Prosim o kontrolu
Napsal: 25 bře 2017 20:25
Dobry den,
prosim kontrolu. PC je vemi spomaleny, vyhadzuje same reklamy.
LOG z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Viliam Gallo at 2017-03-25 20:17:16
Microsoft Windows 10 Home
System drive C: has 394 GB (90%) free of 435 GB
Total RAM: 1931 MB (18% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:17:42, on 25.3.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE
C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
C:\Program Files\Lenovo\iMController\AutoUpdate.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Viliam Gallo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://startpage-home.com/?s=lenovo&m=start
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8E09076A669EAD084ECA0CA2171DD55E] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem10.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\system32\ibtsiva (file missing)
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: LSCWinService - Lenovo - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
O23 - Service: LUService - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9297 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c98fd33a-adbb-461c-8a01-120e7740558c -SystemEventPortName:HostProcess-8c121656-af2a-4fd4-a6c2-f25ee8790e94 -IoCancelEventPortName:HostProcess-8dca00ab-d94f-4e99-97c5-4212d8603305 -NonStateChangingEventPortName:HostProcess-3a7e28c2-3e90-4f83-8cab-62ee3a7d75c3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:4229c689-0802-4ec0-8eeb-18154722c28e -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k netsvcs
dashost.exe {f28f9e67-05de-417e-bc328b1c5504b585}
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\windows\system32\CxAudMsg64.exe
C:\WINDOWS\system32\ibtsiva
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
"C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Explorer.EXE
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Users\Viliam Gallo\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe" /LOGON
igfxEM.exe
igfxHK.exe
"C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE"
igfxTray.exe
service
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Windows\RTFTrack.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe"
"C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe"
"C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe"
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe" /showasync
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files\Lenovo\iMController\AutoUpdate.exe"
"C:\Program Files\Windows Defender\\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 70BA977B-933A-C808-8FE5-5155406EFD63 -Reinvoke
"C:\Program Files\Windows Defender\msascui.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Viliam Gallo\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Viliam Gallo\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=56.0.2924.87 --initial-client-data=0x104,0x254,0x258,0x100,0x25c,0x658a7598,0x658a75bc,0x658a75a4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=6904 --on-initialized-event-handle=708 --parent-handle=712 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,19,23,40,59,71 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.4276 --gpu-driver-date=8-17-2015 --service-request-channel-token=A3C3992E4725DD69A3B6A66B6659F94F --mojo-platform-channel-handle=1352 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=86452CB0C013EA08CE181C23C3414678 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=86452CB0C013EA08CE181C23C3414678 --renderer-client-id=4 --mojo-platform-channel-handle=2880 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=6663BFB497FC7B4C203CAC57FCB95C87 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=6663BFB497FC7B4C203CAC57FCB95C87 --renderer-client-id=5 --mojo-platform-channel-handle=2780 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=5363FD3481AEE46FCC9205B974A8F1FE --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=5363FD3481AEE46FCC9205B974A8F1FE --renderer-client-id=6 --mojo-platform-channel-handle=2784 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=DF5C552AAE145E6B50C2C555CE20F57E --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=DF5C552AAE145E6B50C2C555CE20F57E --renderer-client-id=7 --mojo-platform-channel-handle=2796 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/*EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/*WebFontsInterventionV2/Control-1/ --primordial-pipe-token=DE7FB0E3B50B772CAAFA1C89C589D5D3 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=DE7FB0E3B50B772CAAFA1C89C589D5D3 --renderer-client-id=12 --mojo-platform-channel-handle=6420 /prefetch:1
C:\WINDOWS\system32\AUDIODG.EXE 0x340
C:\WINDOWS\system32\wbem\wmiprvse.exe
"fontdrvhost.exe"
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/*EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled2/*InstanceID/Enabled/*MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/*TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/*WebFontsInterventionV2/Control-1/ --primordial-pipe-token=2CF785609DBEC8767F49542AE5ADCC14 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=2CF785609DBEC8767F49542AE5ADCC14 --renderer-client-id=35 --mojo-platform-channel-handle=8212 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 644 648 656 8192 652
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Users\Viliam Gallo\Downloads\RSITx64.exe"
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2015-06-16 5060864]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-09-05 907480]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2012-06-13 1647616]
"PhoneCompanion"=C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [2014-10-23 836592]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2014-10-23 16094704]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2014-10-23 10841584]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-01-25 3945672]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-09-07 631808]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-02-28 1518304]
"GoogleChromeAutoLaunch_8E09076A669EAD084ECA0CA2171DD55E"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2017-02-01 945496]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-08-26 8912088]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-02-14 27545056]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2011-12-07 214312]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-03-25 20:17:17 ----D---- C:\Program Files\trend micro
2017-03-25 20:17:16 ----D---- C:\rsit
2017-03-16 11:40:28 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\WPDShServiceObj.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\wlanui.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\UserLanguagesCpl.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\themecpl.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\tapi32.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\mscandui.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\msutb.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\msctfui.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\sud.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\msctfp.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-03-16 11:40:21 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2017-03-16 11:40:21 ----A---- C:\WINDOWS\SYSWOW64\PhotoScreensaver.scr
