﻿Logfile of random's system information tool 1.10 (written by random/random)
Run by capík at 2016-01-02 18:42:01
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 85 GB (85%) free of 100 GB
Total RAM: 2047 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:42:05, on 2.1.2016
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\All Users\Data aplikací\Tmp0x0x\ProtectWindowsManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\kingsoft\ksdef\ksdefserver.exe
C:\DOCUME~1\CAPK~1\LOCALS~1\Temp\nsjB6.tmp
C:\Documents and Settings\capík\Data aplikací\TSv\TSvr.exe
C:\Program Files\7B92231C-1447171551-11D5-B7DC-135013F7F630\knsu18C6.tmp
C:\Program Files\SFK\SSFK.exe
C:\Documents and Settings\All Users\Data aplikací\lWdMl\WdMan.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\capík\Local Settings\Data aplikací\gmsd_ra_005010192\upgmsd_ra_005010192.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Maxthon\Bin\Maxthon.exe
C:\Program Files\Maxthon\Bin\Maxthon.exe
C:\Program Files\Maxthon\Bin\Maxthon.exe
C:\Program Files\Maxthon\Bin\Maxthon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Maxthon\Bin\Maxthon.exe
C:\Program Files\Maxthon\Bin\Maxthon.exe
C:\Program Files\Maxthon\Bin\Maxthon.exe
C:\Documents and Settings\capík\Plocha\RSIT.exe
C:\Program Files\trend micro\capík.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yoursites123.com/?type=hp&ts=1449646973&z=2b8bc677e49ba0004c8ffdegdzbzftdqfzcqdt8m1z&from=ient07021&uid=SAMSUNGXHD320KJ_S0PAJ9DQ503293
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBotjuEsagYx-Ruv_m2D1goL74ZDgpFqNObmO5R3MpzezEwIB5rgUts76PYNCZ32pvhL_nrV9h1Wu1Ax8bTdv9lPOrVF0LjLSj9IISoaC-Lev2yfwbhrzYGlKA5zgNwqzdIguzG5YcMeF7ifV6&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBotjuEsagYx-Ruv_m2D1goL74ZDgpFqNObmO5R3MpzezEwIB5rgUts76PYNCZ32pvhL_nrV9h1Wu1Ax8bTdv9lPOrVF0LjLSj9IISoaC-Lev2yfwbhrzYGlKA5zgNwqzdIguzG5YcMeF7ifV6&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBotjuEsagYx-Ruv_m2D1goL74ZDgpFqNObmO5R3MpzezEwIB5rgUts76PYNCZ32pvhL_nrV9h1Wu1Ax8bTdv9lPOrVF0LjLSj9IISoaC-Lev2yfwbhrzYGlKA5zgNwqzdIguzG5YcMeF7ifV6&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yoursites123.com/?type=hp&ts=1449646973&z=2b8bc677e49ba0004c8ffdegdzbzftdqfzcqdt8m1z&from=ient07021&uid=SAMSUNGXHD320KJ_S0PAJ9DQ503293
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yoursites123.com/?type=hp&ts=1449646973&z=2b8bc677e49ba0004c8ffdegdzbzftdqfzcqdt8m1z&from=ient07021&uid=SAMSUNGXHD320KJ_S0PAJ9DQ503293
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.yoursites123.com/web/?type=ds&ts=1449646973&z=2b8bc677e49ba0004c8ffdegdzbzftdqfzcqdt8m1z&from=ient07021&uid=SAMSUNGXHD320KJ_S0PAJ9DQ503293&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yoursites123.com/web/?type=ds&ts=1449646973&z=2b8bc677e49ba0004c8ffdegdzbzftdqfzcqdt8m1z&from=ient07021&uid=SAMSUNGXHD320KJ_S0PAJ9DQ503293&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yoursites123.com/?type=hp&ts=1449646973&z=2b8bc677e49ba0004c8ffdegdzbzftdqfzcqdt8m1z&from=ient07021&uid=SAMSUNGXHD320KJ_S0PAJ9DQ503293
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBotjuEsagYx-Ruv_m2D1goL74ZDgpFqNObmO5R3MpzezEwIB5rgUts76PYNCZ32pvhL_nrV9h1Wu1Ax8bTdv9lPOrVF0LjLSj9IISoaC-Lev2yfwbhrzYGlKA5zgNwqzdIguzG5YcMeF7ifV6&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O4 - HKLM\..\Run: [upgmsd_ra_005010192.exe] C:\Documents and Settings\capík\Local Settings\Data aplikací\gmsd_ra_005010192\upgmsd_ra_005010192.exe -runhelper
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\DOCUME~1\ALLUSE~1\DATAAP~1\Zitenop\Tintop.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DefSrv - Kingsoft Corporation - C:\Program Files\kingsoft\ksdef\ksdefserver.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: Desktop Upload (ginoquci) - Unknown owner - C:\DOCUME~1\CAPK~1\LOCALS~1\Temp\nsjB6.tmp
O23 - Service: IhPul - tsvr.com - C:\Documents and Settings\capík\Data aplikací\TSv\TSvr.exe
O23 - Service: Copy Bitmap (lezuqucy) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: SSFK - TODO: <???> - C:\Program Files\SFK\SSFK.exe
O23 - Service: WdMan Service (WdMan) - TFuns LIMITED - C:\Documents and Settings\All Users\Data aplikací\lWdMl\WdMan.exe
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Sysinternals process Explorer - C:\Documents and Settings\All Users\Data aplikací\Tmp0x0x\ProtectWindowsManager.exe

--
End of file - 7462 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player PPAPI Notifier.job - C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_20_0_0_267_pepper.exe  -check pepperplugin 
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe  
C:\WINDOWS\tasks\Camera Comp.job - C:\WINDOWS\system32\rundll32.exe  "C:\Documents and Settings\capík\Local Settings\Application Data\Camera Comp\zBin\CameraComp.dll",#3 
C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files\globalUpdate\Update\globalupdate.exe  /c 
C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files\globalUpdate\Update\globalupdate.exe  /ua /installsource scheduler 
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe  /c 
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 
C:\WINDOWS\tasks\IQA.job - C:\WINDOWS\system32\cmd.exe  /c start chrome.exe 
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe  
C:\WINDOWS\tasks\nMn8yb4vsjCNq.job - C:\Documents and Settings\capk\Data aplikac\nMn8yb4vsjCNq.exe  --c=mOC6WVDYKnT8u9VdzBo2qPGugMuhyH1LG1g4UYrDS6zIgzwfiTeKoenlef8KT3aJ1O6W5AlYyu5OaAIMAwODVwsMKOcqAzAV0RgiFC0eoJjBaT7cX1qQ8rpPAb1MAUzbMM15qChq3R91g123JMkM/TimwoNQAuYwplXwxkFqxmNawzSe0NgWGMUSa331I1KOsnu+HY2Og98pkaWwCgX0ZdmHyjOoKnQuM4TTjevGeOHoGoI7xgDGQt6CxUxHFFae9GtM5A1S1aVDbIwe5MTPpkc5j5gh2Jdf3AGwu0ARz9unRcsLvAOcOfBcJtcntxEkI3W4bebIAvnb9iRCF6ymEw== 
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe  -c 
C:\WINDOWS\tasks\Super Number.job - C:\WINDOWS\system32\rundll32.exe  "C:\Documents and Settings\capík\Local Settings\Application Data\Super Number\xBin\SuperNumber.dll",#3 
C:\WINDOWS\tasks\Total Kit.job - C:\WINDOWS\system32\rundll32.exe  "C:\Documents and Settings\capík\Local Settings\Application Data\Total Kit\zBin\TotalKit.dll",#3 
C:\WINDOWS\tasks\ZQID1GGme.job - C:\Documents and Settings\capk\Data aplikac\ZQID1GGme.exe  --c=kr/Ewp/n0fxZEzb5rw8aIujNZbDofCyT/+e0XI2SryEvebmdMZFubEn0arnPIE7/CnsY3ZjyXPeGlnV3cXhnHRmtuFun/zWAiKJE24uopUm7DnMW5K2Ve66GW+oG7+R7aXzRZfAN3QHlFepZazPWy8QrBVmBAzbbfT2d5ro+oio0xy0c67eWusxWmGhdfoKylMUoLylOWHLZHVveAzrHwO4JLiRiuygbsTsTSvqLnA6SAO+RoS9dpuxvbX94TebaYhy3TbV/w0Nsl5cnesLVFVTyaP+5jfGKpgTccoWMuSqKfiDLTZjQjp3EYYXNAZ637rLkY4/XhmJqoLXdD6pKGg== 

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"upgmsd_ra_005010192.exe"=C:\Documents and Settings\capík\Local Settings\Data aplikací\gmsd_ra_005010192\upgmsd_ra_005010192.exe [2015-12-30 3263152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-05-08 6369048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apphide]
C:\Program Files\baidu\ppt.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner.exe [2015-05-08 6369048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2015-05-09 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gmsd_ra_005010192]
C:\Program Files\gmsd_ra_005010192\gmsd_ra_005010192.exe [2015-12-30 3613872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gmsd_ra_005010193]
C:\Program Files\gmsd_ra_005010193\gmsd_ra_005010193.exe [2015-12-31 3614384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upgmsd_ra_005010181.exe]
C:\Documents and Settings\capík\Local Settings\Data aplikací\gmsd_ra_005010192\upgmsd_ra_005010181.exe -runhelper []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upgmsd_ra_005010192.exe]
C:\Documents and Settings\capík\Local Settings\Data aplikací\gmsd_ra_005010192\upgmsd_ra_005010192.exe [2015-12-30 3263152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upgmsd_ra_005010193.exe]
C:\Documents and Settings\capík\Local Settings\Data aplikací\gmsd_ra_005010193\upgmsd_ra_005010193.exe [2015-12-31 3263664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\DOCUME~1\ALLUSE~1\DATAAP~1\Zitenop\Tintop.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2012-11-16 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2015-05-09 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Maxthon\Bin\MxUp.exe"="C:\Program Files\Maxthon\Bin\MxUp.exe:*:Enabled:MxUp"
"C:\Program Files\Maxthon\Bin\Maxthon.exe"="C:\Program Files\Maxthon\Bin\Maxthon.exe:*:Enabled:Maxthon"
"C:\Documents and Settings\capík\Data aplikací\uTorrent\uTorrent.exe"="C:\Documents and Settings\capík\Data aplikací\uTorrent\uTorrent.exe:*:Enabled:μTorrent"
"C:\Program Files\Call of Duty\CoDMP.exe"="C:\Program Files\Call of Duty\CoDMP.exe:*:Enabled:CoDMP"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Documents and Settings\capík\Local Settings\Data aplikací\Chromium\Application\chrome.exe"="C:\Documents and Settings\capík\Local Settings\Data aplikací\Chromium\Application\chrome.exe:*:Enabled:Internet Quick Access"
"C:\Program Files\Tencent\QQPCMgr\10.11.16575.227\QMAccountProtection.exe"="C:\Program Files\Tencent\QQPCMgr\10.11.16575.227\QMAccountProtection.exe:*:Enabled:????-???"
"C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMAccountProtection.exe"="C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMAccountProtection.exe:*:Enabled:????-???"
"c:\program files\common files\tencent\qqdownload\130\tencentdl.exe"="c:\program files\common files\tencent\qqdownload\130\tencentdl.exe:*:Enabled:腾讯产品下载组件"
"c:\program files\common files\tencent\qqdownload\130\bugreport_xf.exe"="c:\program files\common files\tencent\qqdownload\130\bugreport_xf.exe:*:Enabled:腾讯产品下载组件Crash上报"
"C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\plugins\WIN10TIPS_1127.EXE"="C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\plugins\WIN10TIPS_1127.EXE:*:Enabled:电脑管家下载器"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Tencent\QQPCMgr\10.11.16575.227\QMAccountProtection.exe"="C:\Program Files\Tencent\QQPCMgr\10.11.16575.227\QMAccountProtection.exe:*:Enabled:????-???"
"C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMAccountProtection.exe"="C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMAccountProtection.exe:*:Enabled:????-???"
"c:\program files\common files\tencent\qqdownload\130\tencentdl.exe"="c:\program files\common files\tencent\qqdownload\130\tencentdl.exe:*:Enabled:腾讯产品下载组件"
"c:\program files\common files\tencent\qqdownload\130\bugreport_xf.exe"="c:\program files\common files\tencent\qqdownload\130\bugreport_xf.exe:*:Enabled:腾讯产品下载组件Crash上报"
"C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\PLUGINS\WIN10TIPS_1127.EXE"="C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\PLUGINS\WIN10TIPS_1127.EXE:*:Enabled:电脑管家下载器"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux9"=wdmaud.drv

======List of files/folders created in the last 1 month======

2016-01-02 18:42:01 ----D---- C:\rsit
2016-01-02 18:42:01 ----D---- C:\Program Files\trend micro
2016-01-02 18:39:03 ----D---- C:\Documents and Settings\capík\Data aplikací\WinRAR
2016-01-02 18:38:42 ----D---- C:\Program Files\WinRAR
2016-01-02 18:36:20 ----D---- C:\FRST
2016-01-02 18:23:38 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-01-01 08:27:46 ----D---- C:\Program Files\gmsd_ra_005010193
2015-12-30 22:16:38 ----D---- C:\Program Files\gmsd_ra_005010192
2015-12-26 11:33:59 ----D---- C:\WINDOWS\pss
2015-12-25 09:12:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\lWdMl
2015-12-17 21:10:43 ----A---- C:\WINDOWS\system32\TempWmicBatchFile.bat
2015-12-09 08:44:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\tWdMt
2015-12-09 08:43:46 ----D---- C:\Documents and Settings\capík\Data aplikací\TSv
2015-12-09 08:42:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\OWdMO
2015-12-08 04:35:33 ----D---- C:\Documents and Settings\capík\Data aplikací\yoursearching
2015-12-05 06:42:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Tmp0x0x

======List of files/folders modified in the last 1 month======

2016-01-02 18:42:01 ----RD---- C:\Program Files
2016-01-02 18:39:49 ----D---- C:\WINDOWS\Temp
2016-01-02 18:37:14 ----D---- C:\WINDOWS
2016-01-02 18:36:40 ----D---- C:\WINDOWS\system32\CatRoot2
2016-01-02 18:31:37 ----D---- C:\Program Files\SFK
2016-01-02 18:29:59 ----D---- C:\WINDOWS\system32
2016-01-02 18:27:26 ----A---- C:\WINDOWS\SchedLgU.Txt
2016-01-02 18:20:17 ----D---- C:\WINDOWS\system32\config
2016-01-02 18:15:18 ----D---- C:\Documents and Settings\capík\Data aplikací\Seznam.cz
2016-01-02 18:10:34 ----D---- C:\Program Files\Google
2016-01-02 18:03:52 ----D---- C:\Documents and Settings\capík\Data aplikací\istartpageing
2016-01-02 18:03:40 ----SD---- C:\WINDOWS\Tasks
2016-01-02 17:59:58 ----D---- C:\WINDOWS\Prefetch
2016-01-02 17:57:55 ----SHD---- C:\WINDOWS\Installer
2016-01-02 14:18:41 ----D---- C:\Documents and Settings\capík\Data aplikací\vlc
2016-01-01 07:58:43 ----D---- C:\Documents and Settings\capík\Data aplikací\systweak
2015-12-29 21:19:45 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-12-26 11:34:34 ----SH---- C:\boot.ini
2015-12-26 11:34:34 ----A---- C:\WINDOWS\win.ini
2015-12-26 11:34:34 ----A---- C:\WINDOWS\system.ini
2015-12-20 10:39:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\kingsoft
2015-12-13 10:00:42 ----D---- C:\WINDOWS\Minidump
2015-12-10 15:27:16 ----D---- C:\WINDOWS\Debug
2015-12-09 08:42:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\WWMiniProW
2015-12-09 07:27:13 ----D---- C:\WINDOWS\system32\MRT
2015-12-09 07:21:28 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 mv61xxmm;mv61xxmm; C:\WINDOWS\system32\drivers\mv61xxmm.sys [2015-05-09 14184]
R0 mv64xxmm;mv64xxmm; C:\WINDOWS\system32\drivers\mv64xxmm.sys [2015-05-09 5632]
R0 mvxxmm;mvxxmm; C:\WINDOWS\system32\drivers\mvxxmm.sys [2015-05-09 14184]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2015-05-09 40192]
R2 KSSafe;KSSafe; \??\C:\WINDOWS\system32\drivers\KSSafe.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2012-11-16 7874560]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdXP3.sys [2012-05-14 103040]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\system32\DRIVERS\dtlitescsibus.sys [2015-05-29 25016]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2015-05-09 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2015-05-09 10368]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2012-02-22 329960]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-07-17 60160]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2015-05-09 20608]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S1 QMUdisk;tencent QMUdisk; \??\C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\QMUdisk.sys []
S1 softaal;softaal; \??\C:\Program Files\Tencent\QQPCMgr\11.1.16923.222\softaal.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\CAPK~1\LOCALS~1\Temp\mbr.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 TSSK;TSSK; C:\WINDOWS\System32\tssk.sys [2015-11-23 67896]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2015-05-09 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2015-05-09 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2015-05-09 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2012-11-16 643072]
R2 DefSrv;DefSrv; C:\Program Files\kingsoft\ksdef\ksdefserver.exe [2015-11-17 1662800]
R2 ginoquci;Desktop Upload; C:\DOCUME~1\CAPK~1\LOCALS~1\Temp\nsjB6.tmp [2015-12-02 222208]
R2 IhPul;IhPul; C:\Documents and Settings\capík\Data aplikací\TSv\TSvr.exe [2015-12-08 580752]
R2 lezuqucy;Copy Bitmap; C:\Program Files\7B92231C-1447171551-11D5-B7DC-135013F7F630\knsu18C6.tmp [2015-11-16 399872]
R2 SSFK;SSFK; C:\Program Files\SFK\SSFK.exe [2016-01-02 183968]
R2 WdMan;WdMan Service; C:\Documents and Settings\All Users\Data aplikací\lWdMl\WdMan.exe [2015-12-25 338056]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\Documents and Settings\All Users\Data aplikací\Tmp0x0x\ProtectWindowsManager.exe [2015-12-10 344232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-29 269504]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-05-21 1026288]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2015-05-09 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-02-04 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2015-05-09 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
