Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o preventivku.

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Uživatelský avatar
Andyfuk
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 29 říj 2011 11:02
Kontaktovat uživatele:

Prosím o preventivku.

#1 Příspěvek od Andyfuk »

Zdravím, chtěl bych poprosit o preventivku jelikož počítač se občasně seká a zpomaluje. Děkuji mnohokrát

Logfile of random's system information tool 1.10 (written by random/random)
Run by SLIP at 2017-03-22 12:09:17
Microsoft Windows 10 Home
System drive C: has 24 GB (10%) free of 238 GB
Total RAM: 16347 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:09:19, on 22.03.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Users\SLIP\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files\Andy\HandyAndy.exe
C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\Xtreme.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe
C:\Program Files\trend micro\SLIP.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Super Charger] C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Corsair Utility Engine] "C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe" --autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\SLIP\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\SLIP\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Steam] "E:\Program Files\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: Curse.lnk = C:\Users\SLIP\AppData\Roaming\Curse Client\Bin\Curse.exe
O4 - Startup: GIGABYTE XTREME GAMING ENGINE.lnk = C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\autorun.exe
O4 - Global Startup: HandyAndy.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: Intel Bluetooth Service (ibtsiva.exe) - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: Intel(R) Security Assist - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Security Assist Helper (isaHelperSvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: Intel Security PEF Service (PEFService) - Intel Security, Inc. - C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\SysWoW64\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\SysWoW64\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 14580 bytes

======Listing Processes======








C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted

C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe"
dashost.exe {d696d067-0544-4cc2-a3b9c36f57157e86}
"C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
C:\WINDOWS\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
"C:\Program Files (x86)\Origin\OriginWebHelperService.exe"
"C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe"
C:\WINDOWS\SysWoW64\vmnetdhcp.exe
"C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe"
C:\WINDOWS\SysWoW64\vmnat.exe
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"

C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-51dbddd8-36e2-4dea-a0de-0328bc29a37a -SystemEventPortName:HostProcess-c2f511da-4d1c-4de6-8d72-b4f9cdf86ce4 -IoCancelEventPortName:HostProcess-a5f2bf2c-3ac5-4e07-85a8-fa2de3e8e1d5 -NonStateChangingEventPortName:HostProcess-aaa51c80-1310-4c20-ab30-6fdc5f59f880 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6216bbac-5177-43e6-bf12-77b08849f148 -DeviceGroupId:WpdFsGroup


C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"dwm.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Users\SLIP\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"C:\Program Files\Andy\HandyAndy.exe"
"C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe"
AvastUI.exe /nogui
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\Xtreme.exe" /h
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"fontdrvhost.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVShNotify.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\AUDIODG.EXE 0x3c8
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe" -Embedding
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=renderer --disable-gpu-compositing --no-sandbox --primordial-pipe-token=0DDEFC81B8B50C3D25FC33F742ADFFCE --lang=en-US --lang=en-US --log-file="C:\Users\SLIP\AppData\Local\NVIDIA Corporation\NVIDIA Share\CefCache\debug.log" --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --service-request-channel-token=0DDEFC81B8B50C3D25FC33F742ADFFCE --renderer-client-id=2 --mojo-platform-channel-handle=1860 /prefetch:1
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
C:\WINDOWS\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\SLIP\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\SLIP\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=56.0.2924.87 --initial-client-data=0x1d0,0x1d4,0x1d8,0x1cc,0x1dc,0x7ffb69111160,0x7ffb69111140,0x7ffb69111118
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=7508 --on-initialized-event-handle=616 --parent-handle=632 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledSynchronousSigning/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_84/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_18/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Default/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,19,20,23,40,71 --gpu-vendor-id=0x10de --gpu-device-id=0x1b81 --gpu-driver-vendor=NVIDIA --gpu-driver-version=21.21.13.7892 --gpu-driver-date=3-16-2017 --service-request-channel-token=7782F083B03C6E3627C9B7C13C449200 --mojo-platform-channel-handle=1316 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledSynchronousSigning/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_84/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_18/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Default/ --primordial-pipe-token=B35543EC1DBFBD846B3B8FDE3182BBF9 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=B35543EC1DBFBD846B3B8FDE3182BBF9 --renderer-client-id=4 --mojo-platform-channel-handle=2940 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledSynchronousSigning/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_84/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_18/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Default/ --primordial-pipe-token=A139A81553A7C53752DE6866E29E894D --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=A139A81553A7C53752DE6866E29E894D --renderer-client-id=5 --mojo-platform-channel-handle=2952 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledSynchronousSigning/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_84/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_18/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Default/ --primordial-pipe-token=8A5D7E9782D201C28B7D0362F9D367E2 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=8A5D7E9782D201C28B7D0362F9D367E2 --renderer-client-id=6 --mojo-platform-channel-handle=2956 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledSynchronousSigning/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_84/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_18/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Default/ --primordial-pipe-token=FA35E0675597203470B3CE54BA5EFB42 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=FA35E0675597203470B3CE54BA5EFB42 --renderer-client-id=7 --mojo-platform-channel-handle=2964 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/*EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledSynchronousSigning/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_84/*UMA-Uniformity-Trial-10-Percent/group_09/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_18/*UMA-Uniformity-Trial-50-Percent/default/*WebFontsInterventionV2/Default/ --primordial-pipe-token=2C91DFBFEF709ADFFF8FAAB016216CBA --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=2C91DFBFEF709ADFFF8FAAB016216CBA --renderer-client-id=10 --mojo-platform-channel-handle=6412 /prefetch:1
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"E:\Downloads\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\SLIP\AppData\Roaming\Mozilla\Firefox\Profiles\4ta3hkdo.default

"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF48
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF48


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf]
"Description"=Handles PDF files in place in the browser
"Path"=C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf]
"Description"=Handles PDF files in place in the browser
"Path"=C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-03-06 213704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-18 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-03-06 3002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-18 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-01-18 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-18 186944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-10-16 8725248]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2017-02-23 1880512]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-09-24 631808]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2017-01-19 176440]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\SLIP\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-03-04 1518304]
"Spotify Web Helper"=C:\Users\SLIP\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-12-16 1444976]
"AdobeBridge"= []
"Steam"=E:\Program Files\Steam\steam.exe [2017-03-13 3019552]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Super Charger"=C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [2015-09-09 1027024]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-02 205512]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"Corsair Utility Engine"=C:\Program Files (x86)\Corsair\Corsair Utility Engine\CUE.exe [2016-10-12 12348112]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HandyAndy.lnk - C:\Program Files\Andy\HandyAndy.exe

