Počítač i internet se zpomalil...prosím o kontrolu logu
Napsal: 30 čer 2017 21:29
Počítač i internet se poslední dobou strašně zpomalil, tak jsem chtěl poprosit o kontrolu logu. Děkuju
Logfile of random's system information tool 1.16 (written by random/random)
Run by Tom78 at 2017-06-30 22:19:17
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 63 GB (48%) free of 130 GB
Total RAM: 8098 MB (74% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:19:27, on 30.6.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18525)
Boot mode: Normal
Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Tom78_RSITx64.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.ru/cnt/10445?gp=811040
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [script_fcbd] "D:\Games\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\fcbd.bat" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [script_fcbd] "D:\Games\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\fcbd.bat" (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: GalaxyClientService - GOG.com - D:\Games\GOG Galaxy\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: Origin Client Service - Electronic Arts - D:\Games\EA-Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Games\EA-Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6977 bytes
====== Enumerating Processes ======
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\Explorer.EXE
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe "-433067321-106255768520462870772657599734761581011839203143111363244377591945
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Windows\system32\NOTEPAD.EXE" C:\Moje\něco.txt
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.0.863151205\1269927522" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 2532 "\\.\pipe\gecko-crash-server-pipe.2532" gpu
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.2.777158795\603521015" -childID 1 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|48:0|50:400|51:1|52:0|53:0|58:0|59:120|60:120|133:2|134:1|147:5000|157:0|159:0|170:10000|182:-1|187:128|188:10000|189:0|195:24|196:32768|198:0|199:0|207:5|211:1048576|212:100|213:5000|215:600|217:1|226:1|231:0|241:60000| -boolPrefs 1:0|2:0|4:0|26:1|27:1|30:0|35:1|36:0|37:0|38:0|39:1|40:0|41:1|42:1|45:0|46:0|47:0|49:0|54:1|55:1|56:0|57:1|61:1|62:1|63:0|64:1|65:1|66:0|67:1|70:0|71:0|74:1|75:1|79:1|80:1|81:0|82:0|84:0|85:0|86:1|87:0|90:0|91:1|92:1|93:1|94:1|95:1|96:0|97:0|98:1|99:0|100:0|101:0|102:1|103:1|104:0|105:1|106:1|107:0|108:0|109:1|110:1|111:1|112:0|113:1|114:1|115:1|116:1|117:1|118:1|119:1|120:1|122:0|123:0|124:0|125:1|126:0|127:1|131:1|132:1|135:1|136:0|141:0|146:0|149:1|152:1|154:1|158:0|161:1|164:1|165:1|171:0|172:0|173:1|175:0|181:0|183:1|184:0|185:0|186:0|193:0|194:0|197:1|200:1|202:0|204:1|205:0|210:0|214:1|219:0|220:0|221:0|222:1|224:1|225:1|228:0|233:0|234:0|235:1|236:1|237:0|238:1|239:1|240:0|242:0|243:0|245:0|253:1|254:1|255:0|256:0|257:0| -stringPrefs "3:7;release|174:3;1.0|191:332; ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵ ‐’․‧ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|192:8;moderate|227:38;{2eb7052b-8514-46f9-b933-a3a2cedb9751}|" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 2532 "\\.\pipe\gecko-crash-server-pipe.2532" tab
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe23_ Global\UsGthrCtrlFltPipeMssGthrPipe23 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Tom78\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
====== Scheduled tasks folder ======
C:\Windows\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_171_pepper.exe -check pepperplugin
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
C:\Windows\system32\tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\Opera scheduled Autoupdate 1498851699 - C:\Moje\Opera_znovu\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1478469413 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
=========Mozilla firefox=========
ProfilePath - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.171 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.171 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\addons.json
uBlock Origin - extension - uBlock0@raymondhill.net
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d}
C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions.json
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
Avast Online Security - webextension - wrc@avast.com - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\wrc@avast.com.xpi
Avast SafePrice - webextension - sp@avast.com - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\sp@avast.com.xpi
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Firefox Screenshots - extension - screenshots@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
uBlock Origin - extension - uBlock0@raymondhill.net - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\uBlock0@raymondhill.net.xpi
C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\pluginreg.dat
Plugin - Shockwave Flash - 25.0.0.171 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll
=========Google Chrome=========
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=
======Registry dump ======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-06-26 896048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-06-26 774440]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-11-11 8899592]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-06-26 213832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShadowPlay]
C:\Windows\system32\nvspcap64.dll [2017-05-03 1893496]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux2"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
====== File associations ======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
====== List of files/folders created in the last 1 month ======
2017-06-30 22:19:18 ----D---- C:\Program Files\trend micro
2017-06-30 22:19:17 ----D---- C:\rsit
2017-06-30 11:03:36 ----D---- C:\ProgramData\SWCUTemp
2017-06-26 15:39:31 ----A---- C:\Windows\system32\aswBoot.exe
2017-06-17 16:53:57 ----D---- C:\Users\Tom78\AppData\Roaming\NVIDIA
2017-06-13 23:36:32 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2017-06-13 23:36:31 ----A---- C:\Windows\system32\user.exe
2017-06-13 23:36:31 ----A---- C:\Windows\system32\setupSNK.exe
2017-06-13 23:36:30 ----A---- C:\Windows\system32\setup16.exe
2017-06-13 23:36:30 ----A---- C:\Windows\system32\regedit.exe
2017-06-13 23:36:29 ----A---- C:\Windows\system32\perfhost.exe
2017-06-13 23:36:29 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-06-13 23:36:21 ----A---- C:\Windows\system32\instnm.exe
2017-06-13 23:36:21 ----A---- C:\Windows\system32\hh.exe
2017-06-13 23:36:20 ----A---- C:\Windows\system32\explorer.exe
2017-06-13 23:36:15 ----A---- C:\Windows\system32\dplaysvr.exe
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vsocklib.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vmhgfs.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vmGuestLibJava.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vmGuestLib.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vm3dum.dll
2017-06-13 23:36:13 ----A---- C:\Windows\SYSWOW64\vm3dgl.dll
2017-06-13 23:36:08 ----A---- C:\Windows\SYSWOW64\mstime.dll
2017-06-13 23:36:06 ----A---- C:\Windows\SYSWOW64\mfc71u.dll
2017-06-13 23:36:04 ----A---- C:\Windows\SYSWOW64\mfc71.dll
2017-06-13 23:36:03 ----A---- C:\Windows\SYSWOW64\LegitCheckControl.DLL
2017-06-13 23:36:00 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2017-06-13 23:35:59 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2017-06-13 23:35:59 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2017-06-13 23:35:58 ----A---- C:\Windows\SYSWOW64\corpol.dll
2017-06-13 23:35:58 ----A---- C:\Windows\SYSWOW64\admparse.dll
2017-06-13 23:35:58 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2017-06-13 23:35:57 ----A---- C:\Windows\system32\wow32.dll
2017-06-13 23:35:57 ----A---- C:\Windows\system32\vsocklib.dll
2017-06-13 23:35:55 ----A---- C:\Windows\system32\vmhgfs.dll
2017-06-13 23:35:55 ----A---- C:\Windows\system32\vmGuestLibJava.dll
2017-06-13 23:35:55 ----A---- C:\Windows\system32\vmGuestLib.dll
2017-06-13 23:35:54 ----A---- C:\Windows\system32\vm3dum.dll
2017-06-13 23:35:54 ----A---- C:\Windows\system32\vm3dgl.dll
2017-06-13 23:35:48 ----A---- C:\Windows\system32\vfpodbc.dll
2017-06-13 23:35:47 ----A---- C:\Windows\system32\vdmdbg.dll
2017-06-13 23:35:47 ----A---- C:\Windows\system32\vbajet32.dll
2017-06-13 23:35:47 ----A---- C:\Windows\system32\typelib.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\storage.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\sqlwoa.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\sqlwid.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\sqlunirl.dll
2017-06-13 23:35:45 ----A---- C:\Windows\system32\olethk32.dll
2017-06-13 23:35:44 ----A---- C:\Windows\system32\olesvr32.dll
2017-06-13 23:35:44 ----A---- C:\Windows\system32\olepro32.dll
2017-06-13 23:35:44 ----A---- C:\Windows\system32\olecli32.dll
2017-06-13 23:35:43 ----A---- C:\Windows\system32\ole2nls.dll
2017-06-13 23:35:43 ----A---- C:\Windows\system32\ole2disp.dll
2017-06-13 23:35:42 ----A---- C:\Windows\system32\ole2.dll
2017-06-13 23:35:42 ----A---- C:\Windows\system32\odtext32.dll
2017-06-13 23:35:41 ----A---- C:\Windows\system32\odpdx32.dll
2017-06-13 23:35:40 ----A---- C:\Windows\system32\odfox32.dll
2017-06-13 23:35:39 ----A---- C:\Windows\system32\odexl32.dll
2017-06-13 23:35:39 ----A---- C:\Windows\system32\oddbse32.dll
2017-06-13 23:35:39 ----A---- C:\Windows\system32\odbcjt32.dll
2017-06-13 23:35:38 ----A---- C:\Windows\system32\odbcji32.dll
2017-06-13 23:35:38 ----A---- C:\Windows\system32\mtxlegih.dll
2017-06-13 23:35:37 ----A---- C:\Windows\system32\msxbde40.dll
2017-06-13 23:35:36 ----A---- C:\Windows\system32\mswstr10.dll
2017-06-13 23:35:35 ----A---- C:\Windows\system32\mswdat10.dll
2017-06-13 23:35:33 ----A---- C:\Windows\system32\msvcrt40.dll
2017-06-13 23:35:32 ----A---- C:\Windows\system32\msvcrt20.dll
2017-06-13 23:35:32 ----A---- C:\Windows\system32\msvcr71.dll
2017-06-13 23:35:31 ----A---- C:\Windows\system32\msvbvm60.dll
2017-06-13 23:35:28 ----A---- C:\Windows\system32\mstime.dll
2017-06-13 23:35:27 ----A---- C:\Windows\system32\mstext40.dll
2017-06-13 23:35:26 ----A---- C:\Windows\system32\msrepl40.dll
2017-06-13 23:35:24 ----A---- C:\Windows\system32\msrd3x40.dll
2017-06-13 23:35:23 ----A---- C:\Windows\system32\msrd2x40.dll
2017-06-13 23:35:22 ----A---- C:\Windows\system32\mspbde40.dll
2017-06-13 23:35:21 ----A---- C:\Windows\system32\msorcl32.dll
2017-06-13 23:35:21 ----A---- C:\Windows\system32\msorc32r.dll
2017-06-13 23:35:20 ----A---- C:\Windows\system32\msltus40.dll
2017-06-13 23:35:20 ----A---- C:\Windows\system32\msjtes40.dll
2017-06-13 23:35:19 ----A---- C:\Windows\system32\msjter40.dll
2017-06-13 23:35:19 ----A---- C:\Windows\system32\msjint40.dll
2017-06-13 23:35:18 ----A---- C:\Windows\system32\msjetoledb40.dll
2017-06-13 23:35:17 ----A---- C:\Windows\system32\msjet40.dll
2017-06-13 23:35:13 ----A---- C:\Windows\system32\msexcl40.dll
2017-06-13 23:35:12 ----A---- C:\Windows\system32\msexch40.dll
2017-06-13 23:35:11 ----A---- C:\Windows\system32\mscpxl32.dLL
2017-06-13 23:35:11 ----A---- C:\Windows\system32\mscpx32r.dLL
2017-06-13 23:35:11 ----A---- C:\Windows\system32\mfc71u.dll
2017-06-13 23:35:09 ----A---- C:\Windows\system32\mfc71.dll
2017-06-13 23:35:07 ----A---- C:\Windows\system32\mfc40u.dll
2017-06-13 23:35:05 ----A---- C:\Windows\system32\mfc40.dll
2017-06-13 23:35:03 ----A---- C:\Windows\system32\LegitCheckControl.DLL
2017-06-13 23:35:00 ----A---- C:\Windows\system32\ir50_qcx.dll
2017-06-13 23:35:00 ----A---- C:\Windows\system32\ir50_qc.dll
2017-06-13 23:34:59 ----A---- C:\Windows\system32\ir50_32.dll
2017-06-13 23:34:57 ----A---- C:\Windows\system32\ir41_qcx.dll
2017-06-13 23:34:57 ----A---- C:\Windows\system32\ir41_qc.dll
2017-06-13 23:34:56 ----A---- C:\Windows\system32\ir32_32.dll
2017-06-13 23:34:56 ----A---- C:\Windows\system32\iprop.dll
2017-06-13 23:34:55 ----A---- C:\Windows\system32\ieakui.dll
2017-06-13 23:34:55 ----A---- C:\Windows\system32\ieaksie.dll
2017-06-13 23:34:54 ----A---- C:\Windows\system32\ieakeng.dll
2017-06-13 23:34:54 ----A---- C:\Windows\system32\iccvid.dll
2017-06-13 23:34:53 ----A---- C:\Windows\system32\FXSXP32.dll
2017-06-13 23:34:52 ----A---- C:\Windows\system32\FXSEXT32.dll
2017-06-13 23:34:52 ----A---- C:\Windows\system32\expsrv.dll
2017-06-13 23:34:51 ----A---- C:\Windows\system32\dpwsockx.dll
2017-06-13 23:34:50 ----A---- C:\Windows\system32\dpmodemx.dll
2017-06-13 23:34:50 ----A---- C:\Windows\system32\dplayx.dll
2017-06-13 23:34:49 ----A---- C:\Windows\system32\dmstyle.dll
2017-06-13 23:34:49 ----A---- C:\Windows\system32\dmscript.dll
2017-06-13 23:34:48 ----A---- C:\Windows\system32\dmime.dll
2017-06-13 23:34:48 ----A---- C:\Windows\system32\dmcompos.dll
2017-06-13 23:34:47 ----A---- C:\Windows\system32\dmband.dll
2017-06-13 23:34:47 ----A---- C:\Windows\system32\d3dxof.dll
2017-06-13 23:34:47 ----A---- C:\Windows\system32\d3dramp.dll
2017-06-13 23:34:46 ----A---- C:\Windows\system32\d3dim700.dll
2017-06-13 23:34:44 ----A---- C:\Windows\system32\d3dim.dll
2017-06-13 23:34:43 ----A---- C:\Windows\system32\d3d8.dll
2017-06-13 23:34:41 ----A---- C:\Windows\system32\ctl3d32.dll
2017-06-13 23:34:40 ----A---- C:\Windows\system32\crtdll.dll
2017-06-13 23:34:40 ----A---- C:\Windows\system32\corpol.dll
2017-06-13 23:34:39 ----A---- C:\Windows\system32\compobj.dll
2017-06-13 23:34:39 ----A---- C:\Windows\system32\audiodev.dll
2017-06-13 23:34:38 ----A---- C:\Windows\system32\admparse.dll
2017-06-13 23:34:38 ----A---- C:\Windows\system32\aaclient.dll
2017-06-13 22:58:22 ----A---- C:\Windows\NvTelemetryContainerRecovery.bat
2017-06-13 22:57:54 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2017-06-13 22:57:42 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2017-06-13 22:57:42 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2017-06-13 22:57:42 ----A---- C:\Windows\system32\vulkaninfo.exe
2017-06-13 22:57:42 ----A---- C:\Windows\system32\vulkan-1.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvsvcr.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvsvc64.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvshext.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvmctray.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvcpl.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nv3dappshextr.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nv3dappshext.dll
2017-06-13 22:57:14 ----A---- C:\Windows\NvContainerRecovery.bat
2017-06-13 22:57:05 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2017-06-13 22:57:05 ----A---- C:\Windows\system32\OpenCL.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvwgf2umx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvumdshimx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvopencl.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvoglv64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvoglshim64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvinitx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\NvIFR64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvhdap64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\NvFBC64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvdispgenco6438253.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvdispco6438253.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvd3dumx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvcuvid.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvcuda.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvcompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvapi64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\drivers\nvvhci.sys
2017-06-13 22:54:42 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2017-06-13 22:54:42 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
====== List of files/folders modified in the last 1 month ======
2017-06-30 22:19:27 ----D---- C:\Windows\Prefetch
2017-06-30 22:19:18 ----RD---- C:\Program Files
2017-06-30 22:12:11 ----D---- C:\Windows\Temp
2017-06-30 21:42:10 ----D---- C:\Windows\system32\Tasks
2017-06-30 21:41:42 ----D---- C:\Users\Tom78\AppData\Roaming\Opera Software
2017-06-30 21:41:18 ----D---- C:\Moje
2017-06-30 21:36:35 ----D---- C:\Windows
2017-06-30 12:25:17 ----D---- C:\ProgramData\NVIDIA
2017-06-30 11:10:52 ----D---- C:\Windows\system32\drivers
2017-06-30 11:03:36 ----HD---- C:\ProgramData
2017-06-29 13:43:57 ----D---- C:\Users\Tom78\AppData\Roaming\uTorrent
2017-06-27 23:19:50 ----D---- C:\Windows\inf
2017-06-26 20:07:10 ----SHD---- C:\System Volume Information
2017-06-26 17:51:21 ----D---- C:\Windows\system32\config
2017-06-26 15:39:31 ----D---- C:\Windows\System32
2017-06-26 15:39:29 ----D---- C:\ProgramData\AVAST Software
2017-06-21 11:58:33 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-06-20 13:59:23 ----D---- C:\Users\Tom78\AppData\Roaming\DAEMON Tools Lite
2017-06-18 15:33:20 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-06-18 15:31:50 ----D---- C:\Program Files (x86)\Common Files
2017-06-16 23:58:06 ----D---- C:\ProgramData\Origin
2017-06-16 23:58:05 ----D---- C:\Users\Tom78\AppData\Roaming\Origin
2017-06-14 17:11:35 ----D---- C:\Program Files (x86)\Rockstar Games
2017-06-14 17:11:26 ----D---- C:\Program Files\Rockstar Games
2017-06-13 23:37:17 ----D---- C:\Windows\SYSWOW64\config
2017-06-13 23:36:32 ----D---- C:\Windows\SysWOW64
2017-06-13 23:28:02 ----RD---- C:\Program Files (x86)
2017-06-13 23:02:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-06-13 22:58:25 ----D---- C:\Windows\system32\DriverStore
2017-06-13 22:58:23 ----D---- C:\Program Files\NVIDIA Corporation
2017-06-13 22:58:22 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-06-13 22:58:21 ----D---- C:\ProgramData\NVIDIA Corporation
2017-06-13 22:57:42 ----D---- C:\Program Files (x86)\VulkanRT
2017-06-13 22:57:27 ----D---- C:\Windows\Help
2017-06-13 22:56:53 ----D---- C:\Windows\system32\catroot2
2017-06-10 14:13:12 ----D---- C:\Program Files (x86)\SpeedFan
2017-06-08 22:44:51 ----D---- C:\Users\Tom78\AppData\Roaming\vlc
2017-06-07 14:22:22 ----SHD---- C:\Windows\Installer
2017-06-07 14:22:20 ----SD---- C:\Users\Tom78\AppData\Roaming\Microsoft
2017-06-03 12:12:53 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-06-03 12:12:51 ----D---- C:\Windows\system32\Macromed
2017-06-03 12:12:40 ----D---- C:\Windows\SYSWOW64\Macromed
File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed
====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-06-26 198944]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-06-26 343264]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-06-26 57704]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-06-26 84392]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-06-26 360792]
R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2016-11-07 118560]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2016-11-11 1469952]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2016-11-11 31712]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2013-10-21 213848]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2016-11-07 276256]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2017-04-22 381440]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-06-26 319984]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-06-26 41800]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-06-26 110352]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-06-26 1015848]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-06-26 585608]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2016-12-02 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO64A.SYS [2016-11-08 27552]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-06-26 146664]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-06-26 198768]
R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-11-11 5276168]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2016-11-11 823816]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2016-12-20 199760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2017-06-08 218712]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2017-05-03 48248]
R3 nvvhci;NVVHCI Enumerator Service; C:\Windows\system32\DRIVERS\nvvhci.sys [2017-06-08 57792]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2016-12-20 1037832]
S1 ZAM;ZAM Helper Driver; \??\C:\Windows\System32\drivers\zam64.sys []
S1 ZAM_Guard;ZAM Guard Driver; \??\C:\Windows\System32\drivers\zamguard64.sys []
S3 an0ldm2h;an0ldm2h; C:\Windows\system32\drivers\an0ldm2h.sys []
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-06-26 46984]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-05-03 30328]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 semav6msr64;semav6msr64; \??\C:\Windows\system32\drivers\semav6msr64.sys [2015-06-04 21984]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-10-21 42496]
====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-06-26 263312]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-10-16 207648]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2015-10-16 415520]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03 495224]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-06-08 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-06-08 449984]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-06-26 7430992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2017-01-26 104448]
S2 Origin Web Helper Service;Origin Web Helper Service; D:\Games\EA-Origin\OriginWebHelperService.exe [2017-06-16 3127192]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2017-04-22 383016]
S3 GalaxyClientService;GalaxyClientService; D:\Games\GOG Galaxy\GalaxyClientService.exe [2017-06-14 513088]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2017-06-14 8077376]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-10-27 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2015-05-22 881152]
S3 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2016-12-14 4317648]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03 495224]
S3 Origin Client Service;Origin Client Service; D:\Games\EA-Origin\OriginClientService.exe [2017-06-16 2157456]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-06-08 1607968]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2016-11-10 1255736]
S4 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2014-05-30 943136]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
-----------------EOF-----------------
Logfile of random's system information tool 1.16 (written by random/random)
Run by Tom78 at 2017-06-30 22:19:17
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 63 GB (48%) free of 130 GB
Total RAM: 8098 MB (74% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:19:27, on 30.6.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18525)
Boot mode: Normal
Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Tom78_RSITx64.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.ru/cnt/10445?gp=811040
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [script_fcbd] "D:\Games\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\fcbd.bat" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [script_fcbd] "D:\Games\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\fcbd.bat" (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: GalaxyClientService - GOG.com - D:\Games\GOG Galaxy\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: Origin Client Service - Electronic Arts - D:\Games\EA-Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Games\EA-Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6977 bytes
====== Enumerating Processes ======
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\Explorer.EXE
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe "-433067321-106255768520462870772657599734761581011839203143111363244377591945
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Windows\system32\NOTEPAD.EXE" C:\Moje\něco.txt
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.0.863151205\1269927522" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 2532 "\\.\pipe\gecko-crash-server-pipe.2532" gpu
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="2532.2.777158795\603521015" -childID 1 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|48:0|50:400|51:1|52:0|53:0|58:0|59:120|60:120|133:2|134:1|147:5000|157:0|159:0|170:10000|182:-1|187:128|188:10000|189:0|195:24|196:32768|198:0|199:0|207:5|211:1048576|212:100|213:5000|215:600|217:1|226:1|231:0|241:60000| -boolPrefs 1:0|2:0|4:0|26:1|27:1|30:0|35:1|36:0|37:0|38:0|39:1|40:0|41:1|42:1|45:0|46:0|47:0|49:0|54:1|55:1|56:0|57:1|61:1|62:1|63:0|64:1|65:1|66:0|67:1|70:0|71:0|74:1|75:1|79:1|80:1|81:0|82:0|84:0|85:0|86:1|87:0|90:0|91:1|92:1|93:1|94:1|95:1|96:0|97:0|98:1|99:0|100:0|101:0|102:1|103:1|104:0|105:1|106:1|107:0|108:0|109:1|110:1|111:1|112:0|113:1|114:1|115:1|116:1|117:1|118:1|119:1|120:1|122:0|123:0|124:0|125:1|126:0|127:1|131:1|132:1|135:1|136:0|141:0|146:0|149:1|152:1|154:1|158:0|161:1|164:1|165:1|171:0|172:0|173:1|175:0|181:0|183:1|184:0|185:0|186:0|193:0|194:0|197:1|200:1|202:0|204:1|205:0|210:0|214:1|219:0|220:0|221:0|222:1|224:1|225:1|228:0|233:0|234:0|235:1|236:1|237:0|238:1|239:1|240:0|242:0|243:0|245:0|253:1|254:1|255:0|256:0|257:0| -stringPrefs "3:7;release|174:3;1.0|191:332; ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵ ‐’․‧ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|192:8;moderate|227:38;{2eb7052b-8514-46f9-b933-a3a2cedb9751}|" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 2532 "\\.\pipe\gecko-crash-server-pipe.2532" tab
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe23_ Global\UsGthrCtrlFltPipeMssGthrPipe23 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Tom78\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
====== Scheduled tasks folder ======
C:\Windows\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_171_pepper.exe -check pepperplugin
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
C:\Windows\system32\tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\Opera scheduled Autoupdate 1498851699 - C:\Moje\Opera_znovu\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1478469413 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
=========Mozilla firefox=========
ProfilePath - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.171 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.171 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\addons.json
uBlock Origin - extension - uBlock0@raymondhill.net
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d}
C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions.json
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
Avast Online Security - webextension - wrc@avast.com - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\wrc@avast.com.xpi
Avast SafePrice - webextension - sp@avast.com - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\sp@avast.com.xpi
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Firefox Screenshots - extension - screenshots@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
uBlock Origin - extension - uBlock0@raymondhill.net - C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\extensions\uBlock0@raymondhill.net.xpi
C:\Users\Tom78\AppData\Roaming\Mozilla\Firefox\Profiles\7s4bl2ji.default\pluginreg.dat
Plugin - Shockwave Flash - 25.0.0.171 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll
=========Google Chrome=========
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=
======Registry dump ======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-06-26 896048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-06-26 774440]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-11-11 8899592]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-06-26 213832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShadowPlay]
C:\Windows\system32\nvspcap64.dll [2017-05-03 1893496]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux2"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
====== File associations ======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
====== List of files/folders created in the last 1 month ======
2017-06-30 22:19:18 ----D---- C:\Program Files\trend micro
2017-06-30 22:19:17 ----D---- C:\rsit
2017-06-30 11:03:36 ----D---- C:\ProgramData\SWCUTemp
2017-06-26 15:39:31 ----A---- C:\Windows\system32\aswBoot.exe
2017-06-17 16:53:57 ----D---- C:\Users\Tom78\AppData\Roaming\NVIDIA
2017-06-13 23:36:32 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2017-06-13 23:36:31 ----A---- C:\Windows\system32\user.exe
2017-06-13 23:36:31 ----A---- C:\Windows\system32\setupSNK.exe
2017-06-13 23:36:30 ----A---- C:\Windows\system32\setup16.exe
2017-06-13 23:36:30 ----A---- C:\Windows\system32\regedit.exe
2017-06-13 23:36:29 ----A---- C:\Windows\system32\perfhost.exe
2017-06-13 23:36:29 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-06-13 23:36:21 ----A---- C:\Windows\system32\instnm.exe
2017-06-13 23:36:21 ----A---- C:\Windows\system32\hh.exe
2017-06-13 23:36:20 ----A---- C:\Windows\system32\explorer.exe
2017-06-13 23:36:15 ----A---- C:\Windows\system32\dplaysvr.exe
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vsocklib.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vmhgfs.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vmGuestLibJava.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vmGuestLib.dll
2017-06-13 23:36:14 ----A---- C:\Windows\SYSWOW64\vm3dum.dll
2017-06-13 23:36:13 ----A---- C:\Windows\SYSWOW64\vm3dgl.dll
2017-06-13 23:36:08 ----A---- C:\Windows\SYSWOW64\mstime.dll
2017-06-13 23:36:06 ----A---- C:\Windows\SYSWOW64\mfc71u.dll
2017-06-13 23:36:04 ----A---- C:\Windows\SYSWOW64\mfc71.dll
2017-06-13 23:36:03 ----A---- C:\Windows\SYSWOW64\LegitCheckControl.DLL
2017-06-13 23:36:00 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2017-06-13 23:35:59 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2017-06-13 23:35:59 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2017-06-13 23:35:58 ----A---- C:\Windows\SYSWOW64\corpol.dll
2017-06-13 23:35:58 ----A---- C:\Windows\SYSWOW64\admparse.dll
2017-06-13 23:35:58 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2017-06-13 23:35:57 ----A---- C:\Windows\system32\wow32.dll
2017-06-13 23:35:57 ----A---- C:\Windows\system32\vsocklib.dll
2017-06-13 23:35:55 ----A---- C:\Windows\system32\vmhgfs.dll
2017-06-13 23:35:55 ----A---- C:\Windows\system32\vmGuestLibJava.dll
2017-06-13 23:35:55 ----A---- C:\Windows\system32\vmGuestLib.dll
2017-06-13 23:35:54 ----A---- C:\Windows\system32\vm3dum.dll
2017-06-13 23:35:54 ----A---- C:\Windows\system32\vm3dgl.dll
2017-06-13 23:35:48 ----A---- C:\Windows\system32\vfpodbc.dll
2017-06-13 23:35:47 ----A---- C:\Windows\system32\vdmdbg.dll
2017-06-13 23:35:47 ----A---- C:\Windows\system32\vbajet32.dll
2017-06-13 23:35:47 ----A---- C:\Windows\system32\typelib.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\storage.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\sqlwoa.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\sqlwid.dll
2017-06-13 23:35:46 ----A---- C:\Windows\system32\sqlunirl.dll
2017-06-13 23:35:45 ----A---- C:\Windows\system32\olethk32.dll
2017-06-13 23:35:44 ----A---- C:\Windows\system32\olesvr32.dll
2017-06-13 23:35:44 ----A---- C:\Windows\system32\olepro32.dll
2017-06-13 23:35:44 ----A---- C:\Windows\system32\olecli32.dll
2017-06-13 23:35:43 ----A---- C:\Windows\system32\ole2nls.dll
2017-06-13 23:35:43 ----A---- C:\Windows\system32\ole2disp.dll
2017-06-13 23:35:42 ----A---- C:\Windows\system32\ole2.dll
2017-06-13 23:35:42 ----A---- C:\Windows\system32\odtext32.dll
2017-06-13 23:35:41 ----A---- C:\Windows\system32\odpdx32.dll
2017-06-13 23:35:40 ----A---- C:\Windows\system32\odfox32.dll
2017-06-13 23:35:39 ----A---- C:\Windows\system32\odexl32.dll
2017-06-13 23:35:39 ----A---- C:\Windows\system32\oddbse32.dll
2017-06-13 23:35:39 ----A---- C:\Windows\system32\odbcjt32.dll
2017-06-13 23:35:38 ----A---- C:\Windows\system32\odbcji32.dll
2017-06-13 23:35:38 ----A---- C:\Windows\system32\mtxlegih.dll
2017-06-13 23:35:37 ----A---- C:\Windows\system32\msxbde40.dll
2017-06-13 23:35:36 ----A---- C:\Windows\system32\mswstr10.dll
2017-06-13 23:35:35 ----A---- C:\Windows\system32\mswdat10.dll
2017-06-13 23:35:33 ----A---- C:\Windows\system32\msvcrt40.dll
2017-06-13 23:35:32 ----A---- C:\Windows\system32\msvcrt20.dll
2017-06-13 23:35:32 ----A---- C:\Windows\system32\msvcr71.dll
2017-06-13 23:35:31 ----A---- C:\Windows\system32\msvbvm60.dll
2017-06-13 23:35:28 ----A---- C:\Windows\system32\mstime.dll
2017-06-13 23:35:27 ----A---- C:\Windows\system32\mstext40.dll
2017-06-13 23:35:26 ----A---- C:\Windows\system32\msrepl40.dll
2017-06-13 23:35:24 ----A---- C:\Windows\system32\msrd3x40.dll
2017-06-13 23:35:23 ----A---- C:\Windows\system32\msrd2x40.dll
2017-06-13 23:35:22 ----A---- C:\Windows\system32\mspbde40.dll
2017-06-13 23:35:21 ----A---- C:\Windows\system32\msorcl32.dll
2017-06-13 23:35:21 ----A---- C:\Windows\system32\msorc32r.dll
2017-06-13 23:35:20 ----A---- C:\Windows\system32\msltus40.dll
2017-06-13 23:35:20 ----A---- C:\Windows\system32\msjtes40.dll
2017-06-13 23:35:19 ----A---- C:\Windows\system32\msjter40.dll
2017-06-13 23:35:19 ----A---- C:\Windows\system32\msjint40.dll
2017-06-13 23:35:18 ----A---- C:\Windows\system32\msjetoledb40.dll
2017-06-13 23:35:17 ----A---- C:\Windows\system32\msjet40.dll
2017-06-13 23:35:13 ----A---- C:\Windows\system32\msexcl40.dll
2017-06-13 23:35:12 ----A---- C:\Windows\system32\msexch40.dll
2017-06-13 23:35:11 ----A---- C:\Windows\system32\mscpxl32.dLL
2017-06-13 23:35:11 ----A---- C:\Windows\system32\mscpx32r.dLL
2017-06-13 23:35:11 ----A---- C:\Windows\system32\mfc71u.dll
2017-06-13 23:35:09 ----A---- C:\Windows\system32\mfc71.dll
2017-06-13 23:35:07 ----A---- C:\Windows\system32\mfc40u.dll
2017-06-13 23:35:05 ----A---- C:\Windows\system32\mfc40.dll
2017-06-13 23:35:03 ----A---- C:\Windows\system32\LegitCheckControl.DLL
2017-06-13 23:35:00 ----A---- C:\Windows\system32\ir50_qcx.dll
2017-06-13 23:35:00 ----A---- C:\Windows\system32\ir50_qc.dll
2017-06-13 23:34:59 ----A---- C:\Windows\system32\ir50_32.dll
2017-06-13 23:34:57 ----A---- C:\Windows\system32\ir41_qcx.dll
2017-06-13 23:34:57 ----A---- C:\Windows\system32\ir41_qc.dll
2017-06-13 23:34:56 ----A---- C:\Windows\system32\ir32_32.dll
2017-06-13 23:34:56 ----A---- C:\Windows\system32\iprop.dll
2017-06-13 23:34:55 ----A---- C:\Windows\system32\ieakui.dll
2017-06-13 23:34:55 ----A---- C:\Windows\system32\ieaksie.dll
2017-06-13 23:34:54 ----A---- C:\Windows\system32\ieakeng.dll
2017-06-13 23:34:54 ----A---- C:\Windows\system32\iccvid.dll
2017-06-13 23:34:53 ----A---- C:\Windows\system32\FXSXP32.dll
2017-06-13 23:34:52 ----A---- C:\Windows\system32\FXSEXT32.dll
2017-06-13 23:34:52 ----A---- C:\Windows\system32\expsrv.dll
2017-06-13 23:34:51 ----A---- C:\Windows\system32\dpwsockx.dll
2017-06-13 23:34:50 ----A---- C:\Windows\system32\dpmodemx.dll
2017-06-13 23:34:50 ----A---- C:\Windows\system32\dplayx.dll
2017-06-13 23:34:49 ----A---- C:\Windows\system32\dmstyle.dll
2017-06-13 23:34:49 ----A---- C:\Windows\system32\dmscript.dll
2017-06-13 23:34:48 ----A---- C:\Windows\system32\dmime.dll
2017-06-13 23:34:48 ----A---- C:\Windows\system32\dmcompos.dll
2017-06-13 23:34:47 ----A---- C:\Windows\system32\dmband.dll
2017-06-13 23:34:47 ----A---- C:\Windows\system32\d3dxof.dll
2017-06-13 23:34:47 ----A---- C:\Windows\system32\d3dramp.dll
2017-06-13 23:34:46 ----A---- C:\Windows\system32\d3dim700.dll
2017-06-13 23:34:44 ----A---- C:\Windows\system32\d3dim.dll
2017-06-13 23:34:43 ----A---- C:\Windows\system32\d3d8.dll
2017-06-13 23:34:41 ----A---- C:\Windows\system32\ctl3d32.dll
2017-06-13 23:34:40 ----A---- C:\Windows\system32\crtdll.dll
2017-06-13 23:34:40 ----A---- C:\Windows\system32\corpol.dll
2017-06-13 23:34:39 ----A---- C:\Windows\system32\compobj.dll
2017-06-13 23:34:39 ----A---- C:\Windows\system32\audiodev.dll
2017-06-13 23:34:38 ----A---- C:\Windows\system32\admparse.dll
2017-06-13 23:34:38 ----A---- C:\Windows\system32\aaclient.dll
2017-06-13 22:58:22 ----A---- C:\Windows\NvTelemetryContainerRecovery.bat
2017-06-13 22:57:54 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2017-06-13 22:57:42 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2017-06-13 22:57:42 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2017-06-13 22:57:42 ----A---- C:\Windows\system32\vulkaninfo.exe
2017-06-13 22:57:42 ----A---- C:\Windows\system32\vulkan-1.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvsvcr.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvsvc64.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvshext.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvmctray.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nvcpl.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nv3dappshextr.dll
2017-06-13 22:57:29 ----A---- C:\Windows\system32\nv3dappshext.dll
2017-06-13 22:57:14 ----A---- C:\Windows\NvContainerRecovery.bat
2017-06-13 22:57:05 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2017-06-13 22:57:05 ----A---- C:\Windows\system32\OpenCL.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvwgf2umx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvumdshimx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvopencl.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvoglv64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvoglshim64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvinitx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\NvIFR64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvhdap64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\NvFBC64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvdispgenco6438253.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvdispco6438253.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvd3dumx.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvcuvid.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvcuda.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvcompiler.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\nvapi64.dll
2017-06-13 22:54:42 ----A---- C:\Windows\system32\drivers\nvvhci.sys
2017-06-13 22:54:42 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2017-06-13 22:54:42 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
====== List of files/folders modified in the last 1 month ======
2017-06-30 22:19:27 ----D---- C:\Windows\Prefetch
2017-06-30 22:19:18 ----RD---- C:\Program Files
2017-06-30 22:12:11 ----D---- C:\Windows\Temp
2017-06-30 21:42:10 ----D---- C:\Windows\system32\Tasks
2017-06-30 21:41:42 ----D---- C:\Users\Tom78\AppData\Roaming\Opera Software
2017-06-30 21:41:18 ----D---- C:\Moje
2017-06-30 21:36:35 ----D---- C:\Windows
2017-06-30 12:25:17 ----D---- C:\ProgramData\NVIDIA
2017-06-30 11:10:52 ----D---- C:\Windows\system32\drivers
2017-06-30 11:03:36 ----HD---- C:\ProgramData
2017-06-29 13:43:57 ----D---- C:\Users\Tom78\AppData\Roaming\uTorrent
2017-06-27 23:19:50 ----D---- C:\Windows\inf
2017-06-26 20:07:10 ----SHD---- C:\System Volume Information
2017-06-26 17:51:21 ----D---- C:\Windows\system32\config
2017-06-26 15:39:31 ----D---- C:\Windows\System32
2017-06-26 15:39:29 ----D---- C:\ProgramData\AVAST Software
2017-06-21 11:58:33 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-06-20 13:59:23 ----D---- C:\Users\Tom78\AppData\Roaming\DAEMON Tools Lite
2017-06-18 15:33:20 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-06-18 15:31:50 ----D---- C:\Program Files (x86)\Common Files
2017-06-16 23:58:06 ----D---- C:\ProgramData\Origin
2017-06-16 23:58:05 ----D---- C:\Users\Tom78\AppData\Roaming\Origin
2017-06-14 17:11:35 ----D---- C:\Program Files (x86)\Rockstar Games
2017-06-14 17:11:26 ----D---- C:\Program Files\Rockstar Games
2017-06-13 23:37:17 ----D---- C:\Windows\SYSWOW64\config
2017-06-13 23:36:32 ----D---- C:\Windows\SysWOW64
2017-06-13 23:28:02 ----RD---- C:\Program Files (x86)
2017-06-13 23:02:18 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-06-13 22:58:25 ----D---- C:\Windows\system32\DriverStore
2017-06-13 22:58:23 ----D---- C:\Program Files\NVIDIA Corporation
2017-06-13 22:58:22 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-06-13 22:58:21 ----D---- C:\ProgramData\NVIDIA Corporation
2017-06-13 22:57:42 ----D---- C:\Program Files (x86)\VulkanRT
2017-06-13 22:57:27 ----D---- C:\Windows\Help
2017-06-13 22:56:53 ----D---- C:\Windows\system32\catroot2
2017-06-10 14:13:12 ----D---- C:\Program Files (x86)\SpeedFan
2017-06-08 22:44:51 ----D---- C:\Users\Tom78\AppData\Roaming\vlc
2017-06-07 14:22:22 ----SHD---- C:\Windows\Installer
2017-06-07 14:22:20 ----SD---- C:\Users\Tom78\AppData\Roaming\Microsoft
2017-06-03 12:12:53 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-06-03 12:12:51 ----D---- C:\Windows\system32\Macromed
2017-06-03 12:12:40 ----D---- C:\Windows\SYSWOW64\Macromed
File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed
====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-06-26 198944]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-06-26 343264]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-06-26 57704]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-06-26 84392]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-06-26 360792]
R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2016-11-07 118560]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2016-11-11 1469952]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2016-11-11 31712]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2013-10-21 213848]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2016-11-07 276256]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2017-04-22 381440]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-06-26 319984]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-06-26 41800]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-06-26 110352]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-06-26 1015848]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-06-26 585608]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2016-12-02 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO64A.SYS [2016-11-08 27552]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-06-26 146664]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-06-26 198768]
R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-11-11 5276168]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2016-11-11 823816]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2016-12-20 199760]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2017-06-08 218712]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2017-05-03 48248]
R3 nvvhci;NVVHCI Enumerator Service; C:\Windows\system32\DRIVERS\nvvhci.sys [2017-06-08 57792]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2016-12-20 1037832]
S1 ZAM;ZAM Helper Driver; \??\C:\Windows\System32\drivers\zam64.sys []
S1 ZAM_Guard;ZAM Guard Driver; \??\C:\Windows\System32\drivers\zamguard64.sys []
S3 an0ldm2h;an0ldm2h; C:\Windows\system32\drivers\an0ldm2h.sys []
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-06-26 46984]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-05-03 30328]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 semav6msr64;semav6msr64; \??\C:\Windows\system32\drivers\semav6msr64.sys [2015-06-04 21984]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-10-21 42496]
====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-06-26 263312]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-10-16 207648]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2015-10-16 415520]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03 495224]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-06-08 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-06-08 449984]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-06-26 7430992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2017-01-26 104448]
S2 Origin Web Helper Service;Origin Web Helper Service; D:\Games\EA-Origin\OriginWebHelperService.exe [2017-06-16 3127192]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2017-04-22 383016]
S3 GalaxyClientService;GalaxyClientService; D:\Games\GOG Galaxy\GalaxyClientService.exe [2017-06-14 513088]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2017-06-14 8077376]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-10-27 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2015-05-22 881152]
S3 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2016-12-14 4317648]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03 495224]
S3 Origin Client Service;Origin Client Service; D:\Games\EA-Origin\OriginClientService.exe [2017-06-16 2157456]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-06-08 1607968]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2016-11-10 1255736]
S4 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2014-05-30 943136]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
-----------------EOF-----------------