Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém jménem : Trojan.Multi.GenAutoranTask.b

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
jekebe
Návštěvník
Návštěvník
Příspěvky: 1
Registrován: 22 dub 2017 13:16

Problém jménem : Trojan.Multi.GenAutoranTask.b

#1 Příspěvek od jekebe »

Zdravím Vás zainteresované a schopné jedince. Moje Pc se ocitlo v pasti vyskakovacích oken, jedná se nejspíše malware, ale jistý si nejsem. proto prosím o pomoc log viz níže:
Logfile of random's system information tool 1.16 (written by random/random)
Run by Jakub at 2017-04-22 14:23:29
Microsoft Windows 10 Enterprise
System drive C: has 52 GB (23%) free of 228 GB
Total RAM: 16269 MB (84% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:23:34, on 22.04.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files\Tablet\Wacom\32\WacomDesktopCenter.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avpui.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Jakub\AppData\Local\Microsoft\BingSvc\BingSvc.exe
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreen Control.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Jakub_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?bcutc=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?bcutc=sp- ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?bcutc=sp-006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?bcutc=sp-006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?bcutc=sp- ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?bcutc=sp-006
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {2E38825B-8815-42CF-9126-C58BC28D4591} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\IEExt\ie_plugin.dll
O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O3 - Toolbar: Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [MSIRegister] "C:\MSI\MSIRegister\MSIRegister.exe"
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [OnScreen Control] C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreenStartUpApp.exe
O4 - HKLM\..\Run: [Bonus.SSR.FR12] "C:\Program Files (x86)\ABBYY FineReader 12\Bonus.ScreenshotReader.exe" /autorun
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Jakub\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
O4 - HKCU\..\Run: [BingSvc] C:\Users\Jakub\AppData\Local\Microsoft\BingSvc\BingSvc.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O21 - SSODL: EldosMountNotificator-cbfs6 - {00AC4EBA-95C2-479C-A4FA-31F7500C592B} - C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {00AC4EBA-95C2-479C-A4FA-31F7500C592B} - C:\WINDOWS\SysWOW64\cbfsMntNtf6.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service 17.0.0 (AVP17.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\igfxCUIService.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Online Connect - Intel Corporation - C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe
O23 - Service: Intel(R) Online Connect Helper - Intel Corporation - C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe
O23 - Service: Intel(R) Online Connect Software Asset Manager - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: Intel(R) Online Connect Access Legacy CS Loader (Intel(R) TechnologyAccessLegacyCSLoader) - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe
O23 - Service: Intel(R) Online Connect Access (Intel(R) TechnologyAccessService) - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: klvssbrigde64 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe
O23 - Service: Kaspersky Secure Connection Service 1.0.0 (KSDE1.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSIREGISTER_MR - Micro-Star INT'L CO., LTD. - C:\MSI\MSIRegister\MSIRegisterService.exe
O23 - Service: MSI Live Update Service (MSI_LiveUpdate_Service) - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe

--
End of file - 13965 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalService
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-68e79473-57ee-4e73-84aa-ab0a4874c9c7 -SystemEventPortName:HostProcess-074a590c-07f0-4ea9-a76d-a718a2fbb810 -IoCancelEventPortName:HostProcess-97102d48-7ac0-4a82-9a94-81f024d248ae -NonStateChangingEventPortName:HostProcess-79a239f1-caed-4aa8-bd4e-6f333f99c2d5 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:87c82dfd-d4aa-48b6-8442-61a1774dd80e -DeviceGroupId:WpdFsGroup
C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Tablet\Wacom\WTabletServicePro.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\dashost.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe" -r
C:\WINDOWS\system32\IProsetMonitor.exe
"C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe"
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe"
"C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
C:\MSI\MSIRegister\MSIRegisterService.exe
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe" -r
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
C:\WINDOWS\System32\dwm.exe
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\igfxEM.exe"
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe"
"C:\Program Files\Tablet\Wacom\WacomHost.exe" "C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe" au
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.13.133.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
"C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe" au
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
"C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe"
"C:\Program Files\Tablet\Wacom\32\WacomDesktopCenter.exe" -fromDriver
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avpui.exe" -hidden
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe" -hidden
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Jakub\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=57.0.2987.133 --initial-client-data=0x230,0x234,0x238,0x22c,0x23c,0x6d3a7dc8,0x6d3a7dbc,0x6d3a7dd4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=5388 --on-initialized-event-handle=676 --parent-handle=680 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1420 --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,19,23,41,61,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x1912 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=21.20.16.4541 --gpu-driver-date=10-20-2016 --service-request-channel-token=BB07981F38FD68FD126B14B85E22B309 --mojo-platform-channel-handle=1440 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Users\Jakub\AppData\Local\Microsoft\BingSvc\BingSvc.exe"
C:\Program Files\CCleaner\CCleaner64.exe
"C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan-11316 C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe"
"C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreen Control.exe" "Minimize"
C:\WINDOWS\System32\fontdrvhost.exe
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe" --onOSstartup=true --showwindow=false --waitForRegistration=true
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe" --type=renderer --disable-3d-apis --disable-pinch --no-sandbox --disable-databases --primordial-pipe-token=4D250371869E0960CC58D2939920EAEA --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\locales" --log-file="C:\Users\Jakub\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --log-severity=warning --user-agent="Mozilla/5.0 (Windows NT 10.0.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/537.36 CreativeCloud/4.0.0.185" --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="11316.0.1741211662\512973111" --mojo-platform-channel-handle=2360 /prefetch:1
"C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\ScreenSplitterHook64App.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\main.js"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\server.js"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420 --primordial-pipe-token=D3179A454385308D1804D907B7785677 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=D3179A454385308D1804D907B7785677 --renderer-client-id=8 --mojo-platform-channel-handle=5128 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1420 --primordial-pipe-token=DE913A26BD1EE2AC43C6500CA1EE62B8 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=DE913A26BD1EE2AC43C6500CA1EE62B8 --renderer-client-id=28 --mojo-platform-channel-handle=5756 /prefetch:1
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 640 644 652 8192 648
C:\Windows\System32\smartscreen.exe -Embedding
C:\WINDOWS\system32\AUDIODG.EXE 0x3a4
"E:\Nová složka\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

====== Scheduled tasks folder ======

C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\AdobeAAMUpdater-1.0-DESKTOP-N0L0ITE-Jakub - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe -mode=scheduled
C:\WINDOWS\system32\tasks\AutoKMS - C:\WINDOWS\AutoKMS\AutoKMS.exe
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Intel PTT EK Recertification - "C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe"
C:\WINDOWS\system32\tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7 - "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
C:\WINDOWS\system32\tasks\IntelIOC-Upgrade-f1c8187b-2653-47cd-a9be-b554b98f68a7-Logon - "C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe" --automatic
C:\WINDOWS\system32\tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic
C:\WINDOWS\system32\tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe /waitUpgrade
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task v2 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval - %systemroot%\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe Reboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - C:\windows\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - C:\windows\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Subscription\EnableLicenseAcquisition - %SystemRoot%\system32\UpgradeSubscription.exe -e
C:\WINDOWS\system32\tasks\Microsoft\Windows\Subscription\LicenseAcquisition - %SystemRoot%\system32\UpgradeSubscription.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Google Chrome=========

C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension ccfifbojenkenpkmnbnndeadpfdiffof 2 Домашняя страница Mail.Ru 11.0.26
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 0 Adobe Acrobat 15.1.0.6
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension fcfenmboojpjinhpgggodefccipikbpd 2 MSN Homepage & Bing Search Engine 0.0.0.9
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension fhoibnponjcgjgcnfacekaijdbbplhib 0 Ochrana Kaspersky 5.0.141.4
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mallpejgeafdahhflmliiahjdpgbegpk 2 FromDocToPDF 12.600.11.23646
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension oelpkepjlgmehajehfeicfbjdiobdkfj 2 Визуальные Закладки Mail.Ru 7.1.30
Extension ojlcebdkbpjdpiligkdbbkdkfjmchbfd 2 Поиск Mail.Ru 12.0.11
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5717.116.0.4
Homepage:
default_search_provider.search_url:
C:\Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib]
"Path"=https://chrome.google.com/webstore/deta ... ijdbbplhib

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\oelpkepjlgmehajehfeicfbjdiobdkfj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ojlcebdkbpjdpiligkdbbkdkfjmchbfd]
"Path"=


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={E9410C70-B6AE-41FF-AB71-32F4B279EA5F}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}]
"URL"=https://www.google.com/search?bcutc=sp- ... earchTerms}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2E38825B-8815-42CF-9126-C58BC28D4591}]
Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-30 1253736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2E38825B-8815-42CF-9126-C58BC28D4591}]
Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\IEExt\ie_plugin.dll [2017-03-30 1028968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23 171704]
{093F479D-712E-46CD-9E06-62E734A05F68} - Kaspersky Protection Toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-30 1253736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23 141496]
{093F479D-712E-46CD-9E06-62E734A05F68} - Kaspersky Protection Toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\IEExt\ie_plugin.dll [2017-03-30 1028968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-12-09 9181696]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Jakub\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-04-14 1518808]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2017-03-23 3019552]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-12-21 9292504]
"Adobe Acrobat Synchronizer"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [2017-04-05 886352]
"BingSvc"=C:\Users\Jakub\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-11-05 144008]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MSIRegister"=C:\MSI\MSIRegister\MSIRegister.exe [2016-10-14 1258448]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2017-01-13 13388752]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [2017-04-05 1870928]
""= []
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2017-03-27 2404952]
"OnScreen Control"=C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreenStartUpApp.exe [2015-12-14 1785328]
"Bonus.SSR.FR12"=C:\Program Files (x86)\ABBYY FineReader 12\Bonus.ScreenshotReader.exe [2017-04-09 1472312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
EldosMountNotificator-cbfs6 - {00AC4EBA-95C2-479C-A4FA-31F7500C592B} - C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-08-03 196000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Virtual Storage Mount Notification - {00AC4EBA-95C2-479C-A4FA-31F7500C592B} - C:\WINDOWS\system32\cbfsMntNtf6.dll [2016-08-03 196000]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"undockwithoutlogon"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"NoDriveTypeAutoRun"=28

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
"StubPath" = %SystemRoot%\inf\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux7"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"vidc.tscc"=C:\WINDOWS\SysWOW64\tsccvid64.dll
"vidc.tsc2"=C:\WINDOWS\SysWOW64\tsc2_codec64.dll

====== File associations ======

.js - edit -
.js - open -

====== List of files/folders created in the last 1 month ======

2017-04-22 14:23:29 ----D---- C:\rsit
2017-04-22 14:23:29 ----D---- C:\Program Files\trend micro
2017-04-22 10:03:14 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_klark.sys
2017-04-22 10:02:35 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_klbg.sys
2017-04-22 10:02:33 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_mark.sys
2017-04-22 10:02:33 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_arkmon.sys
2017-04-22 10:02:32 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_kimul.sys
2017-04-22 10:02:03 ----A---- C:\WINDOWS\system32\klfphc.dll
2017-04-22 10:01:57 ----D---- C:\ProgramData\Kaspersky Lab
2017-04-22 10:01:57 ----D---- C:\Program Files (x86)\Kaspersky Lab
2017-04-22 10:01:55 ----A---- C:\ProgramData\ntuser.dat
2017-04-22 10:01:54 ----A---- C:\WINDOWS\system32\drivers\klif.sys
2017-04-22 10:01:54 ----A---- C:\WINDOWS\system32\drivers\klhk.sys
2017-04-22 10:01:54 ----A---- C:\WINDOWS\system32\drivers\klflt.sys
2017-04-22 10:01:01 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2017-04-22 09:50:46 ----D---- C:\Program Files (x86)\Trend Micro
2017-04-21 20:15:23 ----D---- C:\Program Files\7-Zip
2017-04-21 19:28:58 ----D---- C:\Program Files\Common Files\AV
2017-04-21 19:28:05 ----D---- C:\ProgramData\AVAST Software
2017-04-21 17:14:45 ----D---- C:\ProgramData\BitDefender
2017-04-21 17:07:11 ----D---- C:\Program Files\Common Files\adaware
2017-04-20 00:13:09 ----D---- C:\Program Files (x86)\Mail.Ru
2017-04-20 00:12:37 ----D---- C:\ProgramData\Mail.Ru
2017-04-20 00:12:19 ----D---- C:\Users\Jakub\AppData\Roaming\Blender Foundation
2017-04-19 23:43:24 ----D---- C:\Users\Jakub\AppData\Roaming\TechSmith
2017-04-19 23:40:17 ----D---- C:\Program Files\TechSmith
2017-04-19 23:40:17 ----AD---- C:\ProgramData\TechSmith
2017-04-16 10:16:51 ----HD---- C:\adobeTemp
2017-04-14 11:45:29 ----AD---- C:\Program Files (x86)\Pivot Animator
2017-04-12 20:45:23 ----RD---- C:\Program Files (x86)\Skype
2017-04-12 09:34:13 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-04-12 09:34:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-04-12 09:34:13 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-04-12 09:34:13 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-04-12 09:34:12 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-04-12 09:34:11 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\CompPkgSup.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-04-12 09:34:10 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\wscapi.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\dlnashext.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\asycfilt.dll
2017-04-12 09:34:09 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\wlidcli.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.InkControls.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.UserDeviceAssociation.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\msdtcprx.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\dialclient.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-04-12 09:34:08 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-04-12 09:34:08 ----A---- C:\WINDOWS\system32\drivers\BasicRender.sys
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Lights.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Core.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\mfmjpegdec.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\ipsmsnap.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\ipsecsnp.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\Geolocation.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\AppointmentActivation.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\apds.dll
2017-04-12 09:34:07 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Devices.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerUI.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\sbe.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\enrollmentapi.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2017-04-12 09:34:06 ----A---- C:\WINDOWS\system32\drivers\BasicDisplay.sys
2017-04-12 09:34:05 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-04-12 09:34:05 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-04-12 09:34:04 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.Media.Ocr.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-04-12 09:34:04 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-04-12 09:34:03 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-04-12 09:34:03 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-04-12 09:34:03 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-04-12 09:34:03 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2017-04-12 09:34:03 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-04-12 09:34:03 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-04-12 09:34:03 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2017-04-12 09:34:02 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-04-12 09:34:02 ----A---- C:\WINDOWS\system32\shell32.dll
2017-04-12 09:34:01 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-04-12 09:34:01 ----A---- C:\WINDOWS\system32\mos.dll
2017-04-12 09:34:01 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-04-12 09:34:01 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-04-12 09:34:01 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\usocore.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\puiobj.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\oleaut32.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-04-12 09:34:00 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\wscapi.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\smartscreen.exe
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\rdpshell.exe
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\rdpinit.exe
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\MSVP9DEC.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\LsaIso.exe
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\EmailApis.dll
2017-04-12 09:33:59 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\wpnapps.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\rdpudd.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-04-12 09:33:58 ----A---- C:\WINDOWS\system32\AccountsRt.dll
2017-04-12 09:33:53 ----RA---- C:\WINDOWS\system32\SecureAssessmentHandlers.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\rdpencom.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\localspl.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\cscui.dll
2017-04-12 09:33:53 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2017-04-12 09:33:52 ----A---- C:\WINDOWS\system32\wpninprc.dll
2017-04-12 09:33:52 ----A---- C:\WINDOWS\system32\RdpRelayTransport.dll
2017-04-12 09:33:52 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-04-12 09:33:52 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-04-12 09:33:52 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2017-04-12 09:33:52 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-04-12 09:33:51 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-04-12 09:33:51 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-04-12 09:33:50 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-04-12 09:33:50 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-04-12 09:33:50 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-04-12 09:33:49 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-04-12 09:33:49 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-04-12 09:33:49 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2017-04-12 09:33:49 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\wininet.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\quartz.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\ole32.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\kerberos.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2017-04-12 09:33:48 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-04-12 09:33:48 ----A---- C:\WINDOWS\HelpPane.exe
2017-04-12 09:33:47 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2017-04-12 09:33:47 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-04-12 09:33:47 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2017-04-12 09:33:47 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-04-12 09:33:47 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-04-12 09:33:46 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-04-12 09:33:46 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-04-12 09:33:46 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-04-12 09:33:46 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-04-12 09:33:46 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-04-12 09:33:46 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\d2d1.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2017-04-12 09:33:45 ----A---- C:\WINDOWS\system32\asycfilt.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Windows.Devices.Lights.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\mfmjpegdec.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\Geolocation.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\FontProvider.dll
2017-04-12 09:33:44 ----A---- C:\WINDOWS\system32\dafpos.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\Windows.Devices.Printers.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\webcheck.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\mshtmled.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\dxtrans.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\dosvc.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\DeviceDirectoryClient.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\DdcWnsListener.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-04-12 09:33:43 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-04-12 09:33:42 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-04-12 09:33:42 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-04-12 09:33:42 ----A---- C:\WINDOWS\system32\NaturalLanguage6.dll
2017-04-12 09:33:42 ----A---- C:\WINDOWS\system32\CastLaunch.dll
2017-04-12 09:33:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-04-12 09:33:40 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-04-12 09:33:40 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2017-04-12 09:33:40 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-04-12 09:33:40 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-04-12 09:33:40 ----A---- C:\WINDOWS\system32\AppVOrchestration.dll
2017-04-12 09:33:40 ----A---- C:\WINDOWS\system32\actxprxy.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\twinui.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\atmfd.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-04-12 09:33:39 ----A---- C:\WINDOWS\system32\AppVCatalog.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\wer.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\sbe.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\qedit.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\OneBackupHandler.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\dlnashext.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\CompPkgSup.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-04-12 09:33:38 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\Windows.Media.Devices.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\psmsrv.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\invagent.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\devinv.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\AppContracts.dll
2017-04-12 09:33:37 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\vss_ps.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\oleacc.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-04-12 09:33:36 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\WSManMigrationPlugin.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\vaultcli.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\TokenBrokerUI.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\Family.Client.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\cdp.dll
2017-04-12 09:33:35 ----A---- C:\WINDOWS\system32\atmlib.dll
2017-04-10 16:22:24 ----D---- C:\Users\Jakub\AppData\Roaming\obs-studio
2017-04-10 16:21:42 ----D---- C:\Program Files (x86)\obs-studio
2017-04-09 07:56:54 ----AD---- C:\Program Files (x86)\ABBYY FineReader 12
2017-04-06 09:19:22 ----D---- C:\ProgramData\MSScanAppDataDir
2017-04-01 14:55:27 ----D---- C:\Users\Jakub\AppData\Roaming\.mono
2017-04-01 14:55:27 ----D---- C:\ProgramData\.mono
2017-04-01 14:51:27 ----AD---- C:\Program Files (x86)\Hearthstone
2017-04-01 14:51:17 ----D---- C:\ProgramData\Blizzard Entertainment
2017-04-01 14:49:42 ----AD---- C:\Program Files (x86)\Blizzard App
2017-04-01 14:49:39 ----D---- C:\Users\Jakub\AppData\Roaming\Battle.net
2017-04-01 14:49:15 ----D---- C:\ProgramData\Battle.net
2017-03-30 10:01:53 ----D---- C:\Users\Jakub\AppData\Roaming\ABBYY
2017-03-30 09:58:15 ----D---- C:\ProgramData\ABBYY
2017-03-30 06:19:30 ----A---- C:\WINDOWS\system32\drivers\klwtp.sys
2017-03-30 06:19:30 ----A---- C:\WINDOWS\system32\drivers\klim6.sys
2017-03-25 15:30:20 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2017-03-25 15:30:18 ----D---- C:\Program Files\Reference Assemblies
2017-03-25 15:30:18 ----D---- C:\Program Files\MSBuild
2017-03-25 15:30:18 ----D---- C:\Program Files (x86)\Reference Assemblies
2017-03-25 15:30:18 ----D---- C:\Program Files (x86)\MSBuild
2017-03-25 15:30:00 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2017-03-25 15:30:00 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2017-03-25 15:30:00 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-03-25 15:29:59 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2017-03-25 15:29:59 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-03-25 15:29:59 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-03-25 15:29:22 ----D---- C:\rads

====== List of files/folders modified in the last 1 month ======

2017-04-22 14:23:29 ----RD---- C:\Program Files
2017-04-22 14:15:54 ----D---- C:\WINDOWS\Temp
2017-04-22 14:12:13 ----D---- C:\WINDOWS\system32\sru
2017-04-22 14:12:11 ----D---- C:\WINDOWS\Prefetch
2017-04-22 10:31:28 ----D---- C:\WINDOWS\system32\Tasks
2017-04-22 10:17:13 ----D---- C:\WINDOWS\System32
2017-04-22 10:17:13 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-04-22 10:13:29 ----D---- C:\ProgramData\boost_interprocess
2017-04-22 10:13:05 ----SHD---- C:\System Volume Information
2017-04-22 10:13:00 ----D---- C:\WINDOWS\system32\drivers
2017-04-22 10:12:39 ----D---- C:\WINDOWS\system32\catroot2
2017-04-22 10:12:39 ----D---- C:\WINDOWS\system32\CatRoot
2017-04-22 10:11:42 ----SHD---- C:\WINDOWS\Installer
2017-04-22 10:11:42 ----SHD---- C:\Config.Msi
2017-04-22 10:11:41 ----D---- C:\WINDOWS\system32\DriverStore
2017-04-22 10:11:41 ----D---- C:\WINDOWS\INF
2017-04-22 10:04:45 ----D---- C:\WINDOWS\system32\config
2017-04-22 10:01:59 ----HD---- C:\WINDOWS\ELAMBKUP
2017-04-22 10:01:57 ----RD---- C:\Program Files (x86)
2017-04-22 10:01:57 ----HD---- C:\ProgramData
2017-04-22 09:25:15 ----D---- C:\WINDOWS\system32\appraiser
2017-04-22 09:25:15 ----D---- C:\WINDOWS\CbsTemp
2017-04-22 09:25:07 ----D---- C:\WINDOWS\WinSxS
2017-04-22 09:24:28 ----D---- C:\WINDOWS\AppReadiness
2017-04-22 08:39:39 ----HD---- C:\Program Files\WindowsApps
2017-04-22 01:18:28 ----D---- C:\Program Files (x86)\Steam
2017-04-22 01:03:28 ----D---- C:\Users\Jakub\AppData\Roaming\Skype
2017-04-22 00:31:14 ----D---- C:\WINDOWS\system32\SleepStudy
2017-04-21 19:29:34 ----HD---- C:\temp
2017-04-21 19:28:58 ----D---- C:\Program Files\Common Files
2017-04-21 19:28:58 ----D---- C:\Program Files (x86)\Common Files
2017-04-21 16:02:54 ----RD---- C:\WINDOWS\Microsoft.NET
2017-04-20 17:07:32 ----D---- C:\Users\Jakub\AppData\Roaming\vlc
2017-04-20 00:22:17 ----SD---- C:\Users\Jakub\AppData\Roaming\Microsoft
2017-04-20 00:22:17 ----D---- C:\WINDOWS\system32\appmgmt
2017-04-20 00:12:41 ----HD---- C:\WINDOWS\system32\GroupPolicy
2017-04-20 00:12:39 ----D---- C:\WINDOWS\SYSWOW64\GroupPolicy
2017-04-19 23:40:20 ----RSD---- C:\WINDOWS\Fonts
2017-04-19 23:40:20 ----D---- C:\WINDOWS\SysWOW64
2017-04-19 23:34:51 ----D---- C:\ProgramData\Package Cache
2017-04-17 18:15:55 ----D---- C:\Users\Jakub\AppData\Roaming\Adobe
2017-04-17 17:14:02 ----D---- C:\ProgramData\McNeel
2017-04-16 10:13:29 ----D---- C:\Program Files\Common Files\Adobe
2017-04-16 10:13:29 ----AD---- C:\Program Files\Adobe
2017-04-16 10:06:27 ----D---- C:\ProgramData\Adobe
2017-04-14 21:43:25 ----D---- C:\WINDOWS\rescache
2017-04-13 13:45:43 ----RD---- C:\WINDOWS\assembly
2017-04-12 20:45:25 ----D---- C:\ProgramData\Skype
2017-04-12 17:35:08 ----SD---- C:\WINDOWS\SYSWOW64\F12
2017-04-12 17:35:08 ----SD---- C:\WINDOWS\system32\F12
2017-04-12 17:35:08 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-CS
2017-04-12 17:35:08 ----D---- C:\WINDOWS\SYSWOW64\setup
2017-04-12 17:35:08 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-04-12 17:35:08 ----D---- C:\WINDOWS\system32\wbem
2017-04-12 17:35:08 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-04-12 17:35:08 ----D---- C:\WINDOWS\system32\setup
2017-04-12 17:35:08 ----D---- C:\WINDOWS\system32\migration
2017-04-12 17:35:08 ----D---- C:\WINDOWS\system32\Dism
2017-04-12 17:35:08 ----D---- C:\WINDOWS\system32\cs-CZ
2017-04-12 17:35:07 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-04-12 17:35:07 ----RD---- C:\Program Files\Windows Defender
2017-04-12 17:35:07 ----D---- C:\WINDOWS\ShellExperiences
2017-04-12 17:35:07 ----D---- C:\WINDOWS\Provisioning
2017-04-12 17:35:07 ----D---- C:\WINDOWS\PolicyDefinitions
2017-04-12 17:35:07 ----D---- C:\Windows
2017-04-12 17:35:07 ----D---- C:\Program Files\Windows Photo Viewer
2017-04-12 17:35:07 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-04-12 17:35:07 ----D---- C:\Program Files (x86)\Windows Defender
2017-04-12 09:50:48 ----D---- C:\WINDOWS\system32\MRT
2017-04-12 09:50:00 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-04-12 09:49:57 ----D---- C:\ProgramData\Microsoft Help
2017-04-09 06:57:20 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2017-04-01 20:52:38 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-03-31 07:55:12 ----AD---- C:\Program Files (x86)\Adobe
2017-03-28 08:20:43 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2017-03-25 15:47:15 ----D---- C:\WINDOWS\system32\WDI
2017-03-25 15:32:01 ----D---- C:\WINDOWS\Tasks
2017-03-25 15:30:20 ----D---- C:\WINDOWS\SYSWOW64\MUI
2017-03-25 15:30:20 ----D---- C:\WINDOWS\system32\MUI
2017-03-25 15:29:12 ----D---- C:\Users\Jakub\AppData\Roaming\Riot Games

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit); C:\WINDOWS\system32\DRIVERS\cm_km.sys [2016-06-10 238936]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2017-02-03 48992]
R0 kl1;kl1; C:\WINDOWS\system32\DRIVERS\kl1.sys [2016-06-02 554416]
R0 klbackupdisk;Kaspersky Lab klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [2016-06-07 63920]
R0 klupd_klif_arkmon;klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [2017-04-22 218920]
R0 klupd_klif_klbg;klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [2017-04-22 112920]
R1 cbfs6;cbfs6; \??\C:\WINDOWS\system32\drivers\cbfs6.sys [2016-08-03 460992]
R1 klbackupflt;Kaspersky Lab klbackupflt; C:\WINDOWS\system32\DRIVERS\klbackupflt.sys [2016-06-15 86352]
R1 klhk;@oem55.inf,%klhkDisplayName%;Kaspersky Lab service driver; C:\WINDOWS\System32\drivers\klhk.sys [2017-04-22 520176]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2017-04-22 1018592]
R1 KLIM6;@oem42.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter; C:\WINDOWS\system32\DRIVERS\klim6.sys [2017-03-30 57424]
R1 klpd;Kaspersky Lab format recognizer driver; C:\WINDOWS\system32\DRIVERS\klpd.sys [2016-05-31 45488]
R1 Klwtp;KLwtp - WFP callout traffic inspector; C:\WINDOWS\system32\DRIVERS\klwtp.sys [2017-03-30 136416]
R1 kneps;kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [2017-04-22 199392]
R1 ndisrd;@oem15.inf,%ndisrfl_Desc%;Intel(R) Technology Access Filter Driver; C:\WINDOWS\system32\DRIVERS\ndisrfl.sys [2016-09-13 59792]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 kldisk;kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [2016-05-31 78216]
R3 iwdbus;@oem24.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2015-12-07 39920]
R3 klflt;Kaspersky Lab Kernel DLL; C:\WINDOWS\system32\DRIVERS\klflt.sys [2017-04-22 197336]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [2016-05-19 52136]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2015-06-07 41656]
R3 kltap;@oem46.inf,%DeviceDescription%;Kaspersky Security Data Escort Adapter; C:\WINDOWS\System32\drivers\kltap.sys [2016-06-07 52152]
R3 klupd_klif_kimul;klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [2017-04-22 87584]
R3 klupd_klif_klark;klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [2017-04-22 252232]
R3 klupd_klif_mark;klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [2017-04-22 164888]
R3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvw64e.sys [2016-09-01 50640]
S0 klelam;klelam; C:\WINDOWS\system32\DRIVERS\klelam.sys [2016-03-31 28792]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-02-03 64352]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 AppvStrm;@%systemroot%\system32\drivers\AppvStrm.sys,-101; C:\WINDOWS\system32\drivers\AppvStrm.sys [2017-02-03 127328]
S3 AppvVemgr;@%systemroot%\system32\drivers\AppvVemgr.sys,-101; C:\WINDOWS\system32\drivers\AppvVemgr.sys [2016-07-17 157024]
S3 AppvVfs;@%systemroot%\system32\drivers\AppvVfs.sys,-101; C:\WINDOWS\system32\drivers\AppvVfs.sys [2016-07-17 141152]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2017-02-03 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 ICCWDT;Intel(R) Watchdog Timer Driver (Intel(R) WDT); C:\WINDOWS\System32\drivers\ICCWDT.sys [2015-10-30 38680]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 intaud_WaveExtensible;@oem23.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2015-12-07 51704]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 MsSecFlt;@%SystemRoot%\System32\Drivers\mssecflt.sys,-1001; C:\WINDOWS\system32\drivers\mssecflt.sys [2016-07-17 179040]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S4 klwfp;klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [2016-06-18 85320]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeUpdateService;AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2017-03-14 771672]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2017-02-27 2227312]
R2 AVP17.0.0;Kaspersky Anti-Virus Service 17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\avp.exe [2016-06-28 241544]
R2 CDPUserSvc_38fd37;CDPUserSvc_38fd37; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [2016-10-07 294968]
R2 Intel(R) TechnologyAccessLegacyCSLoader;Intel(R) Online Connect Access Legacy CS Loader; C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe [2016-10-05 173288]
R2 Intel(R) TechnologyAccessService;Intel(R) Online Connect Access; C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe [2016-10-05 496872]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2016-10-20 177440]
R2 KSDE1.0.0;Kaspersky Secure Connection Service 1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [2016-06-28 241544]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2016-10-20 419616]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 MSI_LiveUpdate_Service;MSI Live Update Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2016-11-10 2237392]
R2 MSIREGISTER_MR;MSIREGISTER_MR; C:\MSI\MSIRegister\MSIRegisterService.exe [2016-10-07 132048]
R2 OneSyncSvc_38fd37;Hostitel synchronizace_38fd37; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
R3 Intel(R) Online Connect;Intel(R) Online Connect; C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe [2016-10-04 25824]
R3 PimIndexMaintenanceSvc_38fd37;Data kontaktů_38fd37; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S2 Intel(R) Online Connect Helper;Intel(R) Online Connect Helper; C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe [2016-10-04 22752]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 cplspcon;Intel(R) Content Protection HDCP Service; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\IntelCpHDCPSvc.exe [2016-10-27 462832]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2015-11-03 217888]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2016-07-26 987432]
S3 Intel(R) Online Connect Software Asset Manager;Intel(R) Online Connect Software Asset Manager; C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2016-09-29 18152]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 klvssbrigde64;klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 17.0.0\x64\vssbridge64.exe [2016-06-28 77328]
S3 MessagingService_38fd37;Služba zasílání zpráv_38fd37; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Sense;@%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2017-02-03 2889896]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-03-23 1590560]
S4 AppVClient;@%systemroot%\system32\AppVClient.exe,-102; C:\WINDOWS\system32\AppVClient.exe [2017-02-03 822624]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118283
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém jménem : Trojan.Multi.GenAutoranTask.b

#2 Příspěvek od Rudy »

Zdravím!
Spíš by mne zajímalo, jak jste jako home user přišel k Win10 Enterprise, když je pouze v multilicenci pro organizace. To asi moc legální nebude, že?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět