
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
prosím o kontrolu logu
Logfile of random's system information tool 1.10 (written by random/random)
Run by Pavel at 2015-05-24 16:50:40
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 587 GB (85%) free of 692 GB
Total RAM: 3996 MB (36% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:50:41, on 24.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17801)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Pavel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: Browser Extensions - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons.dll (file missing)
O2 - BHO: (no name) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file)
O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files (x86)\XTab\SupTab.dll (file missing)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12968 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 2136496
\??\C:\Windows\system32\conhost.exe "-3069511431305431118-120848313-730844470964887319-49216216115589764022034971870
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\Windows\SysWOW64\ssins.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2920
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
taskeng.exe {2F7F4E0C-A9BB-40B0-BD10-6C5E0C9F2AD9}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" -byrunkey
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5476.0.2134417513\1867929143" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,19,42 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x6840 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.933.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.2.2074235932\1733496971" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.14.1822436942\363580951" /prefetch:673131151
"C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe" /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='ext coupons' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428043279' /runfrom='task' /brwtype='notbg' /postponedhours='6'
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.22.1525135076\783793556" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.23.228611272\259547357" /prefetch:673131151
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Pavel\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-11.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-11.exe /rawdata=Vu+6/C7XPB/wN4Bpsy3l28XKHTEWq0z/Ob90bue0dUiZn1nePk6j2wZRdJTfS5DSFUVxcY4CA1uuVVATMxPnsDKrln/pEJL1aYCXVTMzQzEGppBvrluN8ddybBfTLzDeCc0HupWGYtaafCoc6RlBGMAYkZ69W1wZlD051zJ3080iLUa4Hw/ZKUJzr3KCAHlHZAFe4Po984Fk56kGX3kB65H3s5IR8YWpy/VPkaVU7G7tC+rA2a/Jia2sH6tt1ukQowqSeCSKJ3q8NiwsTq7eD2ZQJvUZtwf1l/je2jRiey4BXb99vH0QnAuljSUp2kETuAy1v4+nn/U5W9c0Y0wc17V9fdwIz/9SZY++pxnmoHRW2k/Sxd2sU0O148ZsXYzqCA/gOLWPKY6bzoXdKODAy7Bsl4BFcjSgpRHx+1J9uCAtkXCYxOIPQwX5c03pYmEYAq0N3mP//GIfiQ57rFywPNiq1jXus3ZgyTEUk1Ld0IlyXl4G0S/dNxwNuEIl3rT/qkGtgCGWzNgBkYnmBvsUWev3ktzEm7Cu5awaZwfDcTrvYSsYnO2UgMEq/6NM31dG4a3lkGEcclUrXLBOTah5uk4xlwEv9vl0du5YpRqHHKIQFO3ttTI63FLm1892m4DMzr/8ZmQalsZ3w5dX26q6P7S8xEMOed8IfZ0C8jBg8+5f1NaCm2/KDlJZtfmlZ5R1q9o+tGzkoBY1+p5PyS1imVe+vBasooM87h7e4jTnbd8F4F5s1E4d1Q9qTn2Xgrco120yi5U1bpX+qTLiJP1yVW1zjEeuTeK9QpeBL9//MRT4nWUKN8u4Uk0ZhXNxMn5rhtVwBXCGVNHpdI1XcYJoiG6ReI/J5qGQ5hHyykmp0rWDK6ULh7l+93lFnh+ZeL6e2VHqSd5rQpoF9mkZ8Z00AmDC3hqnCnCNTbPG4l9wOGf1jS/z+HjYpV+pN+VubGPD/bg2nzn1vw65X66ayy8jFbx7mxqdb+LOlnQTJ4MwJYxTEfHoi0xm0aMpEH2MH0rlamhBtnj2Yv9sxIac7fdGzUWBiH2EKpevn040UKAqrWyXqenvtGTZRAND8dnyllkkFQb2YOIWoTv9/0FYsC3Pz/w65WZ+zF6I7V9Df976JcljCvqgn+8q/FY3TKkOYdl4YgA2Sl9htBrxQW/qPP/mQ4g1108CgC8izHtjroCVB7Sb/kbPdZLoRGO6lf7dguXvmiAer6HsqKDyXw+uF7JXoq9dCRqqhpvHnX7/HkzAJAXCZPSKRp/nbzGcCrK/Q+X2/1G80UMviMKb+r6+82aCfq8uMVGQJ+c9jQSgLrErwmO5ZLZmOYnscmc5MLqCxhiGRzZ5k9V2OX0N4QK5BXKy7B1lPPLI2d5uN+3MyFVtCZmwqTs7Fq1GQ0DelyeM57WNdNoWRdf4hpFoG0u6AcVkC7XH5UCaofOBeJvC0bYcYHZ7a1kTxgXHrhp00D/u8Ql0DslxDS320+gMeyO9Z20t/c3um0PWMfpGLRGeEghv18EMOc1oKR/+1WJOQU1hNfCeEAdZJJzQDY+ZbfYoKbaL8z8SPYKJxKC0KFU1YETcLVsig1hCgLR8icVP/vbXDI02JMALUuKliU4Jhy5S/J6GXeuITG+diMCvHcXdyJ7fKUPmiflXrP7NmiACjcfY1q1g88b1trZKlxYvJFdoDEXcTExtHZckOX4hUJFH4ifpr6eMach+Z1zOBHOQhJHC+QLