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2014-06-08 27136]
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2015-01-13 102072]
R2 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2016-12-14 4317648]
R2 tbaseprovisioning;tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [2014-02-24 51712]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2015-04-09 5261584]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2014-06-08 27136]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-08 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-01-06 198088]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2014-06-08 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2014-06-08 27136]
S4 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-02-02 344064]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 UsbClientService;UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [2016-03-18 248840]
-----------------EOF-----------------