Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Procesy hostitele služby nonstop zatěžují CPU

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Procesy hostitele služby nonstop zatěžují CPU

#1 Příspěvek od meiilax »

Ahojte,

2 procesy hostitele služby zatěžují permamentně procesor celkem cca 35%. Jedná se o hostitele služby:

1. Místní služba (bez sítě 3) - pod ní jsou Brána Windows Firewall, CoreMessaging, Služba BFE (Base Filtering Engine)
2. Sdílení připojení k interentu (ICS)

Odinstaloval jsem Avast, Malware, ve Windows Defender zakázal antivirus, firewall a nic nepomohlo, tak poprosím vás o pomoc :-) Děkuju,

Milan

RSIT log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Milan at 2017-12-30 17:15:11
Microsoft Windows 10 Pro
System drive C: has 104 GB (21%) free of 500 GB
Total RAM: 8140 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:15:16, on 30.12.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0608)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files\trend micro\Milan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - (no file)
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O3 - Toolbar: DebugBar (Toolbar) - {3E1201F4-1707-409F-BB45-A5F192381DA0} - C:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.dll
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [ControlCenterCount] C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe
O4 - HKLM\..\Run: [Navigraph FMS Data Manager] C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSAgent.exe -autostart
O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\web\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [RazerCortex] C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe -autorun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Google Update] C:\Users\Milan\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe
O4 - HKCU\..\Run: [World of Tanks] "F:\Games\World_of_Tanks\WargamingGameUpdater.exe"
O4 - HKCU\..\Run: [S3AutomaticSTART] C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe /tray
O4 - HKCU\..\Run: [S3Automatic] C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe /tray
O4 - HKCU\..\Run: [Spotify Web Helper] C:\Users\Milan\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Inspect Element with DebugBar - res://C:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.dll/247
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apache24VC10_php52 - Apache Software Foundation - C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe
O23 - Service: Apache24VC10_php53 - Apache Software Foundation - C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe
O23 - Service: Apache24VC10_php54 - Apache Software Foundation - C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe
O23 - Service: Apache24_php55 - Apache Software Foundation - C:\web\Apache Software Foundation\Apache2.4\bin\httpd.exe
O23 - Service: Apache24_php56 - Apache Software Foundation - C:\web\Apache Software Foundation\Apache2.4\bin\httpd.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\web\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FSLabs Service - Flight Sim Labs Ltd. - D:\FlightSimLabs\FSLSpotLights\FSLService\FSLService.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\web\MySQL\MySQL.exe (file missing)
O23 - Service: MySQL57 - Unknown owner - C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\SysWOW64\nlssrv32.exe
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: Origin Client Service - Electronic Arts - F:\Games\Origin\OriginClientService.exe
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: RzKLService - Razer Inc. - C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WTService - Unknown owner - C:\WINDOWS\system32\atwtusb.exe (file missing)

--
End of file - 16207 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
winlogon.exe
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
"fontdrvhost.exe"
"fontdrvhost.exe"
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
"dwm.exe"
c:\windows\system32\svchost.exe -k netsvcs -s gpsvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TabletInputService
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s netprofm
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService

C:\WINDOWS\System32\spoolsv.exe
dashost.exe {f384c93d-2bbf-4869-a595b360ad305132}
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
C:\WINDOWS\system32\AUDIODG.EXE 0x4cc
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k netsvcs -s IKEEXT
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\SysWOW64\nlssrv32.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
"C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe"

c:\windows\system32\svchost.exe -k netsvcs -s SharedAccess
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
D:\FlightSimLabs\FSLSpotLights\FSLService\FSLService.exe

C:\WINDOWS\system32\atwtusb.exe -s

c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k netsvcs -s Browser
C:\WINDOWS\system32\atwtusb.exe
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
c:\windows\system32\svchost.exe -k localservicenonetwork -s NcdAutoSetup
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s FDResPub
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s HomeGroupProvider
sihost.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
C:\WINDOWS\Explorer.EXE
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.10.572.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer

"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca
/QuitInfo:0000000000000200;0000000000000204;
/loadhooks /Parent:00000000000022c8
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Microsoft Device Center\ipoint.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s WdiSystemHost
"C:\Program Files\Microsoft Device Center\itype.exe"
"C:\Windows\System32\AtwtusbIcon.exe"
"C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
"C:\WINDOWS\system32\taskmgr.exe" /4
c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k unistacksvcgroup
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe" -ServerName:SecHealthUI.AppXep4x2tbtjws1v9qqs0rmb3hxykvkpqtn.mca
C:\WINDOWS\system32\DllHost.exe /Processid:{7E55A26D-EF95-4A45-9F55-21E52ADF9887}
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
c:\windows\system32\svchost.exe -k netsvcs -s wlidsvc
"C:\Users\Milan\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core.job - C:\Users\Milan\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA.job - C:\Users\Milan\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 28.0.0.126 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 28.0.0.126 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll


C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\extensions\
2020Player_IKEA@2020Technologies.com
adbhelper@mozilla.org
fxdevtools-adapters@mozilla.org