2017-03-16 11:40:21 ----A---- C:\WINDOWS\SYSWOW64\mprddm.dll
2017-03-16 11:40:20 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-03-16 11:40:20 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-03-16 11:40:20 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-03-16 11:40:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.Search.dll
2017-03-16 11:40:19 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2017-03-16 11:40:19 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2017-03-16 11:40:18 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-03-16 11:40:17 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-03-16 11:40:16 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\hgcpl.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\ddrawex.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\ddraw.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\mtxclu.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\msdtcuiu.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\BrowserSettingSync.dll
2017-03-16 11:40:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2017-03-16 11:40:13 ----A---- C:\WINDOWS\SYSWOW64\PCPTpm12.dll
2017-03-16 11:40:13 ----A---- C:\WINDOWS\SYSWOW64\azroleui.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssphtb.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssitlb.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\XInputUap.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.UI.GameBar.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\hevcdecoder.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\GamePanelExternalHook.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\WMVSENCD.DLL
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-03-16 11:40:08 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-03-16 11:40:08 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-03-16 11:40:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\WsmWmiPl.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\wmpmde.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\wcnwiz.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UIRibbon.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Pimstore.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\cemapi.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\TpmCoreProvisioning.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\tcpipcfg.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\netiougc.exe
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\netiohlp.dll
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2017-03-16 11:40:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\regedit.exe
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Wpc.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSetup.exe
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\MSVP9DEC.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-03-16 11:39:56 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-03-16 11:39:56 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MCCSEngineShared.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MapRouter.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MapGeocoder.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\DavSyncProvider.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\accountaccessor.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\MSPhotography.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\LockAppBroker.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-03-16 11:39:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-03-16 11:39:52 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2017-03-16 11:39:52 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-03-16 11:39:51 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-03-16 11:39:50 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\icm32.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-03-16 11:39:48 ----A---- C:\WINDOWS\SYSWOW64\imapi2fs.dll
2017-03-16 11:39:48 ----A---- C:\WINDOWS\SYSWOW64\gpapi.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\gameux.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\fontext.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-03-16 11:39:45 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2017-03-16 11:39:45 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-03-16 11:39:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CompPkgSup.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CameraCaptureUI.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-03-16 11:39:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-03-16 11:39:39 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2017-03-16 11:39:38 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-03-16 11:39:37 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-03-16 11:39:37 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-03-16 11:39:37 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-03-16 11:39:35 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\tquery.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssvp.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssphtb.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\mssph.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\mssitlb.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\XInputUap.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\XblGameSaveExt.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\wlidprov.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\AppContracts.dll
2017-03-16 11:36:49 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-03-16 11:36:49 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-03-16 11:36:49 ----A---- C:\WINDOWS\system32\icfupgd.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\winhttp.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\drivers\storahci.sys
2017-03-16 11:36:34 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-03-16 11:36:31 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2017-03-16 11:36:31 ----A---- C:\WINDOWS\system32\GamePanelExternalHook.dll
2017-03-16 11:36:31 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\wwanmm.dll
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\wwanconn.dll
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\CspCellularSettings.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\CfgSPCellular.dll
2017-03-16 11:36:28 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2017-03-16 11:36:28 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-03-16 11:36:28 ----A---- C:\WINDOWS\system32\mispace.dll
2017-03-16 11:36:27 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-03-16 11:36:26 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\wlanui.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\wintrust.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\ReAgent.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\winmde.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2017-03-16 11:36:23 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-03-16 11:36:23 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-03-16 11:36:23 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
prosim kontrolu. PC je vemi spomaleny, vyhadzuje same reklamy.
LOG z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Viliam Gallo at 2017-03-25 20:17:16
Microsoft Windows 10 Home
System drive C: has 394 GB (90%) free of 435 GB
Total RAM: 1931 MB (18% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:17:42, on 25.3.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE
C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
C:\Program Files\Lenovo\iMController\AutoUpdate.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Viliam Gallo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://startpage-home.com/?s=lenovo&m=start
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_8E09076A669EAD084ECA0CA2171DD55E] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem10.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\system32\ibtsiva (file missing)
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\Lenovo\iMController\SystemAgentService.exe
O23 - Service: Lenovo WiFiHotspot Service (LenovoWiFiHotspotSvr) - Unknown owner - C:\Windows\System32\LenovoWiFiHotspotSvr.exe (file missing)
O23 - Service: LSCWinService - Lenovo - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
O23 - Service: LUService - Lenovo(beijing) Limited - C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo PhoneCompanionPusher Service (PhoneCompanionPusher) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
O23 - Service: Lenovo PhoneCompanionVap Service (PhoneCompanionVap) - Lenovo - C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9297 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c98fd33a-adbb-461c-8a01-120e7740558c -SystemEventPortName:HostProcess-8c121656-af2a-4fd4-a6c2-f25ee8790e94 -IoCancelEventPortName:HostProcess-8dca00ab-d94f-4e99-97c5-4212d8603305 -NonStateChangingEventPortName:HostProcess-3a7e28c2-3e90-4f83-8cab-62ee3a7d75c3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:4229c689-0802-4ec0-8eeb-18154722c28e -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k netsvcs
dashost.exe {f28f9e67-05de-417e-bc328b1c5504b585}
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\windows\system32\CxAudMsg64.exe
C:\WINDOWS\system32\ibtsiva
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
"C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe"
"C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe"
"C:\Program Files\Lenovo\iMController\SystemAgentService.exe"
C:\Windows\System32\LenovoWiFiHotspotSvr.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Explorer.EXE
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Users\Viliam Gallo\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe" /LOGON
igfxEM.exe
igfxHK.exe
"C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE"
igfxTray.exe
service
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Windows\RTFTrack.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe"
"C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe"
"C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe"
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe" /showasync
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files\Lenovo\iMController\AutoUpdate.exe"
"C:\Program Files\Windows Defender\\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 70BA977B-933A-C808-8FE5-5155406EFD63 -Reinvoke
"C:\Program Files\Windows Defender\msascui.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Viliam Gallo\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Viliam Gallo\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=56.0.2924.87 --initial-client-data=0x104,0x254,0x258,0x100,0x25c,0x658a7598,0x658a75bc,0x658a75a4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=6904 --on-initialized-event-handle=708 --parent-handle=712 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,19,23,40,59,71 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.4276 --gpu-driver-date=8-17-2015 --service-request-channel-token=A3C3992E4725DD69A3B6A66B6659F94F --mojo-platform-channel-handle=1352 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=86452CB0C013EA08CE181C23C3414678 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=86452CB0C013EA08CE181C23C3414678 --renderer-client-id=4 --mojo-platform-channel-handle=2880 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=6663BFB497FC7B4C203CAC57FCB95C87 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=6663BFB497FC7B4C203CAC57FCB95C87 --renderer-client-id=5 --mojo-platform-channel-handle=2780 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=5363FD3481AEE46FCC9205B974A8F1FE --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=5363FD3481AEE46FCC9205B974A8F1FE --renderer-client-id=6 --mojo-platform-channel-handle=2784 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/WebFontsInterventionV2/Control-1/ --primordial-pipe-token=DF5C552AAE145E6B50C2C555CE20F57E --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=DF5C552AAE145E6B50C2C555CE20F57E --renderer-client-id=7 --mojo-platform-channel-handle=2796 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/*EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled2/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/*WebFontsInterventionV2/Control-1/ --primordial-pipe-token=DE7FB0E3B50B772CAAFA1C89C589D5D3 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=DE7FB0E3B50B772CAAFA1C89C589D5D3 --renderer-client-id=12 --mojo-platform-channel-handle=6420 /prefetch:1
C:\WINDOWS\system32\AUDIODG.EXE 0x340
C:\WINDOWS\system32\wbem\wmiprvse.exe
"fontdrvhost.exe"
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXmtcan0h2tfbfy7k9kn8hbxb6dmzz1zh0.mca
