Stránka 1 z 1

Prosím o preventivku

Napsal: 05 pro 2019 08:00
od romcolahvac
Ahoj, prosím o preventivní kontrolu mého PC, děkuji moc :-)¨

LOG RSIT:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Roman at 2019-12-05 08:03:37
Microsoft Windows 10 Pro
System drive C: has 26 GB (21%) free of 121 GB
Total RAM: 4094 MB (29% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:03:40, on 05.12.2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.18362.0001)
Boot mode: Normal

Running processes:
C:\Users\Roman\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
C:\Program Files (x86)\Roche\Exor4\Bin\Exor4.exe
C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Sync\Coresync\Coresync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe
C:\Program Files\trend micro\Roman.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_211\bin\ssv.dll
O2 - BHO: McAfee WebAdvisor - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_211\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [HDD Regenerator] "C:\Program Files (x86)\HDD Regenerator\Shell.exe" /1
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [TeamsMachineInstaller] %ProgramFiles%\Teams Installer\Teams.exe --checkInstall --source=PROPLUS
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Roman\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
O4 - HKCU\..\Run: [Xvid] WScript "C:\Program Files (x86)\Xvid\CheckUpdateLauncher.vbs" "C:\Program Files (x86)\Xvid\CheckUpdate.ps1"
O4 - HKCU\..\Run: [com.squirrel.Teams.Teams] C:\Users\Roman\AppData\Local\Microsoft\Teams\Update.exe --processStart "Teams.exe" --process-start-args "--system-initiated"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2651452621-253113433-2049451952-1006\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'postgres')
O4 - HKUS\S-1-5-21-2651452621-253113433-2049451952-1006\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'postgres')
O4 - Global Startup: Exor4 for XDMS_T.lnk = C:\Program Files (x86)\Roche\Exor4\Bin\Exor4.exe
O4 - Global Startup: Twonky Server.lnk = C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O9 - Extra 'Tools' menuitem: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: vw-wi - {0F3C833F-FB28-40EA-8CB9-6A55B996C3F6} - D:\ElsaWin\bin\wiprot.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
O23 - Service: Autodesk Desktop App Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Monitor Service (AGMService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_f7aba34 - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.108\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: hddrsrv - Unknown owner - C:\Program Files (x86)\HDD Regenerator\hrsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ELSA Administration Service (LcSvrAdm) - Volkswagen AG - D:\ElsaWin\bin\LcSvrAdm.exe
O23 - Service: ELSA Auftragsverwaltungs Service (LcSvrAuf) - Volkswagen AG - D:\ElsaWin\bin\LcSvrAuf.exe
O23 - Service: ELSA DBA Server (LcSvrDba) - Volkswagen AG - D:\ElsaWin\bin\LcSvrDba.exe
O23 - Service: ELSA Historie Server (LcSvrHis) - Volkswagen AG - D:\ElsaWin\bin\LcSvrHis.exe
O23 - Service: ELSA PASS Server (LcSvrPAS) - Volkswagen AG - D:\ElsaWin\bin\LcSvrPas.exe
O23 - Service: ELSA APOSpro Server (LcSvrSaz) - Volkswagen AG - D:\ElsaWin\bin\LcSvrSaz.exe
O23 - Service: McAfee WebAdvisor - McAfee, Inc. - C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Nero Update (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: postgresql-x64-9.2 - PostgreSQL Server 9.2 (postgresql-x64-9.2) - PostgreSQL Global Development Group - C:/Program Files/PostgreSQL/9.2/bin/pg_ctl.exe
O23 - Service: RealtekWlanU - Realtek - C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek DHCP Service (RTLDHCPService) - Realtek - C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RTLDHCP.exe
O23 - Service: RunSwUSB - Unknown owner - C:\Windows\runSW.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: TwonkyServer - PacketVideo - C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16635 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
"fontdrvhost.exe"
C:\WINDOWS\system32\svchost.exe -k RPCSS -p
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s LSM
C:\WINDOWS\System32\svchost.exe -k NetworkService -s TermService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s TimeBrokerSvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ProfSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s nsi
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UserManager
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s Dhcp
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s lfsvc
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s DispBrokerDesktopSvc
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s UmRdpService
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s NlaSvc
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s EventSystem

C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s Themes

C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s SENS
C:\WINDOWS\system32\svchost.exe -k netsvcs -s CertPropSvc
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s LanmanWorkstation
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s AudioEndpointBuilder
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s FontCache
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s netprofm
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s SessionEnv
C:\WINDOWS\system32\svchost.exe -k LocalService -p
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s StateRepository
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s ShellHWDetection

C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s CryptSvc
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc -p
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe"
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe"
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s DeviceAssociationService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s DPS
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s fdPHost
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\HDD Regenerator\hrsrv.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Winmgmt
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s LanmanServer
"C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe"
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s SstpSvc
"C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RtlService.exe"
C:\Windows\runSW.exe
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
C:\WINDOWS\System32\svchost.exe -k NetSvcs -p -s iphlpsvc
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe" -serviceversion 0
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TrkWks
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s TapiSrv
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s WpnService
dashost.exe {e5027dbe-4d5a-443d-87ed6c16f550ed55}
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s WdiServiceHost
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s FDResPub
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s SSDPSRV
"C:\Program Files (x86)\Twonky\TwonkyServer\TwonkyServer.exe" -serviceversion 0
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted -p -s PolicyAgent
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s TokenBroker
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TabletInputService
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s CDPSvc
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s LicenseManager
C:\WINDOWS\System32\svchost.exe -k netsvcs -p



"C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler64.exe"
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Browny02\BrYNSvc.exe"
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s BITS

C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s fhsvc
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc

C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UsoSvc
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Appinfo
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s BthAvctpSvc
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s DsSvc
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVShNotify.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wuauserv
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s DisplayEnhancementService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s QWAVE
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"fontdrvhost.exe"
"dwm.exe"

atieclxx
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s lmhosts
"C:\Program Files\McAfee\WebAdvisor\UIHost.exe"
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s CDPUserSvc
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s WpnUserService
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
taskhostw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"ctfmon.exe"
"C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19102.525.0_x64__8wekyb3d8bbwe\YourPhone.exe" -ServerName:App.AppX9yct9q388jvt4h7y0gn06smzkxcsnt8m.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.54.91.0_x64__kzf8qxf38zg5c\SkypeApp.exe" -ServerName:App.AppXffn3yxqvgawq9fpmnhy90fr3y01d1t5b.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.54.91.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe" -ServerName:SkypeBackgroundHost
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\SecurityHealthSystray.exe"
AvastUI.exe /nogui
"D:\Program Files\iTunes\iTunesHelper.exe"
"C:\Users\Roman\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --ran-launcher --started-from-shortcut
"C:\Program Files\Opera\65.0.3467.48\opera_crashreporter.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win64 --annotation=prod=OperaDesktop --annotation=ver=65.0.3467.48 --initial-client-data=0x304,0x308,0x30c,0x300,0x310,0x7ffd626bafe8,0x7ffd626baff8,0x7ffd626bb008
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=gpu-process --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=2548206920212369142 --mojo-platform-channel-handle=1840 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=utility --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --service-sandbox-type=network --enable-quic --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --service-request-channel-token=13228033424979277797 --mojo-platform-channel-handle=1920 /prefetch:8
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9967517500812645825 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2692 /prefetch:1
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --extension-process --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4716407363222818322 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3144 /prefetch:1
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --extension-process --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17265108724048928667 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3308 /prefetch:1
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4227952735661223419 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3560 /prefetch:1
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=utility --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --service-sandbox-type=audio --enable-quic --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --service-request-channel-token=4526929815189185983 --mojo-platform-channel-handle=4012 /prefetch:8
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --extension-process --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16899186332993126219 --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4648 /prefetch:1
"C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe"
"C:\Program Files (x86)\Roche\Exor4\Bin\Exor4.exe" -f "C:\ProgramData\Roche\Exor4\Bin\XDMS_T.conf"
"C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe"
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
C:\Windows\System32\RuntimeBroker.exe -Embedding
-BootProc
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe" --approot=SOFTWARE\Autodesk --appAgent=/AUTODESKDESKTOPAPP/7.0.7.232/cs-CZ/0001 --lang=cs-CZ --cache-path="C:\Users\Roman\AppData\Local\Autodesk\Autodesk Desktop App\BrowserCache" --peerPid=7056
"C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe" --type=gpu-process --channel="9248.0.812812658\1907241190" --no-sandbox --lang=cs-CZ --log-file="C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\debug.log" --log-severity=disable --peerpid=7056 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,13,25,54 --gpu-vendor-id=0x1002 --gpu-device-id=0x9588 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.9001 --lang=cs-CZ --log-file="C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\debug.log" --log-severity=disable --peerpid=7056 --mojo-platform-channel-handle=1288 /prefetch:2
-BootProc
"HDD Regenerator.exe"
"HDD Regenerator.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe" "-launchedbyvulcan-19316 C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe"
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe" --onOSstartup=true --showwindow=false --waitForRegistration=true
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --log-file="C:\Users\Roman\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --use-gl=swiftshader-webgl --field-trial-handle=3116,2675131088847896869,8395158872780267827,131072 --disable-features=AsyncWheelEvents,TouchpadAndWheelScrollLatching --disable-gpu-compositing --service-pipe-token=3473676564194371821 --lang=en-US --locales-dir-path="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\locales" --log-file="C:\Users\Roman\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --log-severity=warning --user-agent="Mozilla/5.0 (Windows NT 10.0.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.98 Safari/537.36 CreativeCloud/4.9.0.504" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=3473676564194371821 --renderer-client-id=3 --mojo-platform-channel-handle=3132 /prefetch:1
"C:\Program Files (x86)\Adobe\Adobe Sync\Coresync\Coresync.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\main.js"
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe" --type=renderer --no-sandbox --log-file="C:\Users\Roman\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --use-gl=swiftshader-webgl --field-trial-handle=3116,2675131088847896869,8395158872780267827,131072 --disable-features=AsyncWheelEvents,TouchpadAndWheelScrollLatching --disable-gpu-compositing --service-pipe-token=10698237124911341216 --lang=en-US --locales-dir-path="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\locales" --log-file="C:\Users\Roman\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --log-severity=warning --user-agent="Mozilla/5.0 (Windows NT 10.0.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.98 Safari/537.36 CreativeCloud/4.9.0.504" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=10698237124911341216 --renderer-client-id=4 --mojo-platform-channel-handle=3888 /prefetch:1
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12283459558724276065 --renderer-client-id=29 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6800 /prefetch:1
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1908.0.0_x64__8wekyb3d8bbwe\Calculator.exe" -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca
"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.35.14003.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_3.35.14003.0_x64__8wekyb3d8bbwe\GameBarFT.exe" /InvokerPRAID: App
C:\WINDOWS\System32\svchost.exe -k smphost
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup -s WbioSrvc
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=gpu-process --field-trial-handle=6504,14291208295048887196,2534832665850186713,131072 --no-sandbox --log-file="C:\Users\Roman\AppData\Roaming\AVAST Software\Avast\log\cef_log.txt" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.3.3626.1895 Safari/537.36 Avastium (19.8.2393)" --lang=en-US --proxy-auto-detect --disable-webaudio --force-wave-audio --disable-software-rasterizer --no-sandbox --blacklist-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-compositing --disable-accelerated-layers --disable-accelerated-video-decode --blacklist-webgl --disable-bundled-ppapi-flash --disable-flash-3d --enable-aggressive-domstorage-flushing --enable-media-stream --allow-file-access-from-files=1 --pack_loading_disabled=1 --gpu-preferences=KAAAAAAAAACAAwCAAQAAAAAAAAAAAGAAAAAAAAMAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --use-gl=swiftshader-webgl --service-request-channel-token=1341014890813843013 --mojo-platform-channel-handle=6316 /prefetch:2
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13548096157454592386 --renderer-client-id=33 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6812 /prefetch:1
"C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe" -ServerName:App.AppXbdz14xebceycqvrazxqtnx89wn9e0ebz.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Opera\65.0.3467.48\opera.exe" --type=renderer --field-trial-handle=1828,4164592738850752097,15030968702633405651,131072 --disable-features=SharedArrayBuffer --lang=cs --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --ab_tests=DNA-70598-ref:DNA-70598 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5696819151671529655 --renderer-client-id=42 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=8924 /prefetch:1
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s gpsvc
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19071.17920.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s camsvc
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe143_ Global\UsGthrCtrlFltPipeMssGthrPipe143 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 752 756 764 8192 760
C:\WINDOWS\system32\AUDIODG.EXE 0x5d0
"C:\Users\Roman\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\simplitec Power Suite (Autopilot.exe).job - C:\Program Files (x86)\Nero\Nero TuneItUp\Autopilot.exe
C:\WINDOWS\tasks\simplitec Power Suite.job - C:\Program Files (x86)\Nero\Nero TuneItUp\TuneItUp.exe -task

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2019-09-25 221664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor - C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2019-11-17 1356368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-03-17 166360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_211\bin\ssv.dll [2019-04-23 480120]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor - C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2019-11-17 1043128]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_211\bin\jp2ssv.dll [2019-04-23 194424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\WINDOWS\system32\SecurityHealthSystray.exe [2019-03-19 84992]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2019-10-09 268680]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2018-04-10 509936]
"AdobeGCInvoker-1.0"=C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2019-10-08 2872400]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-11-30 4047480]
"iTunesHelper"=D:\Program Files\iTunes\iTunesHelper.exe [2019-07-19 302904]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Roman\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2019-11-21 1585000]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2018-01-12 5263040]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2017-02-03 2007576]
"Xvid"=WScript C:\Program Files (x86)\Xvid\CheckUpdateLauncher.vbs C:\Program Files (x86)\Xvid\CheckUpdate.ps1 []
"com.squirrel.Teams.Teams"=C:\Users\Roman\AppData\Local\Microsoft\Teams\Update.exe [2019-10-13 1789552]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-12 563416]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Autodesk Desktop App"=C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [2017-12-19 706392]
"ControlCenter4"=C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [2013-12-05 139776]
"BrStsMon00"=C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2014-05-22 4513792]
"HDD Regenerator"=C:\Program Files (x86)\HDD Regenerator\Shell.exe [2013-05-08 90336]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-11-30 4047480]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2019-07-19 76600]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2019-07-05 2623032]
"TeamsMachineInstaller"=C:\Program Files\Teams Installer\Teams.exe --checkInstall --source=PROPLUS []
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Exor4 for XDMS_T.lnk - C:\Program Files (x86)\Roche\Exor4\Bin\Exor4.exe
Twonky Server.lnk - C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinQuic]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableFullTrustStartupTasks"=2
"EnableUwpStartupTasks"=2
"SupportFullTrustStartupTasks"=1
"SupportUwpStartupTasks"=1
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux"=wdmaud.drv
"midi"=wdmaud.drv
"midimapper"=midimap.dll
"mixer"=wdmaud.drv
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wave"=wdmaud.drv
"wavemapper"=msacm32.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.XVID"=xvidvfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open -
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2019-11-14 20:12:20 ----A---- C:\WINDOWS\SYSWOW64\wmploc.DLL
2019-11-14 20:12:20 ----A---- C:\WINDOWS\SYSWOW64\spwmp.dll
2019-11-14 20:12:20 ----A---- C:\WINDOWS\SYSWOW64\gnsdk_fp.dll
2019-11-14 20:12:20 ----A---- C:\WINDOWS\SYSWOW64\dxmasf.dll
2019-11-14 20:12:19 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2019-11-14 20:12:19 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2019-11-14 20:12:19 ----A---- C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2019-11-14 20:12:18 ----A---- C:\WINDOWS\system32\cdp.dll
2019-11-14 20:12:17 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2019-11-14 20:12:17 ----A---- C:\WINDOWS\system32\HologramCompositor.dll
2019-11-14 20:12:17 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2019-11-14 20:12:16 ----A---- C:\WINDOWS\system32\Hydrogen.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\SYSWOW64\Microsoft.Uev.Office2013CustomActions.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\SYSWOW64\Microsoft.Uev.Office2010CustomActions.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\SYSWOW64\Microsoft.Uev.AppAgent.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\SYSWOW64\AppVEntSubsystems32.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\system32\uwfservicingapi.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\system32\mfcore.dll
2019-11-14 20:12:15 ----A---- C:\WINDOWS\system32\mf.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\UevTemplateConfigItemGenerator.exe
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\UevTemplateBaselineGenerator.exe
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\UevAppMonitor.exe
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\UevAgentPolicyGenerator.exe
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.SyncController.exe
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.SyncConditions.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.SyncCommon.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.SmbSyncProvider.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.Office2013CustomActions.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.Office2010CustomActions.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.MonitorSyncProvider.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.ModernSync.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.ModernAppData.WinRT.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.Management.WmiAccess.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.Management.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.ManagedEventLogging.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.LocalSyncProvider.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.EventLogMessages.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.ConfigWrapper.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.Common.WinRT.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.Common.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.CmUtil.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.CabUtil.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2019-11-14 20:11:53 ----A---- C:\WINDOWS\system32\AgentService.exe
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\TransportDSA.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVStreamMap.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVScripting.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVReporting.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVPolicy.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVOrchestration.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVManifest.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVIntegration.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVFileSystemMetadata.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-11-14 20:11:52 ----A---- C:\WINDOWS\system32\AppVCatalog.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\wscinterop.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.Mirage.Internal.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\tsgqec.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\msjet40.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\msimsg.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\iemigplugin.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\AcXtrnal.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\AcLayers.dll
2019-11-14 20:11:50 ----A---- C:\WINDOWS\SYSWOW64\AcGenral.dll
2019-11-14 20:11:49 ----A---- C:\WINDOWS\SYSWOW64\IndexedDbLegacy.dll
2019-11-14 20:11:49 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2019-11-14 20:11:49 ----A---- C:\WINDOWS\SYSWOW64\Chakrathunk.dll
2019-11-14 20:11:49 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2019-11-14 20:11:49 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2019-11-14 20:11:48 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\werui.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\upnphost.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\upnpcont.exe
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\udhisapi.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\reg.exe
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\SYSWOW64\DWWIN.EXE
2019-11-14 20:11:46 ----A---- C:\WINDOWS\system32\wscinterop.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\system32\DiagSvc.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\system32\AcXtrnal.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\system32\AcLayers.dll
2019-11-14 20:11:46 ----A---- C:\WINDOWS\system32\AcGenral.dll
2019-11-14 20:11:45 ----A---- C:\WINDOWS\system32\tsgqec.dll
2019-11-14 20:11:45 ----A---- C:\WINDOWS\system32\mstscax.dll
2019-11-14 20:11:45 ----A---- C:\WINDOWS\system32\msimsg.dll
2019-11-14 20:11:45 ----A---- C:\WINDOWS\system32\msi.dll
2019-11-14 20:11:45 ----A---- C:\WINDOWS\system32\iemigplugin.dll
2019-11-14 20:11:44 ----A---- C:\WINDOWS\system32\ieframe.dll
2019-11-14 20:11:44 ----A---- C:\WINDOWS\system32\Chakrathunk.dll
2019-11-14 20:11:44 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2019-11-14 20:11:43 ----A---- C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-11-14 20:11:43 ----A---- C:\WINDOWS\system32\Chakra.dll
2019-11-14 20:11:42 ----A---- C:\WINDOWS\system32\mshtml.dll
2019-11-14 20:11:40 ----A---- C:\WINDOWS\system32\werui.dll
2019-11-14 20:11:40 ----A---- C:\WINDOWS\system32\wercplsupport.dll
2019-11-14 20:11:40 ----A---- C:\WINDOWS\system32\werconcpl.dll
2019-11-14 20:11:40 ----A---- C:\WINDOWS\system32\StorSvc.dll
2019-11-14 20:11:40 ----A---- C:\WINDOWS\system32\jscript.dll
2019-11-14 20:11:40 ----A---- C:\WINDOWS\system32\edgehtml.dll
2019-11-14 20:11:40 ----A---- C:\WINDOWS\system32\DWWIN.EXE
2019-11-14 20:11:40 ----A---- C:\WINDOWS\HelpPane.exe
2019-11-14 20:11:18 ----A---- C:\WINDOWS\system32\WinHvPlatform.dll
2019-11-14 20:11:18 ----A---- C:\WINDOWS\system32\reg.exe
2019-11-14 20:11:16 ----A---- C:\WINDOWS\system32\securekernel.exe
2019-11-14 20:11:16 ----A---- C:\WINDOWS\system32\kdhvcom.dll
2019-11-14 20:11:16 ----A---- C:\WINDOWS\system32\hvhostsvc.dll
2019-11-14 20:11:16 ----A---- C:\WINDOWS\system32\drivers\winhvr.sys
2019-11-14 20:11:15 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.FileExplorer.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\SYSWOW64\KBDJPN.DLL
2019-11-14 20:11:15 ----A---- C:\WINDOWS\SYSWOW64\kbd106.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\SYSWOW64\edgeIso.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\upnphost.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\upnpcont.exe
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\udhisapi.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\hvloader.dll
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\hvix64.exe
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\hvax64.exe
2019-11-14 20:11:15 ----A---- C:\WINDOWS\system32\drivers\hvservice.sys
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\Wldap32.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\wincredui.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\wincorlib.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\wermgr.exe
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\WerFault.exe
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\weretw.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\werdiagcontroller.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\usp10.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\tzres.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\omadmapi.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\Faultrep.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\dtdump.exe
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\cryptui.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2019-11-14 20:11:14 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.AI.MachineLearning.dll
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\win32u.dll
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\win32k.sys
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\Utilman.exe
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\sethc.exe
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\Magnify.exe
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\EaseOfAccessDialog.exe
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\cmd.exe
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\AtBroker.exe
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2019-11-14 20:11:13 ----A---- C:\WINDOWS\SYSWOW64\accessibilitycpl.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\wfapigp.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\OneCoreUAPCommonProxyStub.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\fwpolicyiomgr.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\fwbase.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2019-11-14 20:11:12 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\mssprxy.dll
2019-11-14 20:11:11 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2019-11-14 20:10:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2019-11-14 20:10:22 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2019-11-14 20:10:22 ----A---- C:\WINDOWS\SYSWOW64\mssitlb.dll
2019-11-14 20:10:22 ----A---- C:\WINDOWS\SYSWOW64\msscntrs.dll
2019-11-14 20:10:22 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2019-11-14 20:10:22 ----A---- C:\WINDOWS\SYSWOW64\ApiSetHost.AppExecutionAlias.dll
2019-11-14 20:10:22 ----A---- C:\WINDOWS\SYSWOW64\ActivationManager.dll
2019-11-14 20:10:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2019-11-14 20:10:21 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2019-11-14 20:10:21 ----A---- C:\WINDOWS\SYSWOW64\dmvdsitf.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\wscapi.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\Wpc.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\uxtheme.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\SpatialAudioLicenseSrv.exe
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\BTAGService.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\system32\vbscript.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\system32\RMapi.dll
2019-11-14 20:10:20 ----A---- C:\WINDOWS\system32\posetup.dll
2019-11-14 20:10:19 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-11-14 20:10:19 ----A---- C:\WINDOWS\system32\msIso.dll
2019-11-14 20:10:19 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2019-11-14 20:10:19 ----A---- C:\WINDOWS\system32\edgeIso.dll
2019-11-14 20:10:19 ----A---- C:\WINDOWS\system32\drivers\tunnel.sys
2019-11-14 20:10:19 ----A---- C:\WINDOWS\system32\AxInstUI.exe
2019-11-14 20:10:19 ----A---- C:\WINDOWS\system32\AxInstSv.dll
2019-11-14 20:10:18 ----A---- C:\WINDOWS\system32\urlmon.dll
2019-11-14 20:10:18 ----A---- C:\WINDOWS\system32\iertutil.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\wow64win.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\wincredui.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\WebRuntimeManager.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\omadmapi.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\gdi32full.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\cryptui.dll
2019-11-14 20:09:22 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\SYSWOW64\winnsi.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\SYSWOW64\nsi.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\winnsi.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\winlogon.exe
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\usp10.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\nsisvc.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\nsi.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\netlogon.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\lpk.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\KernelBase.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\fontsub.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\drivers\nsiproxy.sys
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\dciman32.dll
2019-11-14 20:09:21 ----A---- C:\WINDOWS\system32\atmlib.dll
2019-11-14 20:09:20 ----A---- C:\WINDOWS\system32\wersvc.dll
2019-11-14 20:09:20 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2019-11-14 20:09:20 ----A---- C:\WINDOWS\system32\Faultrep.dll
2019-11-14 20:09:20 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2019-11-14 20:09:20 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\Wldap32.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\WinTypes.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\winhttp.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\wincorlib.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\wermgr.exe
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\WerFault.exe
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\weretw.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\wer.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\webio.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\utcutil.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\tzres.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\rpcss.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\profsvc.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\pacjsworker.exe
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\msv1_0.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\diagtrack.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\dcntel.dll
2019-11-14 20:09:19 ----A---- C:\WINDOWS\system32\crypt32.dll
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\uxtheme.dll
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\twinui.dll
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\sppobjs.dll
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\SppExtComObj.Exe
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\combase.dll
2019-11-14 20:09:18 ----A---- C:\WINDOWS\system32\aepic.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\uDWM.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\srpapi.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\shell32.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\generaltel.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\drivers\refs.sys
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\drivers\cldflt.sys
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\drivers\applockerfltr.sys
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\devinv.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\AppLockerCSP.dll
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\appidtel.exe
2019-11-14 20:09:16 ----A---- C:\WINDOWS\system32\acmigration.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\win32appinventorycsp.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\Utilman.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\tier2punctuations.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\SRH.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\sethc.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\pcasvc.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\pcalua.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\pcaevts.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\pcadm.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\osk.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\Narrator.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\Magnify.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\invagent.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\EaseOfAccessDialog.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\AtBroker.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\appraiser.dll
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\aitstatic.exe
2019-11-14 20:09:15 ----A---- C:\WINDOWS\system32\aeinv.dll
2019-11-14 20:08:44 ----A---- C:\WINDOWS\system32\accessibilitycpl.dll
2019-11-14 20:08:43 ----A---- C:\WINDOWS\system32\DevicesFlowBroker.dll
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\vss_ps.dll
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\usocoreworker.exe
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2019-11-14 20:08:40 ----A---- C:\WINDOWS\system32\MusNotification.exe
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\win32u.dll
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\win32kfull.sys
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\win32k.sys
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\usosvc.dll
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2019-11-14 20:08:39 ----A---- C:\WINDOWS\system32\cmd.exe
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\wpnprv.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\wfapigp.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\user32.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\icfupgd.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\fwpolicyiomgr.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\fwbase.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2019-11-14 20:08:38 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-11-14 20:08:37 ----A---- C:\WINDOWS\system32\windows.storage.dll
2019-11-14 20:08:37 ----A---- C:\WINDOWS\system32\tquery.dll
2019-11-14 20:08:37 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\mssvp.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\mssrch.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\mssprxy.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\mssph.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\mssitlb.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\msscntrs.dll
2019-11-14 20:08:36 ----A---- C:\WINDOWS\system32\FntCache.dll
2019-11-14 20:08:35 ----A---- C:\WINDOWS\system32\wups2.dll
2019-11-14 20:08:35 ----A---- C:\WINDOWS\system32\wuaueng.dll
2019-11-14 20:08:35 ----A---- C:\WINDOWS\system32\wuauclt.exe
2019-11-14 20:08:35 ----A---- C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-11-14 20:08:35 ----A---- C:\WINDOWS\system32\EdgeContent.dll
2019-11-14 20:08:35 ----A---- C:\WINDOWS\system32\DWrite.dll
2019-11-14 20:08:34 ----A---- C:\WINDOWS\system32\win32kbase.sys
2019-11-14 20:08:34 ----A---- C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-11-14 20:08:34 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2019-11-14 20:08:34 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2019-11-14 20:08:34 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2019-11-14 20:08:34 ----A---- C:\WINDOWS\system32\cdd.dll
2019-11-14 20:08:33 ----A---- C:\WINDOWS\system32\Windows.AI.MachineLearning.dll
2019-11-14 20:08:33 ----A---- C:\WINDOWS\system32\ClipSVC.dll
2019-11-14 20:08:32 ----A---- C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-11-14 20:08:10 ----A---- C:\WINDOWS\system32\dstokenclean.exe
2019-11-14 20:08:10 ----A---- C:\WINDOWS\system32\dssvc.dll
2019-11-14 20:08:10 ----A---- C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2019-11-14 20:08:10 ----A---- C:\WINDOWS\system32\ActivationManager.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\Windows.CloudStore.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\CustomInstallExec.exe
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\cdpusersvc.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\cdpsvc.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-11-14 20:08:09 ----A---- C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-11-14 20:08:08 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-11-14 20:08:07 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-11-14 20:08:07 ----A---- C:\WINDOWS\system32\vdsbas.dll
2019-11-14 20:08:07 ----A---- C:\WINDOWS\system32\dmvdsitf.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\wscsvc.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\wscproxystub.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\wscisvif.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\wscapi.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\wscadminui.exe
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\Wpc.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\UtcDecoderHost.exe
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\StartTileData.dll
2019-11-14 20:08:05 ----A---- C:\WINDOWS\system32\spoolsv.exe
2019-11-14 20:08:05 ----A---- C:\WINDOWS\splwow64.exe
2019-11-14 20:08:05 ----A---- C:\WINDOWS\explorer.exe
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\WpcTok.exe
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\WpcRefreshTask.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\WpcMon.exe
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\drivers\winnat.sys
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\audiosrv.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\AudioSes.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\audioresourceregistrar.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\AudioEng.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-11-14 20:08:04 ----A---- C:\WINDOWS\system32\audiodg.exe
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\Windows.Management.Service.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\tellib.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\drivers\MbbCx.sys
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\BTAGService.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\autopilotdiag.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\autopilot.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\ApplicationControlCSP.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\agentactivationruntimewindows.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\agentactivationruntime.dll
2019-11-14 20:08:03 ----A---- C:\WINDOWS\system32\AarSvc.dll
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\iscsilog.dll
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\Vid.sys
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\spacedump.sys
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\BthMini.SYS
2019-11-14 20:07:57 ----A---- C:\WINDOWS\system32\drivers\bthenum.sys
2019-11-14 19:41:14 ----D---- C:\Program Files (x86)\Roche
2019-11-14 19:39:43 ----D---- C:\ProgramData\Roche
2019-11-14 19:36:12 ----A---- C:\WINDOWS\system32\poqexec.exe
2019-11-14 19:36:10 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe

======List of files/folders modified in the last 1 month======

2019-12-05 08:03:39 ----D---- C:\Program Files\trend micro
2019-12-05 08:03:34 ----AD---- C:\ProgramData\TEMP
2019-12-05 08:01:30 ----D---- C:\WINDOWS\Temp
2019-12-05 08:01:30 ----D---- C:\WINDOWS\INF
2019-12-05 07:54:17 ----D---- C:\WINDOWS\Prefetch
2019-12-05 07:54:09 ----D---- C:\FRST
2019-12-05 07:52:49 ----SHD---- C:\System Volume Information
2019-12-05 07:50:25 ----D---- C:\WINDOWS\system32\sru
2019-12-05 07:48:56 ----D---- C:\WINDOWS\AppReadiness
2019-12-05 07:46:25 ----D---- C:\ProgramData\TwonkyServer
2019-12-03 20:08:05 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2019-12-03 19:32:39 ----D---- C:\WINDOWS\system32\SleepStudy
2019-12-02 05:43:04 ----D---- C:\Program Files\Opera
2019-12-01 18:08:26 ----RD---- C:\WINDOWS\Microsoft.NET
2019-11-26 21:08:29 ----HD---- C:\Program Files\WindowsApps
2019-11-23 08:21:41 ----SHDC---- C:\WINDOWS\Installer
2019-11-23 08:21:41 ----SHD---- C:\Config.Msi
2019-11-23 08:21:14 ----D---- C:\Program Files\Common Files\microsoft shared
2019-11-23 08:18:42 ----D---- C:\Program Files\Microsoft Office
2019-11-21 21:40:29 ----D---- C:\WINDOWS\system32\Tasks
2019-11-20 23:49:20 ----D---- C:\WINDOWS\system32\config
2019-11-20 21:48:15 ----D---- C:\WINDOWS\System32
2019-11-20 21:48:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2019-11-20 21:42:42 ----D---- C:\ProgramData\boost_interprocess
2019-11-20 21:39:43 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2019-11-20 20:22:58 ----DC---- C:\Users\Roman\AppData\Roaming\vlc
2019-11-20 16:34:14 ----D---- C:\WINDOWS\system32\drivers
2019-11-20 07:43:00 ----D---- C:\WINDOWS\WinSxS
2019-11-20 07:02:22 ----D---- C:\WINDOWS\system32\cs-CZ
2019-11-20 06:56:05 ----D---- C:\WINDOWS\CbsTemp
2019-11-19 21:33:02 ----D---- C:\WINDOWS\system32\catroot2
2019-11-19 20:45:19 ----SD---- C:\Users\Roman\AppData\Roaming\Microsoft
2019-11-17 19:31:03 ----D---- C:\WINDOWS\system32\DriverStore
2019-11-14 21:56:37 ----D---- C:\WINDOWS\SYSWOW64\wbem
2019-11-14 21:56:37 ----D---- C:\WINDOWS\SYSWOW64\migration
2019-11-14 21:56:37 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2019-11-14 21:56:37 ----D---- C:\WINDOWS\SysWOW64
2019-11-14 21:56:36 ----D---- C:\WINDOWS\SystemResources
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\wbem
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\ru-RU
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\ro-RO
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\pt-PT
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\pl-PL
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\nl-NL
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\migration
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\en-US
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\en-GB
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\el-GR
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\Boot
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\ar-SA
2019-11-14 21:56:35 ----D---- C:\WINDOWS\system32\appraiser
2019-11-14 21:56:34 ----RD---- C:\WINDOWS\PrintDialog
2019-11-14 21:56:34 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2019-11-14 21:56:34 ----D---- C:\WINDOWS\ShellExperiences
2019-11-14 21:56:34 ----D---- C:\WINDOWS\ShellComponents
2019-11-14 21:56:34 ----D---- C:\WINDOWS\PolicyDefinitions
2019-11-14 21:56:34 ----D---- C:\WINDOWS\DiagTrack
2019-11-14 21:56:34 ----D---- C:\WINDOWS\bcastdvr
2019-11-14 21:56:34 ----D---- C:\WINDOWS\apppatch
2019-11-14 21:56:34 ----D---- C:\Windows
2019-11-14 21:56:34 ----D---- C:\Program Files (x86)\Windows Media Player
2019-11-14 20:36:19 ----D---- C:\WINDOWS\system32\MRT
2019-11-14 20:31:25 ----AC---- C:\WINDOWS\system32\MRT.exe
2019-11-14 19:41:14 ----RD---- C:\Program Files (x86)
2019-11-14 19:39:43 ----HD---- C:\ProgramData
2019-11-14 19:29:04 ----D---- C:\WINDOWS\system32\Macromed
2019-11-14 19:29:03 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2019-11-06 06:44:42 ----D---- C:\Program Files (x86)\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswArDisk;aswArDisk; C:\WINDOWS\system32\drivers\aswArDisk.sys [2019-10-09 37616]
R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsh.sys [2019-10-09 209552]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniv.sys [2019-10-09 65120]
R0 aswElam;aswElam; C:\WINDOWS\system32\drivers\aswElam.sys [2019-10-09 16304]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2019-10-09 83792]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2019-10-09 316528]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2019-03-19 56632]
R0 MsSecFlt;@%SystemRoot%\System32\Drivers\mssecflt.sys,-1001; C:\WINDOWS\system32\drivers\mssecflt.sys [2019-09-12 252944]
R0 pwdrvio;pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [2013-09-30 19152]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [2013-09-03 56336]
R1 afunix;afunix; C:\WINDOWS\system32\drivers\afunix.sys [2019-03-19 40960]
R1 aswArPot;aswArPot; C:\WINDOWS\system32\drivers\aswArPot.sys [2019-10-09 204824]
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdriver.sys [2019-10-09 274456]
R1 aswHdsKe;aswHdsKe; C:\WINDOWS\system32\drivers\aswHdsKe.sys [2019-10-09 276952]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2019-10-09 42736]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2019-10-09 110320]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2019-10-09 848432]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2019-10-09 460448]
R1 bam;@%SystemRoot%\system32\drivers\bam.sys,-100; C:\WINDOWS\system32\drivers\bam.sys [2019-03-19 70456]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2019-03-19 59392]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2019-03-19 8704]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2019-11-02 161544]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2019-10-09 236024]
R2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2019-11-14 457216]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2019-03-19 53760]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-01-13 11922944]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-01-13 359936]
R3 bindflt;@%systemroot%\system32\drivers\bindflt.sys,-100; C:\WINDOWS\system32\drivers\bindflt.sys [2019-10-09 117048]
R3 dtlitescsibus;@oem23.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2018-01-25 30264]
R3 dtliteusbbus;@oem5.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [2018-01-25 47672]
R3 MTsensor;@oem4.inf,%ASACPI.DisplayName%;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2013-05-17 17280]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2019-03-19 662528]
S0 bttflt;@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter; C:\WINDOWS\System32\drivers\bttflt.sys [2019-03-19 42808]
S0 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2019-03-19 319528]
S0 iaStorAVC;@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller; C:\WINDOWS\System32\drivers\iaStorAVC.sys [2019-03-19 885048]
S0 ItSas35i;ItSas35i; C:\WINDOWS\System32\drivers\ItSas35i.sys [2019-03-19 148520]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2019-03-19 124448]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2019-03-19 128528]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2019-03-19 75280]
S0 megasas35i;megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [2019-03-19 94736]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2019-03-19 58896]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2019-03-19 68624]
S0 Ramdisk;Windows RAM Disk Driver; C:\WINDOWS\system32\DRIVERS\ramdisk.sys [2019-03-19 41784]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2019-03-19 20992]
S3 Acx01000;@%SystemRoot%\system32\drivers\Acx01000.sys,-1000; C:\WINDOWS\system32\drivers\Acx01000.sys [2019-03-19 337920]
S3 amdgpio2;@amdgpio2.inf,%GPIO.SvcDesc%;AMD GPIO Client Driver; C:\WINDOWS\System32\drivers\amdgpio2.sys [2019-03-19 18432]
S3 amdi2c;@amdi2c.inf,%amdi2c.SVCDESC%;AMD I2C Controller Service; C:\WINDOWS\System32\drivers\amdi2c.sys [2019-03-19 37888]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2019-11-14 18432]
S3 AppvStrm;@%systemroot%\system32\drivers\AppvStrm.sys,-101; C:\WINDOWS\system32\drivers\AppvStrm.sys [2019-08-10 137528]
S3 AppvVemgr;@%systemroot%\system32\drivers\AppvVemgr.sys,-101; C:\WINDOWS\system32\drivers\AppvVemgr.sys [2019-08-10 174392]
S3 AppvVfs;@%systemroot%\system32\drivers\AppvVfs.sys,-101; C:\WINDOWS\system32\drivers\AppvVfs.sys [2019-08-10 153912]
S3 BthA2dp;@microsoft_bluetooth_a2dp.inf,%BthA2dp.ServiceDescription%;Microsoft Bluetooth A2dp driver; C:\WINDOWS\System32\drivers\BthA2dp.sys [2019-09-12 231936]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2019-11-14 114688]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [2019-03-19 97280]
S3 BthMini;@bth.inf,%BTHMINI.SvcDesc%;Bluetooth Radio Driver; C:\WINDOWS\System32\drivers\BTHMINI.sys [2019-11-14 36864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\drivers\BTHport.sys [2019-11-14 1428992]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\drivers\BTHUSB.sys [2019-11-14 98304]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2019-03-19 43008]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2019-03-19 64312]
S3 dg_ssudbus;@oem14.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_b9c53b80e63af230\genericusbfn.sys [2019-09-12 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2019-03-19 53560]
S3 hidspi;@hidspi_km.inf,%hidspi.SVCDESC%;Microsoft SPI HID Miniport Driver; C:\WINDOWS\System32\drivers\hidspi.sys [2019-10-09 64000]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2019-11-14 84488]
S3 HwNClx0101;Microsoft Hardware Notifications Class Extension Driver; C:\WINDOWS\System32\Drivers\mshwnclx.sys [2019-03-19 28672]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2019-03-19 1866768]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2019-03-19 36352]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2019-03-19 91136]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2019-03-19 79360]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2019-03-19 93184]
S3 iaLPSS2i_GPIO2_CNL;@iaLPSS2i_GPIO2_CNL.inf,%iaLPSS2i_GPIO2_CNL.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [2019-03-19 112128]
S3 iaLPSS2i_GPIO2_GLK;@iaLPSS2i_GPIO2_GLK.inf,%iaLPSS2i_GPIO2_GLK.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [2019-03-19 96256]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2019-03-19 171520]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2019-03-19 175104]
S3 iaLPSS2i_I2C_CNL;@iaLPSS2i_I2C_CNL.inf,%iaLPSS2i_I2C_CNL.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [2019-03-19 180736]
S3 iaLPSS2i_I2C_GLK;@iaLPSS2i_I2C_GLK.inf,%iaLPSS2i_I2C_GLK.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [2019-03-19 177664]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2019-03-19 566800]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2019-03-19 46592]
S3 intelpmax;@intelpmax.inf,%SvcDesc%;Intel Power Limit Driver; C:\WINDOWS\System32\drivers\intelpmax.sys [2019-03-19 28672]
S3 IPT;IPT; C:\WINDOWS\System32\drivers\ipt.sys [2019-03-19 54584]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2019-03-19 535864]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2019-03-19 62264]
S3 MbbCx;MBB Network Adapter Class Extension; C:\WINDOWS\system32\drivers\MbbCx.sys [2019-11-14 359424]
S3 Microsoft_Bluetooth_AvrcpTransport;@microsoft_bluetooth_avrcptransport.inf,%Microsoft_Bluetooth_AvrcpTransport.ServiceDescription%;Microsoft Bluetooth Avrcp Transport Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [2019-03-19 64512]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2019-03-19 1150480]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2019-03-19 153616]
S3 NDKPing;NDKPing Driver; C:\WINDOWS\system32\drivers\NDKPing.sys [2019-03-19 63488]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2019-03-19 187904]
S3 nvdimm;@nvdimm.inf,%nvdimm.SvcDesc%;Microsoft NVDIMM device driver; C:\WINDOWS\System32\drivers\nvdimm.sys [2019-03-19 158520]
S3 PktMon;Packet Monitor Driver; C:\WINDOWS\system32\drivers\PktMon.sys [2019-03-19 96056]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2019-03-19 127800]
S3 PNPMEM;@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver; C:\WINDOWS\System32\drivers\pnpmem.sys [2019-03-19 17408]
S3 portcfg;portcfg; C:\WINDOWS\System32\drivers\portcfg.sys [2019-03-19 25600]
S3 pwdspio;pwdspio; \??\C:\WINDOWS\system32\pwdspio.sys [2013-09-30 12504]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2019-03-19 987152]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2019-03-19 211456]
S3 rhproxy;@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver; C:\WINDOWS\System32\drivers\rhproxy.sys [2019-03-19 113152]
S4 hvcrash;hvcrash; C:\WINDOWS\System32\drivers\hvcrash.sys [2019-03-19 32568]
S4 RsFx0153;RsFx0153 Driver; C:\WINDOWS\system32\DRIVERS\RsFx0153.sys [2012-06-29 321992]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Desktop App Service; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [2017-12-19 1364904]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2019-09-10 88136]
R2 AdobeUpdateService;AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2019-07-05 816184]
R2 AGMService;Adobe Genuine Monitor Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2019-10-08 3147344]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2019-10-08 2914896]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-01-13 238080]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2019-04-29 96056]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2019-10-09 996880]
R2 AvastWscReporter;AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [2019-10-09 57504]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 CDPUserSvc_f7aba34;Uživatelská služba platformy připojených zařízení_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2019-11-17 11650416]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 DispBrokerDesktopSvc;@%SystemRoot%\system32\dispbroker.desktop.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 hddrsrv;hddrsrv; C:\Program Files (x86)\HDD Regenerator\hrsrv.exe [2013-05-08 82144]
R2 McAfee WebAdvisor;McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [2019-11-17 913208]
R2 NAUpdate;Nero Update; C:\Program Files (x86)\Nero\Update\NASvc.exe [2018-07-19 794904]
R2 OneSyncSvc_f7aba34;Hostitel synchronizace_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 RealtekWlanU;RealtekWlanU; C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RtlService.exe [2014-10-09 48856]
R2 RunSwUSB;RunSwUSB; C:\Windows\runSW.exe [2014-12-15 44760]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2019-10-12 6085360]
R3 BrYNSvc;BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [2013-09-25 282112]
R3 BthAvctpSvc;@%SystemRoot%\system32\BthAvctpSvc.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 camsvc;@%SystemRoot%\system32\CapabilityAccessManager.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 cbdhsvc_f7aba34;Uživatelská služba schránky_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2018-01-12 3480768]
R3 DisplayEnhancementService;@%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 InstallService;@%SystemRoot%\system32\InstallService.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2019-07-19 658232]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 PimIndexMaintenanceSvc_f7aba34;Data kontaktů_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-25 107848]
S2 LcSvrAdm;ELSA Administration Service; D:\ElsaWin\bin\LcSvrAdm.exe [2017-03-14 262656]
S2 LcSvrDba;ELSA DBA Server; D:\ElsaWin\bin\LcSvrDba.exe [2017-03-14 435712]
S2 LcSvrHis;ELSA Historie Server; D:\ElsaWin\bin\LcSvrHis.exe [2017-03-14 387072]
S2 LcSvrPAS;ELSA PASS Server; D:\ElsaWin\bin\LcSvrPas.exe [2017-03-14 519680]
S2 LcSvrSaz;ELSA APOSpro Server; D:\ElsaWin\bin\LcSvrSaz.exe [2017-03-14 438784]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S2 MSSQL$ELSAWINDB;SQL Server (ELSAWINDB); C:\Program Files\Microsoft SQL Server\MSSQL10_50.ELSAWINDB\MSSQL\Binn\sqlservr.exe [2012-06-29 62218696]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 postgresql-x64-9.2;postgresql-x64-9.2 - PostgreSQL Server 9.2; C:/Program Files/PostgreSQL/9.2/bin/pg_ctl.exe runservice -N postgresql-x64-9.2 -D C:/Program Files/PostgreSQL/9.2/data -w []
S2 RTLDHCPService;Realtek DHCP Service; C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RTLDHCP.exe [2014-10-09 262360]
S3 AarSvc;@%SystemRoot%\system32\AarSvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 AarSvc_f7aba34;Agent Activation Runtime_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2019-11-14 335416]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 AssignedAccessManagerSvc;@%SystemRoot%\system32\assignedaccessmanagersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 autotimesvc;@%SystemRoot%\System32\autotimesvc.dll,-6; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BcastDVRUserService;@%SystemRoot%\system32\BcastDVRUserService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BcastDVRUserService_f7aba34;Uživatelská služba pro GameDVR a vysílání her_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BluetoothUserService;@%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BluetoothUserService_f7aba34;Služba pro podporu uživatelů Bluetooth_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BTAGService;@%SystemRoot%\system32\BTAGService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CaptureService;@%SystemRoot%\system32\CaptureService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CaptureService_f7aba34;CaptureService_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 cbdhsvc;@%SystemRoot%\system32\cbdhsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ConsentUxUserSvc;@%SystemRoot%\system32\ConsentUxClient.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ConsentUxUserSvc_f7aba34;ConsentUX_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CredentialEnrollmentManagerUserSvc;@%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2019-03-19 380120]
S3 CredentialEnrollmentManagerUserSvc_f7aba34;CredentialEnrollmentManagerUserSvc_f7aba34; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2019-03-19 380120]
S3 DeviceAssociationBrokerSvc;@%SystemRoot%\system32\deviceaccess.dll,-107; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DeviceAssociationBrokerSvc_f7aba34;DeviceAssociationBroker_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicePickerUserSvc;@%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicePickerUserSvc_f7aba34;DevicePicker_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicesFlowUserSvc_f7aba34;Tok zařízení_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2019-09-12 97792]
S3 diagsvc;@%systemroot%\system32\DiagSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2018-01-26 1591264]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2019-08-10 43704]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.108\elevation_service.exe [2019-11-16 1110512]
S3 GraphicsPerfSvc;@%SystemRoot%\system32\GraphicsPerfSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-01-25 107848]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 LcSvrAuf;ELSA Auftragsverwaltungs Service; D:\ElsaWin\bin\LcSvrAuf.exe [2017-03-14 1352704]
S3 LxpSvc;@%SystemRoot%\system32\LanguageOverlayServer.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MessagingService_f7aba34;Služba zasílání zpráv_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2002-02-01 264504]
S3 perceptionsimulation;@%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101; C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe [2019-03-19 103424]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PrintWorkflowUserSvc;@%SystemRoot%\system32\PrintWorkflowService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PrintWorkflowUserSvc_f7aba34;PrintWorkflow_f7aba34; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PushToInstall;@%SystemRoot%\system32\pushtoinstall.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S4 AppVClient;@%systemroot%\system32\AppVClient.exe,-102; C:\WINDOWS\system32\AppVClient.exe [2019-08-10 828216]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]

-----------------EOF-----------------

Re: Prosím o preventivku

Napsal: 05 pro 2019 22:15
od Conder
Ahoj :)

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Skenovat nyni (Scan now) a pockaj na dokoncenie
  • Nechaj zaskrtnute vsetky nalezy
  • Klikni na Cisteni a opravy (Clean and Repair) a potvrd restart PC teraz
  • Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
  • Otvori sa log, jeho obsah sem skopiruj

Re: Prosím o preventivku

Napsal: 09 pro 2019 14:22
od romcolahvac
Ahoj, provedeno:

jen tam nebylo možné kliknout CLEAN AND REPAIR ale QUARANTINE, což jsem potvrdil :-)

LOG:


# -------------------------------
# Malwarebytes AdwCleaner 8.0.0.0
# -------------------------------
# Build: 11-21-2019
# Database: 2019-11-26.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 12-09-2019
# Duration: 00:00:01
# OS: Windows 10 Pro
# Cleaned: 2
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

Deleted ?????????? ????????
Deleted ???????? ???????? ? ????? ?? Mail.Ru

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [4272 octets] - [02/08/2019 20:59:38]
AdwCleaner[C00].txt - [3890 octets] - [02/08/2019 21:00:01]
AdwCleaner[S01].txt - [1532 octets] - [09/12/2019 14:20:37]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

Re: Prosím o preventivku

Napsal: 10 pro 2019 17:30
od Conder
:arrow: Poprosim o obidva logy z FRST (FRST.txt a Addition.txt) podla tohto navodu: https://forum.viry.cz/viewtopic.php?f=13&t=154679

Re: Prosím o preventivku

Napsal: 10 pro 2019 19:42
od romcolahvac
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2019
Ran by Roman (administrator) on ROMANPCSTOLNI (10-12-2019 19:34:39)
Running from C:\Users\Roman\Desktop
Loaded Profiles: Roman & postgres (Available Profiles: Roman & postgres)
Platform: Windows 10 Pro Version 1903 18362.476 (X64) Language: Čeština (Česko)
Default browser: Opera
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files (x86)\Roche\Exor4\Bin\Exor4.exe
(Abstradrome -> ) C:\Program Files (x86)\HDD Regenerator\HDD Regenerator.exe
(Abstradrome -> ) C:\Program Files (x86)\HDD Regenerator\HDD Regenerator.exe
(Abstradrome -> ) C:\Program Files (x86)\HDD Regenerator\hrsrv.exe
(Adobe Inc. -> ) C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) D:\Program Files\iTunes\iTunesHelper.exe
(Autodesk, Inc. -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe
(Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe
(Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler64.exe
(McAfee, LLC -> McAfee, Inc.) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(McAfee, LLC -> McAfee, Inc.) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Roman\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19071.17920.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1910.0.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Node.js Foundation -> Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera.exe
(Opera Software AS -> Opera Software) C:\Program Files\Opera\65.0.3467.62\opera_crashreporter.exe
(PacketVideo Corporation -> ) [File not signed] C:\Program Files (x86)\Twonky\TwonkyServer\twonkyserver.exe
(PacketVideo Corporation -> PacketVideo) [File not signed] C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe
(PacketVideo Corporation -> PacketVideo) [File not signed] C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\pg_ctl.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\postgres.exe
(PostgreSQL Global Development Group) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\postgres.exe
(Realtek Semiconductor Corp -> ) C:\Windows\runSW.exe
(Realtek Semiconductor Corp -> Realtek) C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RtlService.exe
(Volkswagen AG) [File not signed] D:\ElsaWin\bin\LcSvrAdm.exe
(Volkswagen AG) [File not signed] D:\ElsaWin\bin\LcSvrAuf.exe
(Volkswagen AG) [File not signed] D:\ElsaWin\bin\LcSvrDba.exe
(Volkswagen AG) [File not signed] D:\ElsaWin\bin\LcSvrHis.exe
(Volkswagen AG) [File not signed] D:\ElsaWin\bin\LcSvrPas.exe
(Volkswagen AG) [File not signed] D:\ElsaWin\bin\LcSvrSaz.exe
(ZONER software, a.s. -> ZONER software) C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [4047480 2012-11-30] (VIA Technologies Inc. -> VIA)
HKLM\...\Run: [iTunesHelper] => D:\Program Files\iTunes\iTunesHelper.exe [302904 2019-07-19] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [706392 2017-12-19] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2013-12-05] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.) [File not signed]
HKLM-x32\...\Run: [HDD Regenerator] => C:\Program Files (x86)\HDD Regenerator\Shell.exe [90336 2013-05-08] (Abstradrome -> )
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [4047480 2012-11-30] (VIA Technologies Inc. -> VIA)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [76600 2019-07-19] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2623032 2019-07-05] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [95135168 2019-08-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [5263040 2018-01-12] (Disc Soft Ltd -> Disc Soft Ltd)
HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2007576 2017-02-03] (Autodesk, Inc -> Autodesk, Inc.)
HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\Run: [Xvid] => WScript "C:\Program Files (x86)\Xvid\CheckUpdateLauncher.vbs" "C:\Program Files (x86)\Xvid\CheckUpdate.ps1"
HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Roman\AppData\Local\Microsoft\Teams\Update.exe [1789552 2019-10-13] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\Run: [Zoner Photo Studio Autoupdate] => C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [563416 2015-07-12] (ZONER software, a.s. -> ZONER software)
HKU\S-1-5-21-2651452621-253113433-2049451952-1006\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.108\Installer\chrmstp.exe [2019-11-18] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Exor4 for XDMS_T.lnk [2019-11-20]
ShortcutTarget: Exor4 for XDMS_T.lnk -> C:\Program Files (x86)\Roche\Exor4\Bin\Exor4.exe () [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Twonky Server.lnk [2019-03-27]
ShortcutTarget: Twonky Server.lnk -> C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe (PacketVideo Corporation -> PacketVideo) [File not signed]
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0BA96F4C-815B-4B92-B32E-2BBF36710493} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2108216 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {12CF3DF3-45F4-465B-B586-5D514E28567E} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2108216 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {1806D01B-65C3-4440-825D-B841573A83D2} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [155472 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {306EFAD4-39D4-4150-BB9E-89301CF31E45} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2089864 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {537324FC-C125-46F8-A254-54A46BA58471} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {6934BF88-55D5-489D-A66A-079FBCE6E652} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24671304 2019-11-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {6F76F035-4E18-4C13-BBC2-3DCDFE2E5244} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1873288 2019-09-18] (AVAST Software s.r.o. -> AVAST Software)
Task: {72C81345-3BB7-43B9-900C-C2F5C0B881A9} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24671304 2019-11-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {7DC54B9D-CE3A-42D7-91C5-BCC6DA5A1C3E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2018-01-25] (Google Inc -> Google Inc.)
Task: {80F00345-548D-409F-B300-96589FCF79B5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-12-10] (Adobe Inc. -> Adobe)
Task: {94A07625-4349-40A8-9606-2FEDDDB65AC3} - System32\Tasks\simplitec Power Suite => C:\Program Files (x86)\Nero\Nero TuneItUp\TuneItUp.exe
Task: {A7FB8686-81A4-42E3-BFE8-B12F25CA0357} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [7018264 2018-07-18] (Nero AG -> Nero AG)
Task: {BECD1FF9-6CF0-404C-B3AD-1AEC1A94B094} - System32\Tasks\ASUS Patch for VIA Audio => C:\WINDOWS\system32\AsPatchViaAudio.exe [160448 2012-11-07] (ASUSTeK Computer Inc. -> ASUSTek Computer INC.)
Task: {C273A340-146C-4303-A266-7D6F0ABD0413} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-2651452621-253113433-2049451952-1001 => {201600D8-6EFF-48CE-B842-E14D37A0682D} C:\WINDOWS\System32\wpninprc.dll [24064 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
Task: {C80D10E7-943E-498A-AC78-3E2B04592EEA} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2872400 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {CCC435A9-6F03-42F1-BF72-8A64525EE050} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6072640 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {D5D4A07F-5274-4AB8-B736-D62A2A324887} - System32\Tasks\Opera scheduled Autoupdate 1518342991 => C:\Program Files\Opera\launcher.exe [1528344 2019-12-04] (Opera Software AS -> Opera Software)
Task: {D6D98A0B-BF82-433A-A779-367DE7CC4924} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
Task: {D9774324-F193-4B35-8129-25BDC46413C0} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe
Task: {DFD2A452-FDD9-4591-8BE8-7444741ECAA4} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_303_pepper.exe [1453112 2019-12-10] (Adobe Inc. -> Adobe)
Task: {E50DEBEB-E787-4C95-B361-10246FAF4A2E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6072640 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {ED45877C-58C9-4026-A0AD-A56790DEEA81} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [155472 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Task: {F00FE203-686D-422F-8506-B42D538EC072} - System32\Tasks\simplitec Power Suite (Autopilot.exe) => C:\Program Files (x86)\Nero\Nero TuneItUp\Autopilot.exe
Task: {F6C1DA88-2D3B-4DA4-93D8-A6E64C85FC45} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [107848 2018-01-25] (Google Inc -> Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\simplitec Power Suite (Autopilot.exe).job => C:\Program Files (x86)\Nero\Nero TuneItUp\Autopilot.exe C:\Program Files (x86)\Nero\Nero TuneItUp\ROMANPCSTOLNI\Roman&simplitec Power Suite (Autopilot.exe
Task: C:\WINDOWS\Tasks\simplitec Power Suite.job => C:\Program Files (x86)\Nero\Nero TuneItUp\TuneItUp.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{09273f41-5daf-4fb2-a764-3fb9b3244b5f}: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{75da9a98-fb9f-4c42-9b11-64868e5fca1b}: [DhcpNameServer] 213.46.172.36 213.46.172.37

Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2019-12-08] (McAfee, LLC -> McAfee, Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\ssv.dll [2019-04-23] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2019-12-08] (McAfee, LLC -> McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\jp2ssv.dll [2019-04-23] (Oracle America, Inc. -> Oracle Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: vw-wi - {0F3C833F-FB28-40EA-8CB9-6A55B996C3F6} - D:\ElsaWin\bin\wiprot.dll [2011-12-06] (TODO: <Company name>) [File not signed]

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2019-12-08]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-07-05] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.211.2 -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\dtplugin\npDeployJava1.dll [2019-04-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.211.2 -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\plugin2\npjp2.dll [2019-04-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-06] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-06] (Google Inc -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-11] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-07-05] (Adobe Inc. -> Adobe Systems)

Chrome:
=======
CHR HomePage: Default -> inline.go.mail.ru
CHR DefaultSearchURL: Default -> hxxps://inline.go.mail.ru/search?inline_comp=chxtnhp15.1.4.3&q={searchTerms}&fr=chxtnhp15.1.4.3
CHR DefaultSearchKeyword: Default -> inline.go.mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
CHR Profile: C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default [2019-12-10]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2019-12-10]
CHR Extension: (Avast Online Security) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-10-24]
CHR Extension: (Mail.Ru) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\iepoegkaoeljnbhagabakjodgpfniimo [2019-12-10]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-10-24]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-24]
CHR Extension: (Chrome Media Router) - C:\Users\Roman\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-24]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2651452621-253113433-2049451952-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
CHR HKLM-x32\...\Chrome\Extension: [hjdkfkdkokphfploiiddakjokndinfgb]
CHR HKLM-x32\...\Chrome\Extension: [iepoegkaoeljnbhagabakjodgpfniimo]

Opera:
=======
OPR DownloadDir: D:\Stažené soubory
OPR Extension: (Adblock Plus - free ad blocker) - C:\Users\Roman\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2019-10-23]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1364904 2017-12-19] (Autodesk, Inc. -> Autodesk Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [816184 2019-07-05] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3147344 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2914896 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [238080 2015-01-13] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6085360 2019-10-12] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11345992 2019-11-28] (Microsoft Corporation -> Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3480768 2018-01-12] (Disc Soft Ltd -> Disc Soft Ltd)
R2 hddrsrv; C:\Program Files (x86)\HDD Regenerator\hrsrv.exe [82144 2013-05-08] (Abstradrome -> )
R2 LcSvrAdm; D:\ElsaWin\bin\LcSvrAdm.exe [262656 2017-03-14] (Volkswagen AG) [File not signed]
R3 LcSvrAuf; D:\ElsaWin\bin\LcSvrAuf.exe [1352704 2017-03-14] (Volkswagen AG) [File not signed]
R2 LcSvrDba; D:\ElsaWin\bin\LcSvrDba.exe [435712 2017-03-14] (Volkswagen AG) [File not signed]
R2 LcSvrHis; D:\ElsaWin\bin\LcSvrHis.exe [387072 2017-03-14] (Volkswagen AG) [File not signed]
R2 LcSvrPAS; D:\ElsaWin\bin\LcSvrPas.exe [519680 2017-03-14] (Volkswagen AG) [File not signed]
R2 LcSvrSaz; D:\ElsaWin\bin\LcSvrSaz.exe [438784 2017-03-14] (Volkswagen AG) [File not signed]
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [913208 2019-12-08] (McAfee, LLC -> McAfee, Inc.)
S2 MSSQL$ELSAWINDB; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ELSAWINDB\MSSQL\Binn\sqlservr.exe [62218696 2012-06-29] (Microsoft Corporation -> Microsoft Corporation)
R2 RealtekWlanU; C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RtlService.exe [48856 2014-10-09] (Realtek Semiconductor Corp -> Realtek)
S2 RTLDHCPService; C:\Program Files (x86)\NETIS\USB Wireless LAN Utility\RTLDHCP.exe [262360 2014-10-09] (Realtek Semiconductor Corp -> Realtek)
R2 RunSwUSB; C:\Windows\runSW.exe [44760 2014-12-15] (Realtek Semiconductor Corp -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5796168 2019-09-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 SQLAgent$ELSAWINDB; C:\Program Files\Microsoft SQL Server\MSSQL10_50.ELSAWINDB\MSSQL\Binn\SQLAGENT.EXE [441288 2012-06-29] (Microsoft Corporation -> Microsoft Corporation)
R2 TwonkyServer; C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe [629624 2014-05-12] (PacketVideo Corporation -> PacketVideo) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\NisSrv.exe [2552416 2019-08-12] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MsMpEng.exe [108832 2019-08-12] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 postgresql-x64-9.2; C:/Program Files/PostgreSQL/9.2/bin/pg_ctl.exe runservice -N "postgresql-x64-9.2" -D "C:/Program Files/PostgreSQL/9.2/data" -w [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [11922944 2015-01-13] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [359936 2015-01-13] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37616 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-09] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [276952 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [161544 2019-11-02] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-01-25] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-01-25] (Disc Soft Ltd -> Disc Soft Ltd)
R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] (ASUSTeK Computer Inc. -> )
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> )
R0 PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation -> Corel Corporation)
S4 RsFx0153; C:\WINDOWS\System32\DRIVERS\RsFx0153.sys [321992 2012-06-29] (Microsoft Corporation -> Microsoft Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1156392 2019-11-18] (Realtek Semiconductor Corp. -> Realtek )
R0 sptd2; C:\WINDOWS\System32\Drivers\sptd2.sys [196152 2018-01-25] (Disc Soft Ltd -> Duplex Secure Ltd)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2019-04-03] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [47496 2019-08-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [344288 2019-08-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54496 2019-08-12] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-12-10 15:09 - 2019-12-10 15:09 - 000000000 ____D C:\Program Files (x86)\Realtek
2019-12-10 15:09 - 2019-11-18 09:18 - 001156392 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2019-12-10 15:09 - 2019-11-18 04:29 - 000000000 ____D C:\Users\Roman\Desktop\Install_Win10_10037_11192019
2019-12-09 15:28 - 2019-12-09 15:28 - 000000914 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2019-12-09 14:13 - 2019-12-09 14:14 - 008218800 ____C (Malwarebytes) C:\Users\Roman\Desktop\adwcleaner_8.0.0 (1).exe
2019-12-05 08:12 - 2019-12-05 08:12 - 000000000 _____ C:\WINDOWS\system32\last.dump
2019-12-05 07:54 - 2019-12-09 18:08 - 000060070 ____C C:\Users\Roman\Desktop\Addition.txt
2019-12-05 07:53 - 2019-12-09 15:14 - 000000000 ____D C:\Users\Roman\Desktop\DiscoverCare_v.1.0.4_win
2019-12-05 07:52 - 2019-12-10 19:37 - 000037179 ____C C:\Users\Roman\Desktop\FRST.txt
2019-12-05 07:52 - 2019-12-09 18:05 - 000000000 ___DC C:\Users\Roman\Desktop\FRST-OlderVersion
2019-11-30 15:03 - 2019-11-30 15:04 - 000235520 ____C (BNM Inc.) C:\Users\Roman\Desktop\IP Finder 2.0.exe
2019-11-27 20:29 - 2019-11-27 20:47 - 000000000 ___DC C:\Users\Roman\Desktop\PASSAT B8
2019-11-20 21:39 - 2019-11-20 21:39 - 000002316 _____ C:\Users\Public\Desktop\LightCycler® 480 SW 1.5.1.lnk
2019-11-20 21:39 - 2019-11-20 21:39 - 000002220 _____ C:\Users\Public\Desktop\Exor4 for XDMS_T.lnk
2019-11-20 21:39 - 2019-11-20 21:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roche
2019-11-14 20:12 - 2019-11-14 20:12 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 009711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 005501952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 004307968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 004129408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 002956472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 001866272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 001659192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.AppAgent.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 001495864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000512512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000249856 _____ (Gracenote, Inc.) C:\WINDOWS\SysWOW64\gnsdk_fp.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000030720 _____ C:\WINDOWS\system32\uwfservicingapi.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2019-11-14 20:12 - 2019-11-14 20:12 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2019-11-14 20:12 - 2019-11-14 20:12 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2019-11-14 20:11 - 2019-11-14 20:11 - 025901056 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 022627840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 018020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 008011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 007195648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 007015936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 006521768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 006232576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 006082808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 005914112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 005763848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 004578816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 004150272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AI.MachineLearning.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 003487232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-11-14 20:11 - 2019-11-14 20:11 - 002586816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002562048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002399232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002369552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002258848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002188808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 002158080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001718584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001691648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001664688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001616696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001413864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001399096 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 001387024 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001283072 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001189376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001185792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AgentService.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001126912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 001059840 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 001047352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001017680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 001007616 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000960040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000827192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000822072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000816952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000762880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000741376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2013CustomActions.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000689664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000679152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000666640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000494904 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000452920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000404904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000396088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000380944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000354816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnify.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-11-14 20:11 - 2019-11-14 20:11 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ManagedEventLogging.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ConfigWrapper.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000259384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVFileSystemMetadata.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmd.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000230200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-11-14 20:11 - 2019-11-14 20:11 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagSvc.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CmUtil.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\accessibilitycpl.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000193800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-11-14 20:11 - 2019-11-14 20:11 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000136536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\omadmapi.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinHvPlatform.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Utilman.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000089568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcXtrnal.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000084488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winhvr.sys
2019-11-14 20:11 - 2019-11-14 20:11 - 000084488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-11-14 20:11 - 2019-11-14 20:11 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2019-11-14 20:11 - 2019-11-14 20:11 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncController.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usp10.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\reg.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2019-11-14 20:11 - 2019-11-14 20:11 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AtBroker.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000061240 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvhostsvc.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\reg.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAppMonitor.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CabUtil.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.EventLogMessages.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2010CustomActions.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAgentPolicyGenerator.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.WmiAccess.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppData.WinRT.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncCommon.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.WinRT.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.LocalSyncProvider.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcXtrnal.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernSync.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2019-11-14 20:11 - 2019-11-14 20:11 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateBaselineGenerator.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateConfigItemGenerator.exe
2019-11-14 20:11 - 2019-11-14 20:11 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SmbSyncProvider.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.MonitorSyncProvider.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncConditions.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-11-14 20:11 - 2019-11-14 20:11 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 005943296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 005112320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 003967920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-11-14 20:10 - 2019-11-14 20:10 - 003752960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 002772272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 002576384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 001916984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 001856512 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000832000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000768488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000700416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000632320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000477184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-11-14 20:10 - 2019-11-14 20:10 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000251512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2019-11-14 20:10 - 2019-11-14 20:10 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2019-11-14 20:10 - 2019-11-14 20:10 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2019-11-14 20:10 - 2019-11-14 20:10 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2019-11-14 20:10 - 2019-11-14 20:10 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2019-11-14 20:10 - 2019-11-14 20:10 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\posetup.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 009928208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 007600448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 007262456 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 006435840 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 004047360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 003791360 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 003371928 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 002988344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 002871848 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 002763016 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 002703872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 002698768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 001974824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-11-14 20:09 - 2019-11-14 20:09 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 001726480 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 001647064 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 001327064 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 001171704 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000982840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000874936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000844800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000822200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000811536 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000638264 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000586768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000517432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000514576 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000477712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-11-14 20:09 - 2019-11-14 20:09 - 000466928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000461320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 000446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnify.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000372752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 000324624 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000220472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000164776 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Utilman.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000113160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AtBroker.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usp10.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nsiproxy.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 000047616 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000036368 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winnsi.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsisvc.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000028344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winnsi.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidtel.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000024792 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsi.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nsi.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\applockerfltr.sys
2019-11-14 20:09 - 2019-11-14 20:09 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-11-14 20:09 - 2019-11-14 20:09 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-11-14 20:09 - 2019-11-14 20:09 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 017787904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 007904152 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 007849424 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 007278592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 006227104 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 006166016 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 005890048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AI.MachineLearning.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 004615616 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 004140544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 004005888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 003968512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 003728384 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 003591208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 003387392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 003105792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 002716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 002284032 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 002126112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 002120704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 002114048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001920512 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001656392 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001451520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 001413912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001259416 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 001094656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001069064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000911824 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000874536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 000534528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000530944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000522176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 000416016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 000350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000322504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000291256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-11-14 20:08 - 2019-11-14 20:08 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\accessibilitycpl.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000105488 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000088568 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000065272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000047208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscisvif.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2019-11-14 20:08 - 2019-11-14 20:08 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dstokenclean.exe
2019-11-14 20:08 - 2019-11-14 20:08 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscadminui.exe
2019-11-14 20:07 - 2019-11-14 20:07 - 001428992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-11-14 20:07 - 2019-11-14 20:07 - 000657424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2019-11-14 20:07 - 2019-11-14 20:07 - 000551736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-11-14 20:07 - 2019-11-14 20:07 - 000292664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2019-11-14 20:07 - 2019-11-14 20:07 - 000204816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2019-11-14 20:07 - 2019-11-14 20:07 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2019-11-14 20:07 - 2019-11-14 20:07 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2019-11-14 20:07 - 2019-11-14 20:07 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2019-11-14 20:07 - 2019-11-14 20:07 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsilog.dll
2019-11-14 19:41 - 2019-11-20 21:39 - 000000000 ____D C:\Program Files (x86)\Roche
2019-11-14 19:39 - 2019-11-14 19:41 - 000000000 ____D C:\ProgramData\Roche
2019-11-14 19:38 - 2018-02-20 13:07 - 000000000 ____D C:\Users\Roman\Desktop\LC_480_Software_1.5.1
2019-11-14 19:36 - 2019-11-14 19:36 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2019-11-14 19:36 - 2019-11-14 19:36 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-12-10 19:37 - 2018-05-06 05:52 - 000000000 ____D C:\ProgramData\TEMP
2019-12-10 19:36 - 2019-10-08 05:06 - 000003462 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2019-12-10 19:36 - 2019-10-08 05:06 - 000003238 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2019-12-10 19:36 - 2019-10-05 10:10 - 000002668 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2019-12-10 19:36 - 2019-08-10 07:53 - 000003888 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2019-12-10 19:36 - 2019-08-10 07:53 - 000003590 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2019-12-10 19:36 - 2019-08-10 07:53 - 000003542 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2019-12-10 19:36 - 2019-08-10 07:53 - 000003362 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1518342991
2019-12-10 19:36 - 2019-08-10 07:53 - 000003168 _____ C:\WINDOWS\system32\Tasks\KMSAutoNet
2019-12-10 19:36 - 2019-08-10 07:53 - 000002918 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2651452621-253113433-2049451952-1001
2019-12-10 19:36 - 2019-08-10 07:53 - 000002688 _____ C:\WINDOWS\system32\Tasks\ASUS Patch for VIA Audio
2019-12-10 19:36 - 2019-08-10 07:53 - 000002606 _____ C:\WINDOWS\system32\Tasks\simplitec Power Suite
2019-12-10 19:36 - 2019-08-10 07:53 - 000002586 _____ C:\WINDOWS\system32\Tasks\simplitec Power Suite (Autopilot.exe)
2019-12-10 19:36 - 2019-08-10 07:53 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2019-12-10 19:36 - 2019-07-30 19:52 - 000000456 _____ C:\WINDOWS\Tasks\simplitec Power Suite (Autopilot.exe).job
2019-12-10 19:36 - 2019-07-30 19:51 - 000000362 _____ C:\WINDOWS\Tasks\simplitec Power Suite.job
2019-12-10 19:36 - 2018-02-06 19:05 - 000000000 ____D C:\FRST
2019-12-10 19:30 - 2019-08-10 07:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-12-10 19:30 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-12-10 18:37 - 2019-03-27 14:30 - 000000000 ____D C:\ProgramData\TwonkyServer
2019-12-10 16:45 - 2019-08-10 07:53 - 001786796 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-12-10 16:45 - 2019-03-19 12:57 - 000716944 _____ C:\WINDOWS\system32\perfh005.dat
2019-12-10 16:45 - 2019-03-19 12:57 - 000145024 _____ C:\WINDOWS\system32\perfc005.dat
2019-12-10 16:45 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2019-12-10 16:42 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-12-10 16:39 - 2019-08-10 07:53 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-12-10 16:39 - 2018-01-26 00:29 - 000000000 ____D C:\ProgramData\boost_interprocess
2019-12-10 16:34 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-12-10 15:09 - 2018-01-27 10:12 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2019-12-10 15:05 - 2019-08-10 07:53 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2019-12-10 15:02 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-12-10 15:02 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-12-09 18:05 - 2019-08-02 19:40 - 002263552 _____ (Farbar) C:\Users\Roman\Desktop\FRST64.exe
2019-12-09 17:49 - 2019-08-10 07:44 - 000000000 ____D C:\Users\postgres
2019-12-09 15:28 - 2018-03-19 22:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2019-12-09 15:28 - 2018-03-19 22:44 - 000000000 ____D C:\Program Files\CPUID
2019-12-09 14:12 - 2018-08-25 16:45 - 000000000 ___DC C:\Users\Roman\AppData\Local\CrashDumps
2019-12-08 17:57 - 2018-01-25 23:05 - 000000000 ___DC C:\Users\Roman\AppData\Local\Packages
2019-12-08 10:29 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-12-08 08:03 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-12-08 08:01 - 2018-06-18 13:43 - 000000000 ____D C:\Program Files\Microsoft Office
2019-12-08 07:54 - 2019-10-05 10:10 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2019-12-08 07:52 - 2019-01-11 11:21 - 000001107 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2019-12-08 07:52 - 2018-02-11 10:56 - 000000000 ____D C:\Program Files\Opera
2019-12-05 20:22 - 2019-08-10 07:44 - 000000000 ____D C:\Users\Roman
2019-12-05 19:57 - 2018-02-24 19:37 - 000000000 ___DC C:\Users\Roman\Desktop\Výkresy
2019-12-05 08:03 - 2018-02-01 19:22 - 000000000 ____D C:\Program Files\trend micro
2019-12-03 19:41 - 2018-11-04 09:35 - 000000000 ___DC C:\Users\Roman\Desktop\Anežka
2019-11-27 19:29 - 2018-05-21 18:52 - 000000000 ___DC C:\Users\Roman\AppData\Local\PlaceholderTileLogoFolder
2019-11-21 21:40 - 2019-08-10 07:44 - 000002404 ____C C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-11-21 21:40 - 2018-01-25 23:09 - 000000000 ___RD C:\Users\Roman\OneDrive
2019-11-20 20:22 - 2018-01-25 23:39 - 000000000 ___DC C:\Users\Roman\AppData\Roaming\vlc
2019-11-20 06:56 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-11-18 21:45 - 2018-02-01 19:17 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-11-17 19:34 - 2018-01-25 23:05 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-11-17 19:34 - 2018-01-25 23:05 - 000000000 ___RD C:\Users\Roman\3D Objects
2019-11-17 19:30 - 2019-08-10 07:41 - 000542336 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\DiagTrack
2019-11-14 21:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-11-14 20:36 - 2018-01-26 14:25 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-11-14 20:31 - 2018-01-26 14:24 - 128443096 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-11-14 19:33 - 2018-01-26 00:25 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk

==================== Files in the root of some directories ========

2018-03-18 20:37 - 2018-05-15 18:59 - 000002394 _____ () C:\Users\Roman\IP_Log_Data.js
2018-03-18 21:00 - 2018-05-15 20:00 - 000003599 _____ () C:\Users\Roman\Network_Meter_Data.js
2018-05-09 20:43 - 2018-05-09 20:46 - 000000624 ____C () C:\Users\Roman\AppData\Roaming\All CPU MeterV3_Settings.ini
2018-03-18 21:30 - 2018-05-15 20:03 - 000000026 ____C () C:\Users\Roman\AppData\Roaming\Network Meter_Usage.ini
2019-07-25 06:56 - 2019-07-25 07:49 - 000012518 ____C () C:\Users\Roman\AppData\Roaming\SerialClonerPrefs
2019-03-27 17:05 - 2019-03-27 17:05 - 000000001 ____C () C:\Users\Roman\AppData\Local\llftool.4.40.agreement
2018-11-04 08:23 - 2018-11-04 08:23 - 000000000 ____C () C:\Users\Roman\AppData\Local\oobelibMkey.log

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Re: Prosím o preventivku

Napsal: 10 pro 2019 19:43
od romcolahvac
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-12-2019
Ran by Roman (10-12-2019 19:38:21)
Running from C:\Users\Roman\Desktop
Windows 10 Pro Version 1903 18362.476 (X64) (2019-08-10 06:53:52)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2651452621-253113433-2049451952-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2651452621-253113433-2049451952-503 - Limited - Disabled)
Guest (S-1-5-21-2651452621-253113433-2049451952-501 - Limited - Disabled)
postgres (S-1-5-21-2651452621-253113433-2049451952-1006 - Limited - Enabled) => C:\Users\postgres
Roman (S-1-5-21-2651452621-253113433-2049451952-1001 - Administrator - Enabled) => C:\Users\Roman
WDAGUtilityAccount (S-1-5-21-2651452621-253113433-2049451952-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\uTorrent) (Version: 3.5.5.45311 - BitTorrent Inc.)
8GadgetPack (HKLM-x32\...\{E6BA0C10-856E-452A-954C-85F41072385F}) (Version: 25.0.0 - 8GadgetPack.net)
A360 Desktop (HKLM\...\{B65CD59E-A771-4354-AA4B-C3E01B496BCD}) (Version: 8.2.3.1800 - Autodesk)
ACA & MEP 2018 Object Enabler (HKLM\...\{28B89EEF-1004-0000-5102-CF3F3A09B77D}) (Version: 8.0.40.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{28B89EEF-1001-0000-3102-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.021.20056 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.9.0.504 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.303 - Adobe)
Adobe Premiere Elements 15 (HKLM-x32\...\{FD45A9C9-02BE-4E62-8629-78DF29A10FF5}) (Version: 15.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2019 (HKLM-x32\...\PPRO_13_0_1) (Version: 13.0.1 - Adobe Systems Incorporated)
Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - )
AIDA64 Extreme v5.00 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.00 - FinalWire Ltd.)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
Arduino (HKLM-x32\...\Arduino) (Version: 1.8.5 - Arduino LLC)
AutoCAD 2018 - English (HKLM\...\{28B89EEF-1001-0409-2102-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
AutoCAD 2018 (HKLM\...\{28B89EEF-1001-0000-0102-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
AutoCAD 2018 Language Pack - English (HKLM\...\{28B89EEF-1001-0409-1102-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2018 (HKLM-x32\...\{177AD7F6-9C77-4E50-BA53-B7259C5F282D}) (Version: 16.11.1.0 - Autodesk)
Autodesk App Manager 2016-2018 (HKLM-x32\...\{20EC0CA2-346E-4660-9903-51B278DF15F6}) (Version: 2.4.0 - Autodesk)
Autodesk AutoCAD 2018 - English (HKLM\...\AutoCAD 2018 - English) (Version: 22.0.49.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.8 (HKLM-x32\...\{214D3370-746E-4886-8EAA-5769EB87D044}) (Version: 1.2.8.0 - Autodesk)
Autodesk License Service (x64) - 5.1.4 (HKLM\...\{3609A8D9-FC0C-4C9B-9F58-0B1D1A4FE556}) (Version: 5.1.4.0 - Autodesk)
Autodesk Material Library 2018 (HKLM-x32\...\{7847611E-92E9-4917-B395-71C91D523104}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2018 (HKLM-x32\...\{FCDED119-A969-4E48-8A32-D21AD6B03253}) (Version: 16.11.1.0 - Autodesk)
Autodesk ReCap (HKLM\...\{6ED27C84-0000-1033-0102-D4DAEFFC23C2}) (Version: 4.0.0.28 - Autodesk) Hidden
Autodesk ReCap (HKLM\...\Autodesk ReCap 360) (Version: 4.0.0.28 - Autodesk)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 19.8.2393 - AVAST Software)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Brother MFL-Pro Suite DCP-9020CDW (HKLM-x32\...\{E98A9C92-E767-475B-8BC6-8780A86DDC72}) (Version: 1.0.5.0 - Brother Industries, Ltd.)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.8.7042 - CDBurnerXP)
CPUID CPU-Z 1.90 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.90 - CPUID, Inc.)
CPUID HWMonitor 1.34 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.34 - )
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.7.0.0337 - Disc Soft Ltd)
Data Lifeguard Diagnostic for Windows 1.31 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version: - Western Digital Corporation)
DiskInternals Linux Reader (HKLM-x32\...\DiskInternals Linux Reader) (Version: 3.4.0.27 - DiskInternals Research)
Dukto R6 (HKLM-x32\...\{386C0311-B146-4CE0-89E5-8469A3583156}}_is1) (Version: R6 - Emanuele Colombo)
ElsaWin (HKLM-x32\...\ElsaWin) (Version: 6.00 - )
FARO LS 1.1.600.6 (64bit) (HKLM-x32\...\{510A08AF-1649-4844-94E5-EAC43A023685}) (Version: 6.0.6.5 - FARO Scanner Production)
FOTOLAB CEWE fotosvet (HKLM-x32\...\FOTOLAB CEWE fotosvet) (Version: 6.3.7 - CEWE Stiftung u Co. KGaA)
Free FLAC to MP3 Converter 1.4 (HKLM-x32\...\{A54C01BD-1277-4722-B42B-EC9800A90B1E}_is1) (Version: 1.4 - PolySoft Solutions)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 78.0.3904.108 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.341 - Google LLC) Hidden
HD Tune Pro 5.70 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software)
HDD Regenerator (HKLM-x32\...\{CC5DA723-D428-40D1-B82B-21EB64B1273C}) (Version: 20.11.0011 - Abstradrome)
iTunes (HKLM\...\{281A8A05-80EB-4B93-B825-C9FBEE17CE85}) (Version: 12.9.6.3 - Apple Inc.)
Java 8 Update 211 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180211F0}) (Version: 8.0.2110.12 - Oracle Corporation)
JDiskReport 1.4.1 (HKLM-x32\...\JDiskReport 1.4.1) (Version: 1.4.1 (2014-02-26 11:50:44) - JGoodies Karsten Lentzsch)
KMSpico v9.2.3 (HKLM\...\KMSpico_is1) (Version: 9.2.3 - )
LightCycler® 480 (HKLM-x32\...\{8F07FAB0-5BBA-43EF-979E-6E7C9E4F811E}) (Version: - )
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.52 - McAfee, LLC.)
Microsoft Office 365 ProPlus - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 16.0.12228.20332 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProplusRetail - cs-cz) (Version: 16.0.12228.20332 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProplusRetail - en-us) (Version: 16.0.12228.20332 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\OneDriveSetup.exe) (Version: 19.192.0926.0012 - Microsoft Corporation)
Microsoft Project Professional 2016 - cs-cz (HKLM\...\ProjectProRetail - cs-cz) (Version: 16.0.12228.20332 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM\...\ProjectProRetail - en-us) (Version: 16.0.12228.20332 - Microsoft Corporation)
Microsoft Report Viewer Redistributable 2008 SP1 (HKLM-x32\...\Microsoft Report Viewer Redistributable 2008 (KB971119)) (Version: - Microsoft Corporation)
Microsoft SQL Server 2008 R2 (64-bit) (HKLM\...\Microsoft SQL Server 2008 R2) (Version: - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{79A2C6E8-C727-4D12-B4B3-19790C181DEA}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Policies (HKLM-x32\...\{D21BC5B2-CBAC-48FA-A701-B5A63C1CA7B8}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Setup (English) (HKLM\...\{C3525BF7-3698-4CD3-A8C3-69BD6F57BA3B}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Browser (HKLM-x32\...\{BF9BF038-FE03-429D-9B26-2FA0FD756052}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 Query Tools ENU (HKLM-x32\...\{DDFD8348-058C-4F4B-85E5-6D740D4AB3FE}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\Teams) (Version: 1.2.00.22654 - Microsoft Corporation)
Microsoft Visio Professional 2016 - cs-cz (HKLM\...\VisioProRetail - cs-cz) (Version: 16.0.12228.20332 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM\...\VisioProRetail - en-us) (Version: 16.0.12228.20332 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{CA8A885F-E95B-3FC6-BB91-F4D9377C7686}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{4ECF4BDC-8387-329A-ABE9-CF5798F84BB2}) (Version: 9.0.35191 - Microsoft Corporation)
MiniTool Partition Wizard Free 11 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Software Limited)
Movavi Video Suite 15 (HKLM-x32\...\Movavi Video Suite 15) (Version: 15.4.0 - Movavi)
Nero BurningROM 2019 (HKLM-x32\...\{798AC6BA-CF99-4585-BD3A-89A51CB10530}) (Version: 20.0.00900 - Nero AG)
Nero Core (HKLM-x32\...\{85EFC653-C416-4759-BFD0-0A0095B3FFAC}) (Version: 1.2.00200 - Nero AG)
Nero Info (HKLM-x32\...\{F030BFE8-8476-4C08-A553-233DE80A2BE1}) (Version: 20.0.1011 - Nero AG)
Nero TuneItUp (HKLM-x32\...\Nero_tuneitup_is1) (Version: 2.8.0.84 - Nero AG)
NETIS Wireless LAN Driver and Utility (HKLM-x32\...\{9C049509-055C-4CFF-A116-1D12312225EB}) (Version: 1.00.0290 - Netis Systems Co., Ltd.)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12228.20332 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12228.20332 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0405-1000-0000000FF1CE}) (Version: 16.0.12228.20332 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12228.20332 - Microsoft Corporation) Hidden
Opera Stable 65.0.3467.62 (HKLM-x32\...\Opera 65.0.3467.62) (Version: 65.0.3467.62 - Opera Software)
Paragon Partition Manager™ 14 Free (HKLM\...\{47E5588F-C3A0-11DE-9857-005056C00008}) (Version: 90.00.0003 - Paragon Software)
Platform (HKLM-x32\...\{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Hidden
Počítačová aplikace Autodesk (HKLM-x32\...\Autodesk Desktop App) (Version: 7.0.7.232 - Autodesk)
Podpora aplikací Apple (32bitová) (HKLM-x32\...\{5C028510-A6A1-409A-A2BF-4DCB43B21EF9}) (Version: 7.6 - Apple Inc.)
Podpora aplikací Apple (64bitová) (HKLM\...\{5C7D4FCF-80C5-4520-9934-D50532AAC59C}) (Version: 7.6 - Apple Inc.)
PostgreSQL 9.2 (HKLM\...\PostgreSQL 9.2) (Version: 9.2 - PostgreSQL Global Development Group)
Prerequisite installer (HKLM-x32\...\{37E15A76-F310-4C62-9D32-EE96C83BBD2C}) (Version: 20.2.0001 - Nero AG) Hidden
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
R for Windows 3.6.1 (HKLM\...\R for Windows 3.6.1_is1) (Version: 3.6.1 - R Core Team)
RAD Video Tools (HKLM-x32\...\RADVideo) (Version: - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.37.1028.2019 - Realtek)
RStudio (HKLM-x32\...\RStudio) (Version: 1.2.1335 - RStudio)
Service Pack 2 for SQL Server 2008 R2 (KB2630458) (64-bit) (HKLM\...\KB2630458) (Version: 10.52.4000.0 - Microsoft Corporation)
Siko Kitchen Planner Web (HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\SquareClock_Production_Home_5-2_290df3ae) (Version: - 3DVIA SAS)
Simple Time Lapse (HKLM-x32\...\{D07A4321-C78A-4442-8DC2-F63F1A2D08E3}) (Version: 1.0.1 - Limosoft)
SketchUp 2018 (HKLM\...\{C702DD60-EBF4-4961-8B7D-F209B361F985}) (Version: 18.0.16975 - Trimble, Inc.)
Speciální aplikace Autodesk 2016-2018 (HKLM-x32\...\{384C4B74-B749-4AB6-9367-4D51A6AA9CB8}) (Version: 2.4.0 - Autodesk)
SQL Server 2008 R2 SP2 Common Files (HKLM\...\{234F6B0D-10AE-4BB7-B2F3-E48D4861952D}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Common Files (HKLM\...\{36F70DEE-1EBF-4707-AFA2-E035EEAEBAA1}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Services (HKLM\...\{FA7394B8-CE65-4F9E-AC99-F372AD365424}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Services (HKLM\...\{FBD367D1-642F-47CF-B79B-9BE48FB34007}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Shared (HKLM\...\{A2122A9C-A699-4365-ADF8-68FEAC125D61}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Shared (HKLM\...\{C942A025-A840-4BF2-8987-849C0DD44574}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Management Studio (HKLM\...\{51E5BC99-A087-4CFF-8D93-462903EA7E12}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Management Studio (HKLM\...\{72AB7E6F-BC24-481E-8C45-1AB5B3DD795D}) (Version: 10.52.4000.0 - Microsoft Corporation) Hidden
Sql Server Customer Experience Improvement Program (HKLM\...\{F31183CF-E10F-4DE1-BB59-6C0FF38E481E}) (Version: 10.50.1600.1 - Microsoft Corporation) Hidden
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.2.0.22654 - Microsoft Corporation)
Twonky Server (HKLM-x32\...\TwonkyServer) (Version: 7.3.0.0 - PacketVideo)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
VIA Platforma Ovladače zařízení (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
Xvid Video Codec (HKLM-x32\...\Xvid Video Codec 1.3.5) (Version: 1.3.5 - Xvid Team)
Zoner Photo Studio 17 (HKLM\...\ZonerPhotoStudio17_CZ_is1) (Version: 17.0.1.12 - ZONER software)

Packages:
=========
Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc [2019-08-04] (Adobe Systems Incorporated)
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.153.600.0_x86__kgqvnymyfvs32 [2019-12-05] (king.com)
Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_4.5.1.2_x86__h6adky7gbf63m [2019-11-26] (Gameloft.)
March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_4.5.0.9_x86__h6adky7gbf63m [2019-12-05] (Gameloft.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.11052.0_x64__8wekyb3d8bbwe [2019-11-11] (Microsoft Studios) [MS Ad]
Microsoft Zprávy -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.33.13094.0_x64__8wekyb3d8bbwe [2019-11-19] (Microsoft Corporation) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.33.13253.0_x64__8wekyb3d8bbwe [2019-11-25] (Microsoft Corporation) [MS Ad]
Pošta a Kalendář -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12228.20276.0_x64__8wekyb3d8bbwe [2019-11-26] (Microsoft Corporation) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0 [2019-12-08] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Users\Roman\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll (AddGadgets IT -> )
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\Roman\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler) [File not signed]
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-F7B3E42E758B} -> [Creative Cloud Files] => C:\Users\Roman\Creative Cloud Files [2019-08-04 20:49]
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Roman\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler) [File not signed]
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Roman\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19178.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{9AAF0EB6-42D8-46C1-A2EF-679511B37A0D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{B6EB585B-B467-4E46-A9C7-48D7D6FD26CB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Roman\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19178.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2018\en-US\acadficn.dll (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2651452621-253113433-2049451952-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2017-02-03] (Autodesk, Inc -> Autodesk, Inc.)
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2017-02-03] (Autodesk, Inc -> Autodesk)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-01-12] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-01-12] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-09] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [vidc.XVID] => C:\WINDOWS\system32\xvidvfw.dll [251392 2017-12-08] () [File not signed]
HKLM\...\Drivers32: [vidc.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [235520 2017-12-08] () [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDiskReport 1.4.1\JGoodies Home Page.lnk -> hxxp://www.jgoodies.com

==================== Loaded Modules (Whitelisted) =============

2018-03-14 09:07 - 2009-02-27 16:38 - 000139264 ____R () [File not signed] C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2019-07-31 21:40 - 2013-04-02 04:41 - 000176128 _____ () [File not signed] C:\Program Files\PostgreSQL\9.2\bin\LIBPQ.dll
2019-07-31 21:42 - 2012-08-14 14:31 - 001328128 _____ () [File not signed] C:\Program Files\PostgreSQL\9.2\bin\libxml2.dll
2019-01-20 21:59 - 2014-09-09 13:30 - 000603648 _____ () [File not signed] C:\Program Files\Zoner\Photo Studio 17\Program32\SpiderMonkey.dll
2019-10-14 19:27 - 2019-10-14 19:27 - 004496896 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DiscSoft.NET.Common\b1d5ceb64db1e5c9d42187fed3f8ad71\DiscSoft.NET.Common.ni.dll
2018-03-14 09:07 - 2005-04-22 05:36 - 000143360 _____ () [File not signed] C:\WINDOWS\system32\BrSNMP64.dll
2018-01-26 00:03 - 2017-09-05 09:09 - 059523896 _____ (Autodesk, Inc. -> ) [File not signed] C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libcef.dll
2018-03-14 09:07 - 2013-06-12 19:06 - 000385024 ____R (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BrMonitor.dll
2018-03-14 09:07 - 2010-09-29 17:07 - 000180224 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\BroSNMP.dll
2018-03-14 09:07 - 2011-02-28 11:32 - 000208896 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\Brother\BrFirmUpdateCheck.dll
2018-03-14 09:07 - 2013-10-10 21:55 - 002040320 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\Browny02\Brother\BrStMonWRes.dll
2018-03-14 09:07 - 2013-12-05 13:04 - 000137728 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcAssoc.dll
2018-03-14 09:07 - 2014-02-17 19:24 - 000084480 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcDlgRc.dll
2018-03-14 09:07 - 2014-02-17 19:24 - 017905152 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcGrImg.dll
2018-03-14 09:07 - 2013-11-15 10:17 - 000082944 _____ (Brother Industries, Ltd.) [File not signed] C:\Program Files (x86)\ControlCenter4\BrCcLCze.dll
2018-03-14 09:07 - 2012-07-14 09:53 - 000087040 _____ (Brother Industries, Ltd.) [File not signed] C:\WINDOWS\system32\BrNetSti.dll
2019-07-31 21:42 - 2012-05-08 22:00 - 000981504 _____ (Free Software Foundation) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\iconv.dll
2019-07-31 21:40 - 2011-01-10 16:16 - 000240862 _____ (Free Software Foundation) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\libintl-8.dll
2019-03-27 14:30 - 2014-05-12 15:18 - 000166776 _____ (PacketVideo Corporation -> ) [File not signed] C:\Program Files (x86)\Twonky\TwonkyServer\platform-player.dll
2019-11-20 21:39 - 2012-02-21 17:33 - 001519694 _____ (The Firebird Project) [File not signed] C:\Program Files (x86)\Roche\Exor4\Bin\gds32.dll
2019-07-31 21:42 - 2012-10-12 11:58 - 001577472 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\LIBEAY32.dll
2019-07-31 21:42 - 2012-10-12 11:58 - 000338944 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\PostgreSQL\9.2\bin\SSLEAY32.dll
2017-03-14 14:10 - 2017-03-14 14:10 - 000353792 _____ (Volkswagen AG) [File not signed] D:\ElsaWin\bin\vfc10u.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:B755D674 [134]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-2651452621-253113433-2049451952-1001\Software\Classes\.scr: AutoCADScriptFile =>

==================== Internet Explorer trusted/restricted ==========

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2651452621-253113433-2049451952-1001\...\sharepoint.com -> hxxps://szsruska-files.sharepoint.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-09-29 14:46 - 2019-08-04 17:50 - 000000765 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\Tools\Binn\;C:\Program Files\Microsoft SQL Server\100\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\;C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-2651452621-253113433-2049451952-1001\Control Panel\Desktop\\Wallpaper -> d:\stažené soubory\8749e516-1e8f-4914-b2f3-be3d501117e3.jpeg
HKU\S-1-5-21-2651452621-253113433-2049451952-1006\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 213.46.172.36 - 213.46.172.37
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{3532B99B-941C-4A90-9511-E802EAEEE8BE}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe No File
FirewallRules: [TCP Query User{0742B366-DEBD-44AB-A9C6-4AC233B5A50A}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe No File
FirewallRules: [UDP Query User{D97B37F5-E029-47F5-A05A-451C910EA81C}C:\program files\blackmagic design\davinci resolve\resolve.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\resolve.exe No File
FirewallRules: [TCP Query User{327B901E-13F9-432E-9ED5-F7EBF7DF9717}C:\program files\blackmagic design\davinci resolve\resolve.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\resolve.exe No File
FirewallRules: [UDP Query User{4940C6B8-2333-4D23-A45E-F8A9A742346C}C:\program files\blackmagic design\davinci resolve\dpdecoder.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\dpdecoder.exe No File
FirewallRules: [TCP Query User{F665B926-8D76-4AA4-AB8B-76494A1D726B}C:\program files\blackmagic design\davinci resolve\dpdecoder.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\dpdecoder.exe No File
FirewallRules: [{F560C31E-876E-49B1-BCD7-BBE475BFE3BD}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DPDecoder.exe No File
FirewallRules: [{997E3B83-A47B-45CF-BA90-23AA4082DC9E}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\TangentPanelDaemon.exe No File
FirewallRules: [{8E0C0F18-70EF-426A-86C0-4B64280399BB}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\EuphonixPanelDaemon.exe No File
FirewallRules: [{55213158-CF1A-49FF-93DB-121B38BE6D48}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\JLCooperPanelDaemon.exe No File
FirewallRules: [{82FC34B1-5F49-4C6B-9C4B-AAF2B0208272}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DaVinciPanelDaemon.exe No File
FirewallRules: [{6DB76AAA-455F-4590-90F9-819122E90ED2}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\bmdpaneld.exe No File
FirewallRules: [{C4960669-7A71-4B69-B457-263D0B50B985}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe No File
FirewallRules: [UDP Query User{C8A907AD-2F07-433B-A910-6081C572E181}C:\users\roman\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\roman\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{CB2D43F1-42D6-4C3A-B8C0-992BA5531972}C:\users\roman\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\roman\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{07A1B455-B933-49ED-BEB5-0FB17B74648C}] => (Allow) C:\Program Files (x86)\Nero\Nero 2019\Nero Burning ROM\nero.exe (Nero AG -> Nero AG)
FirewallRules: [{966175E9-8F23-4FE5-B09C-6F8AAAEAC8E1}] => (Allow) C:\Program Files (x86)\Nero\Nero 2019\Nero Burning ROM\StartNBR.exe (Nero AG -> Nero AG)
FirewallRules: [{14697BF9-3D35-4D4B-A153-9934D4259B85}] => (Allow) LPort=1688
FirewallRules: [{A0685C59-6DD4-478C-B8DD-D5ADCA4F7779}] => (Allow) D:\ElsaWin\bin\ElsaWin.exe (Volkswagen AG) [File not signed]
FirewallRules: [{334D8D3D-B5DB-4F8E-9D6D-AB8B562A1B70}] => (Allow) D:\ElsaWin\bin\ElsaWin.exe (Volkswagen AG) [File not signed]
FirewallRules: [{4E1F63C5-D7C7-422C-96A1-34D736360248}] => (Allow) LPort=135
FirewallRules: [UDP Query User{5A0AC7FA-24CC-4AB2-AC71-27C246A5D9E3}C:\users\roman\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\roman\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{66A62E16-C6A0-4147-874B-33F0BD39BFE2}C:\users\roman\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\roman\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{CB58C452-DCC5-437F-9AE3-C8AA5DDB26C7}C:\program files (x86)\dukto\dukto.exe] => (Allow) C:\program files (x86)\dukto\dukto.exe (msec.it) [File not signed]
FirewallRules: [TCP Query User{87C709A4-53A7-4F40-AE9B-04595D6DBC16}C:\program files (x86)\dukto\dukto.exe] => (Allow) C:\program files (x86)\dukto\dukto.exe (msec.it) [File not signed]
FirewallRules: [{82040DAB-D78F-425C-AFC1-9299724370F9}] => (Allow) C:\Program Files (x86)\Twonky\TwonkyServer\twonkyserver.exe (PacketVideo Corporation -> ) [File not signed]
FirewallRules: [{82549BC0-06DB-4B27-9F09-D234836FF7BE}] => (Allow) C:\Program Files (x86)\Twonky\TwonkyServer\twonkyserver.exe (PacketVideo Corporation -> ) [File not signed]
FirewallRules: [{DE449B46-B261-48EC-8096-738191C53F0A}] => (Allow) C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe (PacketVideo Corporation -> PacketVideo) [File not signed]
FirewallRules: [{BA08AA27-13C8-4434-A95D-4766F2454B3E}] => (Allow) C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe (PacketVideo Corporation -> PacketVideo) [File not signed]
FirewallRules: [UDP Query User{A2647A1E-6A65-46A3-892D-41C5F9B26D9D}C:\program files (x86)\philips\media manager\philips media manager.exe] => (Allow) C:\program files (x86)\philips\media manager\philips media manager.exe No File
FirewallRules: [TCP Query User{4F61BE47-61C3-4B9B-99A1-B76C5666975A}C:\program files (x86)\philips\media manager\philips media manager.exe] => (Allow) C:\program files (x86)\philips\media manager\philips media manager.exe No File
FirewallRules: [UDP Query User{A9A18CED-5B03-4B04-8707-45D6D2FF917C}C:\program files (x86)\twonky\twonkyserver\twonkyserver.exe] => (Allow) C:\program files (x86)\twonky\twonkyserver\twonkyserver.exe (PacketVideo Corporation -> ) [File not signed]
FirewallRules: [TCP Query User{E7A15910-8C3F-488C-872B-2D7217870F55}C:\program files (x86)\twonky\twonkyserver\twonkyserver.exe] => (Allow) C:\program files (x86)\twonky\twonkyserver\twonkyserver.exe (PacketVideo Corporation -> ) [File not signed]
FirewallRules: [{013AF469-F68B-4810-AEEE-9DF75EC5801B}] => (Allow) C:\Program Files\Zoner\Photo Studio 17\Program32\MediaServer.exe (ZONER software, a.s. -> ZONER software)
FirewallRules: [TCP Query User{1CDF9CD3-50A6-430E-BAFA-870C874DCCBC}C:\program files\archicad 20\archicad.exe] => (Allow) C:\program files\archicad 20\archicad.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [UDP Query User{EF98864E-03CB-419E-9D6D-AB72D1AD9C8F}C:\program files\archicad 20\archicad.exe] => (Allow) C:\program files\archicad 20\archicad.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [TCP Query User{46AE5067-E908-4463-B237-D19A879B2CB6}C:\program files\archicad 20\overwatchserver.exe] => (Allow) C:\program files\archicad 20\overwatchserver.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [UDP Query User{8807B58A-4757-4684-A7D4-BEDD93A59BAD}C:\program files\archicad 20\overwatchserver.exe] => (Allow) C:\program files\archicad 20\overwatchserver.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [TCP Query User{6B333387-5A7E-4BEB-8E19-180D5C37E225}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [UDP Query User{D5CBC817-5C4B-42D3-9932-554AD66846D5}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [{E9DB556B-B3E1-405A-8D7F-BB1A4A870F78}] => (Allow) LPort=54925
FirewallRules: [{8B90123E-2D78-4658-A664-CF9BB9963358}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{2A25239F-7E2B-444E-8928-5A1D17236909}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{C58FEBDC-8C61-4B61-BFC4-BAEC002E7E8F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{03E757C7-95AE-444E-B071-6A651539FC9B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E16BBF8B-2C69-440F-BC74-1DCE6F3C9C9A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{94B73EF5-20D3-4D3E-AAAB-5356CAEBEB6E}] => (Allow) D:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [TCP Query User{072F2059-FCDE-4A35-A5B2-21B846E98268}C:\program files\rstudio\bin\rsession.exe] => (Block) C:\program files\rstudio\bin\rsession.exe (RStudio, Inc.) [File not signed]
FirewallRules: [UDP Query User{78E548F7-B754-47C1-B558-CE512408AD27}C:\program files\rstudio\bin\rsession.exe] => (Block) C:\program files\rstudio\bin\rsession.exe (RStudio, Inc.) [File not signed]
FirewallRules: [{664C8513-2AD6-4B15-AC94-D4D6B8BBBF27}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6535E804-3721-47C0-9A2E-9114EF8C65B2}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AD59A4C8-EDF9-4330-9019-ED2C3887B4B0}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D98ADF0A-14D5-42F1-BE37-D0B97C7F4D23}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{30128FD8-E251-44DF-B7DF-D2535D7E9E95}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{1B291D9F-4A68-4F6C-94BC-4DA4D7E54735}C:\program files (x86)\roche\exor4\bin\exor4.exe] => (Allow) C:\program files (x86)\roche\exor4\bin\exor4.exe () [File not signed]
FirewallRules: [UDP Query User{7E727B93-A63F-4FC2-88F5-024319F7F9F3}C:\program files (x86)\roche\exor4\bin\exor4.exe] => (Allow) C:\program files (x86)\roche\exor4\bin\exor4.exe () [File not signed]
FirewallRules: [{F009816F-3939-4FD9-8B27-723D60522F22}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{F9C7633E-EC22-484A-96A5-C92D3D0927E6}] => (Allow) C:\Program Files\Opera\65.0.3467.48\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{96E7E6DB-FABC-4B9D-BE94-495165CEC9D9}] => (Allow) C:\Program Files\Opera\65.0.3467.62\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{77114B04-34C0-44A1-AE91-57E97201AD03}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{54EDA298-57FB-4140-9732-EE50426658AD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3FC7BA62-F654-49DB-8C2D-9623CB1A157B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FE1A5F51-2418-431B-918D-78674E099CB2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E2BA823A-2C63-4B8C-85DF-AA95B3F6F15D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{2CE984FD-3422-4D1B-A40A-0229E27CBCB6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{CCC91A9B-3C83-4E26-8061-8C333BF80FF8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{080D419E-4536-40E9-85B7-D29542530B8B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.121.1654.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)

==================== Restore Points =========================

ATTENTION: System Restore is disabled (Total:118.29 GB) (Free:25.05 GB) (21%)

==================== Faulty Device Manager Devices ============

Name: Multimediální adaptér
Description: Multimediální adaptér
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Multimediální video adaptér
Description: Multimediální video adaptér
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Multimediální adaptér
Description: Multimediální adaptér
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Multimediální adaptér
Description: Multimediální adaptér
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (12/10/2019 07:37:23 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (3104,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (12/10/2019 06:54:17 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (13140,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (12/10/2019 06:44:04 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (12500,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (12/10/2019 06:38:11 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x8007232B
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (12/10/2019 06:38:10 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Aktivace licence (slui.exe) se nezdařila s následujícím kódem chyby:
hr=0x8007232B
Argument příkazového řádku:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=2

Error: (12/10/2019 04:58:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 76859

Error: (12/10/2019 04:58:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 76859

Error: (12/10/2019 04:58:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (12/10/2019 06:48:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba AppX Deployment Service (AppXSVC) neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (12/10/2019 06:48:14 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby AppX Deployment Service (AppXSVC) bylo dosaženo časového limitu (30000 ms).

Error: (12/10/2019 04:40:12 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Služba SQL Server (ELSAWINDB) skončila s následující chybou specifickou pro službu:
V souboru bitové kopie nelze nalézt zadaný název prostředku.

Error: (12/10/2019 04:39:24 PM) (Source: atapi) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Ide\IdePort4.

Error: (12/10/2019 04:39:24 PM) (Source: atapi) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Ide\IdePort4.

Error: (12/10/2019 04:39:23 PM) (Source: atapi) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Ide\IdePort4.

Error: (12/10/2019 04:39:22 PM) (Source: atapi) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Ide\IdePort4.

Error: (12/10/2019 04:39:21 PM) (Source: atapi) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Ide\IdePort4.


Windows Defender:
===================================
Date: 2019-08-12 07:29:02.750
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win32/Keygen
ID: 2147593794
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\Users\Roman\Desktop\KMSAuto.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.299.1666.0, AS: 1.299.1666.0, NIS: 1.299.1666.0
Verze modulu: AM: 1.1.16200.1, NIS: 1.1.16200.1

Date: 2019-08-12 07:26:51.663
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win32/Keygen
ID: 2147593794
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\Users\Roman\Desktop\KMSAuto.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: ROMANPCSTOLNI\Roman
Název procesu: C:\Windows\explorer.exe
Verze bezpečnostních informací: AV: 1.299.1666.0, AS: 1.299.1666.0, NIS: 1.299.1666.0
Verze modulu: AM: 1.1.16200.1, NIS: 1.1.16200.1

Date: 2019-08-10 08:56:30.708
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win32/Keygen
ID: 2147593794
Závažnost: Střední
Kategorie: Nástroj
Cesta: file:_C:\Users\Roman\Desktop\KMSAuto.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: ROMANPCSTOLNI\Roman
Název procesu: C:\Windows\explorer.exe
Verze bezpečnostních informací: AV: 1.261.341.0, AS: 1.261.341.0, NIS: 1.261.341.0
Verze modulu: AM: 1.1.14500.5, NIS: 1.1.14500.5

Date: 2019-08-10 08:55:45.299
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win32/Keygen
ID: 2147593794
Závažnost: Střední
Kategorie: Nástroj
Cesta: file:_C:\Users\Roman\Desktop\KMSAuto.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: ROMANPCSTOLNI\Roman
Název procesu: C:\Windows\System32\SearchProtocolHost.exe
Verze bezpečnostních informací: AV: 1.261.341.0, AS: 1.261.341.0, NIS: 1.261.341.0
Verze modulu: AM: 1.1.14500.5, NIS: 1.1.14500.5

Date: 2019-08-10 08:55:16.552
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win32/Keygen
ID: 2147593794
Závažnost: Střední
Kategorie: Nástroj
Cesta: file:_C:\Users\Roman\Desktop\KMSAuto.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: ROMANPCSTOLNI\Roman
Název procesu: C:\Windows\explorer.exe
Verze bezpečnostních informací: AV: 1.261.341.0, AS: 1.261.341.0, NIS: 1.261.341.0
Verze modulu: AM: 1.1.14500.5, NIS: 1.1.14500.5

CodeIntegrity:
===================================

Date: 2019-12-10 19:37:23.737
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

Date: 2019-12-10 19:37:23.736
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

Date: 2019-12-10 19:32:39.584
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

Date: 2019-12-10 19:32:39.582
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

Date: 2019-12-10 19:32:02.964
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements.

Date: 2019-12-10 19:32:02.959
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements.

Date: 2019-12-10 19:28:00.625
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements.

Date: 2019-12-10 19:28:00.620
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 1702 05/21/2010
Motherboard: ASUSTeK Computer INC. P7P55D
Processor: Intel(R) Core(TM) i3 CPU 530 @ 2.93GHz
Percentage of memory in use: 90%
Total physical RAM: 4094.05 MB
Available physical RAM: 373.06 MB
Total Virtual: 7806.05 MB
Available Virtual: 2819.25 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:118.29 GB) (Free:24.98 GB) NTFS
Drive d: (600GB) (Fixed) (Total:596.16 GB) (Free:281.77 GB) NTFS
Drive i: (WD 2TB) (Fixed) (Total:1863.01 GB) (Free:598.02 GB) NTFS

\\?\Volume{3529ca86-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.49 GB) (Free:0.46 GB) NTFS
\\?\Volume{3529ca86-0000-0000-0000-00b21d000000}\ () (Fixed) (Total:0.46 GB) (Free:0.04 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 2 (Size: 596.2 GB) (Disk ID: D28720C0)
Partition 1: (Active) - (Size=596.2 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================

Re: Prosím o preventivku

Napsal: 11 pro 2019 15:38
od Conder
:arrow: Program McAfee WebAdvisor mozes odinstalovat, ak ho nepotrebujes.

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
    Task: {D9774324-F193-4B35-8129-25BDC46413C0} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe
    C:\ProgramData\KMSAutoS
    BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2019-12-08] (McAfee, LLC -> McAfee, Inc.)
    BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2019-12-08] (McAfee, LLC -> McAfee, Inc.)
    FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
    FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2019-12-08]
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
    CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [hjdkfkdkokphfploiiddakjokndinfgb]
    CHR HKLM-x32\...\Chrome\Extension: [iepoegkaoeljnbhagabakjodgpfniimo]
    2019-12-05 07:52 - 2019-12-09 18:05 - 000000000 ___DC C:\Users\Roman\Desktop\FRST-OlderVersion
    2019-12-10 19:36 - 2019-08-10 07:53 - 000003168 _____ C:\WINDOWS\system32\Tasks\KMSAutoNet
    AlternateDataStreams: C:\ProgramData\TEMP:B755D674 [134]
    
    Hosts:
    EmptyTemp:
    End
  • Uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj

Re: Prosím o preventivku

Napsal: 11 pro 2019 20:30
od romcolahvac
Dobrý večer, děkuji, zde je log:


Fix result of Farbar Recovery Scan Tool (x64) Version: 07-12-2019
Ran by Roman (11-12-2019 20:03:48) Run:2
Running from C:\Users\Roman\Desktop
Loaded Profiles: Roman & postgres (Available Profiles: Roman & postgres)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
Task: {D9774324-F193-4B35-8129-25BDC46413C0} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe
C:\ProgramData\KMSAutoS
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2019-12-08] (McAfee, LLC -> McAfee, Inc.)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2019-12-08] (McAfee, LLC -> McAfee, Inc.)
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2019-12-08]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hjdkfkdkokphfploiiddakjokndinfgb]
CHR HKLM-x32\...\Chrome\Extension: [iepoegkaoeljnbhagabakjodgpfniimo]
2019-12-05 07:52 - 2019-12-09 18:05 - 000000000 ___DC C:\Users\Roman\Desktop\FRST-OlderVersion
2019-12-10 19:36 - 2019-08-10 07:53 - 000003168 _____ C:\WINDOWS\system32\Tasks\KMSAutoNet
AlternateDataStreams: C:\ProgramData\TEMP:B755D674 [134]

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Error: (0) Failed to create a restore point.

========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========



Count : 4077
Average :
Sum : 6255784226
Maximum :
Minimum :
Property : Length




========= End of Powershell: =========

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D9774324-F193-4B35-8129-25BDC46413C0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D9774324-F193-4B35-8129-25BDC46413C0}" => removed successfully
C:\WINDOWS\System32\Tasks\KMSAutoNet => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMSAutoNet" => removed successfully
"C:\ProgramData\KMSAutoS" => not found
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => not found
"HKLM\Software\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}" => not found
"C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi" => not found
"HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}" => not found
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho => not found
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hjdkfkdkokphfploiiddakjokndinfgb => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\iepoegkaoeljnbhagabakjodgpfniimo => removed successfully
C:\Users\Roman\Desktop\FRST-OlderVersion => moved successfully
"C:\WINDOWS\system32\Tasks\KMSAutoNet" => not found
C:\ProgramData\TEMP => ":B755D674" ADS removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 340622504 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 55502923 B
Edge => 1484330 B
Chrome => 58751566 B
Firefox => 0 B
Opera => 372917620 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 94686 B
NetworkService => 99192 B
Roman => 145313958 B
postgres => 145313958 B

RecycleBin => 0 B
EmptyTemp: => 1.1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:13:17 ====

Re: Prosím o preventivku

Napsal: 12 pro 2019 16:01
od Conder
Vyzera to OK. Su s PC nejake problemy?