﻿Logfile of random's system information tool 1.10 (written by random/random)
Run by Dan at 2014-07-04 14:32:31
Microsoft Windows 7 Home Premium  Service Pack 1
System drive C: has 21 GB (5%) free of 456 GB
Total RAM: 3691 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:32:48, on 4.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Safari\Safari.exe
C:\Program Files\trend micro\Dan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10640A&gct=hp&d=473-104&v=n12281-389&t=4
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.eazytosearch.info/?pid=721&r=2014/06/09&hid=7934093126362302543&lg=EN&cc=CZ
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\9.3\ytdToolbarIE.dll
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: CrossriderApp0032850 - {11111111-1111-1111-1111-110311281150} - C:\Program Files (x86)\Object Browser\Object Browser-bho.dll
O2 - BHO: CrossriderApp0035510 - {11111111-1111-1111-1111-110311551110} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: CrossriderApp0048559 - {11111111-1111-1111-1111-110411851159} - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O2 - BHO: save! On - {3E7E842B-E047-5E50-14B5-140BD4CE09A6} - C:\Program Files (x86)\save! On\EghgN.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Vizuální záložky - {C93F72A2-2162-4BBA-A07A-F13663C297A6} - C:\Program Files (x86)\Yandex\YandexBarIE\fastdial.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: YoutubeAdblocker - {E4B8FDA7-CF8B-CF69-C495-13C2F2930C3C} - C:\Program Files (x86)\YoutubeAdblocker\TRsI.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\9.3\ytdToolbarIE.dll
O3 - Toolbar: Yandex.Bar - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files (x86)\Yandex\YandexBarIE\yndbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O3 - Toolbar: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YTD Toolbar\IE\9.3\ytdToolbarIE.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\RunOnce: [removeMoviesToolbardatamngr] cmd.exe /c RD /S /Q "C:\Program Files (x86)\Movies Toolbar"
O4 - HKCU\..\Run: [T-Mobile CManager] "C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe" -autorun
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3677469340-1845403465-1766921176-1009\..\Run: [T-Mobile CManager] "C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe" -autorun (User 'Pavel')
O4 - HKUS\S-1-5-21-3677469340-1845403465-1766921176-1009\..\RunOnce: [SeznamInstall-uninstall:7736267ac7d1c20626b98b30433cc1e4] "C:\Users\Pavel\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe" -c "C:\Users\Pavel\AppData\Roaming\Seznam.cz" (User 'Pavel')
O4 - Startup: Dropbox.lnk = Dan.DOMINO-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{6EE8B62C-12DD-4685-8E6A-E676EB04759A}: NameServer =  
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Ask Update Service (APNMCP) - APN LLC. - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 18079 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe 37045408
\??\C:\Windows\system32\conhost.exe "-5361227882096657915145306396-1397764025-10237886751967043733-18407292571639449886
C:\Windows\System32\spoolsv.exe
taskeng.exe {19F31AF5-BB08-498F-AA5D-539B899E3C88}
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe"
"C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"taskhost.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
taskeng.exe {AC6D972F-A127-4FC5-BCCA-4420A8A73302}
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
C:\Windows\SysWOW64\svchost.exe -k MbnExt
C:\Windows\system32\wbem\wmiprvse.exe
WLIDSvcM.exe 2992
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe" 
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" 
"C:\Windows\WindowsMobile\wmdcBase.exe" 
"C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe" -autorun
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe" 
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe" 
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" 
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 
"C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe" 
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" 
"C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" 
"C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe" 
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -scheduled
"C:\Program Files (x86)\Safari\Safari.exe" 
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" /UpdateAndQuickScan /OpenWebPageOnClose
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"c:\Program Files\Microsoft Security Client\MpCmdRun.exe" SignaturesUpdateService -ScheduleJob -UnmanagedUpdate
\??\C:\Windows\system32\conhost.exe "5187743552059331317100795246-5304192426653005291225018774-1306987914-1352965849
"C:\Users\Pavel\AppData\Local\Temp\p9pb03zs.tmp\RSITx64.exe" 
"C:\Program Files (x86)\Apps Hat\Apps Hat-nova.exe" /ZpBCgxxtc='Apps Hat' /opKZNk=48559 /CjftjJ='000820' /JlFutVD='0' /xsGyTcGOL='appshatmadness' /uEdfKzwvS=2A1149FD8D2F41DCAC1ED829254CF18DIE /TRIdwDGm=3a6df9486efc0cc1880ee03150d47eab /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403735385 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /jpelGLu=http://js.democlientnet.com /tQQrCEVl=torch /gpxmTmOHM /RPCvz='nova' /VLUYScLFK=http://js.clientdemocloud.com /bOpFcHBjn='{"asw":[0, 41943233, 0]}' /JGGFP='http://update.democlientnet.com/novarun/{CAMP_ID}/update.json' /rcbYrfph='task' /XeUwvLgUe=''
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" 
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528 
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\0f71c512-1f72-43e2-850f-ab2b8b284eee-1.job - C:\Program Files (x86)\Apps Hat\Apps Hat-codedownloader.exe  /lVhSU /rcbYrfph=task /ZpBCgxxtc='Apps Hat' /opKZNk=48559 /CjftjJ='000820' /JlFutVD='0' /xsGyTcGOL='appshatmadness' /uEdfKzwvS=2A1149FD8D2F41DCAC1ED829254CF18DIE /TRIdwDGm=3a6df9486efc0cc1880ee03150d47eab /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403735385 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /jpelGLu=http://js.democlientnet.com /tQQrCEVl=torch /VLUYScLFK=http://js.clientdemocloud.com /JKizC /bOpFcHBjn='{"asw":[0, 41943233, 0]}' /JGGFP='http://update.democlientnet.com/ie_code_agent_updates/{CAMP_ID}/update.json' /rcbYrfph='task' /XeUwvLgUe='' 
C:\Windows\tasks\0f71c512-1f72-43e2-850f-ab2b8b284eee-11.job - C:\Program Files (x86)\Apps Hat\0f71c512-1f72-43e2-850f-ab2b8b284eee-11.exe  /fazRMXi=lTYQQ58KFQnTvxViDb0cBeLkaa5yMn1o22FWyeo0RqQY4Jq8XfZ+5ZLUJF4FwVDJYi7R6PByz39UcsV3f3pPHM36L/3KeZBmhTkmQRgyxAT93INATJRZu6DT3RowzBFe0RAn0318PXbdn0UXorJNbSp29kLed79qT191SxYItIym/Eaai2Kz6TH+gObkQfNKOGxmrmx0u//NDSgN12YAhZ3NRcEE4FnBIx4HHogktKe197XWqmQsp0X8UlhIcmDr+xGUhfbT3G3iFXuYJRv1fnPX9fSHOvMqa0NwCooBMtNKD0jct1o8ts45LXrpzbA0LSk2sgq77VnB6kaLtuSMyLZql2Emp6S0McvVNze/cHsLwWCTHx5qHJ+i77cEwlRyGXeHx2VdOmvXbEeZl+IgFAtdRkWMQhETzbEhwOoJVXVF/wL9n9iyLFKqeeVsP41SCmqBYFIwPvDYpHxGsj0tsJ1W9nb52k57gQSj//nWJQpMveRtSadqWVCT4530ljf2tOPoffotQbs4Sc1SpfZkUe07FoKUgX2BVuYJrrPGkEoU8XZemdSUUQs9PSVuI902iNH3SuTN56ygNvRQC0WnRVY4+USqS5M/K3t6EMZzdzxt/4gEpSVoHvR9dIRkD326gnM6Hs04eVj/bA0Eu4nj5pLVN5SyNl1eUtSq9p5OkTUhMAB3szVq24Ltdcg2cMHGo3v+MpyAIzdFyMRGz8JNeh4bFgQ2vyoJcz2HDoi8DznHjwctEX2XGock074ddK6PhmHKZlO16dN7TQzIRFvQh5/U0VWnvKLbMg53rZSmL+XSTKRiXeEaSz6INtx4sZXXrVSPKVDnlb9QymfUTuRiy6Tg7yQ/RnR9BOJySdoulqfZn0eE3j1R5e5Z8Nxu04AHXzmgjioB/5RHTVxXxUOONM4yrRouFgrDo5eqfydHxf4Xa7cW0MXxVUT0QyqYdqdsckofBVR9Xj09uHBqNXT8gm6FqWFaSn7gnr2vH0R4iWNvwYWhGt1ulWrwXLgyg9QZfWjCFAIGVMmrHhbVjHM3kNE6Rf+5JmaDjL6V7W9IFBRs4jWNzSeUgTPtm5Np/OLB4SdwxnhZEnNYeVWQU6vnDrId+QhGoRh53T48ZX2iptxvmxvO3lzrJbqyXpFse+vl4YMTnGBW3EgvpXNgeo3a8i1C3HODBAIL94Yh64vonNFEvdIS/+Xs7jFt1YzFqOmEHe+/MNmB4XGbEk+4EPATqsKka/0R+q3O5ClaY3fyl9Sv7iK3Kdd5ip24z2Glag2osYaXuLZRueaSBxeMkcRldDfqU8wnPMBQE/8719y7nTzMRRPqMoJNwyinWXzpBrZJ40vAIIMM5MV2T3RU0ptTIh31bd3sUY5CJ9Q1IOi++LAx2uzXGyIDDuOJT5guTWFo/j0gJlF5O2xQHUYh665GVaVZiwUDzlKC0Pu0Wo4RL2ydbeU4/AdPY5zqYa1kbwi5EBMRiS13B9wC7yPVQDyQ1jmg+wwylCvtRWO27B8KDgUhc3zmmalxH6wfZ1emC0MjvVBGf+ogplEk9IgRTi3S/BlQylpkbWyDyfV/LA39utnqpzDAE/zHO8HX/qUMrN+9VM4rkWhE9ciA1DNF4+lQ4PEcvnu2s4T8bHkNJoOW6XYH3y99nf13HMIvtfby/tasKKPxDBe1E/sVJ2aJcpXy2IBBX8Rc143v0a2NVuGV0Qk= 
C:\Windows\tasks\0f71c512-1f72-43e2-850f-ab2b8b284eee-2.job - C:\Program Files (x86)\Apps Hat\0f71c512-1f72-43e2-850f-ab2b8b284eee-2.exe  /CbEbS /ZpBCgxxtc='Apps Hat' /opKZNk=48559 /CjftjJ='000820' /JlFutVD='0' /xsGyTcGOL='appshatmadness' /uEdfKzwvS=2A1149FD8D2F41DCAC1ED829254CF18DIE /TRIdwDGm=3a6df9486efc0cc1880ee03150d47eab /vxIZPlGJu=1_34_06_10 /nkaOBMRBi=1403735385 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /dyeDbLY=11111111-1111-1111-1111-110411851159 /tQQrCEVl=torch /JKizC /JGGFP='http://update.democlientnet.com/ie_enable_agent_updates/{CAMP_ID}/update.json' /rcbYrfph='task' /XeUwvLgUe='' 
C:\Windows\tasks\0f71c512-1f72-43e2-850f-ab2b8b284eee-4.job - C:\Program Files (x86)\Apps Hat\0f71c512-1f72-43e2-850f-ab2b8b284eee-4.exe  /yiYpEh /ZpBCgxxtc='Apps Hat' /fekQtsK='C:\Program Files (x86)\Apps Hat\48559.xpi' /opKZNk=48559 /CjftjJ='000820' /JlFutVD='0' /xsGyTcGOL='appshatmadness' /uEdfKzwvS=2A1149FD8D2F41DCAC1ED829254CF18DIE /TRIdwDGm=3a6df9486efc0cc1880ee03150d47eab /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403735385 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /jTZPGdj=300 /iHOqOSqX=39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com /CIoZrUwqh=0.94 /rWNAvk=a39ed7c16185d4f88b976666d4928ba01fe4550c17a4f4a62ad1c45e0afdf81a4com48559 /DSfhfiuz=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/48559.rdf /cIstfpesq='Apps Hat' /xpLdKr='Apps Hat is the cool new Android app store that helps you discover hot new apps, both free and discounted. Get personalised recommendations, price drop alerts, and share your favourite apps with your friends.' /kRdSKzd='Nero' /tQQrCEVl=torch /bOpFcHBjn='{"asw":[0, 41943233, 0]}' /JKizC /SaWjDhp /eyWjDj /JGGFP='http://update.democlientnet.com/ff_agent_updates/{CAMP_ID}/update.json' /rcbYrfph='task' /XeUwvLgUe='' 
C:\Windows\tasks\0f71c512-1f72-43e2-850f-ab2b8b284eee-5.job - C:\Program Files (x86)\Apps Hat\0f71c512-1f72-43e2-850f-ab2b8b284eee-5.exe  /ysprChJRm /ZpBCgxxtc='Apps Hat' /opKZNk=48559 /CjftjJ='000820' /JlFutVD='0' /xsGyTcGOL='appshatmadness' /uEdfKzwvS=2A1149FD8D2F41DCAC1ED829254CF18DIE /TRIdwDGm=3a6df9486efc0cc1880ee03150d47eab /vxIZPlGJu=1_34_06_10 /nkaOBMRBi=1403735385 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /VHNSLo=http://ipgeoapi.com/ /rjhDfWc=http://update.democlientnet.com /mOikl=2 /arxkuY=http://logs.democlientnet.com /JGGFP='http://update.democlientnet.com/updater_agent_updates/{CAMP_ID}/update.json' /rcbYrfph='task' /XeUwvLgUe='' 
C:\Windows\tasks\0f71c512-1f72-43e2-850f-ab2b8b284eee-6.job - C:\Program Files (x86)\Apps Hat\Apps Hat-novainstaller.exe  /sCdwlQd /ZpBCgxxtc='Apps Hat' /opKZNk=48559 /CjftjJ='000820' /JlFutVD='0' /xsGyTcGOL='appshatmadness' /uEdfKzwvS=2A1149FD8D2F41DCAC1ED829254CF18DIE /TRIdwDGm=3a6df9486efc0cc1880ee03150d47eab /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403735385 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /jpelGLu=http://js.democlientnet.com /tQQrCEVl=torch /gpxmTmOHM /RPCvz='nova' /VLUYScLFK=http://js.clientdemocloud.com /bOpFcHBjn='{"asw":[0, 41943233, 0]}' /rcbYrfph=task /JGGFP='http://update.democlientnet.com/novacode/{CAMP_ID}/update.json' /rcbYrfph='task' /XeUwvLgUe='' 
C:\Windows\tasks\0f71c512-1f72-43e2-850f-ab2b8b284eee-7.job - C:\Program Files (x86)\Apps Hat\Apps Hat-nova.exe  /ZpBCgxxtc='Apps Hat' /opKZNk=48559 /CjftjJ='000820' /JlFutVD='0' /xsGyTcGOL='appshatmadness' /uEdfKzwvS=2A1149FD8D2F41DCAC1ED829254CF18DIE /TRIdwDGm=3a6df9486efc0cc1880ee03150d47eab /vxIZPlGJu=1_34_06_10 /vHvQAs=1.34.6.10 /nkaOBMRBi=1403735385 /YSZaXHc=http://stats.democlientnet.com /hSYjiK=http://errors.democlientnet.com /jpelGLu=http://js.democlientnet.com /tQQrCEVl=torch /gpxmTmOHM /RPCvz='nova' /VLUYScLFK=http://js.clientdemocloud.com /bOpFcHBjn='{"asw":[0, 41943233, 0]}' /JGGFP='http://update.democlientnet.com/novarun/{CAMP_ID}/update.json' /rcbYrfph='task' /XeUwvLgUe='' 
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe  /yYEHolYG /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNjR6YWRrY0FnMCw0NWI5ZTYxOC0yZDYwLTQ0NzQtYmE3YS1iMGU5OTk5ODg3ZjIsIiwidW5xIjoiNDViOWU2MTgtMmQ2MC00NDc0LWJhN2EtYjBlOTk5OTg4N2YyIn19' /rluRGxYUp=A35DCC6E68D94AF0B1C68413AC242B9FIE /WJOPj=0dbba9660af55e0b2c17551fbd03487e /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401914153 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=opera /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie_code_agent_updates/{CAMP_ID}/update.json' /rgtdh='task' /mxrJU='' 
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-2.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-2.exe  /DSIUmxCpW /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNjR6YWRrY0FnMCw0NWI5ZTYxOC0yZDYwLTQ0NzQtYmE3YS1iMGU5OTk5ODg3ZjIsIiwidW5xIjoiNDViOWU2MTgtMmQ2MC00NDc0LWJhN2EtYjBlOTk5OTg4N2YyIn19' /rluRGxYUp=A35DCC6E68D94AF0B1C68413AC242B9FIE /WJOPj=0dbba9660af55e0b2c17551fbd03487e /WMSqXF=1_34_05_12 /CRFsAs=1401914153 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /GQTowmm=11111111-1111-1111-1111-110311551110 /aZJRhuSIm=opera /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie_enable_agent_updates/{CAMP_ID}/update.json' /rgtdh='task' /mxrJU='' 
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-4.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-4.exe  /amFDNXTmz /dyqGeJy='iWebar' /eZMYoBF='C:\Program Files (x86)\iWebar\35510.xpi' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNjR6YWRrY0FnMCw0NWI5ZTYxOC0yZDYwLTQ0NzQtYmE3YS1iMGU5OTk5ODg3ZjIsIiwidW5xIjoiNDViOWU2MTgtMmQ2MC00NDc0LWJhN2EtYjBlOTk5OTg4N2YyIn19' /rluRGxYUp=A35DCC6E68D94AF0B1C68413AC242B9FIE /WJOPj=0dbba9660af55e0b2c17551fbd03487e /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401914153 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /uymDivZza=300 /DPUmaDDE=2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com /cdQXKzy=0.94 /LkgeR=a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510 /bZxxYEH=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/35510.rdf /RPOkTQZmQ='iWebar' /LZvLlByLh='iWebar' /ZKcdlNo='iWebar' /aZJRhuSIm=opera /JDAXzHtY='{"asw":[0, 131265]}' /mZOxglpw /FizjPHPN /XTYdtoBoe /LWpHklfn='http://update.clientstatsservice.com/ff_agent_updates/{CAMP_ID}/update.json' /rgtdh='task' /mxrJU='' 
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-5.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-5.exe  /yochGqlS /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNjR6YWRrY0FnMCw0NWI5ZTYxOC0yZDYwLTQ0NzQtYmE3YS1iMGU5OTk5ODg3ZjIsIiwidW5xIjoiNDViOWU2MTgtMmQ2MC00NDc0LWJhN2EtYjBlOTk5OTg4N2YyIn19' /rluRGxYUp=A35DCC6E68D94AF0B1C68413AC242B9FIE /WJOPj=0dbba9660af55e0b2c17551fbd03487e /WMSqXF=1_34_05_12 /CRFsAs=1401914153 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /MLIMI=http://ipgeoapi.com/ /jXJieqAhe=http://update.clientstatsservice.com /HiJzz=2 /OmnqxP=http://logs.clientstatsservice.com /LWpHklfn='http://update.clientstatsservice.com/updater_agent_updates/{CAMP_ID}/update.json' /rgtdh='task' /mxrJU='' 
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-6.job - C:\Program Files (x86)\iWebar\iWebar-novainstaller.exe  /UYfdKYRRC /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNjR6YWRrY0FnMCw0NWI5ZTYxOC0yZDYwLTQ0NzQtYmE3YS1iMGU5OTk5ODg3ZjIsIiwidW5xIjoiNDViOWU2MTgtMmQ2MC00NDc0LWJhN2EtYjBlOTk5OTg4N2YyIn19' /rluRGxYUp=A35DCC6E68D94AF0B1C68413AC242B9FIE /WJOPj=0dbba9660af55e0b2c17551fbd03487e /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401914153 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=opera /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/novacode/{CAMP_ID}/update.json' /rgtdh='task' /mxrJU='' 
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-7.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe  /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNjR6YWRrY0FnMCw0NWI5ZTYxOC0yZDYwLTQ0NzQtYmE3YS1iMGU5OTk5ODg3ZjIsIiwidW5xIjoiNDViOWU2MTgtMmQ2MC00NDc0LWJhN2EtYjBlOTk5OTg4N2YyIn19' /rluRGxYUp=A35DCC6E68D94AF0B1C68413AC242B9FIE /WJOPj=0dbba9660af55e0b2c17551fbd03487e /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401914153 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=opera /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/novarun/{CAMP_ID}/update.json' /rgtdh='task' /mxrJU='' 
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe  
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-1.job - C:\Program Files (x86)\Object Browser\Object Browser-codedownloader.exe  /GiFbEM /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=4847E6883DDC424997EB23D9A0A58012IE /nMtcQaJf=4c677a27b6a46d7e4e5e402d922f7730 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401914146 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=opera /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie_code_agent_updates/{CAMP_ID}/update.json' /XIFwaOI='task' /xGDsvkK='' 
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.exe  /LRWiRR /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=4847E6883DDC424997EB23D9A0A58012IE /nMtcQaJf=4c677a27b6a46d7e4e5e402d922f7730 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401914146 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /YqoVZF=11111111-1111-1111-1111-110311281150 /bwgrJeg=opera /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie_enable_agent_updates/{CAMP_ID}/update.json' /XIFwaOI='task' /xGDsvkK='' 
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-4.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-4.exe  /Mqgwm /OTDrBJeO='Object Browser' /MPMNyjzl='C:\Program Files (x86)\Object Browser\32850.xpi' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=4847E6883DDC424997EB23D9A0A58012IE /nMtcQaJf=4c677a27b6a46d7e4e5e402d922f7730 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401914146 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /ThoWids=300 /muCGF=9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com /XPBUZJSKa=0.94 /rDZIxvk=a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850 /TikiFhrO=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/32850.rdf /oAfMV='Object Browser' /jXweLA='Browser enhancer' /OfyCkAUW='Object Browser' /bwgrJeg=opera /LmtgxAKpq='{"asw":[0, 131265]}' /tAsDXB /DKsNh /ePHmzMg /fuiKVYjh='http://update.clientstatsservice.com/ff_agent_updates/{CAMP_ID}/update.json' /XIFwaOI='task' /xGDsvkK='' 
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.exe  /PKXeqKRC /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=4847E6883DDC424997EB23D9A0A58012IE /nMtcQaJf=4c677a27b6a46d7e4e5e402d922f7730 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401914146 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /ALJkDN=http://ipgeoapi.com/ /TDNiHP=http://update.clientstatsservice.com /EVUDo=2 /mHmtsuHV=http://logs.clientstatsservice.com /fuiKVYjh='http://update.clientstatsservice.com/updater_agent_updates/{CAMP_ID}/update.json' /XIFwaOI='task' /xGDsvkK='' 
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-6.job - C:\Program Files (x86)\Object Browser\Object Browser-novainstaller.exe  /LlhaGyRW /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=4847E6883DDC424997EB23D9A0A58012IE /nMtcQaJf=4c677a27b6a46d7e4e5e402d922f7730 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401914146 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=opera /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/novacode/{CAMP_ID}/update.json' /XIFwaOI='task' /xGDsvkK='' 
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-7.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe  /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=4847E6883DDC424997EB23D9A0A58012IE /nMtcQaJf=4c677a27b6a46d7e4e5e402d922f7730 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401914146 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=opera /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/novarun/{CAMP_ID}/update.json' /XIFwaOI='task' /xGDsvkK='' 
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3677469340-1845403465-1766921176-1001Core.job - C:\Users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe  /c /nocrashserver 
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3677469340-1845403465-1766921176-1001UA.job - C:\Users\David\AppData\Local\Facebook\Update\FacebookUpdate.exe  /ua /installsource scheduler 
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3677469340-1845403465-1766921176-1008Core.job - C:\Users\Dan.DOMINO-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe  /c /nocrashserver 
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3677469340-1845403465-1766921176-1008UA.job - C:\Users\Dan.DOMINO-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe  /ua /installsource scheduler 
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3677469340-1845403465-1766921176-1009Core.job - C:\Users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe  /c /nocrashserver 
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3677469340-1845403465-1766921176-1009UA.job - C:\Users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe  /ua /installsource scheduler 
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe  /c 
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe  /ua /installsource scheduler 
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c 
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 
C:\Windows\tasks\HPCeeScheduleForDan.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe  HPCeeScheduleForDan (null) 
C:\Windows\tasks\HPCeeScheduleForDOMINO-PC$.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe  HPCeeScheduleForDOMINO-PC$ (null) 

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311281150}]
Object Browser - C:\Program Files (x86)\Object Browser\Object Browser-bho64.dll [2014-06-04 786288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho64.dll [2014-06-04 787824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho64.dll [2014-06-26 779264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E7E842B-E047-5E50-14B5-140BD4CE09A6}]
save! On - C:\Program Files (x86)\save! On\EghgN.x64.dll [2014-06-09 472064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14 6307960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4B8FDA7-CF8B-CF69-C495-13C2F2930C3C}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\TRsI.x64.dll [2013-06-09 472064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311281150}]
Object Browser - C:\Program Files (x86)\Object Browser\Object Browser-bho.dll [2014-06-04 577392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho.dll [2014-06-04 578416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll [2014-06-26 570880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2011-09-28 1937736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E7E842B-E047-5E50-14B5-140BD4CE09A6}]
save! On - C:\Program Files (x86)\save! On\EghgN.dll [2014-06-09 423936]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-10-15 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14 4531320]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C93F72A2-2162-4BBA-A07A-F13663C297A6}]
Vizuální záložky - C:\Program Files (x86)\Yandex\YandexBarIE\fastdial.dll [2011-10-13 2697528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-10-15 157672]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4B8FDA7-CF8B-CF69-C495-13C2F2930C3C}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\TRsI.dll [2014-06-09 423936]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3FEE66E-E034-436a-86E4-9690573BEE8A}]
YTD Toolbar - C:\Program Files (x86)\YTD Toolbar\IE\9.3\ytdToolbarIE.dll [2014-05-26 1398592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F3FEE66E-E034-436a-86E4-9690573BEE8A} - YTD Toolbar - C:\Program Files (x86)\YTD Toolbar\IE\9.3\ytdToolbarIE64.dll [2014-05-26 1997120]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{91397D20-1446-11D4-8AF4-0040CA1127B6} - Yandex.Bar - C:\Program Files (x86)\Yandex\YandexBarIE\yndbar.dll [2011-10-20 12336440]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll [2011-09-28 1937736]
{F3FEE66E-E034-436a-86E4-9690573BEE8A} - YTD Toolbar - C:\Program Files (x86)\YTD Toolbar\IE\9.3\ytdToolbarIE.dll [2014-05-26 1398592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2011-01-11 6602856]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-06-10 2799912]
"SetDefault"=C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [2011-06-27 42808]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 1271072]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"NCPluginUpdater"=c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe [2014-05-13 21720]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"T-Mobile CManager"=C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe [2013-10-31 2166552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"=C:\Windows\system32\cmd.exe [2010-11-21 345088]
"Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910"=C:\Windows\system32\cmd.exe [2010-11-21 345088]
"Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"=C:\Windows\system32\cmd.exe [2010-11-21 345088]
"Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811"=C:\Windows\system32\cmd.exe [2010-11-21 345088]
"Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64"=C:\Windows\system32\cmd.exe [2010-11-21 345088]
"Uninstall C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217"=C:\Windows\system32\cmd.exe [2010-11-21 345088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon]
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2014-06-14 1956760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppsHat]
C:\Users\Dan.DOMINO-PC\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [2012-10-26 202752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Dan.DOMINO-PC\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Dan.DOMINO-PC\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\Dan.DOMINO-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-09-18 138096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLV Player]
C:\Users\Dan.DOMINO-PC\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe [2012-10-26 202752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveSupport]
C:\Program Files (x86)\LiveSupport\LiveSupport.exe [2014-03-18 1005056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Optimizer Pro]
C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\se]
C:\Users\user\AppData\Roaming\SkypEmoticons\SE.exe  /minimized  []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe [2014-05-26 1404736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyDrive]
C:\Users\Dan.DOMINO-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2014-05-14 257224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPDriver]
C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe [2014-04-28 3350528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VNT]
C:\Program Files (x86)\VNT\vntldr.exe [2014-06-14 196504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files (x86)\Winamp\Winampa.exe [2011-03-22 74752]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YTDownloader]
C:\Program Files (x86)\YTDownloader\YTDownloader.exe [2014-05-22 1974120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Dan.DOMINO-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk]
C:\Users\DAN~1.DOM\AppData\Local\Facebook\MESSEN~1\214814~1.0\FACEBO~1.EXE [2013-03-07 248240]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-07-05 336384]
"HPQuickWebProxy"=C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-06-28 168504]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-15 35736]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2012-11-12 309688]
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2012-03-05 578944]
"HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [2011-08-19 379960]
"Family Tree Builder Update"=C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe [2013-10-13 2532864]
""= []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"network_media_kinotripsvbl"= []
"removeMoviesToolbardatamngr"=cmd.exe /c RD /S /Q C:\Program Files (x86)\Movies Toolbar []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Dan.DOMINO-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Dan.DOMINO-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-04 14:32:32 ----D---- C:\Program Files\trend micro
2014-07-04 14:32:31 ----D---- C:\rsit
2014-07-04 14:23:40 ----A---- C:\Windows\system32\wups2.dll
2014-07-04 14:23:40 ----A---- C:\Windows\system32\wucltux.dll
2014-07-04 14:23:40 ----A---- C:\Windows\system32\wuaueng.dll
2014-07-04 14:23:40 ----A---- C:\Windows\system32\wuauclt.exe
2014-07-04 14:22:37 ----A---- C:\Windows\system32\wuwebv.dll
2014-07-04 14:22:37 ----A---- C:\Windows\system32\wuapp.exe
2014-07-04 14:21:18 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-07-04 14:21:13 ----D---- C:\Program Files\Microsoft Security Client
2014-07-04 14:20:51 ----D---- C:\c4304a987aa53b8060306457b2
2014-07-04 14:10:26 ----D---- C:\Program Files\CCleaner
2014-07-04 13:59:37 ----D---- C:\Windows\pss
2014-06-26 00:30:16 ----D---- C:\Program Files (x86)\Apps Hat
2014-06-26 00:29:16 ----D---- C:\Program Files (x86)\Seznam.cz
2014-06-26 00:28:55 ----D---- C:\Users\Dan.DOMINO-PC\AppData\Roaming\Seznam.cz
2014-06-26 00:25:05 ----D---- C:\Program Files (x86)\Movies Toolbar
2014-06-10 07:11:58 ----HD---- C:\Windows\msdownld.tmp
2014-06-10 07:11:55 ----D---- C:\Windows\SYSWOW64\directx
2014-06-09 23:15:10 ----D---- C:\Program Files (x86)\Electronic Arts
2014-06-09 22:50:01 ----D---- C:\ProgramData\Seaarch-NeewTab
2014-06-09 22:49:59 ----D---- C:\Program Files (x86)\Seaarch-NeewTab
2014-06-09 22:49:38 ----A---- C:\Users\Dan.DOMINO-PC\AppData\Roaming\LiveSupport.exe_log.txt
2014-06-09 22:49:37 ----A---- C:\Users\Dan.DOMINO-PC\AppData\Roaming\regsvr32.exe_log.txt
2014-06-09 22:49:36 ----D---- C:\Program Files (x86)\LiveSupport
2014-06-09 22:49:30 ----D---- C:\Users\Dan.DOMINO-PC\AppData\Roaming\SkypEmoticons
2014-06-09 22:49:19 ----D---- C:\Windows\SYSWOW64\X86
2014-06-09 22:49:19 ----D---- C:\Windows\SYSWOW64\AMD64
2014-06-09 22:49:19 ----D---- C:\Program Files (x86)\EZDownloader
2014-06-09 22:49:15 ----D---- C:\Program Files (x86)\Optimizer Pro
2014-06-09 22:48:57 ----D---- C:\ProgramData\Supersoftware App
2014-06-09 22:48:27 ----D---- C:\ProgramData\savE oon
2014-06-09 22:48:26 ----D---- C:\Program Files (x86)\savE oon
2014-06-09 22:48:08 ----D---- C:\ProgramData\YoutubeAdblocker
2014-06-09 22:48:08 ----D---- C:\Program Files (x86)\YoutubeAdblocker
2014-06-09 22:47:54 ----D---- C:\ProgramData\save! On
2014-06-09 22:47:47 ----D---- C:\Program Files (x86)\save! On
2014-06-09 22:47:34 ----D---- C:\ProgramData\28629508c44c6739
2014-06-09 22:47:01 ----D---- C:\ProgramData\InstallMate

======List of files/folders modified in the last 1 month======

2014-07-04 14:32:34 ----D---- C:\Windows\Temp
2014-07-04 14:32:32 ----RD---- C:\Program Files
2014-07-04 14:26:40 ----SHD---- C:\System Volume Information
2014-07-04 14:24:14 ----D---- C:\Windows\System32
2014-07-04 14:24:12 ----D---- C:\Windows\winsxs
2014-07-04 14:24:08 ----D---- C:\Windows\system32\cs-CZ
2014-07-04 14:23:52 ----D---- C:\Windows\system32\catroot
2014-07-04 14:21:46 ----D---- C:\Windows\system32\config
2014-07-04 14:21:35 ----D---- C:\Windows
2014-07-04 14:21:26 ----SHD---- C:\Windows\Installer
2014-07-04 14:21:25 ----SHD---- C:\Config.Msi
2014-07-04 14:21:19 ----AD---- C:\Windows\system32\drivers
2014-07-04 14:21:18 ----SD---- C:\ProgramData\Microsoft
2014-07-04 14:21:18 ----RD---- C:\Program Files (x86)
2014-07-04 14:16:55 ----D---- C:\Windows\Tasks
2014-07-04 14:16:55 ----D---- C:\Windows\system32\Tasks
2014-07-04 14:16:44 ----D---- C:\Program Files (x86)\ShopperPro
2014-07-04 14:16:37 ----HD---- C:\ProgramData
2014-07-04 14:14:52 ----AD---- C:\ProgramData\Temp
2014-07-04 14:13:51 ----D---- C:\Windows\SysWOW64
2014-07-04 14:10:50 ----D---- C:\Program Files (x86)\Common Files
2014-07-04 14:09:26 ----D---- C:\Program Files (x86)\Microsoft
2014-07-04 14:06:19 ----D---- C:\Program Files (x86)\Winamp
2014-07-04 14:06:10 ----D---- C:\4MCAD14CLASSIC
2014-07-04 14:01:51 ----D---- C:\Windows\tracing
2014-06-24 15:11:04 ----D---- C:\Windows\Prefetch
2014-06-24 15:10:50 ----D---- C:\Program Files (x86)\VNT
2014-06-24 15:10:49 ----D---- C:\Program Files (x86)\AskPartnerNetwork
2014-06-10 20:30:12 ----D---- C:\Program Files (x86)\Counter-Strike 1.6 Non-Steam
2014-06-10 06:13:53 ----D---- C:\HRY
2014-06-09 23:15:10 ----D---- C:\ProgramData\Electronic Arts
2014-06-09 22:48:26 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-06-09 22:48:24 ----D---- C:\Program Files (x86)\Google
2014-06-09 22:47:31 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2011-04-16 79488]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2011-04-16 40064]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-24 279616]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
R2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [2014-05-22 58728]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-06 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-06 309760]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2011-06-16 133160]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2011-10-09 4729408]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 btwampfl;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2011-06-15 620584]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2011-06-15 165416]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2011-06-15 178728]
R3 BTWDPAN;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\btwdpan.sys [2011-05-21 89640]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2011-02-14 39976]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2011-06-15 21544]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2012-04-23 90112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-01-12 2709224]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-02-15 335464]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-03-05 436840]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-03 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-03 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-03 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-03 22376]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-06-10 1451056]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-11-30 44672]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R4 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files (x86)\Movies Toolbar\SafetyNut\x64\configmgrc2.cfg []
R4 SPDRIVER_1.36.1.172;SPDRIVER_1.36.1.172; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.sys []
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-12-31 507392]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2011-12-08 36328]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-02-06 102936]
S3 esgiguard;esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [2011-03-02 13088]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [2010-03-20 13952]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2013-02-05 57840]
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2012-04-23 104448]
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [2012-04-23 30720]
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [2012-04-23 238080]
S3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 30208]
S3 massfilter;Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys [2010-02-22 11776]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-11-01 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2011-11-01 27136]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-11-01 171008]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-12-08 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-12-08 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-12-08 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-12-08 146920]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-02-06 203544]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-11-01 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-11-01 9216]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-06 204288]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-05 365568]
R2 APNMCP;Ask Update Service; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2014-06-14 165784]
R2 Application Updater;Application Updater; C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2014-05-26 807800]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2011-06-16 1083680]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-03-05 35200]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2010-12-28 1817088]
R2 MbnExt;Mobile Broadband Extension Service; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2013-07-18 762192]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-29 935208]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2013-02-08 66872]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-03 483688]
R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2012-08-21 763840]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-03 209768]
S2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-06-26 68608]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-13 257712]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-06-26 68608]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office  Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-11-19 4925184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-01-04 718888]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-26 1255736]

-----------------EOF-----------------