C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\searchplugins\
google-avast.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2017-12-17 206000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{69FC0024-10EB-480A-BBF2-3BF4E78E17B1}]
DebugBar BHO - C:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.x64.dll [2015-03-03 5715456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-08-13 551520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-12-17 3188912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-13 212576]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-12-17 148648]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-12-17 2171056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{3E1201F4-1707-409F-BB45-A5F192381DA0} - DebugBar (Toolbar) - C:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.x64.dll [2015-03-03 1005056]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{3E1201F4-1707-409F-BB45-A5F192381DA0} - DebugBar (Toolbar) - C:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.dll [2015-03-03 808448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-18 629152]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-12-06 7506136]
"IntelliPoint"=c:\Program Files\Microsoft Device Center\ipoint.exe [2012-06-26 2004584]
"IntelliType Pro"=c:\Program Files\Microsoft Device Center\itype.exe [2012-06-26 1464928]
"IntelTBRunOnce"=wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs []
"AtwtusbIcon"=C:\WINDOWS\system32\AtwtusbIcon.exe [2012-09-10 3593728]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2017-08-18 1923008]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-12-05 1551048]
"Google Update"=C:\Users\Milan\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [2017-11-16 601680]
"World of Tanks"=F:\Games\World_of_Tanks\WargamingGameUpdater.exe [2016-11-18 3135752]
"S3AutomaticSTART"=C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe [2018-01-01 31649680]
"S3Automatic"=C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe [2018-01-01 31649680]
"Spotify Web Helper"=C:\Users\Milan\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2017-10-21 777840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenterCount]
C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [2012-03-26 872448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
C:\web\APACHE~1\Apache2.2\bin\APACHE~1.EXE []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"ControlCenterCount"=C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [2012-03-26 872448]
"Navigraph FMS Data Manager"=C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSAgent.exe [2017-12-01 992360]
"FileZilla Server Interface"=C:\web\FileZilla Server\FileZilla Server Interface.exe [2015-06-12 2462680]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2016-10-12 2383040]
"RazerCortex"=C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe [2016-09-28 222160]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-03-28 1160408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableLinkedConnections"=1
"SoftwareSASGeneration"=1
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveTrack"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-12-30 17:15:11 ----D---- C:\rsit
2017-12-30 17:15:11 ----D---- C:\Program Files\trend micro
2017-12-27 22:09:31 ----D---- C:\EZdok Software
2017-12-26 19:46:38 ----D---- C:\Program Files (x86)\EZCA2
2017-12-26 19:46:38 ----A---- C:\Program Files (x86)\unEZCA2.exe
2017-12-26 09:48:00 ----D---- C:\WINDOWS\SYSWOW64\directx
2017-12-24 21:21:43 ----D---- C:\Users\Milan\AppData\Roaming\Hifi
2017-12-24 11:58:50 ----A---- C:\WINDOWS\Ben Gurion X Uninstall Log.txt
2017-12-24 08:32:46 ----D---- C:\Users\Milan\AppData\Roaming\Navigraph
2017-12-20 19:38:05 ----D---- C:\ProgramData\Apple Computer
2017-12-17 13:21:37 ----D---- C:\Program Files\Common Files\DESIGNER
2017-12-14 17:09:49 ----D---- C:\ProgramData\MB2Migration
2017-12-14 16:57:38 ----D---- C:\Program Files\7-Zip
2017-12-13 21:21:23 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2017-12-13 21:21:22 ----A---- C:\WINDOWS\SYSWOW64\werui.dll
2017-12-13 21:21:22 ----A---- C:\WINDOWS\SYSWOW64\wermgr.exe
2017-12-13 21:21:22 ----A---- C:\WINDOWS\SYSWOW64\WerFault.exe
2017-12-13 21:21:22 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-12-13 21:21:22 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-12-13 21:21:22 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-12-13 21:21:22 ----A---- C:\WINDOWS\SYSWOW64\DWWIN.EXE
2017-12-13 21:21:21 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2017-12-13 21:21:21 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-12-13 21:21:21 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2017-12-13 21:21:21 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-12-13 21:21:21 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2017-12-13 21:21:21 ----A---- C:\WINDOWS\SYSWOW64\Faultrep.dll
2017-12-13 21:21:21 ----A---- C:\WINDOWS\SYSWOW64\cldapi.dll
2017-12-13 21:21:20 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-12-13 21:21:20 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-12-13 21:21:20 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-12-13 21:21:20 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-12-13 21:21:20 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2017-12-13 21:21:20 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2017-12-13 21:21:20 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-12-13 21:21:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-12-13 21:21:19 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-12-13 21:21:19 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2017-12-13 21:21:19 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-12-13 21:21:18 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-12-13 21:21:18 ----A---- C:\WINDOWS\SYSWOW64\WerFaultSecure.exe
2017-12-13 21:21:18 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-12-13 21:21:17 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-12-13 21:21:17 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-12-13 21:21:17 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-12-13 21:21:15 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-12-13 21:21:15 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2017-12-13 21:21:15 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-12-13 21:21:15 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2017-12-13 21:21:15 ----A---- C:\WINDOWS\system32\tquery.dll
2017-12-13 21:21:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-12-13 21:21:13 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2017-12-13 21:21:12 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-12-13 21:21:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-12-13 21:21:11 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-12-13 21:21:10 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-12-13 21:21:09 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-12-13 21:21:09 ----A---- C:\WINDOWS\SYSWOW64\msexcl40.dll
2017-12-13 21:21:09 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-12-13 21:21:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.Launcher.dll
2017-12-13 21:21:08 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-12-13 21:21:08 ----A---- C:\WINDOWS\SYSWOW64\dsreg.dll
2017-12-13 21:21:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-12-13 21:21:07 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-12-13 21:21:07 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-12-13 21:21:07 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-12-13 21:21:06 ----A---- C:\WINDOWS\SYSWOW64\scrobj.dll
2017-12-13 21:21:06 ----A---- C:\WINDOWS\SYSWOW64\cscript.exe
2017-12-13 21:21:06 ----A---- C:\WINDOWS\system32\VPNv2CSP.dll
2017-12-13 21:21:06 ----A---- C:\WINDOWS\system32\drivers\stornvme.sys
2017-12-13 21:21:05 ----A---- C:\WINDOWS\SYSWOW64\wscript.exe
2017-12-13 21:21:05 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2017-12-13 21:21:05 ----A---- C:\WINDOWS\SYSWOW64\CertPKICmdlet.dll
2017-12-13 21:21:04 ----A---- C:\WINDOWS\SYSWOW64\tzres.dll
2017-12-13 21:21:04 ----A---- C:\WINDOWS\SYSWOW64\OnDemandConnRouteHelper.dll
2017-12-13 21:21:04 ----A---- C:\WINDOWS\SYSWOW64\itss.dll
2017-12-13 21:21:02 ----A---- C:\WINDOWS\system32\utcutil.dll
2017-12-13 21:21:02 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-12-13 21:21:02 ----A---- C:\WINDOWS\system32\storewuauth.dll
2017-12-13 21:21:02 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-12-13 21:21:01 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-12-13 21:21:01 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2017-12-13 21:20:55 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-12-13 21:20:54 ----A---- C:\WINDOWS\system32\wpdshext.dll
2017-12-13 21:20:54 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-12-13 21:20:53 ----A---- C:\WINDOWS\SYSWOW64\wpdshext.dll
2017-12-13 21:20:51 ----A---- C:\WINDOWS\system32\wuautoappupdate.dll
2017-12-13 21:20:50 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2017-12-13 21:20:50 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-12-13 21:20:48 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-12-13 21:20:47 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-12-13 21:20:45 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-12-13 21:20:45 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2017-12-13 21:20:44 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-12-13 21:20:43 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-12-13 21:20:43 ----A---- C:\WINDOWS\system32\ieproxy.dll
2017-12-13 21:20:42 ----A---- C:\WINDOWS\system32\OOBEUpdater.exe
2017-12-13 21:20:41 ----A---- C:\WINDOWS\system32\vbscript.dll
2017-12-13 21:20:40 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-12-13 21:20:39 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2017-12-13 21:20:36 ----A---- C:\WINDOWS\system32\rdpudd.dll
2017-12-13 21:20:35 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-12-13 21:20:35 ----A---- C:\WINDOWS\system32\MSVPXENC.dll
2017-12-13 21:20:34 ----A---- C:\WINDOWS\system32\jscript.dll
2017-12-13 21:20:32 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-12-13 21:20:30 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-12-13 21:20:30 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2017-12-13 21:20:29 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-12-13 21:20:19 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-12-13 21:20:19 ----A---- C:\WINDOWS\system32\SEMgrPS.dll
2017-12-13 21:20:19 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-12-13 21:20:17 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2017-12-13 21:20:15 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2017-12-13 21:20:14 ----A---- C:\WINDOWS\system32\wmp.dll
2017-12-13 21:20:08 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-12-13 21:20:08 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-12-13 21:20:07 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-12-13 21:20:07 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-12-13 21:20:06 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-12-13 21:20:05 ----A---- C:\WINDOWS\system32\wudriver.dll
2017-12-13 21:20:05 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-12-13 21:20:04 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-12-13 21:20:04 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-12-13 21:20:03 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-12-13 21:20:02 ----A---- C:\WINDOWS\system32\WerFaultSecure.exe
2017-12-13 21:20:01 ----A---- C:\WINDOWS\system32\wersvc.dll
2017-12-13 21:20:01 ----A---- C:\WINDOWS\system32\wermgr.exe
2017-12-13 21:20:01 ----A---- C:\WINDOWS\system32\WerFault.exe
2017-12-13 21:20:01 ----A---- C:\WINDOWS\system32\wer.dll
2017-12-13 21:20:01 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-12-13 21:20:01 ----A---- C:\WINDOWS\system32\Faultrep.dll
2017-12-13 21:20:00 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-12-13 21:19:59 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-12-13 21:19:59 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-12-13 21:19:58 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-12-13 21:19:55 ----A---- C:\WINDOWS\system32\browserbroker.dll
2017-12-13 21:19:51 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-12-13 21:19:50 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-12-13 21:19:49 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2017-12-13 21:19:38 ----A---- C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2017-12-13 21:19:38 ----A---- C:\WINDOWS\system32\itss.dll
2017-12-13 21:19:37 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-12-13 21:19:36 ----A---- C:\WINDOWS\system32\wuuhosdeployment.dll
2017-12-13 21:19:36 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-12-13 21:19:36 ----A---- C:\WINDOWS\system32\securekernel.exe
2017-12-13 21:19:36 ----A---- C:\WINDOWS\system32\dsreg.dll
2017-12-13 21:19:36 ----A---- C:\WINDOWS\system32\ci.dll
2017-12-13 21:19:36 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-12-13 21:19:35 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-12-13 21:19:35 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2017-12-13 21:19:35 ----A---- C:\WINDOWS\system32\winhttp.dll
2017-12-13 21:19:35 ----A---- C:\WINDOWS\system32\wercplsupport.dll
2017-12-13 21:19:35 ----A---- C:\WINDOWS\system32\hvloader.exe
2017-12-13 21:19:35 ----A---- C:\WINDOWS\system32\DWWIN.EXE
2017-12-13 21:19:34 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-12-13 21:19:34 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-12-13 21:19:34 ----A---- C:\WINDOWS\system32\SIHClient.exe
2017-12-13 21:19:34 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-12-13 21:19:34 ----A---- C:\WINDOWS\system32\drivers\WdiWiFi.sys
2017-12-13 21:19:34 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-12-13 21:19:34 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-12-13 21:19:33 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-12-13 21:19:33 ----A---- C:\WINDOWS\system32\werui.dll
2017-12-13 21:19:33 ----A---- C:\WINDOWS\system32\werconcpl.dll
2017-12-13 21:19:33 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2017-12-13 21:19:32 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-12-13 21:19:32 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-12-13 21:19:30 ----A---- C:\WINDOWS\system32\wininet.dll
2017-12-13 21:19:30 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-12-13 21:19:30 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-12-13 21:19:29 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-12-13 21:19:28 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-12-13 21:19:28 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-12-13 21:19:28 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2017-12-13 21:19:27 ----A---- C:\WINDOWS\system32\user32.dll
2017-12-13 21:19:27 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-12-13 21:19:27 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2017-12-13 21:19:27 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-12-13 21:19:26 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-12-13 21:19:26 ----A---- C:\WINDOWS\system32\ClipSVC.dll
2017-12-13 21:19:25 ----A---- C:\WINDOWS\system32\shell32.dll
2017-12-13 21:19:24 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-12-13 21:19:23 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2017-12-13 21:19:22 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-12-13 21:19:22 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-12-13 21:19:19 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-12-13 21:19:19 ----A---- C:\WINDOWS\system32\usocore.dll
2017-12-13 21:19:19 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-12-13 21:19:18 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-12-13 21:19:18 ----A---- C:\WINDOWS\system32\msIso.dll
2017-12-13 21:19:18 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-12-13 21:19:17 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-12-13 21:19:16 ----A---- C:\WINDOWS\system32\aitstatic.exe
2017-12-13 21:19:15 ----A---- C:\WINDOWS\system32\dusmsvc.dll
2017-12-13 21:19:14 ----A---- C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-12-13 21:19:10 ----A---- C:\WINDOWS\system32\wups.dll
2017-12-13 21:19:10 ----A---- C:\WINDOWS\system32\vss_ps.dll
2017-12-13 21:19:10 ----A---- C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-12-13 21:19:09 ----A---- C:\WINDOWS\system32\win32appinventorycsp.dll
2017-12-13 21:19:09 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2017-12-13 21:19:09 ----A---- C:\WINDOWS\system32\dcntel.dll
2017-12-13 21:19:09 ----A---- C:\WINDOWS\system32\aepic.dll
2017-12-13 21:19:08 ----A---- C:\WINDOWS\system32\invagent.dll
2017-12-13 21:19:08 ----A---- C:\WINDOWS\system32\generaltel.dll
2017-12-13 21:19:08 ----A---- C:\WINDOWS\system32\devinv.dll
2017-12-13 21:19:08 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2017-12-13 21:19:08 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-12-13 21:19:08 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-12-13 21:19:06 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-12-13 21:19:06 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-12-13 21:19:05 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-12-13 21:19:03 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-12-13 21:19:02 ----A---- C:\WINDOWS\system32\daxexec.dll
2017-12-13 21:19:01 ----A---- C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-12-13 21:19:01 ----A---- C:\WINDOWS\system32\profsvc.dll
2017-12-13 21:19:01 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-12-13 21:19:00 ----A---- C:\WINDOWS\system32\schedsvc.dll
2017-12-13 21:18:59 ----A---- C:\WINDOWS\system32\wow64win.dll
2017-12-13 21:18:59 ----A---- C:\WINDOWS\system32\ubpm.dll
2017-12-13 21:18:58 ----A---- C:\WINDOWS\system32\SharedPCCSP.dll
2017-12-13 21:18:58 ----A---- C:\WINDOWS\system32\pcasvc.dll
2017-12-13 21:18:58 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2017-12-13 21:18:58 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-12-13 21:18:57 ----A---- C:\WINDOWS\system32\Windows.UI.Storage.dll
2017-12-13 21:18:57 ----A---- C:\WINDOWS\system32\RMapi.dll
2017-12-13 21:18:57 ----A---- C:\WINDOWS\system32\cldapi.dll
2017-12-13 21:18:56 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-12-13 21:18:55 ----A---- C:\WINDOWS\system32\wuauclt.exe
2017-12-13 21:18:55 ----A---- C:\WINDOWS\system32\provhandlers.dll
2017-12-13 21:18:55 ----A---- C:\WINDOWS\system32\drivers\Diskdump.sys
2017-12-13 21:18:55 ----A---- C:\WINDOWS\system32\cscript.exe
2017-12-13 21:18:54 ----A---- C:\WINDOWS\system32\scrobj.dll
2017-12-13 21:18:54 ----A---- C:\WINDOWS\system32\drivers\luafv.sys
2017-12-13 21:18:53 ----A---- C:\WINDOWS\system32\wscript.exe
2017-12-13 21:18:53 ----A---- C:\WINDOWS\system32\drivers\vwifimp.sys
2017-12-13 21:18:52 ----A---- C:\WINDOWS\system32\CertPKICmdlet.dll
2017-12-13 21:18:51 ----A---- C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2017-12-13 21:18:51 ----A---- C:\WINDOWS\system32\drivers\Dumpstorport.sys
2017-12-13 21:18:50 ----A---- C:\WINDOWS\system32\DataUsageLiveTileTask.exe
2017-12-13 21:18:50 ----A---- C:\WINDOWS\system32\DataUsageHandlers.dll
2017-12-13 21:18:49 ----A---- C:\WINDOWS\system32\tzres.dll
2017-12-07 11:44:13 ----D---- C:\Program Files\Common Files\Avast Software
2017-12-03 23:50:26 ----A---- C:\WINDOWS\SYSWOW64\vcruntime140.dll
2017-12-03 23:50:26 ----A---- C:\WINDOWS\SYSWOW64\vccorlib140.dll
2017-12-03 23:50:26 ----A---- C:\WINDOWS\SYSWOW64\msvcp140.dll
2017-12-03 23:50:24 ----A---- C:\WINDOWS\SYSWOW64\concrt140.dll
2017-12-03 23:38:38 ----A---- C:\WINDOWS\system32\vcruntime140.dll
2017-12-03 23:38:38 ----A---- C:\WINDOWS\system32\vccorlib140.dll
2017-12-03 23:38:38 ----A---- C:\WINDOWS\system32\msvcp140.dll
2017-12-03 23:38:38 ----A---- C:\WINDOWS\system32\concrt140.dll

======List of files/folders modified in the last 1 month======

2017-12-30 17:15:11 ----RD---- C:\Program Files
2017-12-30 17:14:54 ----D---- C:\ProgramData\NVIDIA
2017-12-30 17:13:30 ----D---- C:\WINDOWS\Temp
2017-12-30 17:11:21 ----A---- C:\WINDOWS\win.ini
2017-12-30 17:10:28 ----D---- C:\WINDOWS\system32\sru
2017-12-30 17:09:02 ----D---- C:\WINDOWS\Prefetch
2017-12-30 16:40:15 ----AD---- C:\Windows
2017-12-30 16:37:11 ----D---- C:\WINDOWS\system32\drivers
2017-12-30 16:37:11 ----D---- C:\ProgramData\Malwarebytes
2017-12-30 16:27:18 ----D---- C:\ProgramData\AVAST Software
2017-12-30 16:25:30 ----D---- C:\WINDOWS\System32
2017-12-30 16:25:07 ----D---- C:\WINDOWS\system32\Tasks
2017-12-30 16:24:02 ----HD---- C:\ProgramData
2017-12-30 16:15:15 ----D---- C:\WINDOWS\system32\config
2017-12-29 22:55:45 ----D---- C:\Users\Milan\AppData\Roaming\FileZilla
2017-12-29 22:37:52 ----SHDC---- C:\WINDOWS\Installer
2017-12-29 22:27:42 ----D---- C:\WINDOWS\system32\SleepStudy
2017-12-29 22:23:38 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-12-29 22:04:19 ----HD---- C:\WINDOWS\msdownld.tmp
2017-12-29 22:02:10 ----D---- C:\Program Files (x86)\PMDG Operations Center
2017-12-29 22:00:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-12-29 21:55:45 ----D---- C:\ProgramData\Package Cache
2017-12-29 21:21:25 ----D---- C:\WINDOWS\AppReadiness
2017-12-29 21:21:19 ----HD---- C:\Program Files\WindowsApps
2017-12-29 21:20:03 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2017-12-29 21:14:02 ----D---- C:\WINDOWS\system32\catroot2
2017-12-29 20:43:59 ----SHD---- C:\System Volume Information
2017-12-29 19:37:20 ----AD---- C:\Program Files (x86)\Opera
2017-12-27 22:14:41 ----SD---- C:\Users\Milan\AppData\Roaming\Microsoft
2017-12-27 22:11:05 ----RD---- C:\Program Files (x86)
2017-12-26 19:48:01 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-12-26 19:46:39 ----D---- C:\Users\Milan\AppData\Roaming\EZCA
2017-12-26 10:54:51 ----D---- C:\WINDOWS\rescache
2017-12-26 10:43:05 ----RD---- C:\WINDOWS\Microsoft.NET
2017-12-26 09:50:17 ----D---- C:\ProgramData\InstallShield
2017-12-26 09:48:00 ----D---- C:\WINDOWS\SysWOW64
2017-12-26 09:37:24 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2017-12-24 21:36:12 ----D---- C:\WINDOWS\system32\WDI
2017-12-24 16:59:08 ----RSD---- C:\WINDOWS\assembly
2017-12-24 15:31:31 ----SD---- C:\ProgramData\Microsoft
2017-12-24 13:33:46 ----D---- C:\WINDOWS\WinSxS
2017-12-24 12:33:37 ----D---- C:\Program Files (x86)\SquawkBox
2017-12-24 12:19:29 ----RSD---- C:\WINDOWS\Fonts
2017-12-24 11:58:39 ----D---- C:\Program Files (x86)\EZCA
2017-12-24 11:55:49 ----AD---- C:\Program Files (x86)\PokerStars
2017-12-24 09:50:31 ----D---- C:\Users\Milan\AppData\Roaming\Spotify
2017-12-24 08:32:40 ----D---- C:\Program Files (x86)\Navigraph
2017-12-23 15:13:50 ----D---- C:\Program Files (x86)\MSI Afterburner
2017-12-23 14:46:26 ----D---- C:\WINDOWS\Logs
2017-12-23 12:50:41 ----D---- C:\ProgramData\Esellerate
2017-12-23 12:50:41 ----D---- C:\Program Files (x86)\Common Files
2017-12-20 19:38:19 ----AD---- C:\Program Files (x86)\QuickTime
2017-12-20 19:36:48 ----D---- C:\Program Files (x86)\Internet Explorer
2017-12-17 13:22:03 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2017-12-17 13:21:37 ----D---- C:\Program Files\Common Files
2017-12-17 13:21:37 ----AD---- C:\Program Files\Common Files\microsoft shared
2017-12-17 13:20:23 ----AD---- C:\Program Files\Microsoft Office
2017-12-14 17:44:10 ----DC---- C:\WINDOWS\Panther
2017-12-14 17:42:05 ----D---- C:\WINDOWS\INF
2017-12-14 17:38:42 ----D---- C:\WINDOWS\system32\DriverStore
2017-12-14 17:34:38 ----SD---- C:\WINDOWS\UpdateAssistantV2
2017-12-14 17:34:38 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-12-14 17:34:33 ----D---- C:\WINDOWS\system32\wbem
2017-12-14 17:34:33 ----D---- C:\WINDOWS\system32\oobe
2017-12-14 17:34:33 ----D---- C:\WINDOWS\system32\cs-CZ
2017-12-14 17:34:33 ----D---- C:\WINDOWS\system32\appraiser
2017-12-14 17:34:32 ----D---- C:\WINDOWS\ShellExperiences
2017-12-14 17:34:31 ----D---- C:\WINDOWS\Provisioning
2017-12-14 17:34:31 ----D---- C:\WINDOWS\AppPatch
2017-12-14 17:34:31 ----D---- C:\Program Files\Windows Photo Viewer
2017-12-14 17:34:31 ----D---- C:\Program Files\Windows Media Player
2017-12-14 17:34:31 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-12-14 17:34:31 ----D---- C:\Program Files (x86)\Windows Media Player
2017-12-14 17:23:27 ----D---- C:\Program Files (x86)\DsNET Corp
2017-12-14 17:10:02 ----AD---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-12-14 17:04:44 ----D---- C:\WINDOWS\Minidump
2017-12-14 17:02:30 ----AD---- C:\Program Files\CCleaner
2017-12-14 16:58:17 ----D---- C:\WINDOWS\system32\Macromed
2017-12-14 16:58:15 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-12-14 16:10:24 ----D---- C:\WINDOWS\CbsTemp
2017-12-14 15:59:41 ----D---- C:\WINDOWS\system32\MRT
2017-12-13 22:36:31 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-13 22:36:14 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-12-02 03:25:51 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2017-03-18 49568]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2017-03-18 54272]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-03-18 8192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2009-07-27 90544]
R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-06-27 88632]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2017-03-18 14336]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2017-03-18 50688]
R2 rzpmgrk;rzpmgrk; \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys [2016-09-17 44144]
R2 rzpnk;rzpnk; \??\C:\WINDOWS\system32\drivers\rzpnk.sys [2016-09-07 137840]
R3 athur;@oem25.inf,%ATHR.Service.DispName%;Atheros AR9271 Wireless Network Adapter Service; C:\WINDOWS\System32\drivers\athurx.sys [2010-01-05 1847296]
R3 dc3d;@oem12.inf,%dc3d.SvcDesc%;MS Hardware Device Detection Driver; C:\WINDOWS\system32\DRIVERS\dc3d.sys [2012-06-26 52320]
R3 chdrvr01;@oem24.inf,%CHDRVR01.SvcDesc%;chdrvr01; C:\WINDOWS\System32\drivers\chdrvr01.sys [2012-08-25 248496]
R3 chdrvr02;@oem17.inf,%CHDRVR02.SvcDesc%;chdrvr02; C:\WINDOWS\System32\drivers\chdrvr02.sys [2012-08-25 11440]
R3 chdrvr03;@oem32.inf,%CHDRVR03.SvcDesc%;chdrvr03; C:\WINDOWS\System32\drivers\chdrvr03.sys [2012-08-25 24240]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\WINDOWS\system32\DRIVERS\ikbevent.sys [2014-05-27 22216]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\WINDOWS\system32\DRIVERS\imsevent.sys [2014-05-27 22728]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-12-10 3771352]
R3 ISCT;@oem6.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\WINDOWS\System32\drivers\ISCTD.sys [2014-05-27 44744]
R3 iwdbus;@oem13.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-09-26 27032]
R3 MBfilt;MBfilt; C:\WINDOWS\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MEIx64;@oem43.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2013-09-17 99288]
R3 moufiltr;@oem44.inf,%WalMoufiltr.Desc%;Tablet Mouse Filter Driver; C:\WINDOWS\System32\drivers\moufiltr.sys [2009-03-08 7680]
R3 NuidFltr;@oem1.inf,%NuidFltr.SvcDesc%;NUID filter driver; C:\WINDOWS\System32\drivers\NuidFltr.sys [2012-06-26 23648]
R3 NVHDA;@oem50.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2017-11-09 233904]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [2017-11-09 16936048]
R3 nvvad_WaveExtensible;@oem21.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2017-08-18 48064]
R3 nvvhci;@oem15.inf,%ServiceDesc%;NVVHCI Enumerator Service; C:\WINDOWS\System32\drivers\nvvhci.sys [2017-08-18 57792]
R3 Point64;@oem31.inf,%point64.SvcDesc%;Microsoft Mouse and Keyboard Center Filter Driver; C:\WINDOWS\System32\drivers\point64.sys [2012-06-26 46176]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2017-03-18 604160]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-03-18 123808]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-03-18 103328]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-03-18 64416]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2017-03-18 58784]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2017-03-18 61848]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2017-03-18 91040]
S2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2017-03-18 12288]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-03-18 20480]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2017-03-18 17920]
S3 AppvStrm;@%systemroot%\system32\drivers\AppvStrm.sys,-101; C:\WINDOWS\system32\drivers\AppvStrm.sys [2017-03-20 127904]
S3 AppvVemgr;@%systemroot%\system32\drivers\AppvVemgr.sys,-101; C:\WINDOWS\system32\drivers\AppvVemgr.sys [2017-03-20 161696]
S3 AppvVfs;@%systemroot%\system32\drivers\AppvVfs.sys,-101; C:\WINDOWS\system32\drivers\AppvVfs.sys [2017-03-20 143776]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-09-05 39424]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2017-03-18 53664]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2017-03-18 122880]
S3 FARMNTIO;FARMNTIO; \??\c:\windows\system32\drivers\farmntio.sys [2012-01-11 24664]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-03-18 21504]
S3 GPU-Z;GPU-Z; \??\C:\Users\Milan\AppData\Local\Temp\GPU-Z.sys []
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-03-18 51104]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2017-03-18 74648]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-03-18 347032]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-03-18 2104224]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2017-03-18 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2017-03-18 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-03-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-03-18 85504]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-03-18 165376]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-03-18 168448]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2017-03-18 526240]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-03-18 36864]
S3 intaud_WaveExtensible;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-09-26 39320]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2017-03-18 120320]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2017-03-18 405408]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2017-03-18 51104]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-03-18 842656]
S3 MsSecFlt;@%SystemRoot%\System32\Drivers\mssecflt.sys,-1001; C:\WINDOWS\system32\drivers\mssecflt.sys [2017-03-20 230816]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2017-03-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2017-03-18 122368]
S3 NTIOLib_1_0_1;NTIOLib_1_0_1; \??\C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [2009-10-06 14136]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [2010-10-22 14136]
S3 NTIOLib_MSISMB_CC;NTIOLib_MSISMB_CC; \??\C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [2012-11-09 13368]
S3 nvdimmn;@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver; C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-03-18 80896]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-08-18 30144]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2017-03-18 101376]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2017-03-18 936864]
S3 SDFRd;@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector; C:\WINDOWS\System32\drivers\SDFRd.sys [2017-03-18 31128]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter; C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-03-20 40352]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-03-28 82640]
R2 AdobeUpdateService;AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-10-12 744640]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2017-08-23 2257016]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 CDPUserSvc_958e1;Uživatelská služba platformy připojených zařízení_958e1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2017-12-07 7760552]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 FSLabs Service;FSLabs Service; D:\FlightSimLabs\FSLSpotLights\FSLService\FSLService.exe [2017-02-05 85168]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-17 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-17 390616]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\WINDOWS\SysWOW64\nlssrv32.exe [2011-02-15 66560]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-08-18 512960]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-10-27 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-08-18 449984]
R2 OneSyncSvc_958e1;Hostitel synchronizace_958e1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 RzKLService;RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [2016-09-28 133376]
R2 SecurityHealthService;@%systemroot%\system32\SecurityHealthAgent.dll,-1002; C:\WINDOWS\system32\SecurityHealthService.exe [2017-09-30 336320]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 PimIndexMaintenanceSvc_958e1;Data kontaktů_958e1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-07-18 317408]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2015-02-09 72704]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-12-14 272384]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 Apache24_php55;Apache24_php55; C:\web\Apache Software Foundation\Apache2.4\bin\httpd.exe [2015-07-22 29184]
S3 Apache24_php56;Apache24_php56; C:\web\Apache Software Foundation\Apache2.4\bin\httpd.exe [2015-07-22 29184]
S3 Apache24VC10_php52;Apache24VC10_php52; C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe [2015-07-12 22528]
S3 Apache24VC10_php53;Apache24VC10_php53; C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe [2015-07-12 22528]
S3 Apache24VC10_php54;Apache24VC10_php54; C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe [2015-07-12 22528]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevicesFlowUserSvc_958e1;Tok zařízení_958e1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-03-18 86528]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 FileZilla Server;FileZilla Server FTP server; C:\web\FileZilla Server\FileZilla Server.exe [2015-06-12 794584]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2017-12-29 1237992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2017-02-10 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [2014-01-28 520416]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService_958e1;Služba zasílání zpráv_958e1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-12-29 194000]
S3 MySQL5;MySQL5; C:\web\MySQL\MySQL Server 5.5\bin\mysqld --defaults-file=C:\web\MySQL\MySQL Server 5.5\my.ini MySQL5 []
S3 MySQL57;MySQL57; C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe [2015-10-12 38587904]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-08-18 512960]
S3 Origin Client Service;Origin Client Service; F:\Games\Origin\OriginClientService.exe [2014-12-26 1903472]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-12-07 257704]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 Razer Game Scanner Service;Razer Game Scanner; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [2016-09-25 189264]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 SEMgrSvc;@%SystemRoot%\System32\SEMgrSvc.dll,-1001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 Sense;@%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2017-03-20 3913064]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2017-03-18 1284608]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 spectrum;@%systemroot%\system32\spectrum.exe,-101; C:\WINDOWS\system32\spectrum.exe [2017-03-18 891904]
S4 AppVClient;@%systemroot%\system32\AppVClient.exe,-102; C:\WINDOWS\system32\AppVClient.exe [2017-09-30 849816]
S4 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2014-09-18 1723856]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119666
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesy hostitele služby nonstop zatěžují CPU

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Re: Procesy hostitele služby nonstop zatěžují CPU

#3 Příspěvek od meiilax »

# AdwCleaner 7.0.6.0 - Logfile created on Sat Dec 30 17:06:28 2017
# Updated on 2017/21/12 by Malwarebytes
# Database: 12-29-2017.1
# Running on Windows 10 Pro (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [1448 B] - [2017/12/30 16:35:22]
C:/AdwCleaner/AdwCleaner[S0].txt - [1310 B] - [2017/12/30 16:34:39]


########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119666
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesy hostitele služby nonstop zatěžují CPU

#4 Příspěvek od Rudy »

Toto je OK. Teď dejte log FRST: https://forum.viry.cz/viewtopic.php?f=13&t=152707 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Re: Procesy hostitele služby nonstop zatěžují CPU

#5 Příspěvek od meiilax »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-12-2017
Ran by Milan (administrator) on MILAN-PC (30-12-2017 18:13:15)
Running from C:\Users\Milan\Desktop
Loaded Profiles: Milan (Available Profiles: Milan)
Platform: Windows 10 Pro Version 1703 15063.786 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Flight Sim Labs Ltd.) D:\FlightSimLabs\FSLSpotLights\FSLService\FSLService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
() C:\Windows\System32\atwtusb.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
() C:\Windows\System32\atwtusb.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.10.572.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\itype.exe
() C:\Windows\System32\AtwtusbIcon.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Milan\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506136 2013-12-06] (Realtek Semiconductor)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Device Center\ipoint.exe [2004584 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Device Center\itype.exe [1464928 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [AtwtusbIcon] => C:\WINDOWS\system32\AtwtusbIcon.exe [3593728 2012-09-10] ()
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [ControlCenterCount] => C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [872448 2012-03-26] (MSI CO.,LTD.)
HKLM-x32\...\Run: [Navigraph FMS Data Manager] => C:\Program Files (x86)\Navigraph\FMS Data Manager\NGFMSAgent.exe [992360 2017-12-01] (Navigraph)
HKLM-x32\...\Run: [FileZilla Server Interface] => C:\web\FileZilla Server\FileZilla Server Interface.exe [2462680 2015-06-12] (FileZilla Project)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-10-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RazerCortex] => C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe [222160 2016-09-28] (Razer Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1160408 2017-03-28] (Adobe Systems Incorporated)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-649847758-3809949159-3738805346-1000\...\Run: [Google Update] => C:\Users\Milan\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-16] (Google Inc.)
HKU\S-1-5-21-649847758-3809949159-3738805346-1000\...\Run: [World of Tanks] => F:\Games\World_of_Tanks\WargamingGameUpdater.exe [3135752 2016-11-18] (Wargaming.net)
HKU\S-1-5-21-649847758-3809949159-3738805346-1000\...\Run: [S3AutomaticSTART] => C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe [31649680 2018-01-01] (CÍGLER SOFTWARE, a.s.)
HKU\S-1-5-21-649847758-3809949159-3738805346-1000\...\Run: [S3Automatic] => C:\Program Files (x86)\CIGLER SOFTWARE\Money S3\MS3Auto.exe [31649680 2018-01-01] (CÍGLER SOFTWARE, a.s.)
HKU\S-1-5-21-649847758-3809949159-3738805346-1000\...\Run: [Spotify Web Helper] => C:\Users\Milan\AppData\Roaming\Spotify\SpotifyWebHelper.exe [777840 2017-10-21] (Spotify Ltd)
HKU\S-1-5-21-649847758-3809949159-3738805346-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
ShellExecuteHooks-x32: No Name - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - -> No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{3915bc1b-4d7d-4165-93b9-73dffb579dfe}: [DhcpNameServer] 213.46.172.37 213.46.172.36

Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2017-12-17] (Microsoft Corporation)
BHO: DebugBar BHO -> {69FC0024-10EB-480A-BBF2-3BF4E78E17B1} -> C:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.x64.dll [2015-03-03] (Core Services)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-08-13] (Oracle Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-12-17] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-13] (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-12-17] (Microsoft Corporation)
BHO-x32: No Name -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> No File
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-12-17] (Microsoft Corporation)
Toolbar: HKLM - DebugBar (Toolbar) - {3E1201F4-1707-409F-BB45-A5F192381DA0} - C:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.x64.dll [2015-03-03] (Core Services)
Toolbar: HKLM-x32 - DebugBar (Toolbar) - {3E1201F4-1707-409F-BB45-A5F192381DA0} - C:\Program Files (x86)\Core Services\DebugBar\DebugToolBar.dll [2015-03-03] (Core Services)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-12-17] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Milan\AppData\Roaming\TomTom\HOME\Profiles\cht73hv0.default [2015-07-08]
FF Extension: (No Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [not found]
FF ProfilePath: C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default [2017-12-30]
FF NetworkProxy: Mozilla\Firefox\Profiles\txlqgp5i.default -> type", 4
FF Session Restore: Mozilla\Firefox\Profiles\txlqgp5i.default -> is enabled.
FF Extension: (20-20 3D Viewer - IKEA) - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\Extensions\2020Player_IKEA@2020Technologies.com [2016-05-24] [Legacy]
FF Extension: (ADB Helper) - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\Extensions\adbhelper@mozilla.org [2017-10-04] [Legacy]
FF Extension: (Firebug) - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\Extensions\firebug@software.joehewitt.com.xpi [2017-03-01] [Legacy]
FF Extension: (Valence) - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\Extensions\fxdevtools-adapters@mozilla.org [2017-10-04] [Legacy]
FF Extension: (Avast Passwords) - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\Extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi [2017-11-16]
FF Extension: (SEOProfesional) - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\Extensions\seo@profesional.xpi [2016-04-29] [Legacy]
FF Extension: (Web Developer) - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2017-04-10] [Legacy]
FF SearchPlugin: C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\txlqgp5i.default\searchplugins\google-avast.xml [2015-01-25]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2017-12-14] ()
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-13] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-13] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [No File]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-12-17] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-12] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2017-12-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-12-17] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2017-12-17] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-12] (Adobe Systems)
FF Plugin HKU\S-1-5-21-649847758-3809949159-3738805346-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Milan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-649847758-3809949159-3738805346-1000: @talk.google.com/O1DPlugin -> C:\Users\Milan\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-649847758-3809949159-3738805346-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Milan\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-649847758-3809949159-3738805346-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Milan\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Milan\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Milan\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> about:blank
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default [2017-12-30]
CHR Extension: (Disk Google) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-29]
CHR Extension: (YouTube) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-29]
CHR Extension: (Facebook) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2017-03-29]
CHR Extension: (Kalendář Google) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-03-29]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2017-03-29]
CHR Extension: (Avast Passwords) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2017-12-25]
CHR Extension: (Avast SafePrice) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-12-25]
CHR Extension: (Dokumenty Google offline) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-29]
CHR Extension: (AdBlock) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-12-09]
CHR Extension: (Avast Online Security) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-10-09]
CHR Extension: (NetBeans Connector) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hafdlehgocfcodbgjnpecfajgkeejnaa [2015-09-16]
CHR Extension: (World Time Buddy) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdhpjomiingppeefgnohkiapmnaeakoj [2017-03-29]
CHR Extension: (AudioSauna) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2017-03-29]
CHR Extension: (Mapy Google) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-03-29]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2017-03-29]
CHR Extension: (PHP Docs-to-go) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlilmganaobieaclflbciblffhaagnip [2014-10-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-27]
CHR Extension: (SEO for Chrome) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\oangcciaeihlfmhppegpdceadpfaoclj [2017-03-29]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2014-10-20]
CHR Extension: (Gmail) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-14]
CHR Extension: (RSS Feed Reader) - C:\Users\Milan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp [2017-12-27]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2015-02-09] (Adobe Systems) [File not signed]
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-12] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2257016 2017-08-23] (Adobe Systems, Incorporated)
S3 Apache24VC10_php52; C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe [22528 2015-07-12] (Apache Software Foundation) [File not signed]
S3 Apache24VC10_php53; C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe [22528 2015-07-12] (Apache Software Foundation) [File not signed]
S3 Apache24VC10_php54; C:\web\Apache Software Foundation\Apache2.4_VC10\bin\httpd.exe [22528 2015-07-12] (Apache Software Foundation) [File not signed]
S3 Apache24_php55; C:\web\Apache Software Foundation\Apache2.4\bin\httpd.exe [29184 2015-07-22] (Apache Software Foundation) [File not signed]
S3 Apache24_php56; C:\web\Apache Software Foundation\Apache2.4\bin\httpd.exe [29184 2015-07-22] (Apache Software Foundation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7760552 2017-12-07] (Microsoft Corporation)
S3 FileZilla Server; C:\web\FileZilla Server\FileZilla Server.exe [794584 2015-06-12] (FileZilla Project)
R2 FSLabs Service; D:\FlightSimLabs\FSLSpotLights\FSLService\FSLService.exe [85168 2017-02-05] (Flight Sim Labs Ltd.)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2014-01-28] (Futuremark)
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-17] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
S4 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1723856 2014-09-18] (Micro-Star International)
S3 MySQL5; C:\web\MySQL\MySQL Server 5.5\my.ini [8905 2012-09-28] () [File not signed]
S3 MySQL57; C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe [38587904 2015-10-12] () [File not signed]
R2 nlsX86cc; C:\WINDOWS\SysWOW64\nlssrv32.exe [66560 2011-02-15] (Nalpeiron Ltd.) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [512960 2017-08-18] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [512960 2017-08-18] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-10-27] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-08-18] (NVIDIA Corporation)
S3 Origin Client Service; F:\Games\Origin\OriginClientService.exe [1903472 2014-12-26] (Electronic Arts)
S3 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [133376 2016-09-28] (Razer Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-20] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-11] (Microsoft Corporation)
R2 WTService; C:\WINDOWS\system32\atwtusb.exe [581120 2012-09-20] () [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [24664 2012-01-11] ()
R3 ikbevent; C:\WINDOWS\system32\DRIVERS\ikbevent.sys [22216 2014-05-27] ()
R3 imsevent; C:\WINDOWS\system32\DRIVERS\imsevent.sys [22728 2014-05-27] ()
R3 ISCT; C:\WINDOWS\System32\drivers\ISCTD.sys [44744 2014-05-27] ()
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2017-12-30] (Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-17] (Intel Corporation)
R3 moufiltr; C:\WINDOWS\System32\drivers\moufiltr.sys [7680 2009-03-08] (Windows (R) Codename Longhorn DDK provider)
S3 NTIOLib_1_0_1; C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [14136 2009-10-06] (MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MSI)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-08-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48064 2017-08-18] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-08-18] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-03-18] (Realtek )
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 TabletFilter; C:\WINDOWS\System32\drivers\TabletFilter.sys [7680 2012-08-15] (Windows (R) Win 7 DDK provider)
R3 vhidmini; C:\WINDOWS\System32\drivers\walvhid.sys [7552 2009-08-26] (Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
S3 GPU-Z; \??\C:\Users\Milan\AppData\Local\Temp\GPU-Z.sys [X] <==== ATTENTION

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-30 18:13 - 2017-12-30 18:13 - 000028150 _____ C:\Users\Milan\Desktop\FRST.txt
2017-12-30 18:11 - 2017-12-30 18:11 - 000112640 _____ (forum.viry.cz) C:\Users\Milan\Desktop\FRSTLauncher.exe
2017-12-30 18:11 - 2017-12-30 18:11 - 000047093 _____ C:\Users\Milan\Downloads\Addition.txt
2017-12-30 18:10 - 2017-12-30 18:11 - 000078433 _____ C:\Users\Milan\Downloads\FRST.txt
2017-12-30 18:10 - 2017-12-30 18:10 - 000000000 ____D C:\FRST
2017-12-30 18:09 - 2017-12-30 18:09 - 002391552 _____ (Farbar) C:\Users\Milan\Desktop\FRST64.exe
2017-12-30 18:04 - 2017-12-30 18:04 - 008198432 _____ (Malwarebytes) C:\Users\Milan\Downloads\adwcleaner_7.0.6.0(1).exe
2017-12-30 18:02 - 2017-12-30 18:02 - 000000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-649847758-3809949159-3738805346-1000
2017-12-30 17:54 - 2017-12-30 17:54 - 001931969 _____ C:\Users\Milan\Downloads\ProcessExplorer.zip
2017-12-30 17:54 - 2017-12-30 17:54 - 000000000 ____D C:\Users\Milan\Downloads\ProcessExplorer
2017-12-30 17:41 - 2017-12-30 17:41 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2017-12-30 17:41 - 2017-12-30 17:41 - 000001914 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-12-30 17:41 - 2017-12-30 17:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-12-30 17:41 - 2017-12-30 17:41 - 000000000 ____D C:\Program Files\Malwarebytes
2017-12-30 17:41 - 2017-11-29 09:11 - 000077432 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-12-30 17:40 - 2017-12-30 17:41 - 083316440 _____ (Malwarebytes ) C:\Users\Milan\Downloads\mb3-setup-consumer-3.3.1.2183-1.0.262-1.0.3374.exe
2017-12-30 17:33 - 2017-12-30 18:06 - 000000000 ____D C:\AdwCleaner
2017-12-30 17:33 - 2017-12-30 17:33 - 008198432 _____ (Malwarebytes) C:\Users\Milan\Downloads\adwcleaner_7.0.6.0.exe
2017-12-30 17:15 - 2017-12-30 17:15 - 000000000 ____D C:\rsit
2017-12-30 17:15 - 2017-12-30 17:15 - 000000000 ____D C:\Program Files\trend micro
2017-12-30 16:10 - 2017-12-30 16:10 - 008905328 _____ (AVAST Software) C:\Users\Milan\Downloads\avastclear.exe
2017-12-30 16:09 - 2017-12-30 16:09 - 001222144 _____ C:\Users\Milan\Downloads\RSITx64.exe
2017-12-29 22:01 - 2017-12-29 22:03 - 000000000 ____D C:\Users\Milan\Documents\Flight Simulator X - Steam Edition Files
2017-12-28 15:15 - 2017-12-28 15:15 - 000586995 _____ C:\Users\Milan\Downloads\A320-214 CFM56-5B4_v4.00.per
2017-12-28 15:12 - 2017-12-28 15:12 - 000001561 _____ C:\Users\Milan\Downloads\Airbus A320-214 FSLabs.txt
2017-12-27 22:09 - 2017-12-27 22:10 - 000000000 ____D C:\EZdok Software
2017-12-27 22:09 - 2017-12-27 22:09 - 000002048 _____ C:\WINDOWS\ezcamera2.lic
2017-12-27 22:09 - 2017-12-27 22:09 - 000000626 _____ C:\Users\Milan\Desktop\Order_1360254.txt
2017-12-27 21:25 - 2017-12-27 21:25 - 022224159 _____ (FSPS) C:\Users\Milan\Downloads\FSX_Fiber_Accelerator_Setup (1).exe
2017-12-26 20:40 - 2017-12-26 20:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft - Mega Airport Frankfurt 2.0 - FSX STEAM Edition
2017-12-26 19:46 - 2017-12-27 22:11 - 000087746 _____ C:\Program Files (x86)\unEZCA2.exe
2017-12-26 19:46 - 2017-12-27 22:11 - 000000000 ____D C:\Program Files (x86)\EZCA2
2017-12-26 19:46 - 2017-12-26 19:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZCA2
2017-12-26 11:07 - 2017-12-26 11:07 - 024542999 _____ ( Flight One Software, Inc.) C:\Users\Milan\Downloads\EZdokCamera2.exe
2017-12-26 11:06 - 2017-12-26 11:06 - 000000845 _____ C:\Users\Milan\Downloads\EZdok-Upgrade-Coupon.zip
2017-12-26 11:03 - 2017-12-26 11:03 - 014499684 _____ () C:\Users\Milan\Downloads\EZCA 2.6.0.27 update.exe
2017-12-26 09:48 - 2017-12-29 22:04 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2017-12-25 08:03 - 2017-12-25 08:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Essential Plus Overdrive
2017-12-24 22:15 - 2017-12-24 22:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft - Mega Airport Prag - FSX STEAM Edition
2017-12-24 21:52 - 2017-12-24 22:03 - 000000000 ____D C:\Users\Milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flight One Software
2017-12-24 21:28 - 2017-12-24 21:30 - 114619452 _____ C:\Users\Milan\Downloads\ASNext_FSX_Update_B6255.zip
2017-12-24 21:21 - 2017-12-24 21:21 - 000000000 ____D C:\Users\Milan\AppData\Roaming\Hifi
2017-12-24 16:45 - 2017-12-24 16:45 - 000000000 ____D C:\Users\Milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PILOT'S Software
2017-12-24 13:59 - 2017-12-24 14:00 - 004233699 _____ C:\Users\Milan\Downloads\FSUIPC4.zip
2017-12-24 13:29 - 2017-12-28 14:59 - 000000000 ____D C:\Users\Milan\Desktop\FSX SE
2017-12-24 12:03 - 2017-12-24 12:03 - 000000000 ____D C:\Users\Milan\AppData\Local\Deployment
2017-12-24 11:58 - 2017-12-24 11:58 - 000076042 _____ C:\WINDOWS\Ben Gurion X Uninstall Log.txt
2017-12-24 08:47 - 2017-12-24 08:47 - 000236010 _____ C:\Users\Milan\Downloads\ezlauncher.zip
2017-12-24 08:34 - 2017-12-24 08:34 - 000000000 ____D C:\Users\Milan\AppData\Local\NavigraphChartsDesktop
2017-12-24 08:34 - 2017-12-24 08:34 - 000000000 ____D C:\Users\Milan\.QtWebEngineProcess
2017-12-24 08:34 - 2017-12-24 08:34 - 000000000 ____D C:\Users\Milan\.NavigraphChartsDesktop
2017-12-24 08:32 - 2017-12-24 08:34 - 000000000 ____D C:\Users\Milan\AppData\Roaming\Navigraph
2017-12-24 08:32 - 2017-12-24 08:32 - 000001344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph Charts Desktop.lnk
2017-12-24 08:32 - 2017-12-24 08:32 - 000001263 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph Simlink.lnk
2017-12-23 14:46 - 2017-12-23 14:46 - 000000000 ____D C:\Users\Public\Documents\FSLabs Data
2017-12-23 14:46 - 2017-12-23 14:46 - 000000000 ____D C:\Users\Milan\AppData\Local\FlightSimLabs
2017-12-23 12:50 - 2017-12-25 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlightSimLabs, Ltd
2017-12-20 19:38 - 2017-12-20 19:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2017-12-20 19:38 - 2017-12-20 19:38 - 000000000 ____D C:\ProgramData\Apple Computer
2017-12-17 13:21 - 2017-12-17 13:21 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2017-12-14 18:58 - 2017-12-14 18:58 - 001266904 _____ (Opera Software) C:\Users\Milan\Downloads\OperaSetup.exe
2017-12-14 17:02 - 2017-12-29 22:46 - 000002886 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2017-12-14 16:59 - 2017-12-14 17:01 - 011201632 _____ (Piriform Ltd) C:\Users\Milan\Downloads\ccsetup538.exe
2017-12-14 16:58 - 2017-12-29 22:46 - 000003530 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-12-14 16:57 - 2017-12-14 16:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2017-12-14 16:57 - 2017-12-14 16:57 - 000000000 ____D C:\Program Files\7-Zip
2017-12-13 21:21 - 2017-11-30 04:00 - 002166808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-12-13 21:21 - 2017-11-30 03:58 - 006763128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-12-13 21:21 - 2017-11-30 03:58 - 000702032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-12-13 21:21 - 2017-11-30 03:57 - 001123968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-12-13 21:21 - 2017-11-30 03:45 - 000119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-12-13 21:21 - 2017-11-30 03:43 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-12-13 21:21 - 2017-11-30 03:43 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-12-13 21:21 - 2017-11-30 03:42 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2017-12-13 21:21 - 2017-11-30 03:42 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2017-12-13 21:21 - 2017-11-30 03:41 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2017-12-13 21:21 - 2017-11-30 03:40 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-12-13 21:21 - 2017-11-30 03:40 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2017-12-13 21:21 - 2017-11-30 03:40 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2017-12-13 21:21 - 2017-11-30 03:38 - 001248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-12-13 21:21 - 2017-11-30 03:38 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-12-13 21:21 - 2017-11-30 03:38 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-12-13 21:21 - 2017-11-30 03:37 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-12-13 21:21 - 2017-11-30 03:36 - 001019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-12-13 21:21 - 2017-11-30 03:35 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-12-13 21:21 - 2017-11-30 03:34 - 004559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-12-13 21:21 - 2017-11-17 10:31 - 000223640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-12-13 21:21 - 2017-11-17 10:00 - 002953216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-12-13 21:21 - 2017-11-02 06:13 - 000546712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-12-13 21:21 - 2017-11-02 06:13 - 000095640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2017-12-13 21:21 - 2017-11-02 06:04 - 001292360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-12-13 21:21 - 2017-11-02 05:49 - 001838848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-12-13 21:21 - 2017-11-02 05:45 - 000613136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-12-13 21:21 - 2017-11-02 05:45 - 000362144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2017-12-13 21:21 - 2017-11-02 05:45 - 000354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-12-13 21:21 - 2017-11-02 05:45 - 000283544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2017-12-13 21:21 - 2017-11-02 05:45 - 000172952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2017-12-13 21:21 - 2017-11-02 05:45 - 000133896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2017-12-13 21:21 - 2017-11-02 05:44 - 005808640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-12-13 21:21 - 2017-11-02 05:44 - 000519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-12-13 21:21 - 2017-11-02 05:43 - 020372896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-12-13 21:21 - 2017-11-02 05:36 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-12-13 21:21 - 2017-11-02 05:35 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2017-12-13 21:21 - 2017-11-02 05:35 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-12-13 21:21 - 2017-11-02 05:32 - 008213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-12-13 21:21 - 2017-11-02 05:30 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2017-12-13 21:21 - 2017-11-02 05:30 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2017-12-13 21:21 - 2017-11-02 05:30 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2017-12-13 21:21 - 2017-11-02 05:27 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2017-12-13 21:21 - 2017-11-02 05:27 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertPKICmdlet.dll
2017-12-13 21:21 - 2017-11-02 05:26 - 005963776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-12-13 21:21 - 2017-11-02 05:26 - 002671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-12-13 21:21 - 2017-11-02 05:26 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-12-13 21:21 - 2017-11-02 05:26 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2017-12-13 21:21 - 2017-11-02 05:25 - 003377664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-12-13 21:21 - 2017-11-02 05:25 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2017-12-13 21:21 - 2017-11-02 05:25 - 000364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-12-13 21:21 - 2017-11-02 05:24 - 007598080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-12-13 21:21 - 2017-11-02 05:24 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-12-13 21:21 - 2017-11-02 05:24 - 000444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2017-12-13 21:21 - 2017-11-02 05:23 - 002516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-12-13 21:21 - 2017-11-02 05:23 - 000680960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2017-12-13 21:21 - 2017-11-02 05:23 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2017-12-13 21:21 - 2017-11-02 05:23 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dsreg.dll
2017-12-13 21:21 - 2017-11-02 05:22 - 001494528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2017-12-13 21:21 - 2017-11-02 05:21 - 004417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-12-13 21:21 - 2017-11-02 05:21 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-12-13 21:21 - 2017-10-25 08:40 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-12-13 21:21 - 2017-10-15 16:09 - 002259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-12-13 21:21 - 2017-10-15 16:01 - 000583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-12-13 21:21 - 2017-10-15 15:49 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-12-13 21:21 - 2017-10-15 15:45 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-12-13 21:21 - 2017-10-15 15:44 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-12-13 21:21 - 2017-10-15 15:42 - 005225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-12-13 21:21 - 2017-10-15 15:42 - 003667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-12-13 21:21 - 2017-10-15 15:38 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-12-13 21:20 - 2017-11-30 04:33 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-12-13 21:20 - 2017-11-30 04:23 - 001194248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-12-13 21:20 - 2017-11-30 03:59 - 023678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-12-13 21:20 - 2017-11-30 03:44 - 023679488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-12-13 21:20 - 2017-11-30 03:44 - 019334144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-12-13 21:20 - 2017-11-30 03:44 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-12-13 21:20 - 2017-11-30 03:43 - 020511232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-12-13 21:20 - 2017-11-30 03:42 - 000560640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-12-13 21:20 - 2017-11-30 03:42 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-12-13 21:20 - 2017-11-30 03:41 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-12-13 21:20 - 2017-11-30 03:40 - 012803072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-12-13 21:20 - 2017-11-30 03:40 - 000585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-12-13 21:20 - 2017-11-30 03:39 - 011888640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-12-13 21:20 - 2017-11-30 03:38 - 008195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-12-13 21:20 - 2017-11-30 03:37 - 006252544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-12-13 21:20 - 2017-11-30 03:36 - 004726784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-12-13 21:20 - 2017-11-30 03:36 - 003652096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-12-13 21:20 - 2017-11-30 03:36 - 000755200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-12-13 21:20 - 2017-11-30 03:36 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-12-13 21:20 - 2017-11-02 06:16 - 002398696 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-12-13 21:20 - 2017-11-02 06:16 - 002327448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-12-13 21:20 - 2017-11-02 06:15 - 001239448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-12-13 21:20 - 2017-11-02 06:12 - 000727336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-12-13 21:20 - 2017-11-02 06:12 - 000654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-12-13 21:20 - 2017-11-02 06:12 - 000412752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2017-12-13 21:20 - 2017-11-02 06:12 - 000319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2017-12-13 21:20 - 2017-11-02 06:12 - 000144248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2017-12-13 21:20 - 2017-11-02 06:10 - 006557520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-12-13 21:20 - 2017-11-02 06:05 - 000187800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2017-12-13 21:20 - 2017-11-02 05:34 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-12-13 21:20 - 2017-11-02 05:34 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-12-13 21:20 - 2017-11-02 05:34 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2017-12-13 21:20 - 2017-11-02 05:34 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2017-12-13 21:20 - 2017-11-02 05:30 - 013381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-12-13 21:20 - 2017-11-02 05:30 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-12-13 21:20 - 2017-11-02 05:29 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-12-13 21:20 - 2017-11-02 05:29 - 000752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-12-13 21:20 - 2017-11-02 05:27 - 002078720 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-12-13 21:20 - 2017-11-02 05:27 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2017-12-13 21:20 - 2017-11-02 05:26 - 001937408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2017-12-13 21:20 - 2017-11-02 05:25 - 012227072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-12-13 21:20 - 2017-11-02 05:25 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-12-13 21:20 - 2017-11-02 05:24 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-12-13 21:20 - 2017-11-02 05:23 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-12-13 21:20 - 2017-11-02 05:22 - 002009600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-12-13 21:20 - 2017-11-02 05:22 - 001884160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2017-12-13 21:20 - 2017-10-15 15:53 - 002969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-12-13 21:20 - 2017-10-15 15:53 - 000387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-12-13 21:20 - 2017-10-15 15:49 - 000094616 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-12-13 21:20 - 2017-10-15 15:14 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SEMgrPS.dll
2017-12-13 21:20 - 2017-10-15 15:13 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-12-13 21:20 - 2017-10-15 15:10 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-12-13 21:19 - 2017-11-30 04:33 - 001144728 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-12-13 21:19 - 2017-11-30 04:33 - 001015704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-12-13 21:19 - 2017-11-30 04:29 - 008319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-12-13 21:19 - 2017-11-30 04:26 - 002647216 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-12-13 21:19 - 2017-11-30 04:24 - 000870896 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2017-12-13 21:19 - 2017-11-30 04:23 - 007910960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-12-13 21:19 - 2017-11-30 03:44 - 000171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2017-12-13 21:19 - 2017-11-30 03:42 - 001878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-12-13 21:19 - 2017-11-30 03:42 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2017-12-13 21:19 - 2017-11-30 03:41 - 000527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-12-13 21:19 - 2017-11-30 03:39 - 003206656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-12-13 21:19 - 2017-11-30 03:39 - 002809344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-12-13 21:19 - 2017-11-30 03:39 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-12-13 21:19 - 2017-11-30 03:38 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-12-13 21:19 - 2017-11-30 03:37 - 003306496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-12-13 21:19 - 2017-11-30 03:37 - 001293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-12-13 21:19 - 2017-11-30 03:36 - 005557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-12-13 21:19 - 2017-11-30 03:36 - 001802240 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-12-13 21:19 - 2017-11-30 03:36 - 001398784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 002032536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-12-13 21:19 - 2017-11-17 10:46 - 001578904 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000821656 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-12-13 21:19 - 2017-11-17 10:46 - 000678808 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000613784 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000612248 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000484248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000379288 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000259992 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000136088 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-12-13 21:19 - 2017-11-17 10:46 - 000067992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2017-12-13 21:19 - 2017-11-17 10:46 - 000034712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-12-13 21:19 - 2017-11-17 10:39 - 005477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-12-13 21:19 - 2017-11-17 10:39 - 000643200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-12-13 21:19 - 2017-11-17 10:37 - 021353200 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-12-13 21:19 - 2017-11-17 10:03 - 003668992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-12-13 21:19 - 2017-11-17 09:59 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-12-13 21:19 - 2017-11-17 09:56 - 000757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-12-13 21:19 - 2017-11-02 06:20 - 000965016 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-12-13 21:19 - 2017-11-02 06:20 - 000543640 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-12-13 21:19 - 2017-11-02 06:14 - 000667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-12-13 21:19 - 2017-11-02 06:13 - 002443672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-12-13 21:19 - 2017-11-02 06:13 - 001345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-12-13 21:19 - 2017-11-02 06:13 - 000212888 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-12-13 21:19 - 2017-11-02 06:12 - 000714648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2017-12-13 21:19 - 2017-11-02 06:12 - 000430848 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2017-12-13 21:19 - 2017-11-02 05:37 - 001278976 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-12-13 21:19 - 2017-11-02 05:37 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-12-13 21:19 - 2017-11-02 05:37 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2017-12-13 21:19 - 2017-11-02 05:37 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2017-12-13 21:19 - 2017-11-02 05:36 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2017-12-13 21:19 - 2017-11-02 05:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-12-13 21:19 - 2017-11-02 05:34 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2017-12-13 21:19 - 2017-11-02 05:33 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-12-13 21:19 - 2017-11-02 05:31 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-12-13 21:19 - 2017-11-02 05:31 - 000411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2017-12-13 21:19 - 2017-11-02 05:30 - 007339008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-12-13 21:19 - 2017-11-02 05:30 - 000719872 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2017-12-13 21:19 - 2017-11-02 05:30 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-12-13 21:19 - 2017-11-02 05:30 - 000229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-12-13 21:19 - 2017-11-02 05:29 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-12-13 21:19 - 2017-11-02 05:28 - 001468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-12-13 21:19 - 2017-11-02 05:28 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-12-13 21:19 - 2017-11-02 05:28 - 000799744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2017-12-13 21:19 - 2017-11-02 05:28 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2017-12-13 21:19 - 2017-11-02 05:27 - 000565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2017-12-13 21:19 - 2017-11-02 05:26 - 004445696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-12-13 21:19 - 2017-11-02 05:26 - 003060224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-12-13 21:19 - 2017-11-02 05:26 - 000986624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-12-13 21:19 - 2017-11-02 05:25 - 002052608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-12-13 21:19 - 2017-11-02 05:25 - 001886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-12-13 21:19 - 2017-11-02 05:25 - 001713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-12-13 21:19 - 2017-11-02 05:25 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-12-13 21:19 - 2017-11-02 05:25 - 000877568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2017-12-13 21:19 - 2017-11-02 05:24 - 004707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-12-13 21:19 - 2017-11-02 05:23 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-12-13 21:19 - 2017-11-02 05:23 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-12-13 21:19 - 2017-10-15 15:59 - 000923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-12-13 21:19 - 2017-10-15 15:57 - 000712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-12-13 21:19 - 2017-10-15 15:57 - 000409496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-12-13 21:19 - 2017-10-15 15:56 - 000872464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-12-13 21:19 - 2017-10-15 15:51 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-12-13 21:19 - 2017-10-15 15:15 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-12-13 21:19 - 2017-10-15 15:08 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-12-13 21:19 - 2017-10-15 15:05 - 004396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-12-13 21:19 - 2017-10-15 15:02 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2017-12-13 21:19 - 2017-10-15 15:00 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-12-13 21:18 - 2017-11-30 03:45 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-12-13 21:18 - 2017-11-30 03:44 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2017-12-13 21:18 - 2017-11-30 03:43 - 000164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2017-12-13 21:18 - 2017-11-30 03:42 - 000164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2017-12-13 21:18 - 2017-11-30 03:41 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2017-12-13 21:18 - 2017-11-30 03:41 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2017-12-13 21:18 - 2017-11-17 10:46 - 000190360 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-12-13 21:18 - 2017-11-17 10:41 - 000503704 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2017-12-13 21:18 - 2017-11-02 06:20 - 000469568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2017-12-13 21:18 - 2017-11-02 06:12 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2017-12-13 21:18 - 2017-11-02 06:12 - 000026472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2017-12-13 21:18 - 2017-11-02 05:35 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2017-12-13 21:18 - 2017-11-02 05:34 - 000438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2017-12-13 21:18 - 2017-11-02 05:34 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageLiveTileTask.exe
2017-12-13 21:18 - 2017-11-02 05:33 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageHandlers.dll
2017-12-13 21:18 - 2017-11-02 05:33 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2017-12-13 21:18 - 2017-11-02 05:33 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertPKICmdlet.dll
2017-12-13 21:18 - 2017-11-02 05:32 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2017-12-13 21:18 - 2017-11-02 05:32 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Storage.dll
2017-12-13 21:18 - 2017-11-02 05:31 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2017-12-13 21:18 - 2017-11-02 05:30 - 000635392 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-12-13 21:18 - 2017-11-02 05:27 - 000537600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2017-12-13 21:18 - 2017-11-02 05:19 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2017-12-13 21:18 - 2017-10-15 15:08 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-12-13 21:05 - 2017-12-13 21:05 - 000185855 _____ C:\Users\Milan\Downloads\kid-cz-11-2017-cz-cs_en.pdf
2017-12-07 11:44 - 2017-12-07 11:44 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2017-12-06 09:17 - 2017-12-06 09:17 - 000191429 _____ C:\Users\Milan\Downloads\navod-moa.pdf
2017-12-06 09:16 - 2017-12-06 09:16 - 000222539 _____ C:\Users\Milan\Downloads\navod_topna_tyc_gv.pdf
2017-12-06 09:15 - 2017-12-06 09:15 - 000402703 _____ C:\Users\Milan\Downloads\navod_gv_tyce.pdf
2017-12-05 17:10 - 2017-12-05 17:10 - 000728367 _____ C:\Users\Milan\Documents\Faktura_sušička.pdf
2017-12-03 23:50 - 2017-12-03 23:50 - 000440128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140.dll
2017-12-03 23:50 - 2017-12-03 23:50 - 000263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vccorlib140.dll
2017-12-03 23:50 - 2017-12-03 23:50 - 000242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\concrt140.dll
2017-12-03 23:50 - 2017-12-03 23:50 - 000083792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vcruntime140.dll
2017-12-03 23:38 - 2017-12-03 23:38 - 000641696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp140.dll
2017-12-03 23:38 - 2017-12-03 23:38 - 000389296 _____ (Microsoft Corporation) C:\WINDOWS\system32\vccorlib140.dll
2017-12-03 23:38 - 2017-12-03 23:38 - 000331432 _____ (Microsoft Corporation) C:\WINDOWS\system32\concrt140.dll
2017-12-03 23:38 - 2017-12-03 23:38 - 000087728 _____ (Microsoft Corporation) C:\WINDOWS\system32\vcruntime140.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-30 17:41 - 2012-09-29 11:29 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-12-30 17:40 - 2017-10-06 19:32 - 000000000 ____D C:\ProgramData\NVIDIA
2017-12-30 17:38 - 2016-12-01 11:25 - 000000000 ____D C:\Users\Milan\AppData\LocalLow\Mozilla
2017-12-30 17:36 - 2017-10-06 20:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-12-30 17:36 - 2009-07-14 03:30 - 000000695 _____ C:\WINDOWS\win.ini
2017-12-30 17:35 - 2017-03-18 12:40 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2017-12-30 17:30 - 2012-09-28 20:25 - 000000000 ____D C:\Users\Milan\Documents\Soubory aplikace Outlook
2017-12-30 17:29 - 2017-10-06 19:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-12-30 17:10 - 2017-10-06 19:33 - 000000000 ____D C:\Users\Milan
2017-12-30 16:41 - 2013-03-10 18:22 - 000000000 ____D C:\Users\Milan\Documents\ccleaner_registrybackup
2017-12-30 16:27 - 2013-11-04 12:25 - 000000000 ____D C:\ProgramData\AVAST Software
2017-12-30 16:18 - 2015-12-04 20:55 - 000000980 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA.job
2017-12-30 16:18 - 2015-12-04 20:55 - 000000928 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core.job
2017-12-30 16:13 - 2017-06-14 19:42 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-12-29 22:55 - 2012-09-29 10:24 - 000000000 ____D C:\Users\Milan\AppData\Roaming\FileZilla
2017-12-29 22:46 - 2017-10-06 20:01 - 000003654 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA
2017-12-29 22:46 - 2017-10-06 20:01 - 000003602 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA1d2589a1aa26edb
2017-12-29 22:46 - 2017-10-06 20:01 - 000003398 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000003398 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-12-29 22:46 - 2017-10-06 20:01 - 000003386 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core
2017-12-29 22:46 - 2017-10-06 20:01 - 000003338 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4B4B6258-B3AE-4210-BFDC-46145CB0EE12}
2017-12-29 22:46 - 2017-10-06 20:01 - 000003334 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core1d2589a1a98f6ac
2017-12-29 22:46 - 2017-10-06 20:01 - 000003294 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1382555172
2017-12-29 22:46 - 2017-10-06 20:01 - 000003176 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000003174 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-12-29 22:46 - 2017-10-06 20:01 - 000002984 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002968 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002956 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002856 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-649847758-3809949159-3738805346-1000
2017-12-29 22:46 - 2017-10-06 20:01 - 000002838 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002786 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002744 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002588 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2017-12-29 22:46 - 2017-10-06 20:01 - 000002412 _____ C:\WINDOWS\System32\Tasks\{5C371ABD-959A-4DCE-97FA-ECDB2E353BA3}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002326 _____ C:\WINDOWS\System32\Tasks\{AE8F5AAB-6006-4AF2-83E1-C3A59DF04B28}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002302 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe
2017-12-29 22:46 - 2017-10-06 20:01 - 000002300 _____ C:\WINDOWS\System32\Tasks\{19550D02-41E1-43BA-A29D-9B6D691DADA9}
2017-12-29 22:46 - 2017-10-06 20:01 - 000002290 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2017-12-29 22:46 - 2017-10-06 20:01 - 000002288 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2017-12-29 22:46 - 2017-10-06 20:01 - 000002234 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-12-29 22:46 - 2017-10-06 20:01 - 000002180 _____ C:\WINDOWS\System32\Tasks\{C332A3FE-9B5C-41DF-962D-84FA4FB18BE1}
2017-12-29 22:45 - 2015-01-08 22:16 - 000000000 ____D C:\Users\Milan\Documents\Flight Simulator X Files
2017-12-29 22:23 - 2013-01-20 09:59 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-12-29 22:04 - 2013-07-08 18:06 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
2017-12-29 22:02 - 2015-01-16 19:28 - 000000000 ____D C:\Program Files (x86)\PMDG Operations Center
2017-12-29 22:00 - 2012-09-28 17:44 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-12-29 21:55 - 2014-12-26 21:01 - 000000000 ____D C:\ProgramData\Package Cache
2017-12-29 21:55 - 2012-09-30 15:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMDG Simulations
2017-12-29 21:44 - 2012-12-02 00:03 - 000000000 ____D C:\Users\Milan\AppData\Local\Packages
2017-12-29 21:21 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-12-29 21:21 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-12-29 21:20 - 2015-08-10 11:30 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-12-29 21:20 - 2013-01-01 12:27 - 000001137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-12-29 19:37 - 2012-09-28 18:49 - 000000000 ____D C:\Program Files (x86)\Opera
2017-12-29 19:29 - 2015-01-16 22:48 - 000000000 ____D C:\Users\Public\Documents\PFPX Data
2017-12-29 18:36 - 2012-10-09 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aerosoft
2017-12-28 14:53 - 2012-10-10 19:55 - 000000000 ____D C:\Users\Milan\Desktop\FSX
2017-12-27 21:11 - 2015-02-01 13:26 - 000000000 ____D C:\Users\Milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orbx
2017-12-26 19:48 - 2017-10-06 19:58 - 002061690 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-12-26 19:48 - 2017-03-20 05:39 - 000895056 _____ C:\WINDOWS\system32\perfh005.dat
2017-12-26 19:48 - 2017-03-20 05:39 - 000194668 _____ C:\WINDOWS\system32\perfc005.dat
2017-12-26 19:46 - 2015-01-11 14:36 - 000000000 ____D C:\Users\Milan\AppData\Roaming\EZCA
2017-12-26 10:54 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\rescache
2017-12-26 09:50 - 2012-10-27 15:22 - 000000000 ____D C:\ProgramData\InstallShield
2017-12-26 09:37 - 2010-11-21 04:27 - 000545440 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-12-24 21:21 - 2015-01-11 14:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiFi
2017-12-24 14:26 - 2016-06-07 15:22 - 000000026 _____ C:\Users\Milan\AppData\Local\isoworkshop.ini
2017-12-24 12:52 - 2013-09-22 17:52 - 000000000 ____D C:\Users\Milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-12-24 12:35 - 2017-10-08 11:35 - 005321456 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-12-24 12:33 - 2012-12-22 16:32 - 000000000 ____D C:\Program Files (x86)\SquawkBox
2017-12-24 12:24 - 2013-12-25 11:05 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-12-24 12:21 - 2015-01-12 20:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlyTampa
2017-12-24 12:19 - 2013-10-19 21:24 - 000000000 ____D C:\Users\Milan\Documents\EuroScope
2017-12-24 12:03 - 2015-01-22 16:43 - 000000000 ____D C:\Users\Milan\AppData\Local\vPilot
2017-12-24 11:58 - 2016-11-15 16:22 - 000000000 ____D C:\Program Files (x86)\EZCA
2017-12-24 11:55 - 2013-04-13 21:27 - 000000000 ____D C:\Users\Milan\AppData\Local\PokerStars
2017-12-24 11:55 - 2013-04-13 21:26 - 000000000 ____D C:\Program Files (x86)\PokerStars
2017-12-24 09:50 - 2016-10-12 17:28 - 000000000 ____D C:\Users\Milan\AppData\Roaming\Spotify
2017-12-24 09:50 - 2016-10-12 17:28 - 000000000 ____D C:\Users\Milan\AppData\Local\Spotify
2017-12-24 08:32 - 2014-12-26 19:13 - 000000000 ____D C:\Program Files (x86)\Navigraph
2017-12-23 16:16 - 2015-01-03 18:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph FMS Data Manager
2017-12-23 15:13 - 2015-01-08 21:53 - 000001157 _____ C:\Users\Milan\Desktop\MSI Afterburner.lnk
2017-12-23 15:13 - 2015-01-08 21:52 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2017-12-23 12:50 - 2013-04-01 11:39 - 000000000 ____D C:\ProgramData\Esellerate
2017-12-20 19:38 - 2013-11-09 10:54 - 000000000 ____D C:\Program Files (x86)\QuickTime
2017-12-20 19:37 - 2017-07-09 21:01 - 000001188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2017-12-20 19:36 - 2016-01-07 18:45 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-12-17 13:22 - 2017-03-18 22:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-12-17 13:21 - 2017-03-18 22:03 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-12-17 13:20 - 2012-09-28 20:16 - 000000000 ____D C:\Program Files\Microsoft Office
2017-12-14 18:11 - 2013-08-25 17:28 - 000000000 ___RD C:\Users\Milan\Documents\kapela
2017-12-14 17:57 - 2013-11-20 19:17 - 000002208 _____ C:\Users\Public\Desktop\S3 Kasa.lnk
2017-12-14 17:57 - 2013-11-20 19:17 - 000002203 _____ C:\Users\Public\Desktop\Money S3.lnk
2017-12-14 17:44 - 2017-10-05 20:32 - 000000000 ___DC C:\WINDOWS\Panther
2017-12-14 17:42 - 2017-03-18 22:01 - 000000000 ____D C:\WINDOWS\INF
2017-12-14 17:41 - 2017-03-18 12:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-12-14 17:34 - 2017-06-14 21:50 - 000000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-12-14 17:34 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-12-14 17:34 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-12-14 17:34 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-12-14 17:34 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\Provisioning
2017-12-14 17:34 - 2017-03-18 22:03 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-12-14 17:34 - 2017-03-18 22:03 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-12-14 17:23 - 2013-01-27 19:57 - 000000000 ____D C:\Program Files (x86)\DsNET Corp
2017-12-14 17:10 - 2014-12-26 21:29 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2017-12-14 17:04 - 2017-10-21 17:03 - 000000000 ____D C:\WINDOWS\Minidump
2017-12-14 17:02 - 2013-03-10 18:17 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-12-14 17:02 - 2013-03-10 18:17 - 000000000 ____D C:\Program Files\CCleaner
2017-12-14 16:58 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-12-14 16:58 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-12-14 16:58 - 2013-12-13 19:02 - 000001141 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-12-14 16:10 - 2017-03-18 21:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-12-14 15:59 - 2013-07-28 21:22 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-12-13 22:36 - 2017-10-12 20:06 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-13 22:36 - 2012-09-30 23:27 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-12-13 19:36 - 2012-09-28 20:11 - 000002274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-12-05 19:51 - 2015-09-07 19:34 - 000002429 _____ C:\Users\Milan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-12-05 19:51 - 2015-09-07 19:34 - 000000000 ___RD C:\Users\Milan\OneDrive
2017-12-04 20:54 - 2015-03-16 17:49 - 000000132 _____ C:\Users\Milan\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
2017-12-02 19:57 - 2015-01-08 20:14 - 000000000 ____D C:\Users\Milan\AppData\Local\NVIDIA
2017-12-02 03:25 - 2017-03-18 22:06 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-12-02 03:25 - 2017-03-18 22:06 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2017-12-26 19:46 - 2017-12-27 22:11 - 000087746 _____ () C:\Program Files (x86)\unEZCA2.exe
2015-03-16 17:49 - 2017-12-04 20:54 - 000000132 _____ () C:\Users\Milan\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
2016-02-28 12:31 - 2016-12-18 22:10 - 000000000 _____ () C:\Users\Milan\AppData\Roaming\FileIn.cns
2016-02-28 12:31 - 2016-12-18 22:10 - 000000000 _____ () C:\Users\Milan\AppData\Roaming\FileOut.cns
2013-03-24 08:46 - 2016-06-07 15:21 - 000000021 _____ () C:\Users\Milan\AppData\Roaming\ISOWorkshop.ini
2014-12-08 20:03 - 2014-12-08 20:03 - 000000268 ___RH () C:\Users\Milan\AppData\Roaming\Jazz Kit
2014-12-08 20:03 - 2014-12-08 20:03 - 000000268 ___RH () C:\Users\Milan\AppData\Roaming\Jingles
2014-12-08 20:03 - 2014-12-08 20:03 - 000000268 ___RH () C:\Users\Milan\AppData\Roaming\Kernel Extension
2015-01-15 19:12 - 2015-01-15 19:12 - 000000268 ___RH () C:\Users\Milan\AppData\Roaming\Rule Actions
2016-06-07 15:22 - 2017-12-24 14:26 - 000000026 _____ () C:\Users\Milan\AppData\Local\isoworkshop.ini
2012-10-17 18:46 - 2012-10-17 18:46 - 000007605 _____ () C:\Users\Milan\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2017-12-29 21:00 - 2017-12-29 21:00 - 007850088 _____ (Microsoft Corporation) C:\Users\Milan\AppData\Local\Temp\BingBarSetup-Partner.exe

Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\abracadabra08092011.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core.job => C:\Users\Milan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA.job => C:\Users\Milan\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Milan\Desktop" je 14438 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenterCount
C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Apache Servers.lnk
C:\web\APACHE~1\Apache2.2\bin\APACHE~1.EXE [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]


==================== End Of Log ==============================
Přílohy
Addition.zip
(22.57 KiB) Staženo 98 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119666
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesy hostitele služby nonstop zatěžují CPU

#6 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
ShellExecuteHooks-x32: No Name - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - -> No File
FF Extension: (No Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [not found]
C:\Program Files (x86)\unEZCA2.exe
C:\Program Files (x86)\EZCA2
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA1d2589a1aa26edb
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core1d2589a1a98f6ac
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Windows\SysWOW64\abracadabra08092011.exe
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {00D0CA28-BCA4-4B05-B547-E11D6F9B7EA8} - \MySQL\Installer\ManifestUpdate -> No File <==== ATTENTION
Task: {0E4BBA80-DCE3-4651-8777-0B420CB063CD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {18D65383-12E4-4EAA-B0CD-7B2E4574943A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {21B21CD5-91C6-401D-9AD4-5A906D687A45} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
ask: {39161959-CAC9-4FAB-B8C0-E7DCFDB319FF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {54FAE865-8F11-4BCA-AC5D-BCA688AE0727} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {60C5D6F0-0175-4A97-B015-88093D3B4812} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {7554D7C3-9D5E-4AEF-B896-4C393EE8203E} - System32\Tasks\{5C371ABD-959A-4DCE-97FA-ECDB2E353BA3} => C:\Windows\system32\pcalua.exe -a "G:\FS nákupy\Flight Simulator_SOFT\PMDG-MD11_FS2004\PMDG MD-11 FS9 Setup.exe" -d "G:\FS nákupy\Flight Simulator_SOFT\PMDG-MD11_FS2004"
Task: {78FE1630-3783-42BD-9681-E559D8EB3F96} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {990E2F8F-18BB-4A7C-9BD2-A6CD07D1028E} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D8015D01-4266-40D9-89B9-1398410D7450} - System32\Tasks\{C332A3FE-9B5C-41DF-962D-84FA4FB18BE1} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {E69C1FC9-F34E-4276-8AC4-FB088F7E79AD} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {EEC60AB2-E357-42E2-9893-12BAA03B0AB4} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {F9A0E270-31C8-4731-BAE2-AF73DDF570D5} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {FF6A929A-473F-47B1-9FD7-0136F224B7D7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
AlternateDataStreams: C:\Windows:nlsPreferences [0]
AlternateDataStreams: C:\ProgramData\TEMP:EEDA5B17 [424]

EmptyTemp:
End
Z logu:
Velikost slozky "C:\Users\Milan\Desktop" je 14438 MB.
To je příliš mnoho a může to způsobovat zpomalení startu systéku. Vytvořte v C:\Users\Milan novou složku, do níž přesuňte všechna data z plochy (kromě zástupců). Na plochu si pak dejte zástupce té složky pro snazší přístup.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Re: Procesy hostitele služby nonstop zatěžují CPU

#7 Příspěvek od meiilax »

OK, co s tím poznámkovým blokem dále ?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119666
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesy hostitele služby nonstop zatěžují CPU

#8 Příspěvek od Rudy »

Pardon, zapoměl jsem nakopírovat, omlouvám se:

Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Re: Procesy hostitele služby nonstop zatěžují CPU

#9 Příspěvek od meiilax »

Fix result of Farbar Recovery Scan Tool (x64) Version: 26-12-2017
Ran by Milan (30-12-2017 18:47:31) Run:1
Running from C:\Users\Milan\Desktop
Loaded Profiles: Milan (Available Profiles: Milan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
ShellExecuteHooks-x32: No Name - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - -> No File
FF Extension: (No Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [not found]
C:\Program Files (x86)\unEZCA2.exe
C:\Program Files (x86)\EZCA2
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA1d2589a1aa26edb
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core1d2589a1a98f6ac
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\Windows\SysWOW64\abracadabra08092011.exe
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {00D0CA28-BCA4-4B05-B547-E11D6F9B7EA8} - \MySQL\Installer\ManifestUpdate -> No File <==== ATTENTION
Task: {0E4BBA80-DCE3-4651-8777-0B420CB063CD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {18D65383-12E4-4EAA-B0CD-7B2E4574943A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {21B21CD5-91C6-401D-9AD4-5A906D687A45} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
ask: {39161959-CAC9-4FAB-B8C0-E7DCFDB319FF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {54FAE865-8F11-4BCA-AC5D-BCA688AE0727} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {60C5D6F0-0175-4A97-B015-88093D3B4812} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {7554D7C3-9D5E-4AEF-B896-4C393EE8203E} - System32\Tasks\{5C371ABD-959A-4DCE-97FA-ECDB2E353BA3} => C:\Windows\system32\pcalua.exe -a "G:\FS n�kupy\Flight Simulator_SOFT\PMDG-MD11_FS2004\PMDG MD-11 FS9 Setup.exe" -d "G:\FS n�kupy\Flight Simulator_SOFT\PMDG-MD11_FS2004"
Task: {78FE1630-3783-42BD-9681-E559D8EB3F96} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {990E2F8F-18BB-4A7C-9BD2-A6CD07D1028E} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D8015D01-4266-40D9-89B9-1398410D7450} - System32\Tasks\{C332A3FE-9B5C-41DF-962D-84FA4FB18BE1} => C:\Windows\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {E69C1FC9-F34E-4276-8AC4-FB088F7E79AD} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {EEC60AB2-E357-42E2-9893-12BAA03B0AB4} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {F9A0E270-31C8-4731-BAE2-AF73DDF570D5} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {FF6A929A-473F-47B1-9FD7-0136F224B7D7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
AlternateDataStreams: C:\Windows:nlsPreferences [0]
AlternateDataStreams: C:\ProgramData\TEMP:EEDA5B17 [424]

EmptyTemp:
End
*****************

HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" => removed successfully
HKLM\SOFTWARE\WOW6432Node\Classes\CLSID\{B5A7F190-DDA6-4420-B3BA-52453494E6CD} => key not found
C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com => path removed successfully
C:\Program Files (x86)\unEZCA2.exe => moved successfully
C:\Program Files (x86)\EZCA2 => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000UA1d2589a1aa26edb => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-649847758-3809949159-3738805346-1000Core1d2589a1a98f6ac => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\Windows\SysWOW64\abracadabra08092011.exe => moved successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\Gadgets" => removed successfully
HKLM\Software\Classes\CLSID\{6B9228DA-9C15-419e-856C-19E768A13BDC} => key not found
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{00D0CA28-BCA4-4B05-B547-E11D6F9B7EA8} => could not remove key. ErrorCode1: 0x00000002
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00D0CA28-BCA4-4B05-B547-E11D6F9B7EA8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySQL\Installer\ManifestUpdate" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0E4BBA80-DCE3-4651-8777-0B420CB063CD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0E4BBA80-DCE3-4651-8777-0B420CB063CD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{18D65383-12E4-4EAA-B0CD-7B2E4574943A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18D65383-12E4-4EAA-B0CD-7B2E4574943A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{21B21CD5-91C6-401D-9AD4-5A906D687A45}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21B21CD5-91C6-401D-9AD4-5A906D687A45}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
ask: {39161959-CAC9-4FAB-B8C0-E7DCFDB319FF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{54FAE865-8F11-4BCA-AC5D-BCA688AE0727}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{54FAE865-8F11-4BCA-AC5D-BCA688AE0727}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60C5D6F0-0175-4A97-B015-88093D3B4812}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60C5D6F0-0175-4A97-B015-88093D3B4812}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7554D7C3-9D5E-4AEF-B896-4C393EE8203E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7554D7C3-9D5E-4AEF-B896-4C393EE8203E}" => removed successfully
C:\WINDOWS\System32\Tasks\{5C371ABD-959A-4DCE-97FA-ECDB2E353BA3} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5C371ABD-959A-4DCE-97FA-ECDB2E353BA3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78FE1630-3783-42BD-9681-E559D8EB3F96}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78FE1630-3783-42BD-9681-E559D8EB3F96}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{990E2F8F-18BB-4A7C-9BD2-A6CD07D1028E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{990E2F8F-18BB-4A7C-9BD2-A6CD07D1028E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D8015D01-4266-40D9-89B9-1398410D7450}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8015D01-4266-40D9-89B9-1398410D7450}" => removed successfully
C:\WINDOWS\System32\Tasks\{C332A3FE-9B5C-41DF-962D-84FA4FB18BE1} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C332A3FE-9B5C-41DF-962D-84FA4FB18BE1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E69C1FC9-F34E-4276-8AC4-FB088F7E79AD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E69C1FC9-F34E-4276-8AC4-FB088F7E79AD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EEC60AB2-E357-42E2-9893-12BAA03B0AB4}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEC60AB2-E357-42E2-9893-12BAA03B0AB4}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F9A0E270-31C8-4731-BAE2-AF73DDF570D5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9A0E270-31C8-4731-BAE2-AF73DDF570D5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FF6A929A-473F-47B1-9FD7-0136F224B7D7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF6A929A-473F-47B1-9FD7-0136F224B7D7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
C:\Windows => ":nlsPreferences" ADS removed successfully
C:\ProgramData\TEMP => ":EEDA5B17" ADS removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 121602288 B
Java, Flash, Steam htmlcache => 371637756 B
Windows/system/drivers => 1642360 B
Edge => 6108255 B
Chrome => 16001797 B
Firefox => 128158128 B
Opera => 76561952 B

Temp, IE cache, history, cookies, recent:
Default => 16384 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 560 B
LocalService => 48454 B
NetworkService => 75080 B
Milan => 308009064 B

RecycleBin => 23207 B
EmptyTemp: => 992.2 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:48:58 ====

meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Re: Procesy hostitele služby nonstop zatěžují CPU

#10 Příspěvek od meiilax »

Tak teď nevím, mám na něco čekat ? Žádná změna, procesy pořád jedou na 33% CPU.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119666
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesy hostitele služby nonstop zatěžují CPU

#11 Příspěvek od Rudy »

Na zkoušku vypněte aut. aktualizace a zjistěte zatížení.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Re: Procesy hostitele služby nonstop zatěžují CPU

#12 Příspěvek od meiilax »

Jak se to tak asi na Win 10 dělá ?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119666
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesy hostitele služby nonstop zatěžují CPU

#13 Příspěvek od Rudy »

V systému máte nápovědu. Jinak: http://www.mrpear.net/cz/blog/749/jak-v ... windows-10 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

meiilax
Návštěvník
Návštěvník
Příspěvky: 49
Registrován: 27 čer 2004 09:13

Re: Procesy hostitele služby nonstop zatěžují CPU

#14 Příspěvek od meiilax »

Bohužel tento návod nelze použít, v dfialogu přes msconfig a záložce "Služby" službu Windows Update vůbec nemám.

Prosím jen dotaz - to vaříte z vody nebo k tomuto postupu máte nějaký relevantní důvod ? Také jsem nechápal smazání některých souborů dle Vašich instrukcí, např. složku EZCA2, to je pro mě trochu problém, jedná se o jeden modul pro FSX, který tohle 10% nedělá, teď budu mít problém ho zas řádně nakonfigurovat. Já jen abychom neztráceli čas, Vy ani já.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119666
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesy hostitele služby nonstop zatěžují CPU

#15 Příspěvek od Rudy »

Windows10 jsou jen jedny, takže by měl být návod použitelný. Ty soubory, které zmiňujete, Google vůbec nezná (co neznám ani já, vždy Googlím) a pokud je nezná, lze je pokládat za minimálně nedůvěryhodné. Vše regulérní Google zná a lze se o tom docela podrobně dočíst. Z vody nevařím, používám jen standardní postupy, které užívám vždy pokud se jedná o tento, nebo podobný problém. Rozhodně vás nenutím, abyste věřil tomu, co vám tu v dobré víře radím. Směřuji k tomu, abych odhalil, co vám CPU zatěžuje a jako první věc musím PC vyčistit od zbytečností a případně i od malware.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno