Pravděpodobně "zanesený" ntb
Napsal: 21 bře 2017 14:02
Ahoj, prosím o kontrolu logu. Ntb je v podstatě v základu, ale při stahování solidworks 2016 pravděpodobně došlo ke stáhnutí i něčeho jiného. V prohlížeči vyskakují divné stránky, načítají se automaticky různé stránky, při vyhledávání na googlu se zobrazují nejdříve stránky, co normálně ne.
Děkuji za kontrolu.
Nikdy jsem to nedělal snad tedy postupuji takhle správně..
Logfile of random's system information tool 1.16 (written by random/random)
Run by Lukas Fiala at 2017-03-21 13:28:36
Microsoft Windows 10 Home
System drive C: has 507 GB (71%) free of 715 GB
Total RAM: 3994 MB (45% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:28:52, on 21.03.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
C:\Program Files\trend micro\Lukas Fiala_RSITx64.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://noblok.net/wpad.dat?de64c4b528eb ... 3226377721
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Google Update] C:\Users\Lukas Fiala\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2016 Rychlé spuštění.lnk = ?
O4 - Global Startup: SOLIDWORKS Nástroj pro stahování na pozadí.lnk = ?
O4 - Global Startup: Virtual Router Manager.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: SOLIDWORKS Electrical Collaborative Server (ewserver) - Unknown owner - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Electrical\server\EwServer.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2016 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VirtualRouterService (Virtual Router) - Chris Pietschmann (http://pietschsoft.com) - C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 9712 bytes
====== Enumerating Processes ======
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\spoolsv.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Electrical\server\EwServer.exe"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2016"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\ProgramData\SOLIDWORKS Electrical\MSSQL12.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sTEW_SQLEXPRESS
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\WinLogon.exe -SpecialSession
C:\Windows\System32\dwm.exe
C:\Windows\system32\atieclxx.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\Windows\system32\sihost.exe
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
C:\Windows\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\system32\igfxEM.exe
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxHK.exe
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\system32\igfxTray.exe
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\system32\dashost.exe
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"C:\Program Files (x86)\Virtual Router\VirtualRouterClient.exe"
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\alg.exe
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.4.86.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\Windows\System32\fontdrvhost.exe
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe"
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\User Data\Crashpad" "--metrics-dir=C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\User Data" --url=https://clients2.google.com/cr/report --annotation=channel=canary --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=59.0.3046.0 --initial-client-data=0x1a8,0x1ac,0x1b0,0x1a4,0x1b4,0x7fff4e1029a0,0x7fff4e1029c0,0x7fff4e102978
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=watcher --main-thread-id=6452 --on-initialized-event-handle=624 --parent-handle=452 /prefetch:6
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=utility --lang=cs --service-request-channel-token=7EB80B9E0EAF8920BD916498E961B298 --mojo-platform-channel-handle=2960 --ignored=" --type=renderer " /prefetch:8
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=gpu-process --field-trial-handle=1484 --start-stack-profiler --disable-d3d11 --use-gl=swiftshader-webgl --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,16,19,23,41,42,61,74,80 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --disable-webrtc-hw-encoding --gpu-vendor-id=0x1002 --gpu-device-id=0x6840 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.201.1151.1008 --gpu-driver-date=11-4-2015 --gpu-secondary-vendor-ids=0x8086 --gpu-secondary-device-ids=0x0166 --gpu-active-vendor-id=0x8086 --gpu-active-device-id=0x0166 --start-stack-profiler --service-request-channel-token=1A9CED74D97278C0212FE9BED2BA526D --mojo-platform-channel-handle=2232 --ignored=" --type=renderer " /prefetch:2
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=renderer --field-trial-handle=1484 --primordial-pipe-token=B5CE9C4AF87D07194D410F6526132134 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=B5CE9C4AF87D07194D410F6526132134 --renderer-client-id=13 --mojo-platform-channel-handle=4516 /prefetch:1
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=renderer --field-trial-handle=1484 --primordial-pipe-token=D95FD17ED33CA436896638CC24C69023 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=D95FD17ED33CA436896638CC24C69023 --renderer-client-id=19 --mojo-platform-channel-handle=5424 /prefetch:1
"C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe" -Embedding
C:\Windows\System32\smartscreen.exe -Embedding
C:\Windows\system32\AUDIODG.EXE 0x31c
"C:\Users\Lukas Fiala\Downloads\RSITx64.exe"
====== Scheduled tasks folder ======
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2774955484-2510873228-3376545502-1001Core - C:\Users\Lukas Fiala\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2774955484-2510873228-3376545502-1001UA - C:\Users\Lukas Fiala\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\OneDrive Standalone Update Task v2 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1490047428 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\User_Feed_Synchronization-{637236E8-35F1-4609-8CF1-F5A68F581466} - C:\Windows\system32\msfeedssync.exe sync
C:\Windows\system32\tasks\{6D24B0CE-74E8-41D4-BB39-5E8CDB551D45} - "c:\program files (x86)\google\chrome\application\chrome.exe" https://www.skype.com/go/downloading?so ... rror=12007
C:\Windows\system32\tasks\{77F2D994-0933-4A78-B715-744737D26078} - "c:\windows\system32\launchwinapp.exe" https://www.skype.com/go/downloading?so ... rror=12007
C:\Windows\system32\tasks\{BA3B7997-AFCB-400A-B001-DAFC5D30306B} - "c:\program files (x86)\google\chrome\application\chrome.exe" https://www.skype.com/go/downloading?so ... rror=12007
C:\Windows\system32\tasks\{DB7612C9-A14D-4D49-8490-6DA2C6DF3E8A} - "c:\program files (x86)\google\chrome\application\chrome.exe" https://ui.skype.com/ui/0/7.32.0.104/cs ... age=tsBing
C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask - %systemroot%\system32\sc.exe start osppsvc
C:\Windows\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\Windows\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - %ProgramFiles%\Windows Defender\MpCmdRun.exe Scan -ScheduleJob
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\Windows\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe Reboot
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - %systemroot%\system32\MusNotification.exe Display
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - %systemroot%\system32\MusNotification.exe ReadyToReboot
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\Windows\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\Windows\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\Windows\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\Windows\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
======Registry dump ======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-04-28 3954352]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-09-07 631808]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-03-03 1518304]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]
"Google Update"=C:\Users\Lukas Fiala\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [2017-03-21 601752]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-11-04 767176]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-20 205512]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2016 Rychlé spuštění.lnk - C:\Windows\Installer\{768F3B65-1695-47B7-9002-B11400CB111D}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Nástroj pro stahování na pozadí.lnk - C:\Program Files (x86)\Common Files\Manažer instalací SOLIDWORKS\BackgroundDownloading\sldBgDwld.exe
Virtual Router Manager.lnk - C:\Windows\Installer\{BE905C46-2B34-4D73-AEE1-769ED138E0FF}\_118D1A4EFFA6998C3492EB.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
====== File associations ======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
====== List of files/folders created in the last 1 month ======
2017-03-21 13:28:37 ----D---- C:\Program Files\trend micro
2017-03-21 13:28:36 ----D---- C:\rsit
2017-03-21 01:42:12 ----D---- C:\ProgramData\SWCUTemp
2017-03-21 01:39:01 ----D---- C:\ProgramData\dbg
2017-03-21 00:44:04 ----SHD---- C:\Config.Msi
2017-03-21 00:21:27 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\TeamViewer
2017-03-21 00:21:17 ----D---- C:\Program Files (x86)\TeamViewer
2017-03-20 23:04:53 ----RD---- C:\Program Files (x86)\Skype
2017-03-20 23:02:43 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-03-20 23:00:49 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\AVAST Software
2017-03-20 23:00:21 ----D---- C:\Program Files\Common Files\AV
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswvmm.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswStm.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswsp.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbuniva.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbloga.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbidsha.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbidsdrivera.sys
2017-03-20 22:59:55 ----A---- C:\Windows\system32\aswBoot.exe
2017-03-20 22:56:15 ----D---- C:\Program Files\AVAST Software
2017-03-20 22:55:38 ----D---- C:\ProgramData\AVAST Software
2017-03-17 21:28:11 ----D---- C:\ProgramData\Simpoe
2017-03-17 21:27:23 ----D---- C:\ProgramData\COSMOS Applications
2017-03-17 21:27:16 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2017-03-17 21:23:34 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\pdfforge
2017-03-17 21:23:33 ----A---- C:\Windows\system32\pdfcmon.dll
2017-03-17 21:23:32 ----D---- C:\Program Files\PDFCreator
2017-03-17 21:22:51 ----D---- C:\ProgramData\Dassault Systemes
2017-03-17 21:19:34 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2017-03-17 21:19:23 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\help_images_otherUI
2017-03-17 21:17:21 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\DassaultSystemes
2017-03-17 21:17:21 ----D---- C:\ProgramData\DassaultSystemes
2017-03-17 21:02:56 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-03-17 21:02:13 ----AD---- C:\ProgramData\SOLIDWORKS
2017-03-17 21:02:13 ----AD---- C:\Program Files\SOLIDWORKS Corp
2017-03-17 21:02:13 ----AD---- C:\Program Files\Common Files\SOLIDWORKS Shared
2017-03-17 21:01:46 ----D---- C:\Program Files\Common Files\Macrovision Shared
2017-03-17 20:59:28 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2017-03-17 20:56:35 ----A---- C:\Windows\SYSWOW64\perf-MSSQL12.TEW_SQLEXPRESS-sqlagtctr.dll
2017-03-17 20:56:34 ----A---- C:\Windows\system32\perf-MSSQL12.TEW_SQLEXPRESS-sqlagtctr.dll
2017-03-17 20:56:16 ----A---- C:\Windows\SYSWOW64\perf-MSSQL$TEW_SQLEXPRESS-sqlctr12.1.4100.1.dll
2017-03-17 20:56:16 ----A---- C:\Windows\system32\perf-MSSQL$TEW_SQLEXPRESS-sqlctr12.1.4100.1.dll
2017-03-17 20:56:09 ----A---- C:\Windows\system32\fssres.dll
2017-03-17 20:56:07 ----A---- C:\Windows\system32\hadrres.dll
2017-03-17 20:55:06 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2017-03-17 20:54:55 ----D---- C:\Windows\system32\RsFx
2017-03-17 20:54:42 ----D---- C:\Program Files\Microsoft.NET
2017-03-17 20:53:40 ----D---- C:\Windows\SYSWOW64\1033
2017-03-17 20:53:40 ----D---- C:\Windows\system32\1033
2017-03-17 20:52:55 ----AD---- C:\Program Files (x86)\Microsoft SQL Server
2017-03-17 20:51:35 ----AD---- C:\Program Files\Microsoft SQL Server
2017-03-17 20:49:51 ----D---- C:\ProgramData\Apple
2017-03-17 20:49:51 ----AD---- C:\Program Files\Bonjour
2017-03-17 20:49:51 ----AD---- C:\Program Files (x86)\Bonjour
2017-03-17 20:48:07 ----D---- C:\Program Files (x86)\MSECache
2017-03-17 20:41:32 ----AD---- C:\ProgramData\SOLIDWORKS Electrical
2017-03-17 20:41:08 ----D---- C:\ProgramData\FLEXnet
2017-03-17 20:40:52 ----D---- C:\SOLIDWORKS Data
2017-03-17 20:34:51 ----D---- C:\Windows\SolidWorks
2017-03-17 20:34:50 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\SOLIDWORKS
2017-03-17 20:27:09 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\WinRAR
2017-03-17 20:26:41 ----AD---- C:\Program Files\WinRAR
2017-03-17 11:32:20 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\uTorrent
2017-03-17 11:18:44 ----D---- C:\Program Files\My Web Shield
2017-03-17 11:18:44 ----A---- C:\Windows\system32\drivers\mwescontroller.sys
2017-03-17 11:18:09 ----D---- C:\ProgramData\e8bbe469-7fb3-1
2017-03-17 11:18:09 ----D---- C:\ProgramData\e8bbe469-1481-0
2017-03-17 11:18:00 ----D---- C:\Program Files (x86)\OneSystemCare
2017-03-16 22:23:37 ----D---- C:\Program Files (x86)\Adobe
2017-03-16 22:23:17 ----D---- C:\ProgramData\Adobe
2017-03-08 17:35:46 ----AD---- C:\Program Files (x86)\Virtual Router
2017-03-07 17:54:30 ----D---- C:\ProgramData\Skype
2017-03-04 01:12:54 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\vlc
2017-03-04 01:12:20 ----D---- C:\Program Files (x86)\VideoLAN
2017-03-04 00:39:30 ----D---- C:\Program Files (x86)\Google
2017-03-03 14:15:14 ----A---- C:\Windows\AutoKMS.ini
2017-03-03 14:04:50 ----D---- C:\Windows\SYSWOW64\XPSViewer
2017-03-03 14:04:07 ----D---- C:\Program Files (x86)\Reference Assemblies
2017-03-03 14:04:05 ----D---- C:\Program Files\Reference Assemblies
2017-03-03 14:04:05 ----D---- C:\Program Files\MSBuild
2017-03-03 14:01:51 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2017-03-03 14:01:51 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2017-03-03 14:01:51 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-03-03 14:01:44 ----A---- C:\Windows\system32\TsWpfWrp.exe
2017-03-03 14:01:44 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2017-03-03 14:01:44 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-03-03 14:00:38 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\Skype
2017-03-03 13:53:11 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\Macromedia
2017-03-03 13:49:43 ----AD---- C:\Program Files\Common Files\DESIGNER
2017-03-03 13:48:54 ----AD---- C:\Program Files (x86)\MSBuild
2017-03-03 13:48:44 ----D---- C:\Windows\PCHEALTH
2017-03-03 13:48:44 ----D---- C:\Program Files\Microsoft Sync Framework
2017-03-03 13:46:32 ----AD---- C:\Program Files (x86)\Microsoft Visual Studio 8
2017-03-03 13:45:51 ----D---- C:\Windows\SHELLNEW
2017-03-03 13:45:51 ----D---- C:\Program Files\Microsoft Analysis Services
2017-03-03 13:45:51 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2017-03-03 13:45:44 ----D---- C:\Program Files (x86)\Microsoft Office
2017-03-03 13:45:43 ----D---- C:\ProgramData\Microsoft Help
2017-03-03 13:45:43 ----AD---- C:\Program Files\Microsoft Office
2017-03-03 13:45:33 ----RHD---- C:\MSOCache
2017-03-02 00:17:04 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-03-01 19:47:42 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\ATI
2017-03-01 19:47:42 ----D---- C:\ProgramData\ATI
2017-03-01 19:47:10 ----D---- C:\ProgramData\Synaptics
2017-03-01 19:47:09 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\Synaptics
2017-03-01 19:47:04 ----A---- C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2017-03-01 16:20:06 ----D---- C:\Windows\system32\MRT
2017-03-01 16:19:47 ----AC---- C:\Windows\system32\MRT.exe
2017-03-01 16:07:36 ----A---- C:\Windows\system32\wmp.dll
2017-03-01 16:07:35 ----A---- C:\Windows\SYSWOW64\wmp.dll
2017-03-01 16:07:35 ----A---- C:\Windows\SYSWOW64\DolbyDecMFT.dll
2017-03-01 16:07:34 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2017-03-01 16:07:34 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2017-03-01 16:07:33 ----A---- C:\Windows\SYSWOW64\mos.dll
2017-03-01 16:07:33 ----A---- C:\Windows\system32\MFMediaEngine.dll
2017-03-01 16:07:32 ----A---- C:\Windows\SYSWOW64\tquery.dll
2017-03-01 16:07:32 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2017-03-01 16:07:32 ----A---- C:\Windows\system32\d3d10warp.dll
2017-03-01 16:07:32 ----A---- C:\Windows\system32\appraiser.dll
2017-03-01 16:07:32 ----A---- C:\Windows\system32\acmigration.dll
2017-03-01 16:07:31 ----A---- C:\Windows\SYSWOW64\MapRouter.dll
2017-03-01 16:07:31 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\wsp_fs.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\d3d11.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\CoreUIComponents.dll
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\MapGeocoder.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\wlansvc.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\mfsvr.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\mfcore.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\dwmcore.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\wsp_health.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\mfplat.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\mfnetsrc.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\mfnetcore.dll
2017-03-01 16:07:28 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2017-03-01 16:07:28 ----A---- C:\Windows\SYSWOW64\msctf.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\wwansvc.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\Windows.Networking.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\mstsc.exe
2017-03-01 16:07:28 ----A---- C:\Windows\system32\mfreadwrite.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\generaltel.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\FntCache.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\devinv.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-03-01 16:07:27 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\wsp_sr.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\spoolsv.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\msvproc.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\mstscax.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\hvix64.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\hvax64.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\aeinv.dll
2017-03-01 16:07:26 ----A---- C:\Windows\SYSWOW64\ole32.dll
2017-03-01 16:07:26 ----A---- C:\Windows\SYSWOW64\JpMapControl.dll
2017-03-01 16:07:26 ----A---- C:\Windows\SYSWOW64\gdi32full.dll
2017-03-01 16:07:26 ----A---- C:\Windows\system32\Windows.Media.dll
2017-03-01 16:07:26 ----A---- C:\Windows\system32\win32spl.dll
2017-03-01 16:07:26 ----A---- C:\Windows\system32\AppReadiness.dll
2017-03-01 16:07:25 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2017-03-01 16:07:25 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\WWanAPI.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\usercpl.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\LockAppHost.exe
2017-03-01 16:07:25 ----A---- C:\Windows\system32\localspl.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\invagent.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\hvloader.exe
2017-03-01 16:07:25 ----A---- C:\Windows\system32\drivers\bthport.sys
2017-03-01 16:07:25 ----A---- C:\Windows\system32\D3D12.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\wer.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\NMAA.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2017-03-01 16:07:24 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\nettrace.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\mfksproxy.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\dxgi.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\aepic.dll
2017-03-01 16:07:23 ----A---- C:\Windows\SYSWOW64\mprdim.dll
2017-03-01 16:07:23 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2017-03-01 16:07:23 ----A---- C:\Windows\SYSWOW64\InputService.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\Windows.Networking.Vpn.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\SpeechPal.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\services.exe
2017-03-01 16:07:23 ----A---- C:\Windows\system32\ReAgent.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\NetworkBindingEngineMigPlugin.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\mprdim.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\mfaudiocnv.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\LockAppBroker.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2017-03-01 16:07:23 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2017-03-01 16:07:22 ----A---- C:\Windows\SYSWOW64\MapControlCore.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\Windows.Web.Http.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\Windows.Web.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\TSWorkspace.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\nshwfp.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\DscCore.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\drivers\tpm.sys
2017-03-01 16:07:22 ----A---- C:\Windows\system32\drivers\BthLEEnum.sys
2017-03-01 16:07:22 ----A---- C:\Windows\system32\d2d1.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\clusapi.dll
2017-03-01 16:07:21 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2017-03-01 16:07:21 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2017-03-01 16:07:21 ----A---- C:\Windows\SYSWOW64\biwinrt.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\SpaceAgent.exe
2017-03-01 16:07:21 ----A---- C:\Windows\system32\SensorService.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\rdpcore.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\FontProvider.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\drivers\sdbus.sys
2017-03-01 16:07:21 ----A---- C:\Windows\system32\discan.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\aitstatic.exe
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\weretw.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\StoreAgent.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\MapsBtSvc.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\DataExchange.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\wmpps.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\wmpeffects.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\wlancfg.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\MSVideoDSP.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\MiracastReceiver.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\icsvc.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\drivers\dumpsd.sys
2017-03-01 16:07:20 ----A---- C:\Windows\system32\drivers\bowser.sys
2017-03-01 16:07:20 ----A---- C:\Windows\system32\CastLaunch.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\browserbroker.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\MosStorage.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\input.dll
2017-03-01 16:07:18 ----A---- C:\Windows\system32\Windows.Media.Audio.dll
2017-03-01 16:07:18 ----A---- C:\Windows\system32\Sens.dll
2017-03-01 16:07:18 ----A---- C:\Windows\system32\drivers\hidclass.sys
2017-03-01 16:07:18 ----A---- C:\Windows\system32\drivers\EhStorTcgDrv.sys
2017-03-01 16:07:18 ----A---- C:\Windows\system32\drivers\dam.sys
2017-03-01 16:07:18 ----A---- C:\Windows\system32\credprovs.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\UserDataTimeUtil.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\Phoneutil.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\InstallAgentUserBroker.exe
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\EmailApis.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\credprovs.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\wmpshell.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\Windows.Networking.HostName.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\powercfg.exe
2017-03-01 16:07:17 ----A---- C:\Windows\system32\migisol.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\mfps.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\MCRecvSrc.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\iscsiwmi.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\dialserver.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\BootMenuUX.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\WWanAPI.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Picker.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\Windows.Devices.LowLevel.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\InstallAgent.exe
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\ChatApis.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\ActionCenterCPL.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\wmpdxm.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\sppnp.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\ReAgentc.exe
2017-03-01 16:07:16 ----A---- C:\Windows\system32\mfsrcsnk.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\MFCaptureEngine.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\devenum.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\ActionCenter.dll
2017-03-01 16:07:15 ----A---- C:\Windows\SYSWOW64\Windows.UI.CredDialogController.dll
2017-03-01 16:07:15 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2017-03-01 16:07:15 ----A---- C:\Windows\system32\Windows.Graphics.Printing.dll
2017-03-01 16:07:15 ----A---- C:\Windows\system32\kdhvcom.dll
2017-03-01 16:07:15 ----A---- C:\Windows\system32\drivers\hvservice.sys
2017-03-01 16:07:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-03-01 16:07:14 ----A---- C:\Windows\SYSWOW64\UserDataAccountApis.dll
2017-03-01 16:07:14 ----A---- C:\Windows\SYSWOW64\pwrshplugin.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\wlanapi.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\rdpencom.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\cmintegrator.dll
2017-03-01 16:07:14 ----A---- C:\Windows\splwow64.exe
2017-03-01 16:07:13 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-01 16:07:13 ----A---- C:\Windows\SYSWOW64\msdtcuiu.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\pwrshplugin.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\fhcpl.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\encapi.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\WordBreakers.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\Windows.UI.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\PlayToReceiver.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\InputLocaleManager.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\EditBufferTestHook.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\AppointmentApis.dll
2017-03-01 16:07:11 ----A---- C:\Windows\system32\Windows.Media.FaceAnalysis.dll
2017-03-01 16:07:11 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2017-03-01 16:07:11 ----A---- C:\Windows\system32\AboveLockAppHost.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.Media.Ocr.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\msinfo32.exe
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\chartv.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\apprepsync.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\apprepapi.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\AppointmentActivation.dll
2017-03-01 16:07:10 ----A---- C:\Windows\system32\resutils.dll
2017-03-01 16:07:10 ----A---- C:\Windows\system32\netshell.dll
2017-03-01 16:07:10 ----A---- C:\Windows\system32\chartv.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\Windows.Energy.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\VCardParser.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataTypeHelperUtil.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataPlatformHelperUtil.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataLanguageUtil.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataAccessRes.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\POSyncServices.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\NmaDirect.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\MosResource.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\MosHostClient.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\ExtrasXmlParser.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\ExSMime.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\ContactActivation.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\comsvcs.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\BingOnlineServices.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\AddressParser.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\AboveLockAppHost.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\wwanprotdim.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\wlansec.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\OnDemandConnRouteHelper.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\netplwiz.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\drivers\hidparse.sys
2017-03-01 16:07:09 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2017-03-01 16:07:09 ----A---- C:\Windows\system32\drivers\bthenum.sys
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\PhoneutilRes.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\odbcconf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\Microsoft-Windows-MosTrace.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\Microsoft-Windows-MosHost.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\Microsoft-Windows-MapControls.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\MapControlStringsRes.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\deviceassociation.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wlansvcpal.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wlanmsm.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wlanhlp.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wifiprofilessettinghandler.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\WiFiConfigSP.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wfdprov.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\tcpipcfg.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\spwmp.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\odbcconf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\netiougc.exe
2017-03-01 16:07:08 ----A---- C:\Windows\system32\dxmasf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\drivers\hidusb.sys
2017-03-01 16:07:07 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2017-03-01 16:07:07 ----A---- C:\Windows\SYSWOW64\DscCoreConfProv.dll
2017-03-01 16:07:07 ----A---- C:\Windows\system32\wmploc.DLL
2017-03-01 16:07:07 ----A---- C:\Windows\system32\DscCoreConfProv.dll
2017-03-01 16:07:06 ----A---- C:\Windows\system32\sppsvc.exe
2017-03-01 16:07:05 ----A---- C:\Windows\system32\sppobjs.dll
2017-03-01 16:07:05 ----A---- C:\Windows\system32\shell32.dll
2017-03-01 16:07:04 ----A---- C:\Windows\system32\storagewmi.dll
2017-03-01 16:07:04 ----A---- C:\Windows\system32\spaceman.exe
2017-03-01 16:07:04 ----A---- C:\Windows\system32\mispace.dll
2017-03-01 16:07:04 ----A---- C:\Windows\system32\dbgeng.dll
2017-03-01 16:07:03 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2017-03-01 16:07:03 ----A---- C:\Windows\SYSWOW64\combase.dll
2017-03-01 16:07:03 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2017-03-01 16:07:03 ----A---- C:\Windows\system32\esent.dll
2017-03-01 16:07:03 ----A---- C:\Windows\system32\drivers\ClipSp.sys
2017-03-01 16:07:03 ----A---- C:\Windows\system32\combase.dll
2017-03-01 16:07:02 ----A---- C:\Windows\SYSWOW64\shell32.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\WsmSvc.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2017-03-01 16:07:02 ----A---- C:\Windows\system32\msxml6.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\msi.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\CertEnroll.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\wevtsvc.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\qmgr.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\MSVidCtl.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\diagtrack.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\hevcdecoder.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\winhttp.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\UIAutomationCore.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\KernelBase.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\bisrv.dll
2017-03-01 16:06:59 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2017-03-01 16:06:59 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\xpsrchvw.exe
2017-03-01 16:06:59 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\fveapi.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\drivers\fvevol.sys
2017-03-01 16:06:59 ----A---- C:\Windows\system32\crypt32.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\bcastdvr.exe
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.InkControls.dll
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\NetSetupEngine.dll
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\wuaueng.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\sppwinob.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\NetSetupShim.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\ncsi.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\GamePanel.exe
2017-03-01 16:06:58 ----A---- C:\Windows\system32\FrameServer.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\FlightSettings.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\drvstore.dll
2017-03-01 16:06:57 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2017-03-01 16:06:57 ----A---- C:\Windows\SYSWOW64\rasapi32.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\wpx.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\wevtapi.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\uReFS.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\ubpm.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\NetSetupEngine.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\msv1_0.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\lsasrv.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\gpsvc.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\FSClient.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\facecredentialprovider.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\drivers\cng.sys
2017-03-01 16:06:57 ----A---- C:\Windows\system32\dnsapi.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\DeviceCensus.exe
2017-03-01 16:06:57 ----A---- C:\Windows\system32\ci.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2017-03-01 16:06:56 ----A---- C:\Windows\SYSWOW64\wsecedit.dll
2017-03-01 16:06:56 ----A---- C:\Windows\SYSWOW64\WinTypes.dll
2017-03-01 16:06:56 ----A---- C:\Windows\SYSWOW64\webio.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\wwanconn.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\wsecedit.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\wintrust.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\webio.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\schannel.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\SettingsHandlers_WorkAccess.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\nltest.exe
2017-03-01 16:06:56 ----A---- C:\Windows\system32\NetSetupSvc.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\mprapi.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2017-03-01 16:06:55 ----A---- C:\Windows\SYSWOW64\xpsrchvw.exe
2017-03-01 16:06:55 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2017-03-01 16:06:55 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Perception.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\wuapi.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\wer.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\mfsensorgroup.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\fveapibase.dll
2017-03-01 16:06:54 ----A---- C:\Windows\SYSWOW64\ddraw.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\wkssvc.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\w32time.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\SndVolSSO.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\samsrv.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\nlasvc.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\drivers\xboxgip.sys
2017-03-01 16:06:54 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\wlancfg.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\pdh.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\offlinesam.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\dmenrollengine.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\d3d8.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\winlogon.exe
2017-03-01 16:06:53 ----A---- C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\sppcext.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\setupugc.exe
2017-03-01 16:06:53 ----A---- C:\Windows\system32\SettingSync.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\profsvc.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\offlinesam.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\kerberos.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\ImplatSetup.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\wof.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\storport.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\fastfat.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\crashdmp.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\dhcpcore6.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\dab.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\CPFilters.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\biwinrt.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\bcrypt.dll
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\powercfg.exe
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\policymanager.dll
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\aclui.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\WinTypes.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\weretw.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\sbe.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\RDXService.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\qedit.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\dpapisrv.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\DeviceReactivation.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\cmifw.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\CloudStorageWizard.exe
2017-03-01 16:06:52 ----A---- C:\Windows\system32\bcdedit.exe
2017-03-01 16:06:51 ----A---- C:\Windows\SYSWOW64\NetSetupApi.dll
2017-03-01 16:06:51 ----A---- C:\Windows\SYSWOW64\MSVP9DEC.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\wow64.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\Windows.Media.MediaControl.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\updatepolicy.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\NetSetupApi.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\drivers\pdc.sys
2017-03-01 16:06:51 ----A---- C:\Windows\system32\adsmsext.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\pidgenx.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\offreg.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\CloudExperienceHostUser.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\CloudExperienceHostCommon.dll
2017-03-01 16:06:49 ----A---- C:\Windows\system32\wuauclt.exe
2017-03-01 16:06:49 ----A---- C:\Windows\system32\tsmf.dll
2017-03-01 16:06:49 ----A---- C:\Windows\system32\pidgenx.dll
2017-03-01 16:06:49 ----A---- C:\Windows\system32\GenValObj.exe
2017-03-01 16:06:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\wlanapi.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\Windows.Devices.PointOfService.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\updatepolicy.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\wuuhext.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\WinSCard.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\Windows.ApplicationModel.Wallet.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\usermgr.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\umpoext.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\drivers\xinputhid.sys
2017-03-01 16:06:48 ----A---- C:\Windows\system32\CryptoWinRT.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\BitLockerDeviceEncryption.exe
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Management.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\wincorlib.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\RTMediaFrame.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\CryptoWinRT.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\wincorlib.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\TSpkg.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\efsext.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\cryptui.dll
2017-03-01 16:06:46 ----A---- C:\Windows\SYSWOW64\WinSCard.dll
2017-03-01 16:06:46 ----A---- C:\Windows\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-03-01 16:06:46 ----A---- C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2017-03-01 16:06:46 ----A---- C:\Windows\system32\NetCfgNotifyObjectHost.exe
2017-03-01 16:06:46 ----A---- C:\Windows\system32\BcastDVRHelper.dll
2017-03-01 16:06:46 ----A---- C:\Windows\system32\AppCapture.dll
2017-03-01 16:06:45 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.dll
2017-03-01 16:06:45 ----A---- C:\Windows\SYSWOW64\UserMgrProxy.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\wwanmm.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\wups.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\Windows.Media.Ocr.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\UserMgrProxy.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\ntshrui.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\ListSvc.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\EditionUpgradeHelper.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\certprop.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\WinRtTracing.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Core.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\netshell.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\mdmregistration.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\Windows.Web.Diagnostics.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\Windows.StateRepositoryBroker.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\SettingSyncPolicy.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\ScDeviceEnum.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\esentutl.exe
2017-03-01 16:06:44 ----A---- C:\Windows\system32\EncDec.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\wlanhlp.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\wfdprov.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\tzres.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\samlib.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\offlinelsa.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\imapi2.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\container.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\wups2.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\UIRibbonRes.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\tzres.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\storagewmi_passthru.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\sppc.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\smphost.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\slcext.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\slc.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\samlib.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\offlinelsa.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\msxml6r.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\delegatorprovider.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\DbgModel.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\C_IS2022.DLL
2017-03-01 16:06:43 ----A---- C:\Windows\system32\c_GSM7.DLL
2017-03-01 16:06:43 ----A---- C:\Windows\system32\C_G18030.DLL
2017-03-01 16:06:42 ----A---- C:\Windows\system32\mshtml.dll
2017-03-01 16:06:39 ----A---- C:\Windows\system32\edgehtml.dll
2017-03-01 16:06:38 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-03-01 16:06:38 ----A---- C:\Windows\system32\jscript9.dll
2017-03-01 16:06:37 ----A---- C:\Windows\system32\twinui.dll
2017-03-01 16:06:36 ----A---- C:\Windows\SYSWOW64\MSVPXENC.dll
2017-03-01 16:06:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-03-01 16:06:36 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2017-03-01 16:06:35 ----A---- C:\Windows\system32\wininet.dll
2017-03-01 16:06:35 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2017-03-01 16:06:35 ----A---- C:\Windows\system32\MSAudDecMFT.dll
2017-03-01 16:06:34 ----A---- C:\Windows\SYSWOW64\msi.dll
2017-03-01 16:06:34 ----A---- C:\Windows\system32\wlidsvc.dll
2017-03-01 16:06:34 ----A---- C:\Windows\explorer.exe
2017-03-01 16:06:33 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2017-03-01 16:06:33 ----A---- C:\Windows\system32\Chakra.dll
2017-03-01 16:06:32 ----A---- C:\Windows\SYSWOW64\twinui.dll
2017-03-01 16:06:32 ----A---- C:\Windows\SYSWOW64\explorer.exe
2017-03-01 16:06:32 ----A---- C:\Windows\SYSWOW64\esent.dll
2017-03-01 16:06:32 ----A---- C:\Windows\system32\msftedit.dll
2017-03-01 16:06:31 ----A---- C:\Windows\SYSWOW64\wsp_fs.dll
2017-03-01 16:06:31 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2017-03-01 16:06:31 ----A---- C:\Windows\system32\SharedStartModel.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\urlmon.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\ResetEngine.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\iertutil.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-03-01 16:06:29 ----A---- C:\Windows\SYSWOW64\wsp_health.dll
2017-03-01 16:06:29 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll
Děkuji za kontrolu.
Nikdy jsem to nedělal snad tedy postupuji takhle správně..
Logfile of random's system information tool 1.16 (written by random/random)
Run by Lukas Fiala at 2017-03-21 13:28:36
Microsoft Windows 10 Home
System drive C: has 507 GB (71%) free of 715 GB
Total RAM: 3994 MB (45% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:28:52, on 21.03.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
C:\Program Files\trend micro\Lukas Fiala_RSITx64.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://noblok.net/wpad.dat?de64c4b528eb ... 3226377721
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Google Update] C:\Users\Lukas Fiala\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: SOLIDWORKS 2016 Rychlé spuštění.lnk = ?
O4 - Global Startup: SOLIDWORKS Nástroj pro stahování na pozadí.lnk = ?
O4 - Global Startup: Virtual Router Manager.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DTSInterops (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\swScheduler\DTSCoordinatorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: SOLIDWORKS Electrical Collaborative Server (ewserver) - Unknown owner - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Electrical\server\EwServer.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Solver for Flow Simulation 2016 (RemoteSolverDispatcher) - Mentor Graphics Corporation - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VirtualRouterService (Virtual Router) - Chris Pietschmann (http://pietschsoft.com) - C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 9712 bytes
====== Enumerating Processes ======
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\spoolsv.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Electrical\server\EwServer.exe"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\remotesolverdispatcherservice.exe" "SOFTWARE\SRAC\COSMOS_FloWorks 2016"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe"
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Flow Simulation\binCFW\dispatcher.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\ProgramData\SOLIDWORKS Electrical\MSSQL12.TEW_SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sTEW_SQLEXPRESS
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\WinLogon.exe -SpecialSession
C:\Windows\System32\dwm.exe
C:\Windows\system32\atieclxx.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\Windows\system32\sihost.exe
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
C:\Windows\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\system32\igfxEM.exe
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxHK.exe
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\system32\igfxTray.exe
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\system32\dashost.exe
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"C:\Program Files (x86)\Virtual Router\VirtualRouterClient.exe"
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe"
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\alg.exe
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.4.86.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\Windows\System32\fontdrvhost.exe
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe"
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\User Data\Crashpad" "--metrics-dir=C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\User Data" --url=https://clients2.google.com/cr/report --annotation=channel=canary --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=59.0.3046.0 --initial-client-data=0x1a8,0x1ac,0x1b0,0x1a4,0x1b4,0x7fff4e1029a0,0x7fff4e1029c0,0x7fff4e102978
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=watcher --main-thread-id=6452 --on-initialized-event-handle=624 --parent-handle=452 /prefetch:6
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=utility --lang=cs --service-request-channel-token=7EB80B9E0EAF8920BD916498E961B298 --mojo-platform-channel-handle=2960 --ignored=" --type=renderer " /prefetch:8
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=gpu-process --field-trial-handle=1484 --start-stack-profiler --disable-d3d11 --use-gl=swiftshader-webgl --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,16,19,23,41,42,61,74,80 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --disable-webrtc-hw-encoding --gpu-vendor-id=0x1002 --gpu-device-id=0x6840 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.201.1151.1008 --gpu-driver-date=11-4-2015 --gpu-secondary-vendor-ids=0x8086 --gpu-secondary-device-ids=0x0166 --gpu-active-vendor-id=0x8086 --gpu-active-device-id=0x0166 --start-stack-profiler --service-request-channel-token=1A9CED74D97278C0212FE9BED2BA526D --mojo-platform-channel-handle=2232 --ignored=" --type=renderer " /prefetch:2
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=renderer --field-trial-handle=1484 --primordial-pipe-token=B5CE9C4AF87D07194D410F6526132134 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=B5CE9C4AF87D07194D410F6526132134 --renderer-client-id=13 --mojo-platform-channel-handle=4516 /prefetch:1
"C:\Users\Lukas Fiala\AppData\Local\Google\Chrome SxS\Application\chrome.exe" --type=renderer --field-trial-handle=1484 --primordial-pipe-token=D95FD17ED33CA436896638CC24C69023 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=D95FD17ED33CA436896638CC24C69023 --renderer-client-id=19 --mojo-platform-channel-handle=5424 /prefetch:1
"C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe" -Embedding
C:\Windows\System32\smartscreen.exe -Embedding
C:\Windows\system32\AUDIODG.EXE 0x31c
"C:\Users\Lukas Fiala\Downloads\RSITx64.exe"
====== Scheduled tasks folder ======
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2774955484-2510873228-3376545502-1001Core - C:\Users\Lukas Fiala\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2774955484-2510873228-3376545502-1001UA - C:\Users\Lukas Fiala\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\OneDrive Standalone Update Task v2 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1490047428 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\User_Feed_Synchronization-{637236E8-35F1-4609-8CF1-F5A68F581466} - C:\Windows\system32\msfeedssync.exe sync
C:\Windows\system32\tasks\{6D24B0CE-74E8-41D4-BB39-5E8CDB551D45} - "c:\program files (x86)\google\chrome\application\chrome.exe" https://www.skype.com/go/downloading?so ... rror=12007
C:\Windows\system32\tasks\{77F2D994-0933-4A78-B715-744737D26078} - "c:\windows\system32\launchwinapp.exe" https://www.skype.com/go/downloading?so ... rror=12007
C:\Windows\system32\tasks\{BA3B7997-AFCB-400A-B001-DAFC5D30306B} - "c:\program files (x86)\google\chrome\application\chrome.exe" https://www.skype.com/go/downloading?so ... rror=12007
C:\Windows\system32\tasks\{DB7612C9-A14D-4D49-8490-6DA2C6DF3E8A} - "c:\program files (x86)\google\chrome\application\chrome.exe" https://ui.skype.com/ui/0/7.32.0.104/cs ... age=tsBing
C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask - %systemroot%\system32\sc.exe start osppsvc
C:\Windows\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\Windows\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - %ProgramFiles%\Windows Defender\MpCmdRun.exe Scan -ScheduleJob
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\Windows\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe Reboot
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - %systemroot%\system32\MusNotification.exe Display
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - %systemroot%\system32\MusNotification.exe ReadyToReboot
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\Windows\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\Windows\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\Windows\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\Windows\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
======Registry dump ======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-04-28 3954352]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-09-07 631808]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Lukas Fiala\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-03-03 1518304]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]
"Google Update"=C:\Users\Lukas Fiala\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [2017-03-21 601752]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-11-04 767176]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-20 205512]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SOLIDWORKS 2016 Rychlé spuštění.lnk - C:\Windows\Installer\{768F3B65-1695-47B7-9002-B11400CB111D}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SOLIDWORKS Nástroj pro stahování na pozadí.lnk - C:\Program Files (x86)\Common Files\Manažer instalací SOLIDWORKS\BackgroundDownloading\sldBgDwld.exe
Virtual Router Manager.lnk - C:\Windows\Installer\{BE905C46-2B34-4D73-AEE1-769ED138E0FF}\_118D1A4EFFA6998C3492EB.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
====== File associations ======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
====== List of files/folders created in the last 1 month ======
2017-03-21 13:28:37 ----D---- C:\Program Files\trend micro
2017-03-21 13:28:36 ----D---- C:\rsit
2017-03-21 01:42:12 ----D---- C:\ProgramData\SWCUTemp
2017-03-21 01:39:01 ----D---- C:\ProgramData\dbg
2017-03-21 00:44:04 ----SHD---- C:\Config.Msi
2017-03-21 00:21:27 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\TeamViewer
2017-03-21 00:21:17 ----D---- C:\Program Files (x86)\TeamViewer
2017-03-20 23:04:53 ----RD---- C:\Program Files (x86)\Skype
2017-03-20 23:02:43 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2017-03-20 23:00:49 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\AVAST Software
2017-03-20 23:00:21 ----D---- C:\Program Files\Common Files\AV
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswvmm.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswStm.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswsp.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbuniva.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbloga.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbidsha.sys
2017-03-20 23:00:06 ----A---- C:\Windows\system32\drivers\aswbidsdrivera.sys
2017-03-20 22:59:55 ----A---- C:\Windows\system32\aswBoot.exe
2017-03-20 22:56:15 ----D---- C:\Program Files\AVAST Software
2017-03-20 22:55:38 ----D---- C:\ProgramData\AVAST Software
2017-03-17 21:28:11 ----D---- C:\ProgramData\Simpoe
2017-03-17 21:27:23 ----D---- C:\ProgramData\COSMOS Applications
2017-03-17 21:27:16 ----D---- C:\ProgramData\SOLIDWORKS Flow Simulation
2017-03-17 21:23:34 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\pdfforge
2017-03-17 21:23:33 ----A---- C:\Windows\system32\pdfcmon.dll
2017-03-17 21:23:32 ----D---- C:\Program Files\PDFCreator
2017-03-17 21:22:51 ----D---- C:\ProgramData\Dassault Systemes
2017-03-17 21:19:34 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2017-03-17 21:19:23 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\help_images_otherUI
2017-03-17 21:17:21 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\DassaultSystemes
2017-03-17 21:17:21 ----D---- C:\ProgramData\DassaultSystemes
2017-03-17 21:02:56 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-03-17 21:02:13 ----AD---- C:\ProgramData\SOLIDWORKS
2017-03-17 21:02:13 ----AD---- C:\Program Files\SOLIDWORKS Corp
2017-03-17 21:02:13 ----AD---- C:\Program Files\Common Files\SOLIDWORKS Shared
2017-03-17 21:01:46 ----D---- C:\Program Files\Common Files\Macrovision Shared
2017-03-17 20:59:28 ----AD---- C:\Program Files\Microsoft Visual Studio 8
2017-03-17 20:56:35 ----A---- C:\Windows\SYSWOW64\perf-MSSQL12.TEW_SQLEXPRESS-sqlagtctr.dll
2017-03-17 20:56:34 ----A---- C:\Windows\system32\perf-MSSQL12.TEW_SQLEXPRESS-sqlagtctr.dll
2017-03-17 20:56:16 ----A---- C:\Windows\SYSWOW64\perf-MSSQL$TEW_SQLEXPRESS-sqlctr12.1.4100.1.dll
2017-03-17 20:56:16 ----A---- C:\Windows\system32\perf-MSSQL$TEW_SQLEXPRESS-sqlctr12.1.4100.1.dll
2017-03-17 20:56:09 ----A---- C:\Windows\system32\fssres.dll
2017-03-17 20:56:07 ----A---- C:\Windows\system32\hadrres.dll
2017-03-17 20:55:06 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2017-03-17 20:54:55 ----D---- C:\Windows\system32\RsFx
2017-03-17 20:54:42 ----D---- C:\Program Files\Microsoft.NET
2017-03-17 20:53:40 ----D---- C:\Windows\SYSWOW64\1033
2017-03-17 20:53:40 ----D---- C:\Windows\system32\1033
2017-03-17 20:52:55 ----AD---- C:\Program Files (x86)\Microsoft SQL Server
2017-03-17 20:51:35 ----AD---- C:\Program Files\Microsoft SQL Server
2017-03-17 20:49:51 ----D---- C:\ProgramData\Apple
2017-03-17 20:49:51 ----AD---- C:\Program Files\Bonjour
2017-03-17 20:49:51 ----AD---- C:\Program Files (x86)\Bonjour
2017-03-17 20:48:07 ----D---- C:\Program Files (x86)\MSECache
2017-03-17 20:41:32 ----AD---- C:\ProgramData\SOLIDWORKS Electrical
2017-03-17 20:41:08 ----D---- C:\ProgramData\FLEXnet
2017-03-17 20:40:52 ----D---- C:\SOLIDWORKS Data
2017-03-17 20:34:51 ----D---- C:\Windows\SolidWorks
2017-03-17 20:34:50 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\SOLIDWORKS
2017-03-17 20:27:09 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\WinRAR
2017-03-17 20:26:41 ----AD---- C:\Program Files\WinRAR
2017-03-17 11:32:20 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\uTorrent
2017-03-17 11:18:44 ----D---- C:\Program Files\My Web Shield
2017-03-17 11:18:44 ----A---- C:\Windows\system32\drivers\mwescontroller.sys
2017-03-17 11:18:09 ----D---- C:\ProgramData\e8bbe469-7fb3-1
2017-03-17 11:18:09 ----D---- C:\ProgramData\e8bbe469-1481-0
2017-03-17 11:18:00 ----D---- C:\Program Files (x86)\OneSystemCare
2017-03-16 22:23:37 ----D---- C:\Program Files (x86)\Adobe
2017-03-16 22:23:17 ----D---- C:\ProgramData\Adobe
2017-03-08 17:35:46 ----AD---- C:\Program Files (x86)\Virtual Router
2017-03-07 17:54:30 ----D---- C:\ProgramData\Skype
2017-03-04 01:12:54 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\vlc
2017-03-04 01:12:20 ----D---- C:\Program Files (x86)\VideoLAN
2017-03-04 00:39:30 ----D---- C:\Program Files (x86)\Google
2017-03-03 14:15:14 ----A---- C:\Windows\AutoKMS.ini
2017-03-03 14:04:50 ----D---- C:\Windows\SYSWOW64\XPSViewer
2017-03-03 14:04:07 ----D---- C:\Program Files (x86)\Reference Assemblies
2017-03-03 14:04:05 ----D---- C:\Program Files\Reference Assemblies
2017-03-03 14:04:05 ----D---- C:\Program Files\MSBuild
2017-03-03 14:01:51 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2017-03-03 14:01:51 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2017-03-03 14:01:51 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-03-03 14:01:44 ----A---- C:\Windows\system32\TsWpfWrp.exe
2017-03-03 14:01:44 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2017-03-03 14:01:44 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-03-03 14:00:38 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\Skype
2017-03-03 13:53:11 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\Macromedia
2017-03-03 13:49:43 ----AD---- C:\Program Files\Common Files\DESIGNER
2017-03-03 13:48:54 ----AD---- C:\Program Files (x86)\MSBuild
2017-03-03 13:48:44 ----D---- C:\Windows\PCHEALTH
2017-03-03 13:48:44 ----D---- C:\Program Files\Microsoft Sync Framework
2017-03-03 13:46:32 ----AD---- C:\Program Files (x86)\Microsoft Visual Studio 8
2017-03-03 13:45:51 ----D---- C:\Windows\SHELLNEW
2017-03-03 13:45:51 ----D---- C:\Program Files\Microsoft Analysis Services
2017-03-03 13:45:51 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2017-03-03 13:45:44 ----D---- C:\Program Files (x86)\Microsoft Office
2017-03-03 13:45:43 ----D---- C:\ProgramData\Microsoft Help
2017-03-03 13:45:43 ----AD---- C:\Program Files\Microsoft Office
2017-03-03 13:45:33 ----RHD---- C:\MSOCache
2017-03-02 00:17:04 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-03-01 19:47:42 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\ATI
2017-03-01 19:47:42 ----D---- C:\ProgramData\ATI
2017-03-01 19:47:10 ----D---- C:\ProgramData\Synaptics
2017-03-01 19:47:09 ----D---- C:\Users\Lukas Fiala\AppData\Roaming\Synaptics
2017-03-01 19:47:04 ----A---- C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2017-03-01 16:20:06 ----D---- C:\Windows\system32\MRT
2017-03-01 16:19:47 ----AC---- C:\Windows\system32\MRT.exe
2017-03-01 16:07:36 ----A---- C:\Windows\system32\wmp.dll
2017-03-01 16:07:35 ----A---- C:\Windows\SYSWOW64\wmp.dll
2017-03-01 16:07:35 ----A---- C:\Windows\SYSWOW64\DolbyDecMFT.dll
2017-03-01 16:07:34 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2017-03-01 16:07:34 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2017-03-01 16:07:33 ----A---- C:\Windows\SYSWOW64\mos.dll
2017-03-01 16:07:33 ----A---- C:\Windows\system32\MFMediaEngine.dll
2017-03-01 16:07:32 ----A---- C:\Windows\SYSWOW64\tquery.dll
2017-03-01 16:07:32 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2017-03-01 16:07:32 ----A---- C:\Windows\system32\d3d10warp.dll
2017-03-01 16:07:32 ----A---- C:\Windows\system32\appraiser.dll
2017-03-01 16:07:32 ----A---- C:\Windows\system32\acmigration.dll
2017-03-01 16:07:31 ----A---- C:\Windows\SYSWOW64\MapRouter.dll
2017-03-01 16:07:31 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\wsp_fs.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\d3d11.dll
2017-03-01 16:07:31 ----A---- C:\Windows\system32\CoreUIComponents.dll
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2017-03-01 16:07:30 ----A---- C:\Windows\SYSWOW64\MapGeocoder.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\wlansvc.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\mfsvr.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\mfcore.dll
2017-03-01 16:07:30 ----A---- C:\Windows\system32\dwmcore.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2017-03-01 16:07:29 ----A---- C:\Windows\SYSWOW64\d3d9.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\wsp_health.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\mfplat.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\mfnetsrc.dll
2017-03-01 16:07:29 ----A---- C:\Windows\system32\mfnetcore.dll
2017-03-01 16:07:28 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2017-03-01 16:07:28 ----A---- C:\Windows\SYSWOW64\msctf.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\wwansvc.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\Windows.Networking.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\mstsc.exe
2017-03-01 16:07:28 ----A---- C:\Windows\system32\mfreadwrite.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\generaltel.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\FntCache.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\devinv.dll
2017-03-01 16:07:28 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-03-01 16:07:27 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\wsp_sr.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\spoolsv.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\msvproc.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\mstscax.dll
2017-03-01 16:07:27 ----A---- C:\Windows\system32\hvix64.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\hvax64.exe
2017-03-01 16:07:27 ----A---- C:\Windows\system32\aeinv.dll
2017-03-01 16:07:26 ----A---- C:\Windows\SYSWOW64\ole32.dll
2017-03-01 16:07:26 ----A---- C:\Windows\SYSWOW64\JpMapControl.dll
2017-03-01 16:07:26 ----A---- C:\Windows\SYSWOW64\gdi32full.dll
2017-03-01 16:07:26 ----A---- C:\Windows\system32\Windows.Media.dll
2017-03-01 16:07:26 ----A---- C:\Windows\system32\win32spl.dll
2017-03-01 16:07:26 ----A---- C:\Windows\system32\AppReadiness.dll
2017-03-01 16:07:25 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2017-03-01 16:07:25 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\WWanAPI.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\usercpl.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\mfmkvsrcsnk.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\LockAppHost.exe
2017-03-01 16:07:25 ----A---- C:\Windows\system32\localspl.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\invagent.dll
2017-03-01 16:07:25 ----A---- C:\Windows\system32\hvloader.exe
2017-03-01 16:07:25 ----A---- C:\Windows\system32\drivers\bthport.sys
2017-03-01 16:07:25 ----A---- C:\Windows\system32\D3D12.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\wer.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\NMAA.dll
2017-03-01 16:07:24 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2017-03-01 16:07:24 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\nettrace.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\mfksproxy.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\dxgi.dll
2017-03-01 16:07:24 ----A---- C:\Windows\system32\aepic.dll
2017-03-01 16:07:23 ----A---- C:\Windows\SYSWOW64\mprdim.dll
2017-03-01 16:07:23 ----A---- C:\Windows\SYSWOW64\MapConfiguration.dll
2017-03-01 16:07:23 ----A---- C:\Windows\SYSWOW64\InputService.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\Windows.Networking.Vpn.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\SpeechPal.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\services.exe
2017-03-01 16:07:23 ----A---- C:\Windows\system32\ReAgent.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\NetworkBindingEngineMigPlugin.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\mprdim.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\mfaudiocnv.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\LockAppBroker.dll
2017-03-01 16:07:23 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2017-03-01 16:07:23 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2017-03-01 16:07:22 ----A---- C:\Windows\SYSWOW64\MapControlCore.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\Windows.Web.Http.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\Windows.Web.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\TSWorkspace.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\nshwfp.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\DscCore.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\drivers\tpm.sys
2017-03-01 16:07:22 ----A---- C:\Windows\system32\drivers\BthLEEnum.sys
2017-03-01 16:07:22 ----A---- C:\Windows\system32\d2d1.dll
2017-03-01 16:07:22 ----A---- C:\Windows\system32\clusapi.dll
2017-03-01 16:07:21 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2017-03-01 16:07:21 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2017-03-01 16:07:21 ----A---- C:\Windows\SYSWOW64\biwinrt.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\SpaceAgent.exe
2017-03-01 16:07:21 ----A---- C:\Windows\system32\SensorService.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\rdpcore.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\FontProvider.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\drivers\sdbus.sys
2017-03-01 16:07:21 ----A---- C:\Windows\system32\discan.dll
2017-03-01 16:07:21 ----A---- C:\Windows\system32\aitstatic.exe
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\weretw.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\StoreAgent.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\MapsBtSvc.dll
2017-03-01 16:07:20 ----A---- C:\Windows\SYSWOW64\DataExchange.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\wmpps.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\wmpeffects.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\wlancfg.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\MSVideoDSP.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\MiracastReceiver.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\icsvc.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\drivers\dumpsd.sys
2017-03-01 16:07:20 ----A---- C:\Windows\system32\drivers\bowser.sys
2017-03-01 16:07:20 ----A---- C:\Windows\system32\CastLaunch.dll
2017-03-01 16:07:20 ----A---- C:\Windows\system32\browserbroker.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\MosStorage.dll
2017-03-01 16:07:18 ----A---- C:\Windows\SYSWOW64\input.dll
2017-03-01 16:07:18 ----A---- C:\Windows\system32\Windows.Media.Audio.dll
2017-03-01 16:07:18 ----A---- C:\Windows\system32\Sens.dll
2017-03-01 16:07:18 ----A---- C:\Windows\system32\drivers\hidclass.sys
2017-03-01 16:07:18 ----A---- C:\Windows\system32\drivers\EhStorTcgDrv.sys
2017-03-01 16:07:18 ----A---- C:\Windows\system32\drivers\dam.sys
2017-03-01 16:07:18 ----A---- C:\Windows\system32\credprovs.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\Windows.UI.Cred.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\UserDataTimeUtil.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\tsmf.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\Phoneutil.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\InstallAgentUserBroker.exe
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\EmailApis.dll
2017-03-01 16:07:17 ----A---- C:\Windows\SYSWOW64\credprovs.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\wmpshell.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\Windows.Networking.HostName.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\powercfg.exe
2017-03-01 16:07:17 ----A---- C:\Windows\system32\migisol.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\mfps.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\MCRecvSrc.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\iscsiwmi.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\dialserver.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\BootMenuUX.dll
2017-03-01 16:07:17 ----A---- C:\Windows\system32\ActionCenterCPL.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\WWanAPI.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Picker.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\Windows.Devices.LowLevel.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\InstallAgent.exe
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\ChatApis.dll
2017-03-01 16:07:16 ----A---- C:\Windows\SYSWOW64\ActionCenterCPL.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\wmpdxm.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\sppnp.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\ReAgentc.exe
2017-03-01 16:07:16 ----A---- C:\Windows\system32\mfsrcsnk.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\MFCaptureEngine.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\devenum.dll
2017-03-01 16:07:16 ----A---- C:\Windows\system32\ActionCenter.dll
2017-03-01 16:07:15 ----A---- C:\Windows\SYSWOW64\Windows.UI.CredDialogController.dll
2017-03-01 16:07:15 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2017-03-01 16:07:15 ----A---- C:\Windows\system32\Windows.Graphics.Printing.dll
2017-03-01 16:07:15 ----A---- C:\Windows\system32\kdhvcom.dll
2017-03-01 16:07:15 ----A---- C:\Windows\system32\drivers\hvservice.sys
2017-03-01 16:07:14 ----A---- C:\Windows\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-03-01 16:07:14 ----A---- C:\Windows\SYSWOW64\UserDataAccountApis.dll
2017-03-01 16:07:14 ----A---- C:\Windows\SYSWOW64\pwrshplugin.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\wlanapi.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\rdpencom.dll
2017-03-01 16:07:14 ----A---- C:\Windows\system32\cmintegrator.dll
2017-03-01 16:07:14 ----A---- C:\Windows\splwow64.exe
2017-03-01 16:07:13 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-01 16:07:13 ----A---- C:\Windows\SYSWOW64\msdtcuiu.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\pwrshplugin.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\fhcpl.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\encapi.dll
2017-03-01 16:07:13 ----A---- C:\Windows\system32\drivers\kbdhid.sys
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\WordBreakers.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\Windows.UI.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\PlayToReceiver.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\LockAppBroker.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\InputLocaleManager.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\EditBufferTestHook.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\ContactApis.dll
2017-03-01 16:07:11 ----A---- C:\Windows\SYSWOW64\AppointmentApis.dll
2017-03-01 16:07:11 ----A---- C:\Windows\system32\Windows.Media.FaceAnalysis.dll
2017-03-01 16:07:11 ----A---- C:\Windows\system32\Windows.Cortana.Desktop.dll
2017-03-01 16:07:11 ----A---- C:\Windows\system32\AboveLockAppHost.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.UI.BlockedShutdown.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.UI.BioFeedback.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\Windows.Media.Ocr.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\msinfo32.exe
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\chartv.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\apprepsync.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\apprepapi.dll
2017-03-01 16:07:10 ----A---- C:\Windows\SYSWOW64\AppointmentActivation.dll
2017-03-01 16:07:10 ----A---- C:\Windows\system32\resutils.dll
2017-03-01 16:07:10 ----A---- C:\Windows\system32\netshell.dll
2017-03-01 16:07:10 ----A---- C:\Windows\system32\chartv.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\Windows.Energy.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\VCardParser.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataTypeHelperUtil.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataPlatformHelperUtil.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataLanguageUtil.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\UserDataAccessRes.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\POSyncServices.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\NmaDirect.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\MosResource.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\MosHostClient.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\ExtrasXmlParser.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\ExSMime.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\ContactActivation.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\comsvcs.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\BingOnlineServices.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\AddressParser.dll
2017-03-01 16:07:09 ----A---- C:\Windows\SYSWOW64\AboveLockAppHost.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\wwanprotdim.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\wlansec.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\OnDemandConnRouteHelper.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\netplwiz.dll
2017-03-01 16:07:09 ----A---- C:\Windows\system32\drivers\hidparse.sys
2017-03-01 16:07:09 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2017-03-01 16:07:09 ----A---- C:\Windows\system32\drivers\bthenum.sys
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\PhoneutilRes.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\odbcconf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\Microsoft-Windows-MosTrace.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\Microsoft-Windows-MosHost.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\Microsoft-Windows-MapControls.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\MapControlStringsRes.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\SYSWOW64\deviceassociation.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wlansvcpal.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wlanmsm.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wlanhlp.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wifiprofilessettinghandler.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\WiFiConfigSP.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\wfdprov.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\tcpipcfg.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\spwmp.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\odbcconf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\netiougc.exe
2017-03-01 16:07:08 ----A---- C:\Windows\system32\dxmasf.dll
2017-03-01 16:07:08 ----A---- C:\Windows\system32\drivers\hidusb.sys
2017-03-01 16:07:07 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2017-03-01 16:07:07 ----A---- C:\Windows\SYSWOW64\DscCoreConfProv.dll
2017-03-01 16:07:07 ----A---- C:\Windows\system32\wmploc.DLL
2017-03-01 16:07:07 ----A---- C:\Windows\system32\DscCoreConfProv.dll
2017-03-01 16:07:06 ----A---- C:\Windows\system32\sppsvc.exe
2017-03-01 16:07:05 ----A---- C:\Windows\system32\sppobjs.dll
2017-03-01 16:07:05 ----A---- C:\Windows\system32\shell32.dll
2017-03-01 16:07:04 ----A---- C:\Windows\system32\storagewmi.dll
2017-03-01 16:07:04 ----A---- C:\Windows\system32\spaceman.exe
2017-03-01 16:07:04 ----A---- C:\Windows\system32\mispace.dll
2017-03-01 16:07:04 ----A---- C:\Windows\system32\dbgeng.dll
2017-03-01 16:07:03 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2017-03-01 16:07:03 ----A---- C:\Windows\SYSWOW64\combase.dll
2017-03-01 16:07:03 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2017-03-01 16:07:03 ----A---- C:\Windows\system32\esent.dll
2017-03-01 16:07:03 ----A---- C:\Windows\system32\drivers\ClipSp.sys
2017-03-01 16:07:03 ----A---- C:\Windows\system32\combase.dll
2017-03-01 16:07:02 ----A---- C:\Windows\SYSWOW64\shell32.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\WsmSvc.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2017-03-01 16:07:02 ----A---- C:\Windows\system32\msxml6.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\msi.dll
2017-03-01 16:07:02 ----A---- C:\Windows\system32\CertEnroll.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\wevtsvc.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\qmgr.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\MSVidCtl.dll
2017-03-01 16:07:01 ----A---- C:\Windows\system32\diagtrack.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\hevcdecoder.dll
2017-03-01 16:07:00 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\winhttp.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\UIAutomationCore.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\KernelBase.dll
2017-03-01 16:07:00 ----A---- C:\Windows\system32\bisrv.dll
2017-03-01 16:06:59 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2017-03-01 16:06:59 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\xpsrchvw.exe
2017-03-01 16:06:59 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\fveapi.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\drivers\fvevol.sys
2017-03-01 16:06:59 ----A---- C:\Windows\system32\crypt32.dll
2017-03-01 16:06:59 ----A---- C:\Windows\system32\bcastdvr.exe
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.InkControls.dll
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\NetSetupEngine.dll
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2017-03-01 16:06:58 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\wuaueng.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\sppwinob.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\NetSetupShim.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\ncsi.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\GamePanel.exe
2017-03-01 16:06:58 ----A---- C:\Windows\system32\FrameServer.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\FlightSettings.dll
2017-03-01 16:06:58 ----A---- C:\Windows\system32\drvstore.dll
2017-03-01 16:06:57 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2017-03-01 16:06:57 ----A---- C:\Windows\SYSWOW64\rasapi32.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\wpx.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\wevtapi.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\uReFS.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\ubpm.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\NetSetupEngine.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\msv1_0.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\lsasrv.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\gpsvc.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\FSClient.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\facecredentialprovider.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\drivers\cng.sys
2017-03-01 16:06:57 ----A---- C:\Windows\system32\dnsapi.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\DeviceCensus.exe
2017-03-01 16:06:57 ----A---- C:\Windows\system32\ci.dll
2017-03-01 16:06:57 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2017-03-01 16:06:56 ----A---- C:\Windows\SYSWOW64\wsecedit.dll
2017-03-01 16:06:56 ----A---- C:\Windows\SYSWOW64\WinTypes.dll
2017-03-01 16:06:56 ----A---- C:\Windows\SYSWOW64\webio.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\wwanconn.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\wsecedit.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\wintrust.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\webio.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\schannel.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\SettingsHandlers_WorkAccess.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\PsmServiceExtHost.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\nltest.exe
2017-03-01 16:06:56 ----A---- C:\Windows\system32\NetSetupSvc.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\mprapi.dll
2017-03-01 16:06:56 ----A---- C:\Windows\system32\EditionUpgradeManagerObj.dll
2017-03-01 16:06:55 ----A---- C:\Windows\SYSWOW64\xpsrchvw.exe
2017-03-01 16:06:55 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2017-03-01 16:06:55 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Perception.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\wuapi.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\wer.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\mfsensorgroup.dll
2017-03-01 16:06:55 ----A---- C:\Windows\system32\fveapibase.dll
2017-03-01 16:06:54 ----A---- C:\Windows\SYSWOW64\ddraw.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\wkssvc.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\w32time.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\SndVolSSO.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\samsrv.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\nlasvc.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2017-03-01 16:06:54 ----A---- C:\Windows\system32\drivers\xboxgip.sys
2017-03-01 16:06:54 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\wlancfg.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\pdh.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\offlinesam.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\dmenrollengine.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\d3d8.dll
2017-03-01 16:06:53 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\winlogon.exe
2017-03-01 16:06:53 ----A---- C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\sppcext.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\setupugc.exe
2017-03-01 16:06:53 ----A---- C:\Windows\system32\SettingSync.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\profsvc.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\offlinesam.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\kerberos.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\ImplatSetup.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\wof.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\storport.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\fastfat.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\drivers\crashdmp.sys
2017-03-01 16:06:53 ----A---- C:\Windows\system32\dhcpcore6.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\dab.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\CPFilters.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\biwinrt.dll
2017-03-01 16:06:53 ----A---- C:\Windows\system32\bcrypt.dll
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\powercfg.exe
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\policymanager.dll
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-03-01 16:06:52 ----A---- C:\Windows\SYSWOW64\aclui.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\WinTypes.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\weretw.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\sbe.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\RDXService.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\qedit.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\dpapisrv.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\DeviceReactivation.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\cmifw.dll
2017-03-01 16:06:52 ----A---- C:\Windows\system32\CloudStorageWizard.exe
2017-03-01 16:06:52 ----A---- C:\Windows\system32\bcdedit.exe
2017-03-01 16:06:51 ----A---- C:\Windows\SYSWOW64\NetSetupApi.dll
2017-03-01 16:06:51 ----A---- C:\Windows\SYSWOW64\MSVP9DEC.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\wow64.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\Windows.Media.MediaControl.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\updatepolicy.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\NetSetupApi.dll
2017-03-01 16:06:51 ----A---- C:\Windows\system32\drivers\pdc.sys
2017-03-01 16:06:51 ----A---- C:\Windows\system32\adsmsext.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\pidgenx.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\offreg.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\CloudExperienceHostUser.dll
2017-03-01 16:06:49 ----A---- C:\Windows\SYSWOW64\CloudExperienceHostCommon.dll
2017-03-01 16:06:49 ----A---- C:\Windows\system32\wuauclt.exe
2017-03-01 16:06:49 ----A---- C:\Windows\system32\tsmf.dll
2017-03-01 16:06:49 ----A---- C:\Windows\system32\pidgenx.dll
2017-03-01 16:06:49 ----A---- C:\Windows\system32\GenValObj.exe
2017-03-01 16:06:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\wlanapi.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\Windows.Devices.PointOfService.dll
2017-03-01 16:06:48 ----A---- C:\Windows\SYSWOW64\updatepolicy.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\wuuhext.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\WinSCard.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\Windows.ApplicationModel.Wallet.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\usermgr.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\umpoext.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\drivers\xinputhid.sys
2017-03-01 16:06:48 ----A---- C:\Windows\system32\CryptoWinRT.dll
2017-03-01 16:06:48 ----A---- C:\Windows\system32\BitLockerDeviceEncryption.exe
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Management.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\wincorlib.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\RTMediaFrame.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\ntshrui.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2017-03-01 16:06:47 ----A---- C:\Windows\SYSWOW64\CryptoWinRT.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\wincorlib.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\TSpkg.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\efsext.dll
2017-03-01 16:06:47 ----A---- C:\Windows\system32\cryptui.dll
2017-03-01 16:06:46 ----A---- C:\Windows\SYSWOW64\WinSCard.dll
2017-03-01 16:06:46 ----A---- C:\Windows\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-03-01 16:06:46 ----A---- C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2017-03-01 16:06:46 ----A---- C:\Windows\system32\NetCfgNotifyObjectHost.exe
2017-03-01 16:06:46 ----A---- C:\Windows\system32\BcastDVRHelper.dll
2017-03-01 16:06:46 ----A---- C:\Windows\system32\AppCapture.dll
2017-03-01 16:06:45 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.dll
2017-03-01 16:06:45 ----A---- C:\Windows\SYSWOW64\UserMgrProxy.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\wwanmm.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\wups.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\Windows.Media.Ocr.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\UserMgrProxy.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\ntshrui.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\ListSvc.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\EditionUpgradeHelper.dll
2017-03-01 16:06:45 ----A---- C:\Windows\system32\certprop.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\WinRtTracing.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Core.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\SearchFolder.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\netshell.dll
2017-03-01 16:06:44 ----A---- C:\Windows\SYSWOW64\mdmregistration.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\Windows.Web.Diagnostics.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\Windows.StateRepositoryBroker.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\SettingSyncPolicy.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\ScDeviceEnum.dll
2017-03-01 16:06:44 ----A---- C:\Windows\system32\esentutl.exe
2017-03-01 16:06:44 ----A---- C:\Windows\system32\EncDec.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\wlanhlp.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\wfdprov.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\tzres.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\samlib.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\offlinelsa.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\imapi2.dll
2017-03-01 16:06:43 ----A---- C:\Windows\SYSWOW64\container.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\wups2.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\UIRibbonRes.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\tzres.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\storagewmi_passthru.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\sppc.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\smphost.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\slcext.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\slc.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\samlib.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\offlinelsa.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\msxml6r.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\delegatorprovider.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\DbgModel.dll
2017-03-01 16:06:43 ----A---- C:\Windows\system32\C_IS2022.DLL
2017-03-01 16:06:43 ----A---- C:\Windows\system32\c_GSM7.DLL
2017-03-01 16:06:43 ----A---- C:\Windows\system32\C_G18030.DLL
2017-03-01 16:06:42 ----A---- C:\Windows\system32\mshtml.dll
2017-03-01 16:06:39 ----A---- C:\Windows\system32\edgehtml.dll
2017-03-01 16:06:38 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-03-01 16:06:38 ----A---- C:\Windows\system32\jscript9.dll
2017-03-01 16:06:37 ----A---- C:\Windows\system32\twinui.dll
2017-03-01 16:06:36 ----A---- C:\Windows\SYSWOW64\MSVPXENC.dll
2017-03-01 16:06:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-03-01 16:06:36 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2017-03-01 16:06:35 ----A---- C:\Windows\system32\wininet.dll
2017-03-01 16:06:35 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2017-03-01 16:06:35 ----A---- C:\Windows\system32\MSAudDecMFT.dll
2017-03-01 16:06:34 ----A---- C:\Windows\SYSWOW64\msi.dll
2017-03-01 16:06:34 ----A---- C:\Windows\system32\wlidsvc.dll
2017-03-01 16:06:34 ----A---- C:\Windows\explorer.exe
2017-03-01 16:06:33 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2017-03-01 16:06:33 ----A---- C:\Windows\system32\Chakra.dll
2017-03-01 16:06:32 ----A---- C:\Windows\SYSWOW64\twinui.dll
2017-03-01 16:06:32 ----A---- C:\Windows\SYSWOW64\explorer.exe
2017-03-01 16:06:32 ----A---- C:\Windows\SYSWOW64\esent.dll
2017-03-01 16:06:32 ----A---- C:\Windows\system32\msftedit.dll
2017-03-01 16:06:31 ----A---- C:\Windows\SYSWOW64\wsp_fs.dll
2017-03-01 16:06:31 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2017-03-01 16:06:31 ----A---- C:\Windows\system32\SharedStartModel.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\urlmon.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\ResetEngine.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\iertutil.dll
2017-03-01 16:06:30 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-03-01 16:06:29 ----A---- C:\Windows\SYSWOW64\wsp_health.dll
2017-03-01 16:06:29 ----A---- C:\Windows\SYSWOW64\MrmCoreR.dll