Kontrola logu, pomalý pc
Napsal: 25 led 2021 12:55
Zdravím, poprosím o kontrolu logu notebooku.
Chtěl jsem vytvořit FRST log ale nevím proč to nejde dávám screen -> https://ctrlv.cz/Yv0s
Posílám RSIT log
Logfile of random's system information tool 1.10 (written by random/random)
Run by asus at 2021-01-25 12:48:08
Microsoft Windows 8.1
System drive C: has 133 GB (70%) free of 191 GB
Total RAM: 5006 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:48:18, on 25. 1. 2021
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.19036)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\asus.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com/?pc=ASJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Skype for Desktop] C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Asus WebStorage Windows Service - ASUS Cloud Corporation - C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Tools (avast! Tools) - AVAST Software - C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: WildTangentHelper - Unknown owner - C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8505 bytes
======Listing Processes======
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe" /runassvc
"C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe" /runassvc
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe"
"C:\Program Files\AVAST Software\Avast\aswEngSrv.exe" /pipename="634D0622-2066-6AF9-FFC7-7B2D8DF7CB49" /binpath="C:\Program Files\AVAST Software\Avast"
"C:\Program Files\AVAST Software\Avast\aswidsagent.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
taskhost.exe $(Arg0)
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
taskhostex.exe
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
KBFiltr.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
AvastUI.exe /nogui
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe" -critical
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\asus\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\asus\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\asus\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=83.0.4103.97 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=83.0.478.50 --initial-client-data=0xa8,0xac,0xb0,0x84,0xb4,0x7ff9021b2f20,0x7ff9021b2f30,0x7ff9021b2f40
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1500 /prefetch:2
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1564 /prefetch:8
/S
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=gpu-process --field-trial-handle=8552,281470512786156773,2694310766627332328,131072 --enable-features=CastMediaRouteProvider --disable-features=OutOfBlinkCors --no-sandbox --disable-gpu-driver-bug-workarounds --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.3.3626.1895 Safari/537.36 Avastium (20.10.2442)" --lang=en-US --proxy-auto-detect --disable-webaudio --force-wave-audio --disable-software-rasterizer --no-sandbox --blacklist-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-compositing --disable-accelerated-layers --disable-accelerated-video-decode --blacklist-webgl --disable-bundled-ppapi-flash --disable-flash-3d --enable-aggressive-domstorage-flushing --enable-media-stream --allow-file-access-from-files=1 --pack_loading_disabled=1 --gpu-preferences=MAAAAAAAAADgAABwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --mojo-platform-channel-handle=8236 /prefetch:2
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=8552,281470512786156773,2694310766627332328,131072 --enable-features=CastMediaRouteProvider --disable-features=OutOfBlinkCors --lang=en-US --service-sandbox-type=network --no-sandbox --force-wave-audio --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.3.3626.1895 Safari/537.36 Avastium (20.10.2442)" --lang=en-US --proxy-auto-detect --disable-webaudio --force-wave-audio --disable-software-rasterizer --no-sandbox --blacklist-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-compositing --disable-accelerated-layers --disable-accelerated-video-decode --blacklist-webgl --disable-bundled-ppapi-flash --disable-flash-3d --enable-aggressive-domstorage-flushing --enable-media-stream --allow-file-access-from-files=1 --pack_loading_disabled=1 --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --mojo-platform-channel-handle=4368 /prefetch:8
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --service-sandbox-type=audio --enable-audio-service-sandbox --mojo-platform-channel-handle=4572 /prefetch:8
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=59 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6516 /prefetch:1
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=62 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6156 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe
taskhost.exe
taskeng.exe {060E87BC-0DCB-44D2-815F-BA87ECFAEF3C}
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=68 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7096 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=70 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7752 /prefetch:1
"C:\Users\asus\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_271\bin\ssv.dll [2021-01-17 734376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2019-03-14 255088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_271\bin\jp2ssv.dll [2021-01-17 348328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2019-03-14 193136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2019-03-14 255088]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2019-03-14 193136]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AuditSHD"=C:\windows\system32\oobe\auditshd.exe [2014-10-29 30208]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-02-10 391128]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-02-10 771544]
"CanonSolutionMenu"=C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2007-10-25 652624]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-09-13 1840720]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2020-12-26 117352]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype for Desktop"=C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [2019-03-26 53540200]
"CCleaner Smart Cleaning"=C:\Program Files\CCleaner\CCleaner64.exe [2021-01-06 32440376]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WebStorage"=C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [2014-08-20 63296]
"RemoteControl10"=C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2013-03-08 95192]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2020-09-17 706680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-02-10 624640]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcapexe]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McNaiAnn]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2021-01-25 12:48:08 ----D---- C:\rsit
2021-01-25 12:48:08 ----D---- C:\Program Files\trend micro
2021-01-25 12:26:17 ----D---- C:\FRST
2021-01-17 00:22:29 ----D---- C:\Users\asus\AppData\Roaming\Sun
2021-01-16 17:51:17 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2021-01-16 17:48:03 ----A---- C:\WINDOWS\system32\win32k.sys
2021-01-16 17:48:03 ----A---- C:\WINDOWS\system32\tquery.dll
2021-01-16 17:48:02 ----A---- C:\WINDOWS\system32\mssrch.dll
2021-01-16 17:48:01 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2021-01-16 17:48:01 ----A---- C:\WINDOWS\system32\wuaueng.dll
2021-01-16 17:48:00 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2021-01-16 17:48:00 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2021-01-16 17:47:59 ----A---- C:\WINDOWS\system32\rdpcore.dll
2021-01-16 17:47:59 ----A---- C:\WINDOWS\system32\authui.dll
2021-01-16 17:47:58 ----A---- C:\WINDOWS\system32\msi.dll
2021-01-16 17:47:57 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2021-01-16 17:47:57 ----A---- C:\WINDOWS\system32\crypt32.dll
2021-01-16 17:47:56 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2021-01-16 17:47:55 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2021-01-16 17:47:55 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2021-01-16 17:47:54 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2021-01-16 17:47:54 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2021-01-16 17:47:54 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2021-01-16 17:47:53 ----A---- C:\WINDOWS\system32\printfilterpipelinesvc.exe
2021-01-16 17:47:53 ----A---- C:\WINDOWS\system32\gdi32.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2021-01-16 17:47:52 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\system32\wuapi.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\system32\netprofmsvc.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\system32\localspl.dll
2021-01-16 17:47:51 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2021-01-16 17:47:51 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2021-01-16 17:47:51 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2021-01-16 17:47:50 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2021-01-16 17:47:50 ----A---- C:\WINDOWS\system32\upnphost.dll
2021-01-16 17:47:50 ----A---- C:\WINDOWS\system32\spoolsv.exe
2021-01-16 17:47:50 ----A---- C:\WINDOWS\system32\mssph.dll
2021-01-16 17:47:49 ----A---- C:\WINDOWS\system32\WFS.exe
2021-01-16 17:47:49 ----A---- C:\WINDOWS\system32\mssvp.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\upnphost.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\system32\puiobj.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\system32\netprofm.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\netprofm.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\mssphtb.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\netman.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\mssphtb.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\FXSCOMPOSE.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2021-01-16 17:47:46 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2021-01-16 17:47:46 ----A---- C:\WINDOWS\SYSWOW64\rdpcore.dll
2021-01-16 17:47:46 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2021-01-16 17:47:46 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2021-01-16 17:47:46 ----A---- C:\WINDOWS\system32\certcli.dll
2021-01-16 17:47:45 ----A---- C:\WINDOWS\system32\user32.dll
2021-01-16 17:47:44 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2021-01-16 17:47:43 ----A---- C:\WINDOWS\SYSWOW64\CredentialUIBroker.exe
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\FXSUTILITY.dll
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\drivers\bowser.sys
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\CredentialUIBroker.exe
2021-01-16 17:47:43 ----A---- C:\WINDOWS\splwow64.exe
2021-01-16 17:47:42 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\wuauclt.exe
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\prnntfy.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\drivers\luafv.sys
2021-01-16 17:47:41 ----A---- C:\WINDOWS\SYSWOW64\upnpcont.exe
2021-01-16 17:47:41 ----A---- C:\WINDOWS\system32\upnpcont.exe
2021-01-16 17:47:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2021-01-16 17:47:40 ----A---- C:\WINDOWS\system32\printfilterpipelineprxy.dll
2021-01-16 17:47:40 ----A---- C:\WINDOWS\system32\drivers\modem.sys
2021-01-16 17:47:39 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2021-01-16 17:47:39 ----A---- C:\WINDOWS\system32\wudriver.dll
2021-01-16 17:47:39 ----A---- C:\WINDOWS\system32\win32spl.dll
2021-01-16 17:47:39 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2021-01-16 17:47:14 ----D---- C:\Users\asus\AppData\Roaming\java
2021-01-16 17:47:07 ----D---- C:\Users\asus\AppData\Roaming\.tlauncher
2021-01-16 17:46:59 ----D---- C:\ProgramData\Sun
2021-01-16 17:46:51 ----A---- C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2021-01-16 17:46:08 ----D---- C:\ProgramData\Oracle
2021-01-16 17:46:05 ----D---- C:\Program Files\Java
2021-01-16 17:44:48 ----D---- C:\Users\asus\AppData\Roaming\.minecraft
2020-12-26 19:14:38 ----A---- C:\WINDOWS\system32\mshtml.dll
2020-12-26 19:14:37 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2020-12-26 19:14:35 ----A---- C:\WINDOWS\system32\ieframe.dll
2020-12-26 19:14:32 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2020-12-26 19:14:31 ----A---- C:\WINDOWS\system32\mstscax.dll
2020-12-26 19:14:30 ----A---- C:\WINDOWS\system32\jscript9.dll
2020-12-26 19:14:29 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2020-12-26 19:14:29 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2020-12-26 19:14:28 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2020-12-26 19:14:26 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2020-12-26 19:14:26 ----A---- C:\WINDOWS\system32\iertutil.dll
2020-12-26 19:14:25 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2020-12-26 19:14:24 ----A---- C:\WINDOWS\system32\wininet.dll
2020-12-26 19:14:24 ----A---- C:\WINDOWS\system32\urlmon.dll
2020-12-26 19:14:24 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2020-12-26 19:14:23 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2020-12-26 19:14:23 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2020-12-26 19:14:22 ----A---- C:\WINDOWS\system32\msfeeds.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\tsmf.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\rasdlg.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\wintrust.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\tsmf.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\rasdlg.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\rasapi32.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\netcfgx.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2020-12-26 19:14:20 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2020-12-26 19:14:20 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2020-12-26 19:14:20 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2020-12-26 19:14:20 ----A---- C:\WINDOWS\system32\cdd.dll
2020-12-26 19:14:19 ----A---- C:\WINDOWS\system32\rasplap.dll
2020-12-26 19:14:19 ----A---- C:\WINDOWS\system32\netshell.dll
2020-12-26 19:14:19 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2020-12-26 19:14:18 ----A---- C:\WINDOWS\SYSWOW64\rasplap.dll
2020-12-26 19:14:18 ----A---- C:\WINDOWS\system32\DMRServer.exe
2020-12-26 19:14:17 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\SysFxUI.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\RASMM.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\rasmans.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2020-12-26 19:14:15 ----A---- C:\WINDOWS\system32\fdSSDP.dll
2020-12-26 19:14:14 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2020-12-26 19:14:14 ----A---- C:\WINDOWS\SYSWOW64\fdSSDP.dll
2020-12-26 19:14:13 ----A---- C:\WINDOWS\system32\rasgcw.dll
2020-12-26 19:14:12 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2020-12-26 19:14:12 ----A---- C:\WINDOWS\system32\dxtrans.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\btpanui.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\webcheck.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\vbscript.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\mshtmled.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\inetcomm.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\iepeers.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\btpanui.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\system32\jscript.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2020-12-26 19:07:39 ----A---- C:\WINDOWS\system32\drivers\staport.sys
2020-12-26 18:37:18 ----A---- C:\WINDOWS\system32\aswBoot.exe
2020-12-26 18:37:11 ----A---- C:\WINDOWS\system32\drivers\aswStm.sys
======List of files/folders modified in the last 1 month======
2021-01-25 12:48:08 ----RD---- C:\Program Files
2021-01-25 12:48:08 ----AD---- C:\WINDOWS\Temp
2021-01-25 12:42:40 ----D---- C:\WINDOWS\Prefetch
2021-01-25 12:37:33 ----SHD---- C:\System Volume Information
2021-01-25 12:31:42 ----D---- C:\Program Files\CCleaner
2021-01-25 12:27:55 ----D---- C:\WINDOWS\Inf
2021-01-25 12:21:15 ----D---- C:\WINDOWS\SoftwareDistribution
2021-01-25 12:21:15 ----AD---- C:\Windows
2021-01-25 12:17:40 ----D---- C:\WINDOWS\system32\sru
2021-01-25 01:39:31 ----D---- C:\WINDOWS\debug
2021-01-24 16:34:42 ----D---- C:\WINDOWS\system32\config
2021-01-24 15:48:18 ----D---- C:\WINDOWS\Microsoft.NET
2021-01-23 21:38:27 ----D---- C:\ProgramData\AVAST Software
2021-01-23 19:41:34 ----D---- C:\WINDOWS\system32\DriverStore
2021-01-23 19:41:23 ----D---- C:\WINDOWS\WinSxS
2021-01-23 19:39:55 ----D---- C:\WINDOWS\system32\catroot2
2021-01-23 18:58:21 ----RD---- C:\WINDOWS\System32
2021-01-23 18:58:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2021-01-22 20:52:56 ----HD---- C:\Program Files\WindowsApps
2021-01-22 20:52:56 ----D---- C:\WINDOWS\AppReadiness
2021-01-17 00:22:55 ----SHD---- C:\WINDOWS\Installer
2021-01-17 00:22:36 ----D---- C:\Program Files (x86)\Common Files
2021-01-16 23:52:27 ----D---- C:\WINDOWS\rescache
2021-01-16 23:49:37 ----RD---- C:\WINDOWS\ToastData
2021-01-16 23:49:37 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SYSWOW64\migration
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SysWOW64
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\wbem
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\pl-PL
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\migration
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\drivers\pl-PL
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\cs-CZ
2021-01-16 23:49:32 ----D---- C:\WINDOWS\system32\drivers
2021-01-16 23:39:23 ----D---- C:\WINDOWS\CbsTemp
2021-01-16 23:10:00 ----D---- C:\WINDOWS\system32\MRT
2021-01-16 23:07:15 ----AC---- C:\WINDOWS\system32\MRT.exe
2021-01-16 17:46:59 ----HD---- C:\ProgramData
2021-01-16 17:17:19 ----D---- C:\WINDOWS\system32\Tasks
2020-12-26 19:39:49 ----D---- C:\Program Files\Internet Explorer
2020-12-26 19:39:49 ----D---- C:\Program Files (x86)\Internet Explorer
2020-12-26 19:39:48 ----D---- C:\WINDOWS\PolicyDefinitions
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswArDisk;aswArDisk; C:\WINDOWS\system32\drivers\aswArDisk.sys [2020-12-26 36792]
R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsh.sys [2020-12-26 247888]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniv.sys [2020-12-26 97360]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2020-12-26 84496]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2021-01-16 324904]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-08-09 644968]
R1 aswArPot;aswArPot; C:\WINDOWS\system32\drivers\aswArPot.sys [2020-12-26 208672]
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdriver.sys [2020-12-26 332880]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2020-12-26 42424]
R1 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2020-12-26 176384]
R1 aswNetHub;aswNetHub; C:\WINDOWS\system32\drivers\aswNetHub.sys [2020-12-26 522480]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2020-12-26 108928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2020-12-26 851256]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2021-01-16 468888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2021-01-16 214808]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 ATP;@oem10.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2014-02-13 70928]
R3 HIDSwitch;@oem13.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2013-10-08 20280]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-02-10 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-03-04 3882456]
R3 IntcDAud;@oem5.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2014-02-05 450520]
R3 iwdbus;@oem8.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 kbfiltr;@oem14.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-06 17280]
R3 MEIx64;@oem4.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2013-12-09 100312]
R3 NETwNs64;@netwsw00.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwsw00.sys [2013-06-18 11518976]
R3 RSBASTOR;@oem11.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\WINDOWS\system32\DRIVERS\RtsBaStor.sys [2013-07-12 309976]
R3 RTL8168;@oem12.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-07-26 827096]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
S3 AgereSoftModem;@mdmags64.inf,%FullProductName%;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\agrsm64.sys [2013-06-18 1146880]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem7.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 mfesapsn;McAfee Process Start Notification Service; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys []
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2014-03-18 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-10-29 44544]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2013-09-09 111416]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [2014-08-20 71168]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2020-12-26 621728]
R2 avast! Tools;Avast Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [2020-12-26 351848]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-12-09 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-12-09 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-12-09 390616]
R2 WildTangentHelper;WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [2020-10-05 1640240]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2020-12-26 8477080]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 edgeupdate;Služba Microsoft Edge Update (edgeupdate); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-09-10 224152]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2019-03-14 153168]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-02-10 279000]
S3 edgeupdatem;Služba Microsoft Edge Update (edgeupdatem); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-09-10 224152]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\elevation_service.exe [2021-01-06 1431656]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2019-03-14 153168]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2019-03-14 194032]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MicrosoftEdgeElevationService;Microsoft Edge Elevation Service (MicrosoftEdgeElevationService); C:\Program Files (x86)\Microsoft\Edge\Application\83.0.478.50\elevation_service.exe [2020-06-12 1507216]
-----------------EOF-----------------
INFO
info.txt logfile of random's system information tool 1.10 2021-01-25 12:48:22
======MBR======
0x00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005EE9B6F9000000000200EEFFFFFF01000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000055AA
======Uninstall list======
ASUS Backtracker-->MsiExec.exe /I{C15C060C-ED1C-49EB-83B3-F7C0FD1CD661}
ASUS Live Update-->MsiExec.exe /X{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}
ASUS Power4Gear Hybrid-->MsiExec.exe /I{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
ASUS Screen Saver-->MsiExec.exe /I{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}
ASUS Smart Gesture-->MsiExec.exe /I{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /X{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS USB Charger Plus-->MsiExec.exe /X{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}
ASUSDVD-->"C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\Setup.exe" /z-uninstall
ASUSDVD-->"C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\Setup.exe" /z-uninstall
AsusVibe2.0-->C:\Program Files (x86)\Asus\AsusVibe\unins000.exe
ATK Package-->MsiExec.exe /I{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}
Avast Free Antivirus-->C:\Program Files\AVAST Software\Avast\setup\Instup.exe /control_panel
Canon MP Navigator EX 1.2-->"C:\Program Files (x86)\Canon\MP Navigator EX 1.2\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\MP Navigator EX 1.2\uninst.ini
Canon MP190 series MP Drivers-->"C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series /L0x0005
Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
Canon Utilities Easy-PhotoPrint EX-->C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\uninst.exe uninst.ini
Canon Utilities Solution Menu-->C:\Program Files (x86)\Canon\SolutionMenu\uninst.exe uninst.ini
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CPUID HWMonitor 1.41-->"C:\Program Files\CPUID\HWMonitor\unins000.exe"
Device Setup-->MsiExec.exe /I{1F07F2C7-596F-4F34-B805-2C61A3E50E5A}
Foxit PhantomPDF-->MsiExec.exe /X{FC76E6BB-7CBB-4CD6-8178-3BCADC0526C3}
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\Installer\setup.exe" --uninstall --system-level --verbose-logging
Google Toolbar for Internet Explorer-->"C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Intel(R) Processor Graphics-->C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Intel® Trusted Connect Service Client-->MsiExec.exe /I{B5E06417-A4AC-4225-B36E-7E34C91616E7}
Java 8 Update 271 (64-bit)-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180271F0}
Microsoft Edge-->"C:\Program Files (x86)\Microsoft\Edge\Application\83.0.478.50\Installer\setup.exe" --uninstall --system-level --verbose-logging
Microsoft Office-->MsiExec.exe /X{90150000-0138-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
PotPlayer-64 bit-->C:\Program Files\DAUM\PotPlayer\uninstall.exe
Realtek Card Reader-->"C:\Program Files (x86)\InstallShield Installation Information\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}\setup.exe" -runfromtemp -removeonly
Realtek Ethernet Controller Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -removeonly
Skype verze 8.42-->"C:\Program Files (x86)\Microsoft\Skype for Desktop\unins000.exe"
Skype™ 6.18-->MsiExec.exe /X{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}
WebStorage-->C:\Program Files (x86)\ASUS\WebStorage\uninst.exe
WildTangent Helper-->"C:\Program Files (x86)\WildTangent Games\Integration\uninstaller.exe"
WildTangent ShortcutProvider-->"C:\Program Files (x86)\WildTangent Games\ShortcutProvider\uninstaller.exe"
Windows Driver Package - ASUS (ATP) Mouse (01/07/2014 1.0.0.197)-->C:\PROGRA~1\DIFX\D76C4328CBD4A34E\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\asustp.inf_amd64_9784a13f87189ca6\asustp.inf
WinFlash-->MsiExec.exe /X{8F21291E-0444-4B1D-B9F9-4370A73E346D}
======System event log======
Computer Name: asuspc
Event Code: 6013
Message: Doba provozu systému je 164 sekund.
Record Number: 5
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 6005
Message: Služba Event Log byla spuštěna.
Record Number: 4
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 6009
Message: Microsoft (R) Windows (R) 6.03. 9600 Multiprocessor Free.
Record Number: 3
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 6011
Message: Název tohoto počítače v systémech DNS a NetBIOS byl změněn z WIN-18PF66Q16TT na ASUSPC.
Record Number: 2
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 4001
Message: Služba automatické konfigurace sítě WLAN byla úspěšně ukončena.
Record Number: 1
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20160505092245.950721-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Application event log=====
Computer Name: asuspc
Event Code: 5008
Message:
Record Number: 5
Source Name: AVLogEvent
Time Written: 20180511200422.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: asuspc
Event Code: 5615
Message: Služba WMI (Windows Management Instrumentation) byla úspěšně spuštěna.
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20180511200407.949826-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: asuspc
Event Code: 100
Message: Service started.
Record Number: 3
Source Name: SkypeUpdate
Time Written: 20180511200407.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20180511200344.042336-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: ASUSPC
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20180511200343.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\System32\WindowsAnytimeUpgradeui.exe
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení: S:AI
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 1086
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174126.144142-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení:
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Record Number: 1085
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.956617-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinSxS\FileMaps\$$.cdf-ms
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení:
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Record Number: 1084
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.956617-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení:
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Record Number: 1083
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.956617-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinStore\AppxSignature.p7x
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení: S:AI
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 1082
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.831625-000
Event Type: Úspěšný audit
User:
======Environment variables======
"FP_NO_HOST_CHECK"=NO
"USERNAME"=SYSTEM
"Path"=C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT
"ComSpec"=%SystemRoot%\system32\cmd.exe
"TMP"=%SystemRoot%\TEMP
"OS"=Windows_NT
"windir"=%SystemRoot%
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=3a09
-----------------EOF-----------------
Děkuji.
Chtěl jsem vytvořit FRST log ale nevím proč to nejde dávám screen -> https://ctrlv.cz/Yv0s
Posílám RSIT log
Logfile of random's system information tool 1.10 (written by random/random)
Run by asus at 2021-01-25 12:48:08
Microsoft Windows 8.1
System drive C: has 133 GB (70%) free of 191 GB
Total RAM: 5006 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:48:18, on 25. 1. 2021
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.19036)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\asus.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com/?pc=ASJB
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [WebStorage] C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Skype for Desktop] C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Asus WebStorage Windows Service - ASUS Cloud Corporation - C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Tools (avast! Tools) - AVAST Software - C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: WildTangentHelper - Unknown owner - C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8505 bytes
======Listing Processes======
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe" /runassvc
"C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe" /runassvc
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe"
"C:\Program Files\AVAST Software\Avast\aswEngSrv.exe" /pipename="634D0622-2066-6AF9-FFC7-7B2D8DF7CB49" /binpath="C:\Program Files\AVAST Software\Avast"
"C:\Program Files\AVAST Software\Avast\aswidsagent.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
taskhost.exe $(Arg0)
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
taskhostex.exe
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
KBFiltr.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
AvastUI.exe /nogui
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX4
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe" -critical
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\asus\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\asus\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\asus\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=83.0.4103.97 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=83.0.478.50 --initial-client-data=0xa8,0xac,0xb0,0x84,0xb4,0x7ff9021b2f20,0x7ff9021b2f30,0x7ff9021b2f40
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1500 /prefetch:2
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1564 /prefetch:8
/S
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=gpu-process --field-trial-handle=8552,281470512786156773,2694310766627332328,131072 --enable-features=CastMediaRouteProvider --disable-features=OutOfBlinkCors --no-sandbox --disable-gpu-driver-bug-workarounds --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.3.3626.1895 Safari/537.36 Avastium (20.10.2442)" --lang=en-US --proxy-auto-detect --disable-webaudio --force-wave-audio --disable-software-rasterizer --no-sandbox --blacklist-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-compositing --disable-accelerated-layers --disable-accelerated-video-decode --blacklist-webgl --disable-bundled-ppapi-flash --disable-flash-3d --enable-aggressive-domstorage-flushing --enable-media-stream --allow-file-access-from-files=1 --pack_loading_disabled=1 --gpu-preferences=MAAAAAAAAADgAABwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --mojo-platform-channel-handle=8236 /prefetch:2
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=8552,281470512786156773,2694310766627332328,131072 --enable-features=CastMediaRouteProvider --disable-features=OutOfBlinkCors --lang=en-US --service-sandbox-type=network --no-sandbox --force-wave-audio --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --log-severity=error --user-agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.3.3626.1895 Safari/537.36 Avastium (20.10.2442)" --lang=en-US --proxy-auto-detect --disable-webaudio --force-wave-audio --disable-software-rasterizer --no-sandbox --blacklist-accelerated-compositing --disable-accelerated-2d-canvas --disable-accelerated-compositing --disable-accelerated-layers --disable-accelerated-video-decode --blacklist-webgl --disable-bundled-ppapi-flash --disable-flash-3d --enable-aggressive-domstorage-flushing --enable-media-stream --allow-file-access-from-files=1 --pack_loading_disabled=1 --log-file="C:\Users\asus\AppData\Roaming\Avast Software\Avast\log\cef_log.txt" --mojo-platform-channel-handle=4368 /prefetch:8
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --service-sandbox-type=audio --enable-audio-service-sandbox --mojo-platform-channel-handle=4572 /prefetch:8
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=59 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6516 /prefetch:1
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=62 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6156 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe
taskhost.exe
taskeng.exe {060E87BC-0DCB-44D2-815F-BA87ECFAEF3C}
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=68 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7096 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1352,3985480651372873505,7625525832170622396,131072 --lang=cs --disable-client-side-phishing-detection --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=70 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=7752 /prefetch:1
"C:\Users\asus\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_271\bin\ssv.dll [2021-01-17 734376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2019-03-14 255088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_271\bin\jp2ssv.dll [2021-01-17 348328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2019-03-14 193136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2019-03-14 255088]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2019-03-14 193136]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AuditSHD"=C:\windows\system32\oobe\auditshd.exe [2014-10-29 30208]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-02-10 391128]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-02-10 771544]
"CanonSolutionMenu"=C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2007-10-25 652624]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-09-13 1840720]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2020-12-26 117352]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype for Desktop"=C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [2019-03-26 53540200]
"CCleaner Smart Cleaning"=C:\Program Files\CCleaner\CCleaner64.exe [2021-01-06 32440376]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WebStorage"=C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [2014-08-20 63296]
"RemoteControl10"=C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2013-03-08 95192]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2020-09-17 706680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-02-10 624640]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcapexe]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McNaiAnn]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2021-01-25 12:48:08 ----D---- C:\rsit
2021-01-25 12:48:08 ----D---- C:\Program Files\trend micro
2021-01-25 12:26:17 ----D---- C:\FRST
2021-01-17 00:22:29 ----D---- C:\Users\asus\AppData\Roaming\Sun
2021-01-16 17:51:17 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2021-01-16 17:48:03 ----A---- C:\WINDOWS\system32\win32k.sys
2021-01-16 17:48:03 ----A---- C:\WINDOWS\system32\tquery.dll
2021-01-16 17:48:02 ----A---- C:\WINDOWS\system32\mssrch.dll
2021-01-16 17:48:01 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2021-01-16 17:48:01 ----A---- C:\WINDOWS\system32\wuaueng.dll
2021-01-16 17:48:00 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2021-01-16 17:48:00 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2021-01-16 17:47:59 ----A---- C:\WINDOWS\system32\rdpcore.dll
2021-01-16 17:47:59 ----A---- C:\WINDOWS\system32\authui.dll
2021-01-16 17:47:58 ----A---- C:\WINDOWS\system32\msi.dll
2021-01-16 17:47:57 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2021-01-16 17:47:57 ----A---- C:\WINDOWS\system32\crypt32.dll
2021-01-16 17:47:56 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2021-01-16 17:47:55 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2021-01-16 17:47:55 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2021-01-16 17:47:54 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2021-01-16 17:47:54 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2021-01-16 17:47:54 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2021-01-16 17:47:53 ----A---- C:\WINDOWS\system32\printfilterpipelinesvc.exe
2021-01-16 17:47:53 ----A---- C:\WINDOWS\system32\gdi32.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2021-01-16 17:47:52 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\system32\wuapi.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\system32\netprofmsvc.dll
2021-01-16 17:47:52 ----A---- C:\WINDOWS\system32\localspl.dll
2021-01-16 17:47:51 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2021-01-16 17:47:51 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2021-01-16 17:47:51 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2021-01-16 17:47:50 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2021-01-16 17:47:50 ----A---- C:\WINDOWS\system32\upnphost.dll
2021-01-16 17:47:50 ----A---- C:\WINDOWS\system32\spoolsv.exe
2021-01-16 17:47:50 ----A---- C:\WINDOWS\system32\mssph.dll
2021-01-16 17:47:49 ----A---- C:\WINDOWS\system32\WFS.exe
2021-01-16 17:47:49 ----A---- C:\WINDOWS\system32\mssvp.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\upnphost.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\system32\puiobj.dll
2021-01-16 17:47:48 ----A---- C:\WINDOWS\system32\netprofm.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\netprofm.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\mssphtb.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\netman.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\mssphtb.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\FXSCOMPOSE.dll
2021-01-16 17:47:47 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2021-01-16 17:47:46 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2021-01-16 17:47:46 ----A---- C:\WINDOWS\SYSWOW64\rdpcore.dll
2021-01-16 17:47:46 ----A---- C:\WINDOWS\system32\WorkFoldersShell.dll
2021-01-16 17:47:46 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2021-01-16 17:47:46 ----A---- C:\WINDOWS\system32\certcli.dll
2021-01-16 17:47:45 ----A---- C:\WINDOWS\system32\user32.dll
2021-01-16 17:47:44 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2021-01-16 17:47:43 ----A---- C:\WINDOWS\SYSWOW64\CredentialUIBroker.exe
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\FXSUTILITY.dll
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\drivers\bowser.sys
2021-01-16 17:47:43 ----A---- C:\WINDOWS\system32\CredentialUIBroker.exe
2021-01-16 17:47:43 ----A---- C:\WINDOWS\splwow64.exe
2021-01-16 17:47:42 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\wuauclt.exe
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\prnntfy.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2021-01-16 17:47:42 ----A---- C:\WINDOWS\system32\drivers\luafv.sys
2021-01-16 17:47:41 ----A---- C:\WINDOWS\SYSWOW64\upnpcont.exe
2021-01-16 17:47:41 ----A---- C:\WINDOWS\system32\upnpcont.exe
2021-01-16 17:47:40 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2021-01-16 17:47:40 ----A---- C:\WINDOWS\system32\printfilterpipelineprxy.dll
2021-01-16 17:47:40 ----A---- C:\WINDOWS\system32\drivers\modem.sys
2021-01-16 17:47:39 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2021-01-16 17:47:39 ----A---- C:\WINDOWS\system32\wudriver.dll
2021-01-16 17:47:39 ----A---- C:\WINDOWS\system32\win32spl.dll
2021-01-16 17:47:39 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2021-01-16 17:47:14 ----D---- C:\Users\asus\AppData\Roaming\java
2021-01-16 17:47:07 ----D---- C:\Users\asus\AppData\Roaming\.tlauncher
2021-01-16 17:46:59 ----D---- C:\ProgramData\Sun
2021-01-16 17:46:51 ----A---- C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2021-01-16 17:46:08 ----D---- C:\ProgramData\Oracle
2021-01-16 17:46:05 ----D---- C:\Program Files\Java
2021-01-16 17:44:48 ----D---- C:\Users\asus\AppData\Roaming\.minecraft
2020-12-26 19:14:38 ----A---- C:\WINDOWS\system32\mshtml.dll
2020-12-26 19:14:37 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2020-12-26 19:14:35 ----A---- C:\WINDOWS\system32\ieframe.dll
2020-12-26 19:14:32 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2020-12-26 19:14:31 ----A---- C:\WINDOWS\system32\mstscax.dll
2020-12-26 19:14:30 ----A---- C:\WINDOWS\system32\jscript9.dll
2020-12-26 19:14:29 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2020-12-26 19:14:29 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2020-12-26 19:14:28 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2020-12-26 19:14:26 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2020-12-26 19:14:26 ----A---- C:\WINDOWS\system32\iertutil.dll
2020-12-26 19:14:25 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2020-12-26 19:14:24 ----A---- C:\WINDOWS\system32\wininet.dll
2020-12-26 19:14:24 ----A---- C:\WINDOWS\system32\urlmon.dll
2020-12-26 19:14:24 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2020-12-26 19:14:23 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2020-12-26 19:14:23 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2020-12-26 19:14:22 ----A---- C:\WINDOWS\system32\msfeeds.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\tsmf.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\rasdlg.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\wintrust.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\tsmf.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\rasdlg.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\rasapi32.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\netcfgx.dll
2020-12-26 19:14:21 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2020-12-26 19:14:20 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2020-12-26 19:14:20 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2020-12-26 19:14:20 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2020-12-26 19:14:20 ----A---- C:\WINDOWS\system32\cdd.dll
2020-12-26 19:14:19 ----A---- C:\WINDOWS\system32\rasplap.dll
2020-12-26 19:14:19 ----A---- C:\WINDOWS\system32\netshell.dll
2020-12-26 19:14:19 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2020-12-26 19:14:18 ----A---- C:\WINDOWS\SYSWOW64\rasplap.dll
2020-12-26 19:14:18 ----A---- C:\WINDOWS\system32\DMRServer.exe
2020-12-26 19:14:17 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\SysFxUI.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\RASMM.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\rasmans.dll
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\drivers\ks.sys
2020-12-26 19:14:17 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2020-12-26 19:14:15 ----A---- C:\WINDOWS\system32\fdSSDP.dll
2020-12-26 19:14:14 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2020-12-26 19:14:14 ----A---- C:\WINDOWS\SYSWOW64\fdSSDP.dll
2020-12-26 19:14:13 ----A---- C:\WINDOWS\system32\rasgcw.dll
2020-12-26 19:14:12 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2020-12-26 19:14:12 ----A---- C:\WINDOWS\system32\dxtrans.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\SYSWOW64\btpanui.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\webcheck.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\vbscript.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\mshtmled.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\inetcomm.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\iepeers.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2020-12-26 19:14:11 ----A---- C:\WINDOWS\system32\btpanui.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\system32\jscript.dll
2020-12-26 19:14:10 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2020-12-26 19:07:39 ----A---- C:\WINDOWS\system32\drivers\staport.sys
2020-12-26 18:37:18 ----A---- C:\WINDOWS\system32\aswBoot.exe
2020-12-26 18:37:11 ----A---- C:\WINDOWS\system32\drivers\aswStm.sys
======List of files/folders modified in the last 1 month======
2021-01-25 12:48:08 ----RD---- C:\Program Files
2021-01-25 12:48:08 ----AD---- C:\WINDOWS\Temp
2021-01-25 12:42:40 ----D---- C:\WINDOWS\Prefetch
2021-01-25 12:37:33 ----SHD---- C:\System Volume Information
2021-01-25 12:31:42 ----D---- C:\Program Files\CCleaner
2021-01-25 12:27:55 ----D---- C:\WINDOWS\Inf
2021-01-25 12:21:15 ----D---- C:\WINDOWS\SoftwareDistribution
2021-01-25 12:21:15 ----AD---- C:\Windows
2021-01-25 12:17:40 ----D---- C:\WINDOWS\system32\sru
2021-01-25 01:39:31 ----D---- C:\WINDOWS\debug
2021-01-24 16:34:42 ----D---- C:\WINDOWS\system32\config
2021-01-24 15:48:18 ----D---- C:\WINDOWS\Microsoft.NET
2021-01-23 21:38:27 ----D---- C:\ProgramData\AVAST Software
2021-01-23 19:41:34 ----D---- C:\WINDOWS\system32\DriverStore
2021-01-23 19:41:23 ----D---- C:\WINDOWS\WinSxS
2021-01-23 19:39:55 ----D---- C:\WINDOWS\system32\catroot2
2021-01-23 18:58:21 ----RD---- C:\WINDOWS\System32
2021-01-23 18:58:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2021-01-22 20:52:56 ----HD---- C:\Program Files\WindowsApps
2021-01-22 20:52:56 ----D---- C:\WINDOWS\AppReadiness
2021-01-17 00:22:55 ----SHD---- C:\WINDOWS\Installer
2021-01-17 00:22:36 ----D---- C:\Program Files (x86)\Common Files
2021-01-16 23:52:27 ----D---- C:\WINDOWS\rescache
2021-01-16 23:49:37 ----RD---- C:\WINDOWS\ToastData
2021-01-16 23:49:37 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SYSWOW64\migration
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2021-01-16 23:49:35 ----D---- C:\WINDOWS\SysWOW64
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\wbem
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\pl-PL
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\migration
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\drivers\pl-PL
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2021-01-16 23:49:35 ----D---- C:\WINDOWS\system32\cs-CZ
2021-01-16 23:49:32 ----D---- C:\WINDOWS\system32\drivers
2021-01-16 23:39:23 ----D---- C:\WINDOWS\CbsTemp
2021-01-16 23:10:00 ----D---- C:\WINDOWS\system32\MRT
2021-01-16 23:07:15 ----AC---- C:\WINDOWS\system32\MRT.exe
2021-01-16 17:46:59 ----HD---- C:\ProgramData
2021-01-16 17:17:19 ----D---- C:\WINDOWS\system32\Tasks
2020-12-26 19:39:49 ----D---- C:\Program Files\Internet Explorer
2020-12-26 19:39:49 ----D---- C:\Program Files (x86)\Internet Explorer
2020-12-26 19:39:48 ----D---- C:\WINDOWS\PolicyDefinitions
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswArDisk;aswArDisk; C:\WINDOWS\system32\drivers\aswArDisk.sys [2020-12-26 36792]
R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsh.sys [2020-12-26 247888]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniv.sys [2020-12-26 97360]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2020-12-26 84496]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2021-01-16 324904]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-08-09 644968]
R1 aswArPot;aswArPot; C:\WINDOWS\system32\drivers\aswArPot.sys [2020-12-26 208672]
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdriver.sys [2020-12-26 332880]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2020-12-26 42424]
R1 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2020-12-26 176384]
R1 aswNetHub;aswNetHub; C:\WINDOWS\system32\drivers\aswNetHub.sys [2020-12-26 522480]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2020-12-26 108928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2020-12-26 851256]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2021-01-16 468888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2021-01-16 214808]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 ATP;@oem10.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2014-02-13 70928]
R3 HIDSwitch;@oem13.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2013-10-08 20280]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-02-10 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-03-04 3882456]
R3 IntcDAud;@oem5.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2014-02-05 450520]
R3 iwdbus;@oem8.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 kbfiltr;@oem14.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-06 17280]
R3 MEIx64;@oem4.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2013-12-09 100312]
R3 NETwNs64;@netwsw00.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\WINDOWS\system32\DRIVERS\Netwsw00.sys [2013-06-18 11518976]
R3 RSBASTOR;@oem11.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\WINDOWS\system32\DRIVERS\RtsBaStor.sys [2013-07-12 309976]
R3 RTL8168;@oem12.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-07-26 827096]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
S3 AgereSoftModem;@mdmags64.inf,%FullProductName%;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\agrsm64.sys [2013-06-18 1146880]
S3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\system32\DRIVERS\e1i63x64.sys [2013-06-18 460288]
S3 intaud_WaveExtensible;@oem7.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 mfesapsn;McAfee Process Start Notification Service; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys []
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;Ovladač zvuků USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2014-03-18 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-10-29 44544]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2013-09-09 111416]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [2014-08-20 71168]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2020-12-26 621728]
R2 avast! Tools;Avast Tools; C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe [2020-12-26 351848]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2013-12-09 131544]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-12-09 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-12-09 390616]
R2 WildTangentHelper;WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [2020-10-05 1640240]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [2020-12-26 8477080]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 edgeupdate;Služba Microsoft Edge Update (edgeupdate); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-09-10 224152]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2019-03-14 153168]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-02-10 279000]
S3 edgeupdatem;Služba Microsoft Edge Update (edgeupdatem); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-09-10 224152]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\elevation_service.exe [2021-01-06 1431656]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2019-03-14 153168]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2019-03-14 194032]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MicrosoftEdgeElevationService;Microsoft Edge Elevation Service (MicrosoftEdgeElevationService); C:\Program Files (x86)\Microsoft\Edge\Application\83.0.478.50\elevation_service.exe [2020-06-12 1507216]
-----------------EOF-----------------
INFO
info.txt logfile of random's system information tool 1.10 2021-01-25 12:48:22
======MBR======
0x00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005EE9B6F9000000000200EEFFFFFF01000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000055AA
======Uninstall list======
ASUS Backtracker-->MsiExec.exe /I{C15C060C-ED1C-49EB-83B3-F7C0FD1CD661}
ASUS Live Update-->MsiExec.exe /X{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}
ASUS Power4Gear Hybrid-->MsiExec.exe /I{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
ASUS Screen Saver-->MsiExec.exe /I{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}
ASUS Smart Gesture-->MsiExec.exe /I{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /X{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS USB Charger Plus-->MsiExec.exe /X{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}
ASUSDVD-->"C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\Setup.exe" /z-uninstall
ASUSDVD-->"C:\Program Files (x86)\InstallShield Installation Information\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\Setup.exe" /z-uninstall
AsusVibe2.0-->C:\Program Files (x86)\Asus\AsusVibe\unins000.exe
ATK Package-->MsiExec.exe /I{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}
Avast Free Antivirus-->C:\Program Files\AVAST Software\Avast\setup\Instup.exe /control_panel
Canon MP Navigator EX 1.2-->"C:\Program Files (x86)\Canon\MP Navigator EX 1.2\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\MP Navigator EX 1.2\uninst.ini
Canon MP190 series MP Drivers-->"C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series /L0x0005
Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
Canon Utilities Easy-PhotoPrint EX-->C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\uninst.exe uninst.ini
Canon Utilities Solution Menu-->C:\Program Files (x86)\Canon\SolutionMenu\uninst.exe uninst.ini
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CPUID HWMonitor 1.41-->"C:\Program Files\CPUID\HWMonitor\unins000.exe"
Device Setup-->MsiExec.exe /I{1F07F2C7-596F-4F34-B805-2C61A3E50E5A}
Foxit PhantomPDF-->MsiExec.exe /X{FC76E6BB-7CBB-4CD6-8178-3BCADC0526C3}
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\87.0.4280.141\Installer\setup.exe" --uninstall --system-level --verbose-logging
Google Toolbar for Internet Explorer-->"C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Intel(R) Processor Graphics-->C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Intel® Trusted Connect Service Client-->MsiExec.exe /I{B5E06417-A4AC-4225-B36E-7E34C91616E7}
Java 8 Update 271 (64-bit)-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F64180271F0}
Microsoft Edge-->"C:\Program Files (x86)\Microsoft\Edge\Application\83.0.478.50\Installer\setup.exe" --uninstall --system-level --verbose-logging
Microsoft Office-->MsiExec.exe /X{90150000-0138-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
PotPlayer-64 bit-->C:\Program Files\DAUM\PotPlayer\uninstall.exe
Realtek Card Reader-->"C:\Program Files (x86)\InstallShield Installation Information\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}\setup.exe" -runfromtemp -removeonly
Realtek Ethernet Controller Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -removeonly
Skype verze 8.42-->"C:\Program Files (x86)\Microsoft\Skype for Desktop\unins000.exe"
Skype™ 6.18-->MsiExec.exe /X{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}
WebStorage-->C:\Program Files (x86)\ASUS\WebStorage\uninst.exe
WildTangent Helper-->"C:\Program Files (x86)\WildTangent Games\Integration\uninstaller.exe"
WildTangent ShortcutProvider-->"C:\Program Files (x86)\WildTangent Games\ShortcutProvider\uninstaller.exe"
Windows Driver Package - ASUS (ATP) Mouse (01/07/2014 1.0.0.197)-->C:\PROGRA~1\DIFX\D76C4328CBD4A34E\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\asustp.inf_amd64_9784a13f87189ca6\asustp.inf
WinFlash-->MsiExec.exe /X{8F21291E-0444-4B1D-B9F9-4370A73E346D}
======System event log======
Computer Name: asuspc
Event Code: 6013
Message: Doba provozu systému je 164 sekund.
Record Number: 5
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 6005
Message: Služba Event Log byla spuštěna.
Record Number: 4
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 6009
Message: Microsoft (R) Windows (R) 6.03. 9600 Multiprocessor Free.
Record Number: 3
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 6011
Message: Název tohoto počítače v systémech DNS a NetBIOS byl změněn z WIN-18PF66Q16TT na ASUSPC.
Record Number: 2
Source Name: EventLog
Time Written: 20180511200342.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 4001
Message: Služba automatické konfigurace sítě WLAN byla úspěšně ukončena.
Record Number: 1
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20160505092245.950721-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Application event log=====
Computer Name: asuspc
Event Code: 5008
Message:
Record Number: 5
Source Name: AVLogEvent
Time Written: 20180511200422.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: asuspc
Event Code: 5615
Message: Služba WMI (Windows Management Instrumentation) byla úspěšně spuštěna.
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20180511200407.949826-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: asuspc
Event Code: 100
Message: Service started.
Record Number: 3
Source Name: SkypeUpdate
Time Written: 20180511200407.000000-000
Event Type: Informace
User:
Computer Name: asuspc
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20180511200344.042336-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: ASUSPC
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20180511200343.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\System32\WindowsAnytimeUpgradeui.exe
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení: S:AI
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 1086
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174126.144142-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení:
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Record Number: 1085
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.956617-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinSxS\FileMaps\$$.cdf-ms
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení:
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Record Number: 1084
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.956617-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení:
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;0x1f0116;;;WD)
Record Number: 1083
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.956617-000
Event Type: Úspěšný audit
User:
Computer Name: asuspc
Event Code: 4907
Message: Nastavení auditu objektu se změnila.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: ASUSPC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7
Objekt:
Server objektu: Security
Typ objektu: File
Název objektu: C:\Windows\WinStore\AppxSignature.p7x
ID popisovače: 0x58
Informace o procesu:
ID procesu: 0x214
Název procesu: C:\Windows\System32\poqexec.exe
Nastavení auditu:
Původní popisovač zabezpečení: S:AI
Nový popisovač zabezpečení: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 1082
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20180522174125.831625-000
Event Type: Úspěšný audit
User:
======Environment variables======
"FP_NO_HOST_CHECK"=NO
"USERNAME"=SYSTEM
"Path"=C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT
"ComSpec"=%SystemRoot%\system32\cmd.exe
"TMP"=%SystemRoot%\TEMP
"OS"=Windows_NT
"windir"=%SystemRoot%
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=3a09
-----------------EOF-----------------
Děkuji.