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,DisableFirstRunAutoImport<DisableFirstRunAutoImport,EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExpectCTReporting<ExpectCTReporting,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,MediaFoundationH264Encoding<MediaFoundationH264Encoding,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,*PrioritySupportedRequestsDelayable<NetDelayableH2AndQuicRequests,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/AutoImportDisabled/*DisallowFetchForDocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup_20161208_Launch/*EnableSyncClientToServerCompression/Enabled/ExpectCTReporting/ExpectCTReportingDisabled/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled2/*InstanceID/Enabled/*MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetDelayableH2AndQuicRequests/Default/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/ChromeDesktopPSuggestModerateControlStable/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingV4LocalDatabaseManagerEnabled/Default/SaveAsMenuText/default/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled2/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Enabled_100/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/*TranslateRankerLogging/TranslateRankerLoggingLaunched/TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_75/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_15/*UMA-Uniformity-Trial-50-Percent/default/*WebFontsInterventionV2/Control-1/ --primordial-pipe-token=2CF785609DBEC8767F49542AE5ADCC14 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=2CF785609DBEC8767F49542AE5ADCC14 --renderer-client-id=35 --mojo-platform-channel-handle=8212 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 644 648 656 8192 652
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Users\Viliam Gallo\Downloads\RSITx64.exe"
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2015-06-16 5060864]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2013-09-05 907480]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2012-06-13 1647616]
"PhoneCompanion"=C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [2014-10-23 836592]
"Energy Manager"=C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [2014-10-23 16094704]
"Lenovo Utility"=C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [2014-10-23 10841584]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-01-25 3945672]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-09-07 631808]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Viliam Gallo\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-02-28 1518304]
"GoogleChromeAutoLaunch_8E09076A669EAD084ECA0CA2171DD55E"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2017-02-01 945496]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-08-26 8912088]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-02-14 27545056]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2011-12-07 214312]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-03-25 20:17:17 ----D---- C:\Program Files\trend micro
2017-03-25 20:17:16 ----D---- C:\rsit
2017-03-16 11:40:28 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\WPDShServiceObj.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\wlanui.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\UserLanguagesCpl.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-03-16 11:40:25 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\themecpl.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\tapi32.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\mscandui.dll
2017-03-16 11:40:24 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\msutb.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\msctfui.dll
2017-03-16 11:40:23 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\sud.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\msctfp.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-03-16 11:40:22 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-03-16 11:40:21 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2017-03-16 11:40:21 ----A---- C:\WINDOWS\SYSWOW64\PhotoScreensaver.scr
2017-03-16 11:40:21 ----A---- C:\WINDOWS\SYSWOW64\mprddm.dll
2017-03-16 11:40:20 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-03-16 11:40:20 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-03-16 11:40:20 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-03-16 11:40:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.Search.dll
2017-03-16 11:40:19 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2017-03-16 11:40:19 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2017-03-16 11:40:18 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-03-16 11:40:17 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-03-16 11:40:16 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\hgcpl.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\ddrawex.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\ddraw.dll
2017-03-16 11:40:15 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\mtxclu.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\msdtcuiu.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2017-03-16 11:40:14 ----A---- C:\WINDOWS\SYSWOW64\BrowserSettingSync.dll
2017-03-16 11:40:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2017-03-16 11:40:13 ----A---- C:\WINDOWS\SYSWOW64\PCPTpm12.dll
2017-03-16 11:40:13 ----A---- C:\WINDOWS\SYSWOW64\azroleui.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssphtb.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\mssitlb.dll
2017-03-16 11:40:12 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\XInputUap.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.UI.GameBar.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-03-16 11:40:11 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\hevcdecoder.dll
2017-03-16 11:40:10 ----A---- C:\WINDOWS\SYSWOW64\GamePanelExternalHook.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\WMVSENCD.DLL
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-03-16 11:40:09 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-03-16 11:40:08 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-03-16 11:40:08 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-03-16 11:40:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\WsmWmiPl.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\wmpmde.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\wcnwiz.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\UIRibbon.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\Pimstore.dll
2017-03-16 11:40:07 ----A---- C:\WINDOWS\SYSWOW64\cemapi.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\TpmCoreProvisioning.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\tcpipcfg.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\netiougc.exe
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2017-03-16 11:40:06 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\netiohlp.dll
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-03-16 11:40:05 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2017-03-16 11:40:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSettingSyncProvider.dll
2017-03-16 11:40:03 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-03-16 11:40:02 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\regedit.exe
2017-03-16 11:40:01 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Wpc.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-03-16 11:40:00 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\wfdprov.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\OneDriveSetup.exe
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2017-03-16 11:39:59 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\MSVP9DEC.dll
2017-03-16 11:39:58 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2017-03-16 11:39:57 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-03-16 11:39:56 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-03-16 11:39:56 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-03-16 11:39:55 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MCCSEngineShared.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MapRouter.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MapGeocoder.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\DavSyncProvider.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-03-16 11:39:54 ----A---- C:\WINDOWS\SYSWOW64\accountaccessor.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\MSPhotography.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\LockAppBroker.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2017-03-16 11:39:53 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-03-16 11:39:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-03-16 11:39:52 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2017-03-16 11:39:52 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-03-16 11:39:51 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-03-16 11:39:50 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\icm32.dll
2017-03-16 11:39:49 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-03-16 11:39:48 ----A---- C:\WINDOWS\SYSWOW64\imapi2fs.dll
2017-03-16 11:39:48 ----A---- C:\WINDOWS\SYSWOW64\gpapi.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\gameux.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\fontext.dll
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2017-03-16 11:39:47 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-03-16 11:39:46 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-03-16 11:39:45 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2017-03-16 11:39:45 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-03-16 11:39:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-03-16 11:39:43 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-03-16 11:39:42 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CompPkgSup.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-03-16 11:39:41 ----A---- C:\WINDOWS\SYSWOW64\CameraCaptureUI.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-03-16 11:39:40 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-03-16 11:39:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-03-16 11:39:39 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2017-03-16 11:39:38 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-03-16 11:39:37 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-03-16 11:39:37 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-03-16 11:39:37 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2017-03-16 11:39:36 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-03-16 11:39:35 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\tquery.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssvp.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-03-16 11:36:55 ----A---- C:\WINDOWS\system32\mssphtb.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\mssph.dll
2017-03-16 11:36:54 ----A---- C:\WINDOWS\system32\mssitlb.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\XInputUap.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\XblGameSaveExt.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\wlidprov.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Gaming.UI.GameBar.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-03-16 11:36:53 ----A---- C:\WINDOWS\system32\AppContracts.dll
2017-03-16 11:36:49 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-03-16 11:36:49 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-03-16 11:36:49 ----A---- C:\WINDOWS\system32\icfupgd.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\winhttp.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2017-03-16 11:36:35 ----A---- C:\WINDOWS\system32\drivers\storahci.sys
2017-03-16 11:36:34 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-03-16 11:36:31 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2017-03-16 11:36:31 ----A---- C:\WINDOWS\system32\GamePanelExternalHook.dll
2017-03-16 11:36:31 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\wwanmm.dll
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\wwanconn.dll
2017-03-16 11:36:30 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\EnterpriseAPNCsp.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\CspCellularSettings.dll
2017-03-16 11:36:29 ----A---- C:\WINDOWS\system32\CfgSPCellular.dll
2017-03-16 11:36:28 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2017-03-16 11:36:28 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-03-16 11:36:28 ----A---- C:\WINDOWS\system32\mispace.dll
2017-03-16 11:36:27 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-03-16 11:36:26 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\wlanui.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\wintrust.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2017-03-16 11:36:25 ----A---- C:\WINDOWS\system32\ReAgent.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\winmde.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-03-16 11:36:24 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2017-03-16 11:36:23 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-03-16 11:36:23 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-03-16 11:36:23 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll