Stránka 1 z 1

Prosim kontrolu, oteviraji se nahodne stranky s reklamou

Napsal: 09 lis 2017 14:27
od Sergeii
Logfile of random's system information tool 1.10 (written by random/random)
Run by ludovico at 2017-11-09 14:24:26
Microsoft Windows 10 Home
System drive C: has 470 GB (51%) free of 912 GB
Total RAM: 8106 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:24:53 PM, on 09-Nov-17
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0608)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE
C:\ProgramData\{150FCB7A-A2A4-7CD1-7FF8-BDC8B7154083}\CD523F8D-7AF9-8826-EC9E-7B181F93E8A8.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
C:\Program Files\trend micro\ludovico.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll
O2 - BHO: YoutubeAdBlock - {C0D38E5A-7CF8-4105-8FE8-31B81443A114} - C:\Program Files (x86)\ZfJRwqLPhIE\k198CqJYv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\ludovico\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-600 Series"
O4 - HKCU\..\Run: [RuneApps Alt1] "C:\Users\ludovico\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe"
O4 - HKCU\..\Run: [Bloody2] "C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe" Minimum
O4 - HKCU\..\Run: [Discord] C:\Users\ludovico\AppData\Local\Discord\app-0.0.298\Discord.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Monitor Ink Alerts - HP DeskJet 3630 series.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{03244fb4-42a0-424d-a548-8341a1a432ed}: NameServer = 82.163.143.176 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\..\{5a254169-dcc9-4854-9e1d-0db0029c3462}: NameServer = 82.163.143.176 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\..\{78974a5b-a40d-48e4-93c1-6181a62e78b3}: NameServer = 82.163.143.176 82.163.142.178
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.143.176 82.163.142.178
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.143.176 82.163.142.178
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: @oem41.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Genie Timeline Service (GenieTimelineService) - Genie9 - C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Heroes & Generals Steam Service (HnGSteamService) - Reto-Moto ApS - C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: @oem47.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Limited - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12134 bytes

======Listing Processes======







C:\WINDOWS\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
"fontdrvhost.exe"
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-46da9a7b-61f2-4751-b7ae-1ed6dfa9a3cc -SystemEventPortName:HostProcess-0aeabc7f-5ee7-4f18-b8f5-ed6034eeb352 -IoCancelEventPortName:HostProcess-d9241119-51ea-4d87-8549-36a8add41409 -NonStateChangingEventPortName:HostProcess-e0655e30-44a2-48cf-be40-65aa7fe21766 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0492e947-ee4e-493b-8bd8-98f9b2b6af78 -DeviceGroupId:
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
C:\WINDOWS\system32\igfxCUIService.exe
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k localservice -s netprofm
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\system32\WLANExt.exe 2216014870320
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
C:\WINDOWS\system32\BtwRSupportService.exe
"C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
C:\WINDOWS\System32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
C:\WINDOWS\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc

C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks

c:\windows\system32\svchost.exe -k netsvcs -s WpnService
dashost.exe {7538bdc2-e941-4e49-b3692b89a1d4c9ab}

c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent

c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
c:\windows\system32\svchost.exe -k netsvcs -s BITS
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\svchost.exe -k netsvcs -s seclogon
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s RmSvc
c:\windows\system32\svchost.exe -k localservice -s SstpSvc
c:\windows\system32\svchost.exe -k networkservice -s TapiSrv
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s FDResPub
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s HomeGroupProvider
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
"C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DsSvc
"C:\Program Files (x86)\Origin\OriginWebHelperService.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SensorService
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s QWAVE

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"fontdrvhost.exe"
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
igfxEM.exe
igfxHK.exe
igfxTray.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files\Genie9\Genie Timeline\GenieTimelineAgent.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Windows\RTFTrack.exe"
"C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe"
"C:\WINDOWS\system32\RunDll32.exe" "C:\Program Files\HP\HP DeskJet 3630 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN69S3H6G0067R;CONNECTION=USB;MONITOR=1;
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\ludovico\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=61.0.3163.100 --initial-client-data=0x1f8,0x1fc,0x200,0x1f4,0x204,0x7ffa9e8c1988,0x7ffa9e8c1948,0x7ffa9e8c1958
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3440 --on-initialized-event-handle=572 --parent-handle=68 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --supports-dual-gpus=false --gpu-driver-bug-workarounds=9,12,13,23,27,29,49,70,84 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x1616 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=20.19.15.4642 --gpu-driver-date=3-28-2017 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x1341 --service-request-channel-token=FE993D5E414F65F9B14774B00CF8A958 --mojo-platform-channel-handle=1444 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=A015A3193C586F01155A6E5B0CA26B0B --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=A015A3193C586F01155A6E5B0CA26B0B --renderer-client-id=4 --mojo-platform-channel-handle=3296 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=7F3944E3CA51DC0B4C5AAFFE01974EC9 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=7F3944E3CA51DC0B4C5AAFFE01974EC9 --renderer-client-id=5 --mojo-platform-channel-handle=3376 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=78F365B769FAACB842DFD947DF913722 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=78F365B769FAACB842DFD947DF913722 --renderer-client-id=6 --mojo-platform-channel-handle=3384 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=F3678EF140B25F79F3B94F63D9DDA120 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=F3678EF140B25F79F3B94F63D9DDA120 --renderer-client-id=11 --mojo-platform-channel-handle=7516 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=FAB42821B7BB5A28AD2B7D12FE005107 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=FAB42821B7BB5A28AD2B7D12FE005107 --renderer-client-id=12 --mojo-platform-channel-handle=7844 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=B47A2D888CA531CBE66056D4B8E6E6BE --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=B47A2D888CA531CBE66056D4B8E6E6BE --renderer-client-id=13 --mojo-platform-channel-handle=7472 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=0E4F9736AF571517AF1BCDB1552C8020 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=0E4F9736AF571517AF1BCDB1552C8020 --renderer-client-id=14 --mojo-platform-channel-handle=8244 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=046CE05083BD5E22AA24670A0F11333A --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=046CE05083BD5E22AA24670A0F11333A --renderer-client-id=15 --mojo-platform-channel-handle=7848 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=1094A524DA45A953C683633969C70CE1 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=1094A524DA45A953C683633969C70CE1 --renderer-client-id=16 --mojo-platform-channel-handle=8512 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=B41D7949BD2BE4F46DE9324056626F98 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=B41D7949BD2BE4F46DE9324056626F98 --renderer-client-id=17 --mojo-platform-channel-handle=8232 /prefetch:1
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17092.13511.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39081.15820.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\SkypeApp.exe" -ServerName:App.AppXffn3yxqvgawq9fpmnhy90fr3y01d1t5b.mca
C:\WINDOWS\system32\svchost.exe -k LocalService -s WinHttpAutoProxySvc
C:\WINDOWS\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
C:\WINDOWS\system32\AUDIODG.EXE 0x598
C:\WINDOWS\System32\svchost.exe -k netsvcs -s Browser
C:\WINDOWS\system32\svchost.exe -k netsvcs -s XblAuthManager
"C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE" /e
C:\ProgramData\{150FCB7A-A2A4-7CD1-7FF8-BDC8B7154083}\CD523F8D-7AF9-8826-EC9E-7B181F93E8A8.exe /run
-name a776bcfb-34e9-4e6c-83ed-fbd474016717 -runas -pluginName LenovoAudioPlugin -pluginVersion 1.2.211.0
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s lmhosts
"C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe" 1 69
"C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe" 1 70
"C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe" 1 71
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=D894B516E4E53AADDE312767414590A0 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=D894B516E4E53AADDE312767414590A0 --renderer-client-id=229 --mojo-platform-channel-handle=6892 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=87F374801394F6855A5D6DF9B700B4A3 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=87F374801394F6855A5D6DF9B700B4A3 --renderer-client-id=258 --mojo-platform-channel-handle=11112 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=480B2B7E2FD9A0250169BF7A8A14BCAA --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=480B2B7E2FD9A0250169BF7A8A14BCAA --renderer-client-id=288 --mojo-platform-channel-handle=10960 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=768879922D9D7E1CB2086A6F1149525D --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=768879922D9D7E1CB2086A6F1149525D --renderer-client-id=296 --mojo-platform-channel-handle=9552 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=4C10FACEDA85FFBA1C702D37E5D741F0 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=4C10FACEDA85FFBA1C702D37E5D741F0 --renderer-client-id=297 --mojo-platform-channel-handle=10924 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=CF56A6B7E910A48F289B99C046287423 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=CF56A6B7E910A48F289B99C046287423 --renderer-client-id=326 --mojo-platform-channel-handle=1776 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=4E39D691615EC93B8E27F34BAD0CB3CA --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=4E39D691615EC93B8E27F34BAD0CB3CA --renderer-client-id=327 --mojo-platform-channel-handle=6716 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=0832C11127C3C2B95F1263496E228145 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=0832C11127C3C2B95F1263496E228145 --renderer-client-id=328 --mojo-platform-channel-handle=11900 /prefetch:1
C:\WINDOWS\system32\svchost.exe -k netsvcs -s gpsvc

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=948DE8FDA9AFA49AB26EB940B1596B51 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=948DE8FDA9AFA49AB26EB940B1596B51 --renderer-client-id=339 --mojo-platform-channel-handle=11044 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe136_ Global\UsGthrCtrlFltPipeMssGthrPipe136 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 696 700 708 8192 704
C:\Windows\System32\smartscreen.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k netsvcs -s wlidsvc
"C:\Users\ludovico\Downloads\RSITx64.exe"
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=30FDFF853ABD3A96A9F0ACBD5F32137D --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=30FDFF853ABD3A96A9F0ACBD5F32137D --renderer-client-id=340 --mojo-platform-channel-handle=12036 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1428,17730998692125498380,15445598015020860993,131072 --service-pipe-token=A2B8925DB0B8C5CBBB60908408126D78 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --enable-gpu-async-worker-context --service-request-channel-token=A2B8925DB0B8C5CBBB60908408126D78 --renderer-client-id=341 --mojo-platform-channel-handle=12172 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\WINDOWS\tasks\Online Application V2G1.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 69
C:\WINDOWS\tasks\Online Application V2G2.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 70
C:\WINDOWS\tasks\Online Application V2G3.job - C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe 1 71
C:\WINDOWS\tasks\PjDfytumxbayONn.job - rundll32 "C:\Program Files (x86)\kqEuPYMaU\RfEGAK.dll",#1
C:\WINDOWS\tasks\Updater_Online_Application.job - C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe /silentall -nofreqcheck

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]
YoutubeAdBlock - C:\Program Files (x86)\ZfJRwqLPhIE\tIMInOG.dll [2017-10-28 491008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28 473664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]
YoutubeAdBlock - C:\Program Files (x86)\ZfJRwqLPhIE\k198CqJYv.dll [2017-10-28 462336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28 187968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-18 629152]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2015-06-16 5060864]
"LenovoUtility"=C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [2017-07-27 911272]
"SERVICE"= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\ludovico\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-11-07 1685704]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-11-15 9105112]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2017-10-31 3102496]
"EPLTarget\P0000000000000000"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE [2012-02-29 283232]
"RuneApps Alt1"=C:\Users\ludovico\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe [2017-07-27 1521664]
"Bloody2"=C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe [2017-10-13 17696768]
"Discord"=C:\Users\ludovico\AppData\Local\Discord\app-0.0.298\Discord.exe [2017-08-08 57477112]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2017-08-14 4836032]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-07-21 587288]

C:\Users\ludovico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Monitor Ink Alerts - HP DeskJet 3630 series.lnk - C:\WINDOWS\system32\RunDll32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 09 lis 2017 14:28
od Sergeii
======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-11-09 14:24:27 ----D---- C:\Program Files\trend micro
2017-11-09 14:24:26 ----D---- C:\rsit
2017-11-09 08:19:00 ----D---- C:\ProgramData\61673b52-3ed1-1
2017-11-09 08:19:00 ----D---- C:\ProgramData\61673b52-0671-0
2017-11-09 08:18:39 ----D---- C:\ProgramData\803f88d0-1cf5-0
2017-11-09 08:18:34 ----D---- C:\ProgramData\803f88d0-11c5-1
2017-11-08 18:24:00 ----D---- C:\ProgramData\803f88d0-6cd3-1
2017-11-08 18:24:00 ----D---- C:\ProgramData\803f88d0-0077-0
2017-11-08 11:42:25 ----D---- C:\ProgramData\61673b52-3175-0
2017-11-08 11:42:25 ----D---- C:\ProgramData\61673b52-10c1-1
2017-11-08 11:37:33 ----D---- C:\ProgramData\803f88d0-4735-1
2017-11-08 11:37:33 ----D---- C:\ProgramData\803f88d0-0095-0
2017-11-07 18:40:06 ----D---- C:\ProgramData\61673b52-2bc7-0
2017-11-07 18:40:06 ----D---- C:\ProgramData\61673b52-1503-1
2017-11-07 18:24:02 ----D---- C:\ProgramData\803f88d0-3ae1-1
2017-11-07 18:24:02 ----D---- C:\ProgramData\803f88d0-3771-0
2017-11-07 18:08:21 ----D---- C:\ProgramData\{1beb29b0-212c-1}
2017-11-07 18:08:21 ----D---- C:\ProgramData\{0c76053f-112c-0}
2017-11-07 08:09:33 ----D---- C:\ProgramData\803f88d0-0f87-0
2017-11-07 08:09:32 ----D---- C:\ProgramData\803f88d0-5157-1
2017-11-06 07:29:29 ----D---- C:\ProgramData\803f88d0-7d91-1
2017-11-06 07:29:29 ----D---- C:\ProgramData\803f88d0-6d11-0
2017-11-05 18:24:00 ----D---- C:\ProgramData\803f88d0-6f43-0
2017-11-05 18:24:00 ----D---- C:\ProgramData\803f88d0-1eb1-1
2017-11-03 19:59:21 ----D---- C:\ProgramData\803f88d0-7ae3-1
2017-11-03 19:59:21 ----D---- C:\ProgramData\803f88d0-5b85-0
2017-11-02 18:35:10 ----D---- C:\ProgramData\61673b52-7605-1
2017-11-02 18:35:10 ----D---- C:\ProgramData\61673b52-1e77-0
2017-11-02 18:35:00 ----D---- C:\ProgramData\4cdb9ace
2017-11-02 18:34:59 ----D---- C:\ProgramData\{150FCB7A-A2A4-7CD1-7FF8-BDC8B7154083}
2017-11-02 18:34:42 ----D---- C:\ProgramData\{59f75c9c-712c-0}
2017-11-02 18:34:42 ----D---- C:\ProgramData\{0c5c4d18-312c-1}
2017-10-30 12:37:53 ----D---- C:\Program Files (x86)\VulkanRT
2017-10-30 12:37:53 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2017-10-30 12:37:53 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2017-10-30 12:37:53 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2017-10-30 12:37:53 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\system32\nvopencl.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2017-10-30 12:32:33 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFTH264.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\nvEncMFTH264.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\nvdispgenco6438800.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\nvdispco6438800.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2017-10-30 12:32:32 ----A---- C:\WINDOWS\system32\nvcuda.dll
2017-10-30 12:32:30 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2017-10-30 12:32:30 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2017-10-30 11:58:43 ----D---- C:\WINDOWS\LastGood.Tmp
2017-10-28 18:02:53 ----D---- C:\Program Files (x86)\FileASSASSIN
2017-10-28 18:01:12 ----AD---- C:\Program Files (x86)\Unlocker
2017-10-28 17:35:59 ----D---- C:\Program Files (x86)\Seznam.cz
2017-10-28 17:34:21 ----D---- C:\Users\ludovico\AppData\Roaming\Seznam.cz
2017-10-28 17:21:51 ----A---- C:\WINDOWS\system32\drivers\dtliteusbbus.sys
2017-10-28 17:21:46 ----D---- C:\Users\ludovico\AppData\Roaming\DAEMON Tools Lite
2017-10-28 17:21:32 ----D---- C:\Program Files\DAEMON Tools Lite
2017-10-28 17:19:53 ----D---- C:\Program Files (x86)\JIdcnntTvnKU2
2017-10-28 17:19:45 ----D---- C:\Program Files (x86)\zTWnHlzwjSUn
2017-10-28 17:19:43 ----D---- C:\Program Files (x86)\ZfJRwqLPhIE
2017-10-28 17:19:25 ----D---- C:\Program Files (x86)\kqEuPYMaU
2017-10-28 17:19:01 ----D---- C:\ProgramData\803f88d0-1597-0
2017-10-28 17:19:00 ----D---- C:\ProgramData\803f88d0-38a7-1
2017-10-28 17:18:54 ----AD---- C:\Program Files (x86)\FastDataX
2017-10-28 17:18:06 ----D---- C:\ProgramData\DAEMON Tools Lite
2017-10-28 17:17:00 ----D---- C:\ProgramData\Microleaves
2017-10-28 17:16:42 ----AD---- C:\Program Files (x86)\Microsoft Silverlight
2017-10-28 17:14:52 ----D---- C:\Program Files (x86)\Microleaves
2017-10-28 17:14:07 ----D---- C:\Users\ludovico\AppData\Roaming\Microleaves
2017-10-28 17:13:59 ----D---- C:\WinSys
2017-10-28 17:13:57 ----D---- C:\Applications
2017-10-28 17:13:46 ----D---- C:\Windat
2017-10-28 17:13:45 ----D---- C:\Disk
2017-10-28 17:13:45 ----AD---- C:\Program Files\LaCie Private Public
2017-10-28 17:04:55 ----D---- C:\Users\ludovico\AppData\Roaming\uTorrent
2017-10-27 17:28:26 ----D---- C:\Users\ludovico\AppData\Roaming\discord
2017-10-21 14:11:07 ----AD---- C:\Program Files\Recuva
2017-10-19 13:07:55 ----D---- C:\WINDOWS\system32\♐
2017-10-12 14:59:34 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2017-10-12 14:41:50 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-10-12 14:41:50 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-10-12 14:41:48 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-10-12 14:41:48 ----A---- C:\WINDOWS\SYSWOW64\rpchttp.dll
2017-10-12 14:41:48 ----A---- C:\WINDOWS\SYSWOW64\Robocopy.exe
2017-10-12 14:41:48 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-10-12 14:41:44 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2017-10-12 14:41:44 ----A---- C:\WINDOWS\SYSWOW64\mswstr10.dll
2017-10-12 14:41:44 ----A---- C:\WINDOWS\SYSWOW64\msjint40.dll
2017-10-12 14:41:44 ----A---- C:\WINDOWS\SYSWOW64\msexcl40.dll
2017-10-12 14:41:44 ----A---- C:\WINDOWS\SYSWOW64\mcbuilder.exe
2017-10-12 14:41:43 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-10-12 14:41:43 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-10-12 14:41:43 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2017-10-12 14:41:42 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2017-10-12 14:41:42 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2017-10-12 14:41:39 ----A---- C:\WINDOWS\SYSWOW64\cipher.exe
2017-10-12 14:41:37 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-10-12 14:41:37 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2017-10-12 14:41:37 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2017-10-12 14:41:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2017-10-12 14:41:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-10-12 14:41:36 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2017-10-12 14:41:35 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-10-12 14:41:35 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-10-12 14:41:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-10-12 14:41:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-10-12 14:41:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.dll
2017-10-12 14:41:35 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-10-12 14:41:34 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-10-12 14:41:34 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-10-12 14:41:34 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2017-10-12 14:41:34 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-10-12 14:41:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-10-12 14:41:33 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-10-12 14:41:33 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2017-10-12 14:41:33 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-10-12 14:41:32 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2017-10-12 14:41:29 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-10-12 14:41:29 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2017-10-12 14:41:29 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-10-12 14:41:28 ----A---- C:\WINDOWS\SYSWOW64\TpmCoreProvisioning.dll
2017-10-12 14:41:28 ----A---- C:\WINDOWS\SYSWOW64\smartscreenps.dll
2017-10-12 14:41:28 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-10-12 14:41:28 ----A---- C:\WINDOWS\SYSWOW64\mgmtapi.dll
2017-10-12 14:41:27 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-10-12 14:41:27 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-10-12 14:41:27 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-10-12 14:41:26 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerUI.dll
2017-10-12 14:41:26 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2017-10-12 14:41:26 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-10-12 14:41:26 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2017-10-12 14:41:26 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2017-10-12 14:41:26 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-10-12 14:41:24 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2017-10-12 14:41:20 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2017-10-12 14:41:19 ----A---- C:\WINDOWS\SYSWOW64\OneCoreUAPCommonProxyStub.dll
2017-10-12 14:41:16 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-10-12 14:41:15 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-10-12 14:41:15 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-10-12 14:41:14 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-10-12 14:41:14 ----A---- C:\WINDOWS\SYSWOW64\sspicli.dll
2017-10-12 14:41:14 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-10-12 14:41:14 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-10-12 14:41:12 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-10-12 14:41:10 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-10-12 14:41:09 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-10-12 14:41:08 ----RA---- C:\WINDOWS\SYSWOW64\icuuc.dll
2017-10-12 14:41:07 ----A---- C:\WINDOWS\SYSWOW64\t2embed.dll
2017-10-12 14:41:07 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-10-12 14:41:07 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-10-12 14:41:06 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-10-12 14:41:06 ----A---- C:\WINDOWS\SYSWOW64\BitLockerCsp.dll
2017-10-12 14:41:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-10-12 14:41:05 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-10-12 14:41:05 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-10-12 14:41:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-10-12 14:41:04 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-10-12 14:41:03 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-10-12 14:40:59 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-10-12 14:40:57 ----A---- C:\WINDOWS\SYSWOW64\tetheringclient.dll
2017-10-12 14:40:57 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-10-12 14:35:28 ----A---- C:\WINDOWS\system32\tquery.dll
2017-10-12 14:35:28 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-10-12 14:35:27 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2017-10-12 14:35:27 ----A---- C:\WINDOWS\system32\SecurityHealthService.exe
2017-10-12 14:35:24 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-10-12 14:35:16 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-10-12 14:35:16 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2017-10-12 14:34:43 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-10-12 14:34:36 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-10-12 14:34:36 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-10-12 14:34:36 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-10-12 14:34:36 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2017-10-12 14:34:36 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-10-12 14:34:34 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-10-12 14:34:34 ----A---- C:\WINDOWS\system32\Windows.Graphics.dll
2017-10-12 14:34:33 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-10-12 14:34:33 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-10-12 14:34:33 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-10-12 14:34:32 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-10-12 14:34:32 ----A---- C:\WINDOWS\system32\webio.dll
2017-10-12 14:34:31 ----A---- C:\WINDOWS\system32\wuuhosdeployment.dll
2017-10-12 14:34:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-10-12 14:34:28 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-10-12 14:34:28 ----A---- C:\WINDOWS\system32\wups.dll
2017-10-12 14:34:28 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-10-12 14:34:20 ----A---- C:\WINDOWS\system32\usoapi.dll
2017-10-12 14:34:20 ----A---- C:\WINDOWS\system32\user32.dll
2017-10-12 14:34:20 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-10-12 14:34:19 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-10-12 14:34:15 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2017-10-12 14:34:14 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-10-12 14:34:12 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-10-12 14:34:11 ----A---- C:\WINDOWS\system32\usocore.dll
2017-10-12 14:34:11 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-10-12 14:34:11 ----A---- C:\WINDOWS\system32\MusNotifyIcon.exe
2017-10-12 14:34:11 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-10-12 14:34:06 ----A---- C:\WINDOWS\system32\UserDataService.dll
2017-10-12 14:34:04 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2017-10-12 14:34:01 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2017-10-12 14:34:01 ----A---- C:\WINDOWS\system32\twinui.dll
2017-10-12 14:34:01 ----A---- C:\WINDOWS\system32\twinapi.dll
2017-10-12 14:34:01 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-10-12 14:34:00 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2017-10-12 14:34:00 ----A---- C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-10-12 14:34:00 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-10-12 14:33:58 ----A---- C:\WINDOWS\system32\TabSvc.dll
2017-10-12 14:33:58 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-10-12 14:33:57 ----A---- C:\WINDOWS\system32\mstsc.exe
2017-10-12 14:33:57 ----A---- C:\WINDOWS\system32\msctf.dll
2017-10-12 14:33:55 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2017-10-12 14:33:52 ----A---- C:\WINDOWS\system32\StartTileData.dll
2017-10-12 14:33:52 ----A---- C:\WINDOWS\system32\smartscreenps.dll
2017-10-12 14:33:52 ----A---- C:\WINDOWS\system32\mgmtapi.dll
2017-10-12 14:33:52 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2017-10-12 14:33:52 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2017-10-12 14:33:52 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-10-12 14:33:52 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2017-10-12 14:33:51 ----A---- C:\WINDOWS\system32\smartscreen.exe
2017-10-12 14:33:51 ----A---- C:\WINDOWS\system32\scksp.dll
2017-10-12 14:33:51 ----A---- C:\WINDOWS\system32\basecsp.dll
2017-10-12 14:33:50 ----A---- C:\WINDOWS\system32\shell32.dll
2017-10-12 14:33:49 ----A---- C:\WINDOWS\system32\wscsvc.dll
2017-10-12 14:33:49 ----A---- C:\WINDOWS\system32\TokenBrokerUI.dll
2017-10-12 14:33:49 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-10-12 14:33:49 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-10-12 14:33:48 ----A---- C:\WINDOWS\system32\NgcCtnr.dll
2017-10-12 14:33:48 ----A---- C:\WINDOWS\system32\msv1_0.dll
2017-10-12 14:33:48 ----A---- C:\WINDOWS\system32\manage-bde.exe
2017-10-12 14:33:48 ----A---- C:\WINDOWS\system32\fveui.dll
2017-10-12 14:33:48 ----A---- C:\WINDOWS\system32\easinvoker.exe
2017-10-12 14:33:48 ----A---- C:\WINDOWS\system32\cryptngc.dll
2017-10-12 14:33:47 ----A---- C:\WINDOWS\system32\fveapibase.dll
2017-10-12 14:33:47 ----A---- C:\WINDOWS\system32\fveapi.dll
2017-10-12 14:33:47 ----A---- C:\WINDOWS\system32\bdesvc.dll
2017-10-12 14:33:46 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-10-12 14:33:46 ----A---- C:\WINDOWS\system32\jscript.dll
2017-10-12 14:33:46 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-10-12 14:33:46 ----A---- C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2017-10-12 14:33:45 ----A---- C:\WINDOWS\system32\fvewiz.dll
2017-10-12 14:33:45 ----A---- C:\WINDOWS\system32\fvecpl.dll
2017-10-12 14:33:45 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-10-12 14:33:32 ----A---- C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-10-12 14:33:18 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2017-10-12 14:33:17 ----A---- C:\WINDOWS\system32\rpchttp.dll
2017-10-12 14:33:17 ----A---- C:\WINDOWS\system32\Robocopy.exe
2017-10-12 14:33:17 ----A---- C:\WINDOWS\system32\regsvc.dll
2017-10-12 14:33:17 ----A---- C:\WINDOWS\system32\RecoveryDrive.exe
2017-10-12 14:33:16 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-10-12 14:32:59 ----A---- C:\WINDOWS\system32\wlansec.dll
2017-10-12 14:32:59 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-10-12 14:32:58 ----A---- C:\WINDOWS\system32\oleaut32.dll
2017-10-12 14:32:57 ----A---- C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-10-12 14:32:54 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-10-12 14:32:51 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2017-10-12 14:32:51 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2017-10-12 14:32:48 ----A---- C:\WINDOWS\system32\mcbuilder.exe
2017-10-12 14:32:47 ----A---- C:\WINDOWS\system32\msftedit.dll
2017-10-12 14:32:45 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2017-10-12 14:32:44 ----A---- C:\WINDOWS\system32\BingMaps.dll
2017-10-12 14:32:38 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-10-12 14:32:38 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\sspisrv.dll
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\sspicli.dll
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\lsass.exe
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\drivers\ksecdd.sys
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-10-12 14:32:36 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-10-12 14:32:34 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-10-12 14:32:32 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-10-12 14:32:32 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2017-10-12 14:32:31 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-10-12 14:32:30 ----A---- C:\WINDOWS\system32\ServiceWorkerHost.exe
2017-10-12 14:32:30 ----A---- C:\WINDOWS\system32\msIso.dll
2017-10-12 14:32:28 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-10-12 14:32:26 ----A---- C:\WINDOWS\system32\wininet.dll
2017-10-12 14:32:24 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-10-12 14:32:14 ----A---- C:\WINDOWS\system32\iscsiexe.dll
2017-10-12 14:32:05 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-10-12 14:32:01 ----RA---- C:\WINDOWS\system32\icuuc.dll
2017-10-12 14:31:58 ----A---- C:\WINDOWS\system32\t2embed.dll
2017-10-12 14:31:58 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-10-12 14:31:58 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-10-12 14:31:57 ----A---- C:\WINDOWS\system32\resutils.dll
2017-10-12 14:31:57 ----A---- C:\WINDOWS\system32\clusapi.dll
2017-10-12 14:31:49 ----A---- C:\WINDOWS\explorer.exe
2017-10-12 14:31:48 ----A---- C:\WINDOWS\system32\wer.dll
2017-10-12 14:31:48 ----A---- C:\WINDOWS\system32\efssvc.dll
2017-10-12 14:31:48 ----A---- C:\WINDOWS\system32\efscore.dll
2017-10-12 14:31:48 ----A---- C:\WINDOWS\system32\BitLockerCsp.dll
2017-10-12 14:31:42 ----A---- C:\WINDOWS\system32\dusmsvc.dll
2017-10-12 14:31:42 ----A---- C:\WINDOWS\system32\dnsapi.dll
2017-10-12 14:31:41 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-10-12 14:31:41 ----A---- C:\WINDOWS\system32\FntCache.dll
2017-10-12 14:31:41 ----A---- C:\WINDOWS\system32\DWrite.dll
2017-10-12 14:31:40 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-10-12 14:31:40 ----A---- C:\WINDOWS\system32\quartz.dll
2017-10-12 14:31:39 ----A---- C:\WINDOWS\system32\dosvc.dll
2017-10-12 14:31:39 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2017-10-12 14:31:38 ----A---- C:\WINDOWS\system32\domgmt.dll
2017-10-12 14:31:37 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-10-12 14:31:21 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-10-12 14:31:16 ----A---- C:\WINDOWS\system32\cipher.exe
2017-10-12 14:30:48 ----A---- C:\WINDOWS\system32\eShims.dll
2017-10-12 14:30:47 ----A---- C:\WINDOWS\system32\winresume.exe
2017-10-12 14:30:46 ----A---- C:\WINDOWS\system32\winload.exe
2017-10-12 14:30:21 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-10-12 14:30:21 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-10-12 14:30:21 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-10-12 14:30:21 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-10-12 14:30:21 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2017-10-12 14:30:19 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2017-10-12 14:30:19 ----A---- C:\WINDOWS\system32\advapi32.dll
2017-10-12 14:30:00 ----A---- C:\WINDOWS\system32\daxexec.dll
2017-10-12 14:29:51 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-10-12 14:29:48 ----A---- C:\WINDOWS\system32\WindowManagement.dll
2017-10-12 14:29:48 ----A---- C:\WINDOWS\system32\UpdateAgent.dll
2017-10-12 14:29:48 ----A---- C:\WINDOWS\system32\TileDataRepository.dll
2017-10-12 14:29:48 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2017-10-12 14:29:48 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2017-10-12 14:29:45 ----A---- C:\WINDOWS\system32\hvloader.exe
2017-10-12 14:29:45 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-10-12 14:29:45 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-10-12 14:28:27 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2017-10-12 14:28:27 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2017-10-12 14:28:27 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2017-10-12 14:28:27 ----A---- C:\WINDOWS\system32\drivers\BasicRender.sys

======List of files/folders modified in the last 1 month======

2017-11-09 14:24:30 ----D---- C:\WINDOWS\Prefetch
2017-11-09 14:24:27 ----RD---- C:\Program Files
2017-11-09 14:03:18 ----D---- C:\WINDOWS\Temp
2017-11-09 13:26:00 ----D---- C:\WINDOWS\system32\sru
2017-11-09 12:48:54 ----D---- C:\WINDOWS\system32\SleepStudy
2017-11-09 12:25:13 ----D---- C:\ProgramData\NVIDIA
2017-11-09 08:51:39 ----SHD---- C:\System Volume Information
2017-11-09 08:45:32 ----D---- C:\WINDOWS\system32\config
2017-11-09 08:39:21 ----RD---- C:\WINDOWS\Microsoft.NET
2017-11-09 08:19:30 ----D---- C:\ProgramData\Jagex
2017-11-09 08:19:00 ----HD---- C:\ProgramData
2017-11-08 15:11:44 ----RD---- C:\WINDOWS\assembly
2017-11-08 15:07:59 ----D---- C:\Program Files (x86)\Steam
2017-11-08 15:06:16 ----D---- C:\WINDOWS\System32
2017-11-08 15:06:16 ----A---- C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-11-07 20:36:44 ----D---- C:\Users\ludovico\AppData\Roaming\vlc
2017-11-07 18:12:48 ----SHDC---- C:\WINDOWS\Installer
2017-11-07 18:12:48 ----SHD---- C:\Config.Msi
2017-11-07 18:12:46 ----D---- C:\WINDOWS\WinSxS
2017-11-07 18:08:13 ----D---- C:\WINDOWS\Logs
2017-11-07 08:26:56 ----D---- C:\WINDOWS\system32\Tasks
2017-11-07 08:20:14 ----D---- C:\WINDOWS\AppReadiness
2017-11-07 08:20:13 ----HD---- C:\Program Files\WindowsApps
2017-11-05 20:42:08 ----AD---- C:\Program Files (x86)\Origin
2017-11-02 19:23:26 ----D---- C:\WINDOWS\system32\catroot2
2017-11-02 10:36:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-02 10:29:36 ----D---- C:\WINDOWS\system32\drivers
2017-11-01 15:58:43 ----D---- C:\WINDOWS\system32\NDF
2017-10-30 20:18:19 ----D---- C:\WINDOWS\system32\WDI
2017-10-30 20:13:34 ----D---- C:\WINDOWS\SysWOW64
2017-10-30 20:13:34 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-10-30 20:12:12 ----D---- C:\Windows
2017-10-30 20:11:45 ----D---- C:\WINDOWS\system32\CatRoot
2017-10-30 12:38:05 ----D---- C:\WINDOWS\system32\DriverStore
2017-10-30 12:38:05 ----D---- C:\WINDOWS\INF
2017-10-30 12:37:54 ----D---- C:\Users\ludovico\AppData\Roaming\NVIDIA
2017-10-30 12:37:53 ----RD---- C:\Program Files (x86)
2017-10-30 12:36:15 ----D---- C:\Program Files\NVIDIA Corporation
2017-10-30 12:29:23 ----D---- C:\ProgramData\NVIDIA Corporation
2017-10-28 17:36:40 ----D---- C:\WINDOWS\Tasks
2017-10-28 17:19:00 ----D---- C:\WINDOWS\system32\GroupPolicy
2017-10-28 17:18:45 ----SD---- C:\Users\ludovico\AppData\Roaming\Microsoft
2017-10-28 17:17:47 ----SD---- C:\ProgramData\Microsoft
2017-10-22 16:12:22 ----D---- C:\emulator
2017-10-21 14:11:25 ----D---- C:\WINDOWS\LiveKernelReports
2017-10-18 11:07:42 ----D---- C:\WINDOWS\CbsTemp
2017-10-15 13:28:17 ----D---- C:\WINDOWS\rescache
2017-10-13 01:21:46 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-10-12 22:38:03 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.DLL
2017-10-12 22:38:03 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2017-10-12 22:38:03 ----A---- C:\WINDOWS\system32\OpenCL.DLL
2017-10-12 22:38:03 ----A---- C:\WINDOWS\system32\nvapi64.dll
2017-10-12 21:25:58 ----A---- C:\WINDOWS\NvContainerRecovery.bat
2017-10-12 20:55:22 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2017-10-12 20:55:22 ----A---- C:\WINDOWS\system32\nvcpl.dll
2017-10-12 20:55:18 ----A---- C:\WINDOWS\SYSWOW64\oemdspif.dll
2017-10-12 20:55:18 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2017-10-12 20:55:18 ----A---- C:\WINDOWS\system32\nvshext.dll
2017-10-12 20:55:18 ----A---- C:\WINDOWS\system32\nvmctray.dll
2017-10-12 20:55:18 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2017-10-12 20:55:18 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2017-10-12 19:05:26 ----D---- C:\WINDOWS\SYSWOW64\wbem
2017-10-12 19:05:26 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-10-12 19:05:26 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2017-10-12 19:05:26 ----D---- C:\WINDOWS\system32\wbem
2017-10-12 19:05:26 ----D---- C:\WINDOWS\system32\en-US
2017-10-12 19:05:26 ----D---- C:\WINDOWS\system32\en-GB
2017-10-12 19:05:26 ----D---- C:\WINDOWS\system32\Boot
2017-10-12 19:05:25 ----D---- C:\WINDOWS\ShellExperiences
2017-10-12 19:05:25 ----D---- C:\WINDOWS\Provisioning
2017-10-12 19:04:57 ----A---- C:\WINDOWS\SYSWOW64\msclmd.dll
2017-10-12 19:04:57 ----A---- C:\WINDOWS\system32\msclmd.dll
2017-10-12 15:06:06 ----D---- C:\WINDOWS\system32\MRT
2017-10-12 14:59:43 ----D---- C:\WINDOWS\debug
2017-10-12 14:59:29 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-10-11 02:05:52 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2017-10-11 02:05:52 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2017-10-11 02:05:51 ----A---- C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-10-11 02:05:47 ----A---- C:\WINDOWS\SYSWOW64\nvaudcap32v.dll
2017-10-11 02:05:47 ----A---- C:\WINDOWS\system32\nvaudcap64v.dll
2017-10-11 00:26:14 ----A---- C:\WINDOWS\NvTelemetryContainerRecovery.bat

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2014-06-25 670056]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2017-03-18 49568]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2017-03-18 54272]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-03-18 8192]
R1 MpKsld9d9a73b;MpKsld9d9a73b; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BFF9736C-054D-486D-B9C6-B010161D0D15}\MpKsld9d9a73b.sys [2017-11-09 58120]
R1 MpKsle9337fe6;MpKsle9337fe6; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D537B9B5-4080-4B31-BB80-FB9164337C17}\MpKsle9337fe6.sys [2017-11-02 58120]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2017-03-18 14336]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2017-03-18 50688]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2017-03-18 79872]
R3 ACPIVPC;@oem70.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2014-12-15 35064]
R3 bcbtums;@oem41.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-03-27 173312]
R3 BCM43XX;@oem116.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-11-20 7504560]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\system32\DRIVERS\BTHUSB.sys [2017-03-18 85504]
R3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2017-03-18 53664]
R3 CnxtHdAudService;@oem22.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2015-05-19 1543912]
R3 dtlitescsibus;@oem25.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2016-01-20 30264]
R3 dtliteusbbus;@oem51.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [2017-10-28 47672]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2017-05-26 7970232]
R3 MEIx64;@oem117.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_fe2829cc8f7bc487\nvlddmkm.sys [2017-10-13 16924088]
R3 nvvad_WaveExtensible;@oem69.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2017-10-11 50624]
R3 nvvhci;@oem27.inf,%ServiceDesc%;NVVHCI Enumerator Service; C:\WINDOWS\System32\drivers\nvvhci.sys [2017-10-12 57792]
R3 rt640x64;@oem119.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-07-22 886528]
R3 RTSUER;@oem42.inf,%RtsUER%;Realtek USB Card Reader - UER; C:\WINDOWS\system32\Drivers\RtsUer.sys [2015-07-03 410880]
R3 rtsuvc;@oem87.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2015-06-16 3068160]
R3 SynTP;@oem128.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2016-06-01 642168]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-03-18 123808]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-03-18 103328]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-03-18 64416]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2017-03-18 58784]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2017-03-18 61848]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2017-03-18 91040]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2017-03-18 36760]
S1 hdaceafi;hdaceafi; \??\C:\WINDOWS\system32\drivers\hdaceafi.sys []
S1 jizbkmbk;jizbkmbk; \??\C:\WINDOWS\system32\drivers\jizbkmbk.sys []
S1 jpvmzmxa;jpvmzmxa; \??\C:\WINDOWS\system32\drivers\jpvmzmxa.sys []
S1 kkyxttfk;kkyxttfk; \??\C:\WINDOWS\system32\drivers\kkyxttfk.sys []
S2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2017-03-18 12288]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-03-18 20480]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2017-03-18 17920]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\system32\DRIVERS\BTHport.sys [2017-09-27 982016]
S3 btwampfl;@oem41.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-03-27 188160]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-09-27 39424]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2017-03-18 122880]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-03-18 347032]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-03-18 2104224]
S3 dc3d;MS Hardware Device Detection Driver (USB); C:\WINDOWS\System32\drivers\dc3d.sys [2015-12-09 95024]
S3 dg_ssudbus;@oem15.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-03-18 21504]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-03-18 51104]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2017-03-18 74648]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2017-03-18 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2017-03-18 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-03-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-03-18 85504]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-03-18 165376]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-03-18 168448]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2017-03-18 526240]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-03-18 36864]
S3 IntcDAud;@oem11.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2016-05-12 481768]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2017-03-18 120320]
S3 KMDFVirtualKbd;Lenovo Virtual Keyboard Device; C:\WINDOWS\System32\drivers\KMDFVirtualKbd.sys [2014-08-05 22264]
S3 KMDFVirtualMouse;Lenovo Virtual Mouse Device; C:\WINDOWS\System32\drivers\KMDFVirtualMouse.sys [2014-08-05 21240]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2017-03-18 405408]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2017-03-18 51104]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-03-18 842656]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2017-03-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2017-03-18 122368]
S3 nvdimmn;@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver; C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-03-18 80896]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-10-11 30144]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver; C:\WINDOWS\System32\drivers\nvstusb.sys [2016-09-12 486976]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2017-03-18 101376]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2017-03-18 936864]
S3 SDFRd;@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector; C:\WINDOWS\System32\drivers\SDFRd.sys [2017-03-18 31128]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter; C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-03-19 40352]
S3 ss_conn_usb_driver;SAMSUNG Mobile USB Connectivity Device Driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [2014-01-22 26368]
S3 ssudcdf;SAMSUNG Mobile Mode Changer Device; C:\WINDOWS\System32\drivers\ssudcdf.sys [2014-01-22 36608]
S3 ssuddmgr;SAMSUNG Mobile USB Device Management Serial Port(DEVGURU Ver.); C:\WINDOWS\System32\drivers\ssuddmgr.sys [2014-01-22 206080]
S3 ssudmdm;@oem39.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.); C:\WINDOWS\System32\drivers\ssudobex.sys [2014-01-22 206080]
S3 ssudqcfilter;SAMSUNG Mobile USB QCRMNET Filter Driver; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [2015-12-08 57648]
S3 ssudrmnet;SAMSUNG Mobile USB RMNET Drivers; C:\WINDOWS\System32\drivers\ssudrmnet.sys [2014-01-22 70400]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\System32\drivers\ssudserd.sys [2014-01-22 206080]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2014-07-23 172344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-07-19 83032]
R2 BcmBtRSupport;@oem41.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-03-27 2251992]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 CDPUserSvc_74e253e;Connected Devices Platform User Service_74e253e; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 GenieTimelineService;Genie Timeline Service; C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe [2012-09-16 662104]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2017-05-26 373680]
R2 ImControllerService;@oem47.inf,%ImcSvcDisplayName%;System Interface Foundation Service; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2017-09-08 68416]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11 518080]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-10-12 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-10-11 460736]
R2 OneSyncSvc_74e253e;Sync Host_74e253e; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2017-11-02 3002728]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2017-08-22 76152]
R2 SecurityHealthService;@%systemroot%\system32\SecurityHealthAgent.dll,-1002; C:\WINDOWS\system32\SecurityHealthService.exe [2017-09-30 336320]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2016-06-01 255608]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2017-02-10 43696]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 PimIndexMaintenanceSvc_74e253e;Contact Data_74e253e; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-28 153752]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2017-11-07 1548808]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2017-05-26 301488]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevicesFlowUserSvc_74e253e;DevicesFlow_74e253e; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-03-18 86528]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2017-08-14 2291904]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-28 153752]
S3 HnGSteamService;Heroes & Generals Steam Service; C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe [2017-11-07 777512]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService_74e253e;MessagingService_74e253e; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11 518080]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2017-11-02 2123104]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 SEMgrSvc;@%SystemRoot%\System32\SEMgrSvc.dll,-1001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2017-03-18 1284608]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 spectrum;@%systemroot%\system32\spectrum.exe,-101; C:\WINDOWS\system32\spectrum.exe [2017-03-18 891904]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-10-31 1641248]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]

-----------------EOF-----------------

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 09 lis 2017 15:41
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 23 lis 2017 08:12
od Sergeii
# AdwCleaner 7.0.4.0 - Logfile created on Wed Nov 22 10:31:37 2017
# Updated on 2017/27/10 by Malwarebytes
# Running on Windows 10 Home (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:\Users\ludovico\AppData\Local\AdvinstAnalytics
Deleted: C:\Users\All Users\Documents\XMUpdate
Deleted: C:\Users\Public\Documents\XMUpdate
Deleted: C:\Program Files (x86)\FastDataX
Deleted: C:\Users\ludovico\AppData\Local\AdService
Deleted: C:\Program Files (x86)\zTWnHlzwjSUn
Deleted: C:\ProgramData\Microleaves
Deleted: C:\ProgramData\Application Data\Microleaves
Deleted: C:\Program Files (x86)\Microleaves
Deleted: C:\Users\All Users\Microleaves
Deleted: C:\Users\ludovico\AppData\Roaming\Microleaves
Deleted: C:\Program Files (x86)\kqEuPYMaU
Deleted: C:\Program Files (x86)\ZfJRwqLPhIE
Deleted: C:\Program Files (x86)\JIdcnntTvnKU2
Deleted: C:\\Users\Public\Documents\XMUpdate
Deleted: C:\ProgramData\4cdb9ace
Deleted: C:\ProgramData\61673b52-0671-0
Deleted: C:\ProgramData\61673b52-09c3-0
Deleted: C:\ProgramData\61673b52-0e13-1
Deleted: C:\ProgramData\61673b52-10c1-1
Deleted: C:\ProgramData\61673b52-1503-1
Deleted: C:\ProgramData\61673b52-1895-0
Deleted: C:\ProgramData\61673b52-1e77-0
Deleted: C:\ProgramData\61673b52-2bc7-0
Deleted: C:\ProgramData\61673b52-2ff5-1
Deleted: C:\ProgramData\61673b52-3175-0
Deleted: C:\ProgramData\61673b52-3ed1-1
Deleted: C:\ProgramData\61673b52-5a05-0
Deleted: C:\ProgramData\61673b52-6185-1
Deleted: C:\ProgramData\61673b52-6f57-0
Deleted: C:\ProgramData\61673b52-7605-1
Deleted: C:\ProgramData\61673b52-78c1-0
Deleted: C:\ProgramData\61673b52-7e07-1
Deleted: C:\ProgramData\803f88d0-0077-0
Deleted: C:\ProgramData\803f88d0-0095-0
Deleted: C:\ProgramData\803f88d0-0f87-0
Deleted: C:\ProgramData\803f88d0-11c5-1
Deleted: C:\ProgramData\803f88d0-1597-0
Deleted: C:\ProgramData\803f88d0-1cf5-0
Deleted: C:\ProgramData\803f88d0-1eb1-1
Deleted: C:\ProgramData\803f88d0-3771-0
Deleted: C:\ProgramData\803f88d0-38a7-1
Deleted: C:\ProgramData\803f88d0-3ae1-1
Deleted: C:\ProgramData\803f88d0-3ed3-1
Deleted: C:\ProgramData\803f88d0-4041-0
Deleted: C:\ProgramData\803f88d0-4735-1
Deleted: C:\ProgramData\803f88d0-5157-1
Deleted: C:\ProgramData\803f88d0-5b85-0
Deleted: C:\ProgramData\803f88d0-6cd3-1
Deleted: C:\ProgramData\803f88d0-6d11-0
Deleted: C:\ProgramData\803f88d0-6f43-0
Deleted: C:\ProgramData\803f88d0-7ae3-1
Deleted: C:\ProgramData\803f88d0-7d91-1
Deleted: C:\ProgramData\{0c5c4d18-312c-1}
Deleted: C:\ProgramData\{0c76053f-112c-0}
Deleted: C:\ProgramData\{1beb29b0-212c-1}
Deleted: C:\ProgramData\{59f75c9c-712c-0}


***** [ Files ] *****

Deleted: C:\Users\ludovico\appdata\local\installationconfiguration.xml
Deleted: C:\Windows\SysNative\drivers\wfcre.sys
Deleted: C:\Users\ludovico\AppData\Local\PO.DB


***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted: Online Application V2G1
Deleted: Online Application V2G3
Deleted: Online Application V2G2
Deleted: LaCieS
Deleted: ShadowsocksS
Deleted: zjwPaeaadZaNwF
Deleted: PjDfytumxbayONn2
Deleted: PjDfytumxbayONn
Deleted: Updater_Online_Application
Deleted: Updater_Online_Application


***** [ Registry ] *****

Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{59A09B2C-E8FD-4756-ADEA-1436E9F8A74E}_is1
Deleted: [Key] - HKU\S-1-5-21-2449969739-3869695409-109372524-1001\Software\FastDataX
Deleted: [Key] - HKCU\Software\FastDataX
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|AdsServiceGroup
Deleted: [Key] - HKLM\SOFTWARE\Microleaves
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}
Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
Deleted: [Key] - HKU\S-1-5-21-2449969739-3869695409-109372524-1001\Software\SetupCompany
Deleted: [Key] - HKCU\Software\SetupCompany
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost|AdsServiceGroup
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

SearchProvider deleted: Ask Search - ask search


*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [6470 B] - [2017/11/22 10:29:55]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 23 lis 2017 18:35
od Rudy

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 28 lis 2017 08:18
od Sergeii
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-11-2017
Ran by ludovico (administrator) on TABULA-RASA (24-11-2017 13:16:45)
Running from C:\Users\ludovico\Downloads
Loaded Profiles: ludovico (Available Profiles: ludovico)
Platform: Windows 10 Home Version 1703 15063.726 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(SecureMix LLC) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimeLineAgent.exe
(SecureMix LLC) C:\Program Files (x86)\GlassWire\GWIdlMon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo(beijing) Limited) C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11710.1001.27.0_x64__8wekyb3d8bbwe\WinStore.App.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.17085.22311.0_x64__8wekyb3d8bbwe\Music.UI.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1709.2703.0_x64__8wekyb3d8bbwe\Calculator.exe
() C:\ProgramData\{150FCB7A-A2A4-7CD1-7FF8-BDC8B7154083}\CD523F8D-7AF9-8826-EC9E-7B181F93E8A8.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17092.13511.0_x64__8wekyb3d8bbwe\Video.UI.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39091.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE
(Jagex Ltd.) C:\Program Files\Jagex\RuneScape Launcher\RuneScape.exe
(Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe
(Jagex Ltd.) C:\ProgramData\Jagex\launcher\rs2client.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

"Path" (C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\ -> C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;%SystemRoot%\System32\WindowsPowerShell\v1.0;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SystemRoot%\System32\WindowsPowerShell\v1.0;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\) <==== Repaired successfully
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5060864 2015-06-16] (Realtek semiconductor)
HKLM\...\Run: [LenovoUtility] => C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [911272 2017-07-27] (Lenovo(beijing) Limited)
HKLM\...\Run: [SERVICE] => [X]
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9105112 2016-11-15] (Piriform Ltd)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3102496 2017-10-31] (Valve Corporation)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [RuneApps Alt1] => C:\Users\ludovico\AppData\Local\Alt1Toolkit\app-1.4.5\Runeapps.Alt1.exe [1521664 2017-07-27] (RuneApps)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [Bloody2] => C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe [17696768 2017-10-13] ()
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [Discord] => C:\Users\ludovico\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4836032 2017-08-14] (Disc Soft Ltd)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\Run: [GlassWire] => C:\Program Files (x86)\GlassWire\glasswire.exe [5800400 2017-11-16] (SecureMix LLC)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\MountPoints2: {9d9adefa-49c9-11e6-8278-0071cca142f0} - "F:\Autorun.exe"
Startup: C:\Users\ludovico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP DeskJet 3630 series.lnk [2017-11-22]
ShortcutTarget: Monitor Ink Alerts - HP DeskJet 3630 series.lnk -> C:\Program Files\HP\HP DeskJet 3630 series\Bin\HPStatusBL.dll (Hewlett-Packard Development Company, LP)
GroupPolicy: Restriction - Chrome <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{03244fb4-42a0-424d-a548-8341a1a432ed}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{03244fb4-42a0-424d-a548-8341a1a432ed}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{5a254169-dcc9-4854-9e1d-0db0029c3462}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{5a254169-dcc9-4854-9e1d-0db0029c3462}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{78974a5b-a40d-48e4-93c1-6181a62e78b3}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{78974a5b-a40d-48e4-93c1-6181a62e78b3}: [DhcpNameServer] 82.163.143.176
Tcpip\..\Interfaces\{8c1740e1-3778-4e7e-865d-c779c99c971a}: [NameServer] 82.163.143.176 82.163.142.178
Tcpip\..\Interfaces\{8c1740e1-3778-4e7e-865d-c779c99c971a}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28] (Oracle Corporation)

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-28] (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Profile: C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default [2017-11-24]
CHR Extension: (Slides) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-28]
CHR Extension: (YouTube) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-28]
CHR Extension: (Adblock Plus) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-27]
CHR Extension: (Full Page Screen Capture) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2017-10-21]
CHR Extension: (Sheets) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Google Docs Offline) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-30]
CHR Extension: (Black red shards) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpjlkkaalgfbbegfnjoclhfidancjpch [2017-05-27]
CHR Extension: (Adblocker for Youtube™) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\knmnopfmccchnnfdoiddbihbcboeedll [2017-10-28]
CHR Extension: (Ghostery) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-10-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-25]
CHR Extension: (Gmail) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-28]
CHR Extension: (Chrome Media Router) - C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-27]
CHR Profile: C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\System Profile [2017-11-24]
CHR HKU\S-1-5-21-2449969739-3869695409-109372524-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2449969739-3869695409-109372524-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olfeabkoenfaoljndfecamgilllcpiak] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 BcmBtRSupport; C:\WINDOWS\system32\BtwRSupportService.exe [2251992 2015-03-27] (Broadcom Corporation.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2017-11-12] ()
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2291904 2017-08-14] (Disc Soft Ltd)
R2 GenieTimelineService; C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe [662104 2012-09-16] (Genie9)
R2 GlassWire; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [4459984 2017-11-16] (SecureMix LLC)
S3 HnGSteamService; C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe [777512 2017-11-24] (Reto-Moto ApS)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373680 2017-05-26] (Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [68416 2017-09-08] (Lenovo Group Limited)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-11-14] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-10-11] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2123104 2017-11-02] (Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3002728 2017-11-02] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2017-08-22] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [255608 2016-06-01] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-11] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 bcbtums; C:\WINDOWS\system32\drivers\bcbtums.sys [173312 2015-03-27] (Broadcom Corporation.)
R3 BCM43XX; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [7504560 2013-11-20] (Broadcom Corporation)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-01-20] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2017-10-28] (Disc Soft Ltd)
R1 gwdrv; C:\WINDOWS\system32\DRIVERS\gwdrv.sys [33152 2015-05-29] (SecureMix LLC)
S3 KMDFVirtualKbd; C:\WINDOWS\System32\drivers\KMDFVirtualKbd.sys [22264 2014-08-05] ()
S3 KMDFVirtualMouse; C:\WINDOWS\System32\drivers\KMDFVirtualMouse.sys [21240 2014-08-05] ()
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
R1 MpKsl6f3504c3; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{786CF0C0-3B26-46D9-AB73-482BDACD5D76}\MpKsl6f3504c3.sys [58120 2017-11-23] (Microsoft Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_982b5ed5f18523b0\nvlddmkm.sys [16989296 2017-11-15] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-11] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57976 2017-10-27] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [57648 2015-12-08] (QUALCOMM Incorporated)
S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [70400 2014-01-22] (DEVGURU Co., LTD.)
S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [26368 2014-01-22] (DEVGURU Co., LTD.)
R1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-28] (Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [205952 2017-04-28] (Oracle Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
S1 hdaceafi; \??\C:\WINDOWS\system32\drivers\hdaceafi.sys [X]
S1 jizbkmbk; \??\C:\WINDOWS\system32\drivers\jizbkmbk.sys [X]
S1 jpvmzmxa; \??\C:\WINDOWS\system32\drivers\jpvmzmxa.sys [X]
S1 kkyxttfk; \??\C:\WINDOWS\system32\drivers\kkyxttfk.sys [X]
S1 tiexfiea; \??\C:\WINDOWS\system32\drivers\tiexfiea.sys [X]
S1 uiwblmyk; \??\C:\WINDOWS\system32\drivers\uiwblmyk.sys [X]
S1 vfjqfdkc; \??\C:\WINDOWS\system32\drivers\vfjqfdkc.sys [X]
S1 vrdmkfli; \??\C:\WINDOWS\system32\drivers\vrdmkfli.sys [X]
S1 wfcre; system32\drivers\wfcre.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-24 13:16 - 2017-11-24 13:18 - 000023007 _____ C:\Users\ludovico\Downloads\FRST.txt
2017-11-24 13:16 - 2017-11-24 13:16 - 002393088 _____ (Farbar) C:\Users\ludovico\Downloads\FRST64.exe
2017-11-24 13:16 - 2017-11-24 13:16 - 000000000 ____D C:\FRST
2017-11-24 13:10 - 2017-11-24 13:10 - 000000165 ____H C:\Users\ludovico\Downloads\~$OA artikly - Price list.xlsx
2017-11-22 14:33 - 2017-11-22 14:33 - 000006470 _____ C:\Users\ludovico\Desktop\AdwCleaner[S0].txt
2017-11-22 11:46 - 2017-11-22 11:46 - 000000000 ____D C:\Users\ludovico\AppData\Local\GlassWire
2017-11-22 11:45 - 2017-11-22 11:45 - 000001981 _____ C:\Users\Public\Desktop\GlassWire.lnk
2017-11-22 11:45 - 2017-11-22 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GlassWire
2017-11-22 11:44 - 2017-11-22 11:45 - 000000000 ____D C:\Program Files (x86)\GlassWire
2017-11-22 11:44 - 2017-11-22 11:44 - 000000000 ____D C:\ProgramData\GlassWire
2017-11-22 11:44 - 2015-05-29 05:30 - 000008392 _____ C:\WINDOWS\system32\Drivers\gwdrv.cat
2017-11-22 11:44 - 2015-05-29 05:15 - 000033152 _____ (SecureMix LLC) C:\WINDOWS\system32\Drivers\gwdrv.sys
2017-11-22 11:31 - 2017-11-22 11:31 - 000005421 _____ C:\Users\ludovico\Desktop\AdwCleaner[C0].txt
2017-11-22 11:28 - 2017-11-22 11:29 - 030756192 _____ (SecureMix LLC) C:\Users\ludovico\Downloads\glasswire-free-firewall_1.2.120.exe
2017-11-22 11:27 - 2017-11-22 18:45 - 000000000 ____D C:\AdwCleaner
2017-11-22 11:26 - 2017-11-22 11:27 - 008261584 _____ (Malwarebytes) C:\Users\ludovico\Downloads\adwcleaner_7.0.4.0.exe
2017-11-20 11:41 - 2017-11-20 11:41 - 001996130 _____ C:\Users\ludovico\Downloads\SartoriTotalitarianismNB!!.pdf
2017-11-20 11:36 - 2017-11-20 11:36 - 003894033 _____ C:\Users\ludovico\Downloads\Friedrich_-_Brzezinski.pdf
2017-11-18 14:07 - 2017-11-18 14:07 - 000000000 ____D C:\Users\ludovico\AppData\Local\ElevatedDiagnostics
2017-11-18 12:54 - 2017-11-18 13:35 - 725141504 _____ C:\Users\ludovico\Desktop\Massage - Tutorial, Guide, Naked, Erotic, Intim - en - Female Orgasm Mastery - The Art of creating (squirting) Orgasms.avi
2017-11-17 12:25 - 2017-11-17 12:25 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-11-17 12:25 - 2017-09-14 00:20 - 000798008 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-11-17 12:25 - 2017-09-14 00:20 - 000490296 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-11-17 12:25 - 2017-09-14 00:19 - 000927544 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-11-17 12:25 - 2017-09-14 00:19 - 000591160 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-11-17 12:18 - 2017-11-14 23:48 - 040237504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 036239480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 035156600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 029272000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 023264864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 019038976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 013865256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 013255032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 011780376 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 010883928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 004201592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 003614328 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 001989056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438831.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 001673664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438831.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 001321264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 001135280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 001099712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 001038680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 001031288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 000980928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 000932288 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 000885496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 000794576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 000634224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 000615544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-11-17 12:18 - 2017-11-14 23:48 - 000505976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-11-17 11:05 - 2017-11-02 06:16 - 008319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-11-17 11:05 - 2017-11-02 06:16 - 002398696 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-11-17 11:05 - 2017-11-02 06:16 - 002327448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-11-17 11:05 - 2017-11-02 06:15 - 001239448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-11-17 11:05 - 2017-11-02 06:13 - 000546712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-11-17 11:05 - 2017-11-02 06:13 - 000212888 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-11-17 11:05 - 2017-11-02 06:13 - 000095640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2017-11-17 11:05 - 2017-11-02 06:12 - 000727336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-11-17 11:05 - 2017-11-02 06:12 - 000654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-11-17 11:05 - 2017-11-02 06:12 - 000412752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2017-11-17 11:05 - 2017-11-02 06:12 - 000319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2017-11-17 11:05 - 2017-11-02 06:12 - 000144248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2017-11-17 11:05 - 2017-11-02 06:10 - 006557520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-11-17 11:05 - 2017-11-02 06:05 - 000187800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2017-11-17 11:05 - 2017-11-02 06:04 - 001292360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-11-17 11:05 - 2017-11-02 06:03 - 000223640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-11-17 11:05 - 2017-11-02 05:49 - 001838848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-11-17 11:05 - 2017-11-02 05:45 - 000703056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-11-17 11:05 - 2017-11-02 05:45 - 000613136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-11-17 11:05 - 2017-11-02 05:45 - 000362144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2017-11-17 11:05 - 2017-11-02 05:45 - 000354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-11-17 11:05 - 2017-11-02 05:45 - 000283544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2017-11-17 11:05 - 2017-11-02 05:45 - 000172952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2017-11-17 11:05 - 2017-11-02 05:45 - 000133896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2017-11-17 11:05 - 2017-11-02 05:44 - 023680000 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-11-17 11:05 - 2017-11-02 05:44 - 005808640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-11-17 11:05 - 2017-11-02 05:44 - 000519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-11-17 11:05 - 2017-11-02 05:43 - 020372896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-11-17 11:05 - 2017-11-02 05:36 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-11-17 11:05 - 2017-11-02 05:35 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2017-11-17 11:05 - 2017-11-02 05:35 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-11-17 11:05 - 2017-11-02 05:34 - 012803072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-11-17 11:05 - 2017-11-02 05:34 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-11-17 11:05 - 2017-11-02 05:34 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-11-17 11:05 - 2017-11-02 05:34 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-11-17 11:05 - 2017-11-02 05:34 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2017-11-17 11:05 - 2017-11-02 05:34 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2017-11-17 11:05 - 2017-11-02 05:32 - 008213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-11-17 11:05 - 2017-11-02 05:31 - 020512256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-11-17 11:05 - 2017-11-02 05:30 - 013381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-11-17 11:05 - 2017-11-02 05:30 - 002953216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-11-17 11:05 - 2017-11-02 05:30 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2017-11-17 11:05 - 2017-11-02 05:30 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-11-17 11:05 - 2017-11-02 05:30 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-11-17 11:05 - 2017-11-02 05:30 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2017-11-17 11:05 - 2017-11-02 05:30 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2017-11-17 11:05 - 2017-11-02 05:29 - 019338240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-11-17 11:05 - 2017-11-02 05:29 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-11-17 11:05 - 2017-11-02 05:29 - 000752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-11-17 11:05 - 2017-11-02 05:29 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-11-17 11:05 - 2017-11-02 05:28 - 023684096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-11-17 11:05 - 2017-11-02 05:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-11-17 11:05 - 2017-11-02 05:27 - 002078720 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-11-17 11:05 - 2017-11-02 05:27 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2017-11-17 11:05 - 2017-11-02 05:27 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-11-17 11:05 - 2017-11-02 05:27 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2017-11-17 11:05 - 2017-11-02 05:27 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertPKICmdlet.dll
2017-11-17 11:05 - 2017-11-02 05:26 - 008197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-11-17 11:05 - 2017-11-02 05:26 - 005963776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-11-17 11:05 - 2017-11-02 05:26 - 002671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-11-17 11:05 - 2017-11-02 05:26 - 001937408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2017-11-17 11:05 - 2017-11-02 05:26 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-11-17 11:05 - 2017-11-02 05:26 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-11-17 11:05 - 2017-11-02 05:26 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2017-11-17 11:05 - 2017-11-02 05:25 - 012227072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-11-17 11:05 - 2017-11-02 05:25 - 011888128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-11-17 11:05 - 2017-11-02 05:25 - 004727808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-11-17 11:05 - 2017-11-02 05:25 - 003377664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-11-17 11:05 - 2017-11-02 05:25 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2017-11-17 11:05 - 2017-11-02 05:25 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-11-17 11:05 - 2017-11-02 05:25 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-11-17 11:05 - 2017-11-02 05:24 - 007598080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-11-17 11:05 - 2017-11-02 05:24 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-11-17 11:05 - 2017-11-02 05:24 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-11-17 11:05 - 2017-11-02 05:24 - 000444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2017-11-17 11:05 - 2017-11-02 05:24 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-11-17 11:05 - 2017-11-02 05:23 - 002516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-11-17 11:05 - 2017-11-02 05:23 - 000680960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2017-11-17 11:05 - 2017-11-02 05:23 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-11-17 11:05 - 2017-11-02 05:23 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2017-11-17 11:05 - 2017-11-02 05:23 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2017-11-17 11:05 - 2017-11-02 05:22 - 006254080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-11-17 11:05 - 2017-11-02 05:22 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-11-17 11:05 - 2017-11-02 05:22 - 002009600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-11-17 11:05 - 2017-11-02 05:22 - 001884160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2017-11-17 11:05 - 2017-11-02 05:22 - 001494528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2017-11-17 11:05 - 2017-11-02 05:21 - 004417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-11-17 11:05 - 2017-11-02 05:21 - 003653120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-11-17 11:05 - 2017-11-02 05:21 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-11-17 11:05 - 2017-11-02 05:21 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-11-17 11:05 - 2017-10-25 08:40 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-11-17 11:05 - 2017-10-15 16:09 - 002259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-11-17 11:05 - 2017-10-15 16:03 - 006765728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-11-17 11:05 - 2017-10-15 16:01 - 000583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-11-17 11:05 - 2017-10-15 15:53 - 002969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-11-17 11:05 - 2017-10-15 15:53 - 000387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-11-17 11:05 - 2017-10-15 15:49 - 000094616 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-11-17 11:05 - 2017-10-15 15:49 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-11-17 11:05 - 2017-10-15 15:45 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-11-17 11:05 - 2017-10-15 15:45 - 001248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-11-17 11:05 - 2017-10-15 15:44 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-11-17 11:05 - 2017-10-15 15:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-11-17 11:05 - 2017-10-15 15:42 - 005225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-11-17 11:05 - 2017-10-15 15:42 - 003667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-11-17 11:05 - 2017-10-15 15:41 - 004559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-11-17 11:05 - 2017-10-15 15:41 - 001019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-11-17 11:05 - 2017-10-15 15:38 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-11-17 11:05 - 2017-10-15 15:14 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SEMgrPS.dll
2017-11-17 11:05 - 2017-10-15 15:13 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-11-17 11:05 - 2017-10-15 15:10 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-11-17 11:05 - 2017-10-15 15:05 - 004396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-11-17 11:05 - 2017-10-15 15:04 - 005557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-11-17 11:04 - 2017-11-02 06:21 - 001578904 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-11-17 11:04 - 2017-11-02 06:21 - 000678808 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-11-17 11:04 - 2017-11-02 06:21 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-11-17 11:04 - 2017-11-02 06:21 - 000379288 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-11-17 11:04 - 2017-11-02 06:21 - 000190360 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-11-17 11:04 - 2017-11-02 06:21 - 000136088 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-11-17 11:04 - 2017-11-02 06:20 - 002032536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-11-17 11:04 - 2017-11-02 06:20 - 001144728 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-11-17 11:04 - 2017-11-02 06:20 - 001015704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-11-17 11:04 - 2017-11-02 06:20 - 000965016 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-11-17 11:04 - 2017-11-02 06:20 - 000821656 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-11-17 11:04 - 2017-11-02 06:20 - 000613784 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-11-17 11:04 - 2017-11-02 06:20 - 000543640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-11-17 11:04 - 2017-11-02 06:20 - 000484248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-11-17 11:04 - 2017-11-02 06:20 - 000469568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2017-11-17 11:04 - 2017-11-02 06:20 - 000259992 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-11-17 11:04 - 2017-11-02 06:20 - 000034712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-11-17 11:04 - 2017-11-02 06:15 - 000503704 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2017-11-17 11:04 - 2017-11-02 06:14 - 000667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-11-17 11:04 - 2017-11-02 06:14 - 000067992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2017-11-17 11:04 - 2017-11-02 06:13 - 005477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-11-17 11:04 - 2017-11-02 06:13 - 002443672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-11-17 11:04 - 2017-11-02 06:13 - 001345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-11-17 11:04 - 2017-11-02 06:12 - 000714648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2017-11-17 11:04 - 2017-11-02 06:12 - 000643192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-11-17 11:04 - 2017-11-02 06:12 - 000430848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2017-11-17 11:04 - 2017-11-02 06:12 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2017-11-17 11:04 - 2017-11-02 06:12 - 000026472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2017-11-17 11:04 - 2017-11-02 06:11 - 021353200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-11-17 11:04 - 2017-11-02 06:05 - 000871408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-11-17 11:04 - 2017-11-02 05:37 - 003668992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-11-17 11:04 - 2017-11-02 05:37 - 001278976 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-11-17 11:04 - 2017-11-02 05:37 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-11-17 11:04 - 2017-11-02 05:37 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2017-11-17 11:04 - 2017-11-02 05:37 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2017-11-17 11:04 - 2017-11-02 05:36 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2017-11-17 11:04 - 2017-11-02 05:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-11-17 11:04 - 2017-11-02 05:35 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2017-11-17 11:04 - 2017-11-02 05:35 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-11-17 11:04 - 2017-11-02 05:34 - 000438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2017-11-17 11:04 - 2017-11-02 05:34 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageLiveTileTask.exe
2017-11-17 11:04 - 2017-11-02 05:34 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2017-11-17 11:04 - 2017-11-02 05:33 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-11-17 11:04 - 2017-11-02 05:33 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageHandlers.dll
2017-11-17 11:04 - 2017-11-02 05:33 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2017-11-17 11:04 - 2017-11-02 05:33 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-11-17 11:04 - 2017-11-02 05:33 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertPKICmdlet.dll
2017-11-17 11:04 - 2017-11-02 05:32 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2017-11-17 11:04 - 2017-11-02 05:32 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll
2017-11-17 11:04 - 2017-11-02 05:31 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-11-17 11:04 - 2017-11-02 05:31 - 000411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2017-11-17 11:04 - 2017-11-02 05:31 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2017-11-17 11:04 - 2017-11-02 05:30 - 007339008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-11-17 11:04 - 2017-11-02 05:30 - 000719872 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2017-11-17 11:04 - 2017-11-02 05:30 - 000635392 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-11-17 11:04 - 2017-11-02 05:30 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-11-17 11:04 - 2017-11-02 05:30 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-11-17 11:04 - 2017-11-02 05:29 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-11-17 11:04 - 2017-11-02 05:29 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-11-17 11:04 - 2017-11-02 05:28 - 001468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-11-17 11:04 - 2017-11-02 05:28 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-11-17 11:04 - 2017-11-02 05:28 - 000799744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2017-11-17 11:04 - 2017-11-02 05:28 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2017-11-17 11:04 - 2017-11-02 05:27 - 000565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2017-11-17 11:04 - 2017-11-02 05:27 - 000537600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2017-11-17 11:04 - 2017-11-02 05:26 - 004445696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-11-17 11:04 - 2017-11-02 05:26 - 003060224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-11-17 11:04 - 2017-11-02 05:26 - 002809344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-11-17 11:04 - 2017-11-02 05:26 - 000986624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-11-17 11:04 - 2017-11-02 05:25 - 003307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-11-17 11:04 - 2017-11-02 05:25 - 002052608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-11-17 11:04 - 2017-11-02 05:25 - 001886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-11-17 11:04 - 2017-11-02 05:25 - 001713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-11-17 11:04 - 2017-11-02 05:25 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-11-17 11:04 - 2017-11-02 05:25 - 000877568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2017-11-17 11:04 - 2017-11-02 05:25 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-11-17 11:04 - 2017-11-02 05:24 - 004707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-11-17 11:04 - 2017-11-02 05:23 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-11-17 11:04 - 2017-11-02 05:23 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-11-17 11:04 - 2017-11-02 05:19 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2017-11-17 11:04 - 2017-10-15 15:59 - 000923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-11-17 11:04 - 2017-10-15 15:57 - 000712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-11-17 11:04 - 2017-10-15 15:57 - 000409496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-11-17 11:04 - 2017-10-15 15:56 - 000872464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-11-17 11:04 - 2017-10-15 15:55 - 007910960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-11-17 11:04 - 2017-10-15 15:51 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-11-17 11:04 - 2017-10-15 15:15 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-11-17 11:04 - 2017-10-15 15:09 - 001878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-11-17 11:04 - 2017-10-15 15:09 - 000527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-11-17 11:04 - 2017-10-15 15:08 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-11-17 11:04 - 2017-10-15 15:08 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-11-17 11:04 - 2017-10-15 15:07 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-11-17 11:04 - 2017-10-15 15:05 - 001293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-11-17 11:04 - 2017-10-15 15:02 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2017-11-17 11:04 - 2017-10-15 15:00 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-11-13 13:21 - 2017-10-27 18:50 - 001989056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438813.dll
2017-11-13 13:21 - 2017-10-27 18:50 - 001673848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438813.dll
2017-11-12 15:50 - 2017-11-12 15:50 - 007940217 _____ C:\Users\ludovico\Downloads\aEByEWp_460sv.mp4
2017-11-10 10:05 - 2017-11-10 10:05 - 000000000 ____D C:\Users\ludovico\Documents\FeedbackHub
2017-11-09 14:24 - 2017-11-09 14:24 - 000000000 ____D C:\rsit
2017-11-09 14:24 - 2017-11-09 14:24 - 000000000 ____D C:\Program Files\trend micro
2017-11-09 14:23 - 2017-11-09 14:24 - 001222144 _____ C:\Users\ludovico\Downloads\RSITx64.exe
2017-11-07 14:11 - 2017-11-07 14:11 - 000000233 _____ C:\Users\ludovico\Desktop\Watch_Dogs.url
2017-11-07 14:11 - 2017-11-07 14:11 - 000000233 _____ C:\Users\ludovico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Watch_Dogs.url
2017-11-02 18:35 - 2017-11-02 18:35 - 000023584 _____ C:\WINDOWS\System32\Tasks\{0D0B0C47-090E-0B7D-0F11-0D79780D1179}
2017-11-02 18:35 - 2017-11-02 18:35 - 000004188 _____ C:\WINDOWS\System32\Tasks\{A64E92B5-11E5-251E-1470-43F2793F85C4}
2017-11-02 18:35 - 2017-11-02 18:35 - 000003888 _____ C:\WINDOWS\System32\Tasks\{07125A73-1ED1-EEE1-533B-67614F4B466A}
2017-11-02 18:34 - 2017-11-02 18:34 - 000000000 ____D C:\ProgramData\{150FCB7A-A2A4-7CD1-7FF8-BDC8B7154083}
2017-10-30 13:06 - 2017-11-23 13:54 - 000357468 _____ C:\Users\ludovico\Downloads\OA artikly - Price list.xlsx
2017-10-30 12:32 - 2017-10-12 22:38 - 001988032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438800.dll
2017-10-30 12:32 - 2017-10-12 22:38 - 001606592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438800.dll
2017-10-30 12:32 - 2017-10-12 22:38 - 000000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-10-30 12:32 - 2017-10-12 22:38 - 000000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-10-28 18:07 - 2017-10-28 18:07 - 000000258 __RSH C:\Users\ludovico\ntuser.pol
2017-10-28 18:02 - 2017-10-28 18:02 - 000001135 _____ C:\Users\Public\Desktop\FileASSASSIN.lnk
2017-10-28 18:02 - 2017-10-28 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN
2017-10-28 18:02 - 2017-10-28 18:02 - 000000000 ____D C:\Program Files (x86)\FileASSASSIN
2017-10-28 18:01 - 2017-10-28 18:01 - 000001967 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unlocker.lnk
2017-10-28 18:01 - 2017-10-28 18:01 - 000000000 ____D C:\Program Files (x86)\Unlocker
2017-10-28 18:00 - 2017-10-28 18:01 - 000346112 _____ C:\Users\ludovico\Downloads\Unlocker 1.9.2.msi
2017-10-28 17:35 - 2017-10-28 17:43 - 000000000 ____D C:\Program Files (x86)\Seznam.cz
2017-10-28 17:34 - 2017-10-28 17:43 - 000000000 ____D C:\Users\ludovico\AppData\Roaming\Seznam.cz
2017-10-28 17:30 - 2017-10-28 17:30 - 000000000 ____D C:\Users\ludovico\AppData\Local\Disc_Soft_Ltd
2017-10-28 17:25 - 2017-10-28 17:33 - 000002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk
2017-10-28 17:25 - 2017-10-28 17:33 - 000002144 _____ C:\Users\Public\Desktop\Gооglе Сhrоmе.lnk
2017-10-28 17:21 - 2017-10-28 17:24 - 000000000 ____D C:\Users\ludovico\AppData\Roaming\DAEMON Tools Lite
2017-10-28 17:21 - 2017-10-28 17:21 - 000047672 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtliteusbbus.sys
2017-10-28 17:21 - 2017-10-28 17:21 - 000001825 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2017-10-28 17:21 - 2017-10-28 17:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2017-10-28 17:21 - 2017-10-28 17:21 - 000000000 ____D C:\Program Files\DAEMON Tools Lite
2017-10-28 17:19 - 2017-10-28 17:19 - 000140800 _____ C:\Users\ludovico\AppData\Local\installer.dat
2017-10-28 17:19 - 2017-10-28 17:19 - 000000258 __RSH C:\ProgramData\ntuser.pol
2017-10-28 17:18 - 2017-10-28 17:18 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite
2017-10-28 17:17 - 2017-10-28 17:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-10-28 17:16 - 2017-10-28 17:16 - 000000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-10-28 17:14 - 2017-10-28 17:15 - 000790488 _____ (Disc Soft Ltd.) C:\Users\ludovico\Downloads\DTLiteInstaller.exe
2017-10-28 17:13 - 2017-10-28 18:07 - 000000000 ____D C:\Disk
2017-10-28 17:13 - 2017-10-28 18:07 - 000000000 ____D C:\Applications
2017-10-28 17:13 - 2017-10-28 17:13 - 000000000 ____D C:\WinSys
2017-10-28 17:13 - 2017-10-28 17:13 - 000000000 ____D C:\Windat
2017-10-28 17:13 - 2017-10-28 17:13 - 000000000 ____D C:\Program Files\LaCie Private Public
2017-10-28 17:07 - 2017-10-28 17:07 - 000000000 ____D C:\Users\ludovico\AppData\LocalLow\uTorrent
2017-10-28 17:04 - 2017-10-28 18:05 - 000000000 ____D C:\Users\ludovico\AppData\Roaming\uTorrent
2017-10-28 17:04 - 2017-10-28 17:04 - 000000910 _____ C:\Users\ludovico\Desktop\µTorrent.lnk
2017-10-28 17:04 - 2017-10-28 17:04 - 000000890 _____ C:\Users\ludovico\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2017-10-28 17:03 - 2017-10-28 17:03 - 002849376 _____ (BitTorrent Inc.) C:\Users\ludovico\Downloads\uTorrent.exe
2017-10-27 17:28 - 2017-11-05 21:09 - 000002259 _____ C:\Users\ludovico\Desktop\Discord.lnk
2017-10-27 17:28 - 2017-10-27 18:23 - 000000000 ____D C:\Users\ludovico\AppData\Roaming\discord
2017-10-27 17:28 - 2017-10-27 17:28 - 000000000 ____D C:\Users\ludovico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2017-10-27 17:28 - 2017-10-27 17:28 - 000000000 ____D C:\Users\ludovico\AppData\Local\Discord
2017-10-27 17:23 - 2017-10-27 17:24 - 054332920 _____ (Discord Inc.) C:\Users\ludovico\Downloads\DiscordSetup.exe
2017-10-26 16:50 - 2017-10-26 16:50 - 000003788 _____ C:\Users\ludovico\Downloads\tiedup-2.txt
2017-10-26 16:34 - 2017-10-26 16:34 - 000014391 _____ C:\Users\ludovico\Downloads\Demon.txt
2017-10-25 16:58 - 2017-11-21 21:10 - 000001546 _____ C:\Users\ludovico\Desktop\diplomova prace.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-24 13:10 - 2016-11-30 14:28 - 000000000 ____D C:\Users\ludovico\AppData\Local\Jagex
2017-11-24 13:10 - 2016-11-30 14:27 - 000000000 ____D C:\ProgramData\Jagex
2017-11-24 13:07 - 2017-09-26 14:57 - 000000000 ____D C:\ProgramData\NVIDIA
2017-11-24 13:04 - 2017-09-26 14:51 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-11-23 16:34 - 2017-04-19 13:34 - 000080938 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2017-11-23 12:44 - 2016-11-30 13:34 - 000000000 ____D C:\Program Files (x86)\Steam
2017-11-23 09:17 - 2017-10-20 14:09 - 000020870 _____ C:\Users\ludovico\Desktop\money earned rs.xlsx
2017-11-23 08:16 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-11-23 08:16 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-11-22 21:02 - 2017-08-18 15:13 - 000000000 ____D C:\Program Files (x86)\Origin
2017-11-22 20:34 - 2017-09-26 15:01 - 000000000 ____D C:\Users\ludovico
2017-11-22 18:52 - 2017-09-26 14:58 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-11-22 18:52 - 2015-12-24 21:29 - 000000000 __SHD C:\Users\ludovico\IntelGraphicsProfiles
2017-11-22 18:50 - 2017-09-26 15:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-22 18:50 - 2017-03-18 12:40 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2017-11-22 11:39 - 2017-09-26 15:17 - 001004726 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-21 17:59 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\rescache
2017-11-21 17:50 - 2016-12-01 14:21 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-11-21 17:37 - 2017-10-12 14:59 - 127017032 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-11-21 17:36 - 2016-12-01 14:21 - 127017032 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-11-21 12:11 - 2017-04-19 12:54 - 000545440 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-11-20 14:54 - 2016-02-04 18:38 - 000000000 ____D C:\Users\ludovico\Documents\bp
2017-11-20 10:28 - 2017-04-20 12:20 - 000000600 _____ C:\Users\ludovico\PUTTY.RND
2017-11-19 10:12 - 2017-09-16 13:54 - 000000000 ___DC C:\WINDOWS\Panther
2017-11-19 10:12 - 2015-12-25 13:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-11-19 10:07 - 2017-03-18 22:01 - 000000000 ____D C:\WINDOWS\INF
2017-11-19 10:06 - 2017-09-26 14:51 - 000486152 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-11-18 22:09 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\SysWOW64\en-GB
2017-11-18 22:09 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\en-GB
2017-11-18 22:09 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-11-18 22:09 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-11-18 22:09 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\Provisioning
2017-11-18 22:09 - 2017-03-18 22:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-11-18 22:09 - 2017-03-18 22:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-11-18 15:53 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-11-17 12:42 - 2017-08-06 11:49 - 000000000 ____D C:\Users\ludovico\AppData\Local\NVIDIA
2017-11-17 12:12 - 2017-03-18 21:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-11-17 10:55 - 2017-09-26 15:19 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-11-17 10:54 - 2016-11-30 13:44 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-11-14 23:48 - 2017-08-06 11:45 - 004484864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-11-14 23:48 - 2017-08-06 11:45 - 003817584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-11-14 23:48 - 2017-08-06 11:45 - 000048442 _____ C:\WINDOWS\system32\nvinfo.pb
2017-11-14 21:15 - 2017-09-26 14:57 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-11-14 20:56 - 2017-09-26 14:57 - 005960640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-11-14 20:56 - 2017-09-26 14:57 - 002587584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-11-14 20:56 - 2017-09-26 14:57 - 001766336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-11-14 20:56 - 2017-09-26 14:57 - 000607352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-11-14 20:56 - 2017-09-26 14:57 - 000449472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-11-14 20:56 - 2017-09-26 14:57 - 000146880 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2017-11-14 20:56 - 2017-09-26 14:57 - 000123000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-11-14 20:56 - 2017-09-26 14:57 - 000082040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-11-14 18:51 - 2016-11-30 19:27 - 000000000 ____D C:\Users\ludovico\AppData\Roaming\vlc
2017-11-13 10:26 - 2017-06-01 19:08 - 000000000 ____D C:\Users\ludovico\AppData\Local\Ubisoft Game Launcher
2017-11-10 07:09 - 2017-09-26 14:57 - 007855841 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-11-07 18:13 - 2015-12-25 01:46 - 000000000 ____D C:\Users\ludovico\Documents\My games
2017-11-07 09:14 - 2017-10-20 13:24 - 000354247 _____ C:\Users\ludovico\Downloads\OA artikly - Technické parametry.xlsx
2017-11-07 08:26 - 2017-09-26 15:19 - 000003374 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2449969739-3869695409-109372524-1001
2017-11-07 08:26 - 2016-11-28 15:08 - 000002383 _____ C:\Users\ludovico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-11-07 08:26 - 2015-12-24 21:40 - 000000000 ___RD C:\Users\ludovico\OneDrive
2017-11-06 10:51 - 2016-10-03 09:18 - 000000000 ____D C:\Users\ludovico\Documents\cevro
2017-11-05 02:40 - 2017-03-18 22:06 - 000835568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-11-05 02:40 - 2017-03-18 22:06 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-11-02 17:36 - 2016-01-04 09:46 - 000000047 _____ C:\Users\ludovico\jagex_cl_oldschool_LIVE.dat
2017-10-30 20:13 - 2017-09-26 14:57 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-10-30 12:37 - 2016-11-30 14:28 - 000000000 ____D C:\Users\ludovico\AppData\Roaming\NVIDIA
2017-10-30 12:36 - 2017-09-26 14:57 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-10-30 12:29 - 2017-09-26 14:57 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-10-30 12:00 - 2017-09-26 15:19 - 000004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 12:00 - 2017-09-26 15:19 - 000003940 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 12:00 - 2017-08-06 11:49 - 000001496 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-10-30 11:59 - 2017-09-26 15:19 - 000004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 11:58 - 2017-09-26 15:19 - 000003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 11:58 - 2017-09-26 15:19 - 000003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 11:58 - 2017-09-26 15:19 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 11:58 - 2017-09-26 15:19 - 000003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-30 11:58 - 2017-09-26 15:19 - 000003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-28 17:25 - 2017-02-26 16:36 - 000000000 ____D C:\Users\ludovico\AppData\Local\CrashDumps
2017-10-28 17:19 - 2016-11-28 22:42 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-10-27 18:50 - 2017-09-22 19:42 - 000057976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-10-27 17:29 - 2017-07-27 18:53 - 000000000 ____D C:\Users\ludovico\AppData\Local\SquirrelTemp

==================== Files in the root of some directories =======

2017-10-28 17:19 - 2017-10-28 17:19 - 000140800 _____ () C:\Users\ludovico\AppData\Local\installer.dat

Some files in TEMP:
====================
2017-10-28 17:12 - 2017-10-28 17:12 - 000024576 _____ (Philadelphia, NJ 19103) C:\Users\ludovico\AppData\Local\Temp\capi.exe
2017-10-28 17:24 - 2017-10-28 17:24 - 000020480 _____ (Fremont, CA 94539) C:\Users\ludovico\AppData\Local\Temp\cuinsta.exe
2017-10-28 17:12 - 2017-10-28 17:12 - 003287243 _____ () C:\Users\ludovico\AppData\Local\Temp\golm.exe
2017-10-28 17:24 - 2017-10-28 17:24 - 000947112 _____ () C:\Users\ludovico\AppData\Local\Temp\instalelerxvid.exe
2017-10-28 17:24 - 2017-10-28 17:24 - 000712433 _____ (aagiotoyU) C:\Users\ludovico\AppData\Local\Temp\installer_campaign_20522.exe
2017-10-28 17:12 - 2017-10-28 17:29 - 001792071 _____ () C:\Users\ludovico\AppData\Local\Temp\pi.exe
2017-10-28 17:12 - 2017-10-28 17:12 - 000779776 _____ () C:\Users\ludovico\AppData\Local\Temp\XvidCodecInstaller.exe
2017-10-28 17:43 - 2017-10-28 17:43 - 000534528 _____ () C:\Users\ludovico\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-18 12:30

==================== End of FRST.txt ============================

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 28 lis 2017 19:16
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM\...\Run: [SERVICE] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\MountPoints2: {9d9adefa-49c9-11e6-8278-0071cca142f0} - "F:\Autorun.exe"
GroupPolicy: Restriction - Chrome <==== ATTENTION
S1 hdaceafi; \??\C:\WINDOWS\system32\drivers\hdaceafi.sys [X]
S1 jizbkmbk; \??\C:\WINDOWS\system32\drivers\jizbkmbk.sys [X]
S1 jpvmzmxa; \??\C:\WINDOWS\system32\drivers\jpvmzmxa.sys [X]
S1 kkyxttfk; \??\C:\WINDOWS\system32\drivers\kkyxttfk.sys [X]
S1 tiexfiea; \??\C:\WINDOWS\system32\drivers\tiexfiea.sys [X]
S1 uiwblmyk; \??\C:\WINDOWS\system32\drivers\uiwblmyk.sys [X]
S1 vfjqfdkc; \??\C:\WINDOWS\system32\drivers\vfjqfdkc.sys [X]
S1 vrdmkfli; \??\C:\WINDOWS\system32\drivers\vrdmkfli.sys [X]
S1 wfcre; system32\drivers\wfcre.sys [X]
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\Users\ludovico\AppData\Local\Temp

EmptyTemp:
End
Uložte do C:\Users\ludovico\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 07 pro 2017 09:44
od Sergeii
Fix result of Farbar Recovery Scan Tool (x64) Version: 30-11-2017
Ran by ludovico (04-12-2017 10:29:29) Run:1
Running from C:\Users\ludovico\Downloads
Loaded Profiles: ludovico (Available Profiles: ludovico)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKLM\...\Run: [SERVICE] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation)
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\...\MountPoints2: {9d9adefa-49c9-11e6-8278-0071cca142f0} - "F:\Autorun.exe"
GroupPolicy: Restriction - Chrome <==== ATTENTION
S1 hdaceafi; \??\C:\WINDOWS\system32\drivers\hdaceafi.sys [X]
S1 jizbkmbk; \??\C:\WINDOWS\system32\drivers\jizbkmbk.sys [X]
S1 jpvmzmxa; \??\C:\WINDOWS\system32\drivers\jpvmzmxa.sys [X]
S1 kkyxttfk; \??\C:\WINDOWS\system32\drivers\kkyxttfk.sys [X]
S1 tiexfiea; \??\C:\WINDOWS\system32\drivers\tiexfiea.sys [X]
S1 uiwblmyk; \??\C:\WINDOWS\system32\drivers\uiwblmyk.sys [X]
S1 vfjqfdkc; \??\C:\WINDOWS\system32\drivers\vfjqfdkc.sys [X]
S1 vrdmkfli; \??\C:\WINDOWS\system32\drivers\vrdmkfli.sys [X]
S1 wfcre; system32\drivers\wfcre.sys [X]
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\Users\ludovico\AppData\Local\Temp

EmptyTemp:
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SERVICE => value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
HKU\S-1-5-21-2449969739-3869695409-109372524-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d9adefa-49c9-11e6-8278-0071cca142f0} => key not found
HKLM\Software\Classes\CLSID\{9d9adefa-49c9-11e6-8278-0071cca142f0} => key not found
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
hdaceafi => service not found.
jizbkmbk => service not found.
jpvmzmxa => service not found.
kkyxttfk => service not found.
tiexfiea => service not found.
uiwblmyk => service not found.
vfjqfdkc => service not found.
vrdmkfli => service not found.
wfcre => service not found.
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully

"C:\Users\ludovico\AppData\Local\Temp" folder move:

Could not move "C:\Users\ludovico\AppData\Local\Temp" => Scheduled to move on reboot.


=========== EmptyTemp: ==========

BITS transfer queue => 6053888 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 188119893 B
Java, Flash, Steam htmlcache => 356193433 B
Windows/system/drivers => 6726453 B
Edge => 1125383 B
Chrome => 829162806 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 34816 B
ludovico => 101347591 B

RecycleBin => 19568 B
EmptyTemp: => 1.4 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 04-12-2017 10:40:50)

C:\Users\ludovico\AppData\Local\Temp => moved successfully

==== End of Fixlog 10:41:10 ====

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 07 pro 2017 22:09
od Rudy
OK. Nastala nějaká změna?

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 11 pro 2017 10:53
od Sergeii
není to tak časté, ale občas ještě reklama vyběhne
např.:
giveaways.com-register online
hellspy
love4single.com

vše v google chrome

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 11 pro 2017 16:40
od Rudy
Spusťte posrupně tato utility:

1. Stahnete Zoek.exe http://download.bleepingcomputer.com/smeenk/zoek.exe a ulozte jej na plochu

Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
Do okna vlozte skript nize




autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;





Nasledne kliknete na Run Script
PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem.

a

2. Junkware removal tool: http://www.stahuj.centrum.cz/utility_a_ ... oval-tool/
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 18 pro 2017 15:14
od Sergeii
díky moc, junk:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by ludovico (Administrator) on 18-Dec-17 at 15:04:55.66
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 1

Successfully deleted: HKCU\Software\Google\Chrome\Extensions\olfeabkoenfaoljndfecamgilllcpiak (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18-Dec-17 at 15:11:00.77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

zoek:


Zoek.exe v5.0.0.1 Updated 24-October-2017
Tool run by ludovico on 18-Dec-17 at 14:41:01.01.
Microsoft Windows 10 Home 10.0.16299 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\ludovico\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

18-Dec-17 2:43:02 PM Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IESR02

==== Reset Google Chrome ======================

C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Web Data will be reset at reboot
C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal will be reset at reboot

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ludovico\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\ludovico\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\ludovico\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\ludovico\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Cache will be emptied at reboot

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\ludovico\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Web Data" not found
"C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal" not found
"C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0" deleted
"C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1" deleted
"C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2" deleted
"C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3" deleted
"C:\Users\ludovico\AppData\Local\Google\Chrome\User Data\Default\Cache\index" deleted

==== EOF on 18-Dec-17 at 14:54:46.20 ======================

Re: Prosim kontrolu, oteviraji se nahodne stranky s reklamo

Napsal: 18 pro 2017 18:03
od Rudy
Něco bylo smazáno. Nastala nějaká změna?