C:\Users\SLIP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Curse.lnk - C:\Users\SLIP\AppData\Roaming\Curse Client\Bin\Curse.exe
GIGABYTE XTREME GAMING ENGINE.lnk - C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\autorun.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeaack]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeaack.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeavfk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeavfk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfemms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfencbdc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfencbdc.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux"=wdmaud.drv
"wave7"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

Uživatelský avatar
Andyfuk
Návštěvník
Návštěvník
Příspěvky: 65
Registrován: 29 říj 2011 11:02
Kontaktovat uživatele:

Re: Prosím o preventivku.

#2 Příspěvek od Andyfuk »

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"

======List of files/folders created in the last 1 month======

2017-03-22 12:09:17 ----D---- C:\rsit
2017-03-22 11:42:44 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2017-03-22 11:42:38 ----D---- C:\Program Files (x86)\VulkanRT
2017-03-22 11:42:38 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2017-03-22 11:42:38 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2017-03-22 11:42:38 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2017-03-22 11:42:38 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2017-03-22 11:41:47 ----D---- C:\WINDOWS\LastGood
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFThevc.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFTH264.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvDecMFTMjpeg.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvopencl.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvmcumd.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvEncMFThevc.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvEncMFTH264.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvdispgenco6437892.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvdispco6437892.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2017-03-22 11:40:32 ----A---- C:\WINDOWS\system32\nvcuda.dll
2017-03-22 11:40:31 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2017-03-22 11:40:31 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2017-03-17 00:27:14 ----D---- C:\ProgramData\SWCUTemp
2017-03-15 19:43:51 ----RD---- C:\Program Files (x86)\Skype
2017-03-15 17:28:08 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2017-03-15 17:28:04 ----A---- C:\WINDOWS\SYSWOW64\WPDShServiceObj.dll
2017-03-15 17:28:04 ----A---- C:\WINDOWS\SYSWOW64\wlanui.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\UserLanguagesCpl.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\themecpl.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\tapi32.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\msutb.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\msctfui.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\mscandui.dll
2017-03-15 17:28:03 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\sud.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\msctfp.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-03-15 17:28:02 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-03-15 17:28:00 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2017-03-15 17:28:00 ----A---- C:\WINDOWS\SYSWOW64\PhotoScreensaver.scr
2017-03-15 17:28:00 ----A---- C:\WINDOWS\SYSWOW64\mprddm.dll
2017-03-15 17:27:59 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-03-15 17:27:59 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-03-15 17:27:59 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-03-15 17:27:57 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2017-03-15 17:27:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.Search.dll
2017-03-15 17:27:56 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2017-03-15 17:27:54 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-03-15 17:27:52 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-03-15 17:27:50 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-03-15 17:27:50 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2017-03-15 17:27:50 ----A---- C:\WINDOWS\SYSWOW64\hgcpl.dll
2017-03-15 17:27:50 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2017-03-15 17:27:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-03-15 17:27:49 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-03-15 17:27:49 ----A---- C:\WINDOWS\SYSWOW64\ddrawex.dll
2017-03-15 17:27:49 ----A---- C:\WINDOWS\SYSWOW64\ddraw.dll
2017-03-15 17:27:48 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2017-03-15 17:27:46 ----A---- C:\WINDOWS\SYSWOW64\mtxclu.dll
2017-03-15 17:27:46 ----A---- C:\WINDOWS\SYSWOW64\msdtcuiu.dll
2017-03-15 17:27:46 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2017-03-15 17:27:46 ----A---- C:\WINDOWS\SYSWOW64\BrowserSettingSync.dll
2017-03-15 17:27:44 ----A---- C:\WINDOWS\SYSWOW64\PCPTpm12.dll
2017-03-15 17:27:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2017-03-15 17:27:43 ----A---- C:\WINDOWS\SYSWOW64\azroleui.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\mssphtb.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\mssitlb.dll
2017-03-15 17:27:41 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\XInputUap.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.UI.GameBar.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-03-15 17:27:40 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-03-15 17:27:39 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2017-03-15 17:27:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-03-15 17:27:39 ----A---- C:\WINDOWS\SYSWOW64\hevcdecoder.dll
2017-03-15 17:27:38 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-03-15 17:27:38 ----A---- C:\WINDOWS\SYSWOW64\GamePanelExternalHook.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\WMVSENCD.DLL
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-03-15 17:27:37 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-03-15 17:27:36 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-03-15 17:27:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-03-15 17:27:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-03-15 17:27:36 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-03-15 17:27:35 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-03-15 17:27:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\WsmWmiPl.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\wmpmde.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\wcnwiz.dll
2017-03-15 17:27:34 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\UIRibbon.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\Pimstore.dll
2017-03-15 17:27:33 ----A---- C:\WINDOWS\SYSWOW64\cemapi.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\TpmCoreProvisioning.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\tcpipcfg.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\netiougc.exe
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\netiohlp.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2017-03-15 17:27:32 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2017-03-15 17:27:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-03-15 17:27:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-15 17:27:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-03-15 17:27:31 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-03-15 17:27:31 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-03-15 17:27:31 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-03-15 17:27:31 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-03-15 17:27:30 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-03-15 17:27:29 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-03-15 17:27:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-03-15 17:27:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-03-15 17:27:28 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-03-15 17:27:28 ----A---- C:\WINDOWS\SYSWOW64\regedit.exe
2017-03-15 17:27:28 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2017-03-15 17:27:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-03-15 17:27:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-03-15 17:27:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-03-15 17:27:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-03-15 17:27:27 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\Wpc.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-03-15 17:27:26 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-03-15 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2017-03-15 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2017-03-15 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSetup.exe
2017-03-15 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-03-15 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2017-03-15 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2017-03-15 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-03-15 17:27:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-15 17:27:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-03-15 17:27:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-03-15 17:27:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-03-15 17:27:22 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-03-15 17:27:22 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2017-03-15 17:27:22 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-03-15 17:27:22 ----A---- C:\WINDOWS\SYSWOW64\MSVP9DEC.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-03-15 17:27:21 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\MCCSEngineShared.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\DavSyncProvider.dll
2017-03-15 17:27:20 ----A---- C:\WINDOWS\SYSWOW64\accountaccessor.dll
2017-03-15 17:27:19 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-03-15 17:27:19 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-03-15 17:27:19 ----A---- C:\WINDOWS\SYSWOW64\MapRouter.dll
2017-03-15 17:27:19 ----A---- C:\WINDOWS\SYSWOW64\MapGeocoder.dll
2017-03-15 17:27:19 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2017-03-15 17:27:19 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\MSPhotography.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\LockAppBroker.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2017-03-15 17:27:18 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-03-15 17:27:16 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-03-15 17:27:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-03-15 17:27:15 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2017-03-15 17:27:15 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-03-15 17:27:14 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-03-15 17:27:13 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-03-15 17:27:13 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2017-03-15 17:27:13 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2017-03-15 17:27:13 ----A---- C:\WINDOWS\SYSWOW64\icm32.dll
2017-03-15 17:27:13 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\imapi2fs.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\gpapi.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\gameux.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\fontext.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-03-15 17:27:08 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-03-15 17:27:07 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-03-15 17:27:06 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-03-15 17:27:05 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-03-15 17:27:04 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-03-15 17:27:04 ----A---- C:\WINDOWS\SYSWOW64\CompPkgSup.dll
2017-03-15 17:27:04 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll
2017-03-15 17:27:04 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-03-15 17:27:04 ----A---- C:\WINDOWS\SYSWOW64\CameraCaptureUI.dll
2017-03-15 17:27:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-03-15 17:27:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-03-15 17:27:03 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2017-03-15 17:27:03 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-03-15 17:27:03 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-03-15 17:27:03 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-03-15 17:27:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-03-15 17:27:02 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-03-15 17:27:02 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-03-15 17:27:02 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-03-15 17:27:02 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2017-03-15 17:27:01 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-03-15 17:27:01 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-03-15 17:27:01 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-03-15 17:27:01 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2017-03-15 17:27:01 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2017-03-15 17:27:01 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-03-15 17:21:33 ----A---- C:\WINDOWS\system32\tquery.dll
2017-03-15 17:21:33 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2017-03-15 17:21:33 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\XblGameSaveExt.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\wlidprov.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\mssvp.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\mssphtb.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\mssph.dll
2017-03-15 17:21:32 ----A---- C:\WINDOWS\system32\mssitlb.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\XInputUap.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-03-15 17:21:31 ----A---- C:\WINDOWS\system32\AppContracts.dll
2017-03-15 17:21:24 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-03-15 17:21:24 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-03-15 17:21:24 ----A---- C:\WINDOWS\system32\icfupgd.dll
2017-03-15 17:21:10 ----A---- C:\WINDOWS\system32\winhttp.dll
2017-03-15 17:21:10 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-03-15 17:21:10 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2017-03-15 17:21:10 ----A---- C:\WINDOWS\system32\drivers\storahci.sys
2017-03-15 17:21:07 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-03-15 17:21:00 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2017-03-15 17:21:00 ----A---- C:\WINDOWS\system32\GamePanelExternalHook.dll
2017-03-15 17:21:00 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\wwanmm.dll
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\wwanconn.dll
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\CspCellularSettings.dll
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\CfgSPCellular.dll
2017-03-15 17:20:59 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-03-15 17:20:58 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2017-03-15 17:20:58 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-03-15 17:20:58 ----A---- C:\WINDOWS\system32\mispace.dll
2017-03-15 17:20:57 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-03-15 17:20:57 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2017-03-15 17:20:57 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2017-03-15 17:20:57 ----A---- C:\WINDOWS\system32\wlanui.dll
2017-03-15 17:20:57 ----A---- C:\WINDOWS\system32\wintrust.dll
2017-03-15 17:20:57 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\winmde.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\ReAgent.dll
2017-03-15 17:20:56 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-03-15 17:20:55 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-03-15 17:20:55 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2017-03-15 17:20:54 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-03-15 17:20:54 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-03-15 17:20:54 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-03-15 17:20:54 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2017-03-15 17:20:53 ----A---- C:\WINDOWS\system32\wups.dll
2017-03-15 17:20:53 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-03-15 17:20:53 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\WsmWmiPl.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\wmpmde.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\wcnwiz.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\VSSVC.exe
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\vssapi.dll
2017-03-15 17:20:52 ----A---- C:\WINDOWS\system32\vds.exe
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\usoapi.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\UserLanguagesCpl.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\usercpl.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\UIRibbon.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\Pimstore.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\DuCsps.dll
2017-03-15 17:20:51 ----A---- C:\WINDOWS\system32\cemapi.dll
2017-03-15 17:20:50 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-03-15 17:20:50 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2017-03-15 17:20:50 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-03-15 17:20:50 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-03-15 17:20:50 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-03-15 17:20:50 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-03-15 17:20:50 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-03-15 17:20:49 ----A---- C:\WINDOWS\system32\usocore.dll
2017-03-15 17:20:49 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-03-15 17:20:48 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-03-15 17:20:48 ----A---- C:\WINDOWS\system32\UserDataService.dll
2017-03-15 17:20:48 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-03-15 17:20:48 ----A---- C:\WINDOWS\system32\ubpm.dll
2017-03-15 17:20:48 ----A---- C:\WINDOWS\system32\PimIndexMaintenance.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\VCardParser.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\Unistore.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\twinui.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\ChatApis.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\ExSMime.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\EmailApis.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\ContactApis.dll
2017-03-15 17:20:47 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\twinapi.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\thumbcache.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\themecpl.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\netiougc.exe
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\netiohlp.dll
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2017-03-15 17:20:46 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\tapi32.dll
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\tabcal.exe
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\Tabbtn.dll
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\MultiDigiMon.exe
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\mscandui.dll
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\IPHLPAPI.DLL
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\input.dll
2017-03-15 17:20:45 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\systemreset.exe
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\reseteng.dll
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\RADCUI.dll
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\msutb.dll
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\msctfui.dll
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\msctfp.dll
2017-03-15 17:20:44 ----A---- C:\WINDOWS\system32\msctf.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\sud.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\storagewmi.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\stobject.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\SpeechPal.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2017-03-15 17:20:43 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\shutdownux.dll
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\shell32.dll
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\scksp.dll
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\certprop.dll
2017-03-15 17:20:42 ----A---- C:\WINDOWS\system32\basecsp.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\SHCore.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\SettingSync.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\SensorDataService.exe
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-03-15 17:20:41 ----A---- C:\WINDOWS\system32\AuthHost.exe
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\vaultcli.dll
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\TokenBrokerCookies.exe
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\tbauth.dll
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\schannel.dll
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-03-15 17:20:40 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\vbscript.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\sdshext.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\sdengin2.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-03-15 17:20:39 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-03-15 17:20:38 ----A---- C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2017-03-15 17:20:38 ----A---- C:\WINDOWS\system32\spaceman.exe
2017-03-15 17:20:38 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2017-03-15 17:20:38 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-03-15 17:20:38 ----A---- C:\WINDOWS\system32\DataSenseHandlers.dll
2017-03-15 17:20:37 ----A---- C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2017-03-15 17:20:37 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2017-03-15 17:20:37 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2017-03-15 17:20:37 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-03-15 17:20:37 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-03-15 17:20:37 ----A---- C:\WINDOWS\system32\BluetoothDesktopHandlers.dll
2017-03-15 17:20:37 ----A---- C:\WINDOWS\system32\ApplicationFrame.dll
2017-03-15 17:20:36 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-03-15 17:20:36 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-03-15 17:20:36 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-03-15 17:20:36 ----A---- C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2017-03-15 17:20:34 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2017-03-15 17:20:33 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-03-15 17:20:33 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-03-15 17:20:33 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2017-03-15 17:20:33 ----A---- C:\WINDOWS\system32\RelPost.exe
2017-03-15 17:20:33 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-03-15 17:20:32 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-03-15 17:20:32 ----A---- C:\WINDOWS\system32\rasgcw.dll
2017-03-15 17:20:32 ----A---- C:\WINDOWS\system32\mprddm.dll
2017-03-15 17:20:32 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2017-03-15 17:20:32 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2017-03-15 17:20:32 ----A---- C:\WINDOWS\regedit.exe
2017-03-15 17:20:31 ----A---- C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-03-15 17:20:31 ----A---- C:\WINDOWS\system32\vpnike.dll
2017-03-15 17:20:31 ----A---- C:\WINDOWS\system32\rascustom.dll
2017-03-15 17:20:30 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-03-15 17:20:30 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-03-15 17:20:30 ----A---- C:\WINDOWS\system32\spoolsv.exe
2017-03-15 17:20:30 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-03-15 17:20:30 ----A---- C:\WINDOWS\system32\PrintDialogs3D.dll
2017-03-15 17:20:30 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\wpnapps.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\Wpc.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\pnidui.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\PhotoScreensaver.scr
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2017-03-15 17:20:29 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2017-03-15 17:20:27 ----A---- C:\WINDOWS\system32\wpncore.dll
2017-03-15 17:20:27 ----A---- C:\WINDOWS\system32\WpcMon.exe
2017-03-15 17:20:27 ----A---- C:\WINDOWS\system32\win32spl.dll
2017-03-15 17:20:27 ----A---- C:\WINDOWS\system32\localspl.dll
2017-03-15 17:20:26 ----A---- C:\WINDOWS\system32\wpninprc.dll
2017-03-15 17:20:26 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-03-15 17:20:26 ----A---- C:\WINDOWS\system32\puiobj.dll
2017-03-15 17:20:26 ----A---- C:\WINDOWS\system32\puiapi.dll
2017-03-15 17:20:26 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2017-03-15 17:20:25 ----A---- C:\WINDOWS\system32\wlansvc.dll
2017-03-15 17:20:25 ----A---- C:\WINDOWS\system32\wlansec.dll
2017-03-15 17:20:25 ----A---- C:\WINDOWS\system32\wlanapi.dll
2017-03-15 17:20:25 ----A---- C:\WINDOWS\system32\wfdprov.dll
2017-03-15 17:20:25 ----A---- C:\WINDOWS\system32\PrintRenderAPIHost.DLL
2017-03-15 17:20:25 ----A---- C:\WINDOWS\system32\oleacc.dll
2017-03-15 17:20:25 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-03-15 17:20:24 ----A---- C:\WINDOWS\system32\ntshrui.dll
2017-03-15 17:20:24 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-03-15 17:20:23 ----A---- C:\WINDOWS\system32\Windows.Networking.HostName.dll
2017-03-15 17:20:23 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2017-03-15 17:20:23 ----A---- C:\WINDOWS\system32\netshell.dll
2017-03-15 17:20:22 ----A---- C:\WINDOWS\system32\WlanMediaManager.dll
2017-03-15 17:20:22 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-03-15 17:20:22 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-15 17:20:22 ----A---- C:\WINDOWS\system32\NaturalLanguage6.dll
2017-03-15 17:20:22 ----A---- C:\WINDOWS\system32\drivers\WdiWiFi.sys
2017-03-15 17:20:22 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2017-03-15 17:20:22 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2017-03-15 17:20:18 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-03-15 17:20:18 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-03-15 17:20:18 ----A---- C:\WINDOWS\system32\msxml3.dll
2017-03-15 17:20:18 ----A---- C:\WINDOWS\system32\MSVPXENC.dll
2017-03-15 17:20:18 ----A---- C:\WINDOWS\system32\MSVP9DEC.dll
2017-03-15 17:20:18 ----A---- C:\WINDOWS\system32\mspaint.exe
2017-03-15 17:20:18 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2017-03-15 17:20:17 ----A---- C:\WINDOWS\system32\msftedit.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\MMDevAPI.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\MFPlay.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\mfplat.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2017-03-15 17:20:16 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\wmp.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mfsvr.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mfds.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-03-15 17:20:15 ----A---- C:\WINDOWS\system32\mf.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\moshost.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\mos.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\MCCSEngineShared.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\MapsStore.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\MapRouter.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\MapGeocoder.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\internetmail.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\DavSyncProvider.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\BingMaps.dll
2017-03-15 17:20:14 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2017-03-15 17:20:13 ----A---- C:\WINDOWS\system32\inetcomm.dll
2017-03-15 17:20:12 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\Windows.Storage.Search.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\MSPhotography.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-03-15 17:20:11 ----A---- C:\WINDOWS\system32\FrameServer.dll
2017-03-15 17:20:10 ----A---- C:\WINDOWS\system32\mmc.exe
2017-03-15 17:20:10 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\LockAppBroker.dll
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\appinfo.dll
2017-03-15 17:20:09 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2017-03-15 17:20:08 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-03-15 17:20:08 ----A---- C:\WINDOWS\system32\drivers\tcpipreg.sys
2017-03-15 17:20:06 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-03-15 17:20:06 ----A---- C:\WINDOWS\system32\drivers\mskssrv.sys
2017-03-15 17:20:06 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2017-03-15 17:20:04 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-03-15 17:20:04 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2017-03-15 17:20:04 ----A---- C:\WINDOWS\system32\InputService.dll
2017-03-15 17:20:03 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-03-15 17:20:02 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2017-03-15 17:20:02 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-03-15 17:20:01 ----A---- C:\WINDOWS\system32\icm32.dll
2017-03-15 17:20:01 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-03-15 17:20:00 ----A---- C:\WINDOWS\system32\wininet.dll
2017-03-15 17:20:00 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-03-15 17:19:56 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2017-03-15 17:19:51 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-03-15 17:19:51 ----A---- C:\WINDOWS\system32\imapi2fs.dll
2017-03-15 17:19:50 ----A---- C:\WINDOWS\system32\hgcpl.dll
2017-03-15 17:19:50 ----A---- C:\WINDOWS\HelpPane.exe
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\gpsvc.dll
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\gpapi.dll
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\Geolocation.dll
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\gameux.dll
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2017-03-15 17:19:49 ----A---- C:\WINDOWS\system32\atmfd.dll
2017-03-15 17:19:48 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-03-15 17:19:48 ----A---- C:\WINDOWS\system32\fhcfg.dll
2017-03-15 17:19:46 ----A---- C:\WINDOWS\system32\resutils.dll
2017-03-15 17:19:46 ----A---- C:\WINDOWS\system32\clusapi.dll
2017-03-15 17:19:45 ----A---- C:\WINDOWS\system32\uReFS.dll
2017-03-15 17:19:44 ----A---- C:\WINDOWS\system32\werui.dll
2017-03-15 17:19:44 ----A---- C:\WINDOWS\system32\wer.dll
2017-03-15 17:19:44 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-03-15 17:19:44 ----A---- C:\WINDOWS\explorer.exe
2017-03-15 17:19:43 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2017-03-15 17:19:43 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2017-03-15 17:19:43 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2017-03-15 17:19:43 ----A---- C:\WINDOWS\system32\werconcpl.dll
2017-03-15 17:19:43 ----A---- C:\WINDOWS\system32\evr.dll
2017-03-15 17:19:43 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\WorkFoldersGPExt.dll
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\WorkFolders.exe
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\DXP.dll
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\dui70.dll
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2017-03-15 17:19:42 ----A---- C:\WINDOWS\system32\dnsapi.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\FntCache.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\dxgi.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\DWrite.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\DMRServer.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\ddrawex.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\ddraw.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-03-15 17:19:41 ----A---- C:\WINDOWS\system32\d3d11.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\quartz.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\dialclient.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2017-03-15 17:19:40 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2017-03-15 17:19:39 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2017-03-15 17:19:39 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-03-15 17:19:39 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-03-15 17:19:39 ----A---- C:\WINDOWS\system32\uDWM.dll
2017-03-15 17:19:39 ----A---- C:\WINDOWS\system32\dwmcore.dll
2017-03-15 17:19:39 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2017-03-15 17:19:39 ----A---- C:\WINDOWS\system32\dcntel.dll
2017-03-15 17:19:38 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-03-15 17:19:38 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2017-03-15 17:19:37 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-03-15 17:19:37 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-03-15 17:19:37 ----A---- C:\WINDOWS\system32\policymanager.dll
2017-03-15 17:19:36 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-03-15 17:19:36 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2017-03-15 17:19:36 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-03-15 17:19:36 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-03-15 17:19:35 ----A---- C:\WINDOWS\system32\generaltel.dll
2017-03-15 17:19:35 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2017-03-15 17:19:35 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-03-15 17:19:35 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-03-15 17:19:34 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-03-15 17:19:34 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-03-15 17:19:34 ----A---- C:\WINDOWS\system32\drivers\Classpnp.sys
2017-03-15 17:19:34 ----A---- C:\WINDOWS\system32\combase.dll
2017-03-15 17:19:34 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-03-15 17:19:34 ----A---- C:\WINDOWS\system32\ci.dll
2017-03-15 17:19:33 ----A---- C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-03-15 17:19:33 ----A---- C:\WINDOWS\system32\cdp.dll
2017-03-15 17:19:33 ----A---- C:\WINDOWS\system32\CameraCaptureUI.dll
2017-03-15 17:19:30 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-03-15 17:19:29 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2017-03-15 17:19:29 ----A---- C:\WINDOWS\system32\CompPkgSup.dll
2017-03-15 17:19:28 ----A---- C:\WINDOWS\system32\comsvcs.dll
2017-03-15 17:19:27 ----A---- C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2017-03-15 17:19:27 ----A---- C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2017-03-15 17:19:23 ----A---- C:\WINDOWS\system32\BrowserSettingSync.dll
2017-03-15 17:19:23 ----A---- C:\WINDOWS\system32\bisrv.dll
2017-03-15 17:19:22 ----A---- C:\WINDOWS\system32\winresume.exe
2017-03-15 17:19:22 ----A---- C:\WINDOWS\system32\wbengine.exe
2017-03-15 17:19:22 ----A---- C:\WINDOWS\system32\CloudBackupSettings.dll
2017-03-15 17:19:22 ----A---- C:\WINDOWS\system32\bootux.dll
2017-03-15 17:19:22 ----A---- C:\WINDOWS\system32\BootMenuUX.dll
2017-03-15 17:19:21 ----A---- C:\WINDOWS\system32\winload.exe
2017-03-15 17:19:18 ----A---- C:\WINDOWS\system32\PCPTpm12.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\AudioSes.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-03-15 17:19:17 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-03-15 17:19:16 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-03-15 17:19:15 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-03-15 17:19:15 ----A---- C:\WINDOWS\system32\invagent.dll
2017-03-15 17:19:14 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-03-15 17:19:14 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2017-03-15 17:19:14 ----A---- C:\WINDOWS\system32\devinv.dll
2017-03-15 17:19:14 ----A---- C:\WINDOWS\system32\authui.dll
2017-03-15 17:19:14 ----A---- C:\WINDOWS\system32\aepic.dll
2017-03-15 17:19:14 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-03-15 17:19:11 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2017-03-15 17:19:11 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-03-15 17:19:11 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2017-03-15 17:19:11 ----A---- C:\WINDOWS\system32\daxexec.dll
2017-03-15 17:19:11 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-03-15 17:19:10 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-03-15 17:19:10 ----A---- C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-03-15 17:19:08 ----A---- C:\WINDOWS\system32\hvloader.exe
2017-03-15 17:19:08 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-03-15 17:19:08 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-03-15 17:19:08 ----A---- C:\WINDOWS\system32\drivers\vmbkmclr.sys
2017-03-15 17:19:08 ----A---- C:\WINDOWS\system32\drivers\vmbkmcl.sys
2017-03-15 17:19:08 ----A---- C:\WINDOWS\system32\drivers\hvsocket.sys
2017-03-15 17:19:07 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2017-03-15 17:19:07 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2017-03-15 17:19:06 ----A---- C:\WINDOWS\system32\icsvcext.dll
2017-03-15 17:18:42 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2017-03-15 17:18:42 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2017-03-10 02:01:43 ----D---- C:\Users\SLIP\AppData\Roaming\WinClient
2017-03-10 01:20:31 ----D---- C:\Users\SLIP\AppData\Roaming\1xCorp. N.V
2017-03-09 23:02:09 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2017-03-09 23:02:08 ----A---- C:\WINDOWS\system32\nvdispgenco6437878.dll
2017-03-09 23:02:08 ----A---- C:\WINDOWS\system32\nvdispco6437878.dll
2017-03-02 18:38:38 ----A---- C:\WINDOWS\system32\aswBoot.exe
2017-02-26 15:49:08 ----D---- C:\Users\SLIP\AppData\Roaming\VMware
2017-02-26 15:48:10 ----A---- C:\WINDOWS\SYSWOW64\vsocklib.dll
2017-02-26 15:48:10 ----A---- C:\WINDOWS\system32\vsocklib.dll
2017-02-26 15:48:10 ----A---- C:\WINDOWS\system32\drivers\vsock.sys
2017-02-26 15:48:09 ----A---- C:\WINDOWS\system32\drivers\vmx86.sys
2017-02-26 15:48:08 ----A---- C:\WINDOWS\system32\drivers\vmkbd.sys
2017-02-26 15:47:59 ----A---- C:\WINDOWS\SYSWOW64\vmnetdhcp.exe
2017-02-26 15:47:55 ----A---- C:\WINDOWS\SYSWOW64\vmnat.exe
2017-02-26 15:47:55 ----A---- C:\WINDOWS\system32\vnetinst.dll
2017-02-26 15:47:55 ----A---- C:\WINDOWS\system32\drivers\vmnetuserif.sys
2017-02-26 15:47:53 ----A---- C:\WINDOWS\system32\vnetlib64.dll
2017-02-26 15:47:50 ----DC---- C:\WINDOWS\system32\DRVSTORE
2017-02-26 15:47:50 ----A---- C:\WINDOWS\system32\drivers\hcmon.sys
2017-02-26 15:47:48 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2017-02-26 15:47:46 ----D---- C:\Program Files\Common Files\VMware
2017-02-26 15:47:46 ----D---- C:\Program Files (x86)\VMware
2017-02-26 15:47:46 ----AD---- C:\ProgramData\VMware
2017-02-26 15:45:00 ----D---- C:\Users\SLIP\AppData\Roaming\Andy
2017-02-26 15:44:49 ----AD---- C:\Program Files\Andy======List of files/folders modified in the last 1 month======

2017-03-22 12:09:19 ----D---- C:\Program Files\trend micro
2017-03-22 12:08:31 ----D---- C:\WINDOWS\Temp
2017-03-22 12:08:20 ----D---- C:\Users\SLIP\AppData\Roaming\uTorrent
2017-03-22 12:07:30 ----D---- C:\AdwCleaner
2017-03-22 11:57:14 ----SHD---- C:\WINDOWS\Installer
2017-03-22 11:43:15 ----D---- C:\WINDOWS\system32\DriverStore
2017-03-22 11:43:15 ----D---- C:\WINDOWS\system32\drivers
2017-03-22 11:43:15 ----D---- C:\WINDOWS\system32\CatRoot
2017-03-22 11:43:15 ----D---- C:\WINDOWS\INF
2017-03-22 11:43:13 ----D---- C:\ProgramData\NVIDIA Corporation
2017-03-22 11:43:04 ----D---- C:\ProgramData\NVIDIA
2017-03-22 11:42:55 ----D---- C:\WINDOWS\SysWOW64
2017-03-22 11:42:38 ----RD---- C:\Program Files (x86)
2017-03-22 11:42:38 ----AD---- C:\WINDOWS\System32
2017-03-22 11:41:47 ----D---- C:\Windows
2017-03-22 11:39:36 ----SHD---- C:\System Volume Information
2017-03-22 11:38:55 ----AD---- C:\Users\SLIP\AppData\Roaming\Curse Client
2017-03-22 11:34:04 ----HD---- C:\Program Files\WindowsApps
2017-03-22 11:34:04 ----D---- C:\WINDOWS\AppReadiness
2017-03-22 11:31:34 ----D---- C:\WINDOWS\system32\config
2017-03-22 11:30:32 ----D---- C:\WINDOWS\system32\sru
2017-03-22 11:30:25 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2017-03-22 11:30:17 ----D---- C:\WINDOWS\Prefetch
2017-03-22 11:30:16 ----RD---- C:\WINDOWS\Microsoft.NET
2017-03-22 11:30:12 ----D---- C:\Program Files (x86)\Common Files
2017-03-22 11:29:43 ----AD---- C:\Program Files (x86)\Microsoft Office
2017-03-21 00:24:50 ----D---- C:\WINDOWS\system32\SleepStudy
2017-03-20 23:45:08 ----D---- C:\Users\SLIP\AppData\Roaming\TS3Client
2017-03-20 01:09:08 ----D---- C:\WINDOWS\Tasks
2017-03-20 01:09:04 ----D---- C:\WINDOWS\system32\Macromed
2017-03-20 01:09:03 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-03-20 00:46:50 ----D---- C:\WINDOWS\WinSxS
2017-03-20 00:43:50 ----D---- C:\WINDOWS\system32\catroot2
2017-03-20 00:40:37 ----RSD---- C:\WINDOWS\assembly
2017-03-20 00:31:43 ----D---- C:\WINDOWS\system32\appraiser
2017-03-20 00:31:43 ----D---- C:\WINDOWS\CbsTemp
2017-03-17 02:01:06 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2017-03-17 02:01:06 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2017-03-17 02:01:06 ----A---- C:\WINDOWS\system32\nvapi64.dll
2017-03-17 00:32:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-17 00:31:01 ----A---- C:\WINDOWS\NvContainerRecovery.bat
2017-03-17 00:27:14 ----HD---- C:\ProgramData
2017-03-17 00:26:13 ----AD---- C:\Program Files (x86)\Hi-Rez Studios
2017-03-17 00:16:11 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2017-03-17 00:16:11 ----A---- C:\WINDOWS\system32\nvcpl.dll
2017-03-17 00:16:09 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2017-03-17 00:16:09 ----A---- C:\WINDOWS\system32\nvshext.dll
2017-03-17 00:16:09 ----A---- C:\WINDOWS\system32\nvmctray.dll
2017-03-17 00:16:09 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2017-03-17 00:16:09 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2017-03-16 14:35:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2017-03-16 14:35:03 ----AD---- C:\Program Files\Microsoft Silverlight
2017-03-16 03:57:53 ----SD---- C:\WINDOWS\SYSWOW64\F12
2017-03-16 03:57:53 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-CS
2017-03-16 03:57:53 ----D---- C:\WINDOWS\SYSWOW64\setup
2017-03-16 03:57:53 ----D---- C:\WINDOWS\SYSWOW64\migration
2017-03-16 03:57:53 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-03-16 03:57:53 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-03-16 03:57:52 ----SD---- C:\WINDOWS\system32\F12
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\wbem
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\setup
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\oobe
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\migration
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\en-US
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\cs-CZ
2017-03-16 03:57:52 ----D---- C:\WINDOWS\system32\Boot
2017-03-16 03:57:51 ----RD---- C:\WINDOWS\PrintDialog
2017-03-16 03:57:51 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-03-16 03:57:51 ----RD---- C:\Program Files\Windows Defender
2017-03-16 03:57:51 ----D---- C:\WINDOWS\ShellExperiences
2017-03-16 03:57:51 ----D---- C:\WINDOWS\bcastdvr
2017-03-16 03:57:51 ----D---- C:\WINDOWS\AppPatch
2017-03-16 03:57:51 ----D---- C:\Program Files\Windows Photo Viewer
2017-03-16 03:57:51 ----D---- C:\Program Files\Windows Mail
2017-03-16 03:57:51 ----D---- C:\Program Files\Internet Explorer
2017-03-16 03:57:51 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-03-16 03:57:51 ----D---- C:\Program Files (x86)\Windows Mail
2017-03-16 03:57:51 ----D---- C:\Program Files (x86)\Windows Defender
2017-03-16 03:57:51 ----D---- C:\Program Files (x86)\Internet Explorer
2017-03-15 19:43:52 ----D---- C:\ProgramData\Skype
2017-03-15 17:44:53 ----D---- C:\WINDOWS\system32\MRT
2017-03-15 17:43:23 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-03-12 23:37:17 ----D---- C:\Users\SLIP\AppData\Roaming\Adobe
2017-03-12 16:53:04 ----D---- C:\Users\SLIP\AppData\Roaming\AIMP
2017-03-12 16:42:26 ----D---- C:\Users\SLIP\AppData\Roaming\TeamViewer
2017-03-10 18:06:08 ----D---- C:\WINDOWS\system32\Tasks
2017-03-10 14:17:00 ----D---- C:\WINDOWS\LiveKernelReports
2017-03-10 06:17:56 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-03-06 20:40:24 ----D---- C:\Program Files\NVIDIA Corporation
2017-03-06 20:40:24 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-03-04 08:09:22 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2017-02-26 15:47:46 ----D---- C:\Program Files\Common Files
2017-02-26 15:45:00 ----RD---- C:\Users
2017-02-26 15:44:49 ----RD---- C:\Program Files
2017-02-24 01:37:20 ----D---- C:\WINDOWS\debug
2017-02-23 23:55:24 ----A---- C:\WINDOWS\system32\nvhdagenco6420103.dll
2017-02-23 19:35:22 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2017-02-23 19:35:21 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2017-02-23 19:35:21 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2017-02-23 19:35:21 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2017-02-23 19:35:21 ----A---- C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-02-23 15:30:51 ----A---- C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-02-23 11:32:10 ----A---- C:\WINDOWS\SYSWOW64\SET9136.tmp
2017-02-23 11:32:10 ----A---- C:\WINDOWS\SYSWOW64\SET8C10.tmp
2017-02-23 11:32:10 ----A---- C:\WINDOWS\system32\SET82F5.tmp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [2017-03-02 189768]
R0 aswblog;aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [2017-03-02 334600]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [2017-03-02 48528]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2017-03-02 75704]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2017-03-15 337592]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992]
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [2017-03-02 309272]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2017-03-02 32088]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2017-03-02 100640]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2017-03-02 993608]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2017-03-15 548928]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-07-16 88576]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2016-07-16 8192]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2017-03-02 126600]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2017-03-02 162528]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 hcmon;VMware hcmon; C:\WINDOWS\system32\DRIVERS\hcmon.sys [2016-09-06 83008]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2016-07-16 48128]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2016-07-16 78336]
R3 CorsairGamingAudioService;@oem47.inf,%CorsairAudioFilterServiceDisplayName%;Corsair Gaming Audio Service; C:\WINDOWS\system32\DRIVERS\CorsairGamingAudioamd64.sys [2016-09-12 123392]
R3 CorsairVBusDriver;@oem26.inf,%dev.SVCDESC%;Corsair Bus; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [2016-10-06 45056]
R3 CorsairVHidDriver;@oem19.inf,%dev.SVCDESC%;Corsair virtual device; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [2016-10-06 22520]
R3 iaLPSS2_UART2;@oem14.inf,%iaLPSS2_UART2.SVCDESC%;Intel(R) Serial IO UART Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2_UART2.sys [2016-05-16 281400]
R3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
R3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2016-07-16 176384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-10-16 4628736]
R3 MEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [2015-10-08 185600]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [2012-10-25 13368]
R3 NVHDA;@oem79.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2017-02-23 217528]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f37f8f12da8b10d7\nvlddmkm.sys [2017-03-17 14574640]
R3 nvvad_WaveExtensible;@oem69.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2017-01-20 46016]
R3 nvvhci;@oem70.inf,%ServiceDesc%;NVVHCI Enumerator Service; C:\WINDOWS\System32\drivers\nvvhci.sys [2017-02-23 59448]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2016-07-16 589824]
R3 rtwlane_13;@netrtwlane_13.inf,%rtwlane_13.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\WINDOWS\System32\drivers\rtwlane_13.sys [2016-07-16 3717120]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2016-07-16 105824]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2016-07-16 101216]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 64352]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2016-07-16 58720]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2016-07-16 61792]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2016-07-16 32096]
S2 sinaC1Drv;sinaGameC1 Hypervisor; \??\E:\Program Files\sinashouyouzs\Bin\bsEmulator\0937\bsEmulator\sinaC1-Hypervisor-amd64.sys []
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 aswHwid;aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [2017-03-02 38296]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2016-07-16 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2016-07-16 38912]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-09-10 118272]
S3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D; C:\WINDOWS\system32\DRIVERS\e1d65x64.sys [2015-08-13 531424]
S3 EasyAntiCheatSys;EasyAntiCheatSys; \??\C:\WINDOWS\system32\drivers\EasyAntiCheat.sys [2016-10-21 512760]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [2010-03-30 26752]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2016-07-16 20480]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2016-07-16 50016]
S3 HipShieldK;McAfee Inc. HipShieldK; C:\WINDOWS\system32\drivers\HipShieldK.sys [2016-02-24 207968]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-09-24 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2016-07-16 81408]
S3 iaLPSS2_I2C;iaLPSS2_I2C; C:\WINDOWS\System32\drivers\iaLPSS2_I2C.sys [2015-07-20 185128]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2016-07-16 526176]
S3 ibtusb;Intel(R) Wireless Bluetooth(R); C:\WINDOWS\system32\DRIVERS\ibtusb.sys [2015-06-19 250096]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 ipadtst;ipadtst; \??\C:\Program Files (x86)\MSI\Super Charger\ipadtst_64.sys [2013-11-11 20464]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2016-11-06 192216]
S3 mfeaack;McAfee Inc. mfeaack; C:\WINDOWS\system32\drivers\mfeaack.sys [2016-04-27 419616]
S3 mfencrk;McAfee Inc. mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [2016-08-01 100136]
S3 mfesapsn;McAfee Process Start Notification Service; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys []
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2016-07-16 842584]
S3 NAL;Nal Service ; \??\C:\Windows\system32\Drivers\iqvw64e.sys [2015-09-18 37832]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2016-07-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 Netwtw02;___ Ovladač adaptéru Intel(R) Wireless pro systém Windows 10 64 Bit; C:\WINDOWS\System32\drivers\Netwtw02.sys [2015-06-21 9391896]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-02-23 27584]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver; C:\WINDOWS\System32\drivers\nvstusb.sys [2016-06-03 467912]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2016-07-16 928608]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-09-22 83768]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-02 262736]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 CDPUserSvc_113310da;CDPUserSvc_113310da; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2017-03-05 3736776]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2015-06-12 640928]
R2 ibtsiva.exe;Intel Bluetooth Service; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [2015-06-19 135408]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2015-09-18 273376]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-10-16 207648]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2015-10-16 415520]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [2015-05-18 163280]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23 462784]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-03-17 464440]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-02-23 425408]
R2 OneSyncSvc_113310da;Hostitel synchronizace_113310da; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-12-04 2180112]
R2 PEFService;Intel Security PEF Service; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [2016-05-25 1045336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2016-11-28 76152]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2015-06-12 157088]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-02 7147320]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R3 Intel(R) Security Assist;Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [2015-05-19 335872]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2017-01-19 651576]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R3 PimIndexMaintenanceSvc_113310da;Data kontaktů_113310da; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-15 153752]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2016-10-10 9728]
S2 isaHelperSvc;Intel(R) Security Assist Helper; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [2015-05-19 7680]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-03-20 271960]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-12-12 1447944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-07-16 93184]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 EasyAntiCheat;EasyAntiCheat; C:\WINDOWS\syswow64\EasyAntiCheat.exe [2016-09-16 227104]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-15 153752]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2015-05-22 881152]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService_113310da;Služba zasílání zpráv_113310da; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-12-18 172488]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2015-06-12 268192]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23 462784]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-12-04 2118664]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-03-05 207056]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2017-03-04 1312768]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2016-07-16 44496]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-03-13 1590560]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2016-07-16 44496]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Prosím o preventivku.

#3 Příspěvek od Roli »

Zdravím, máš celkem málo místa na disku cca 10%.

No uklidíme a uvidíme :)

Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a spusť AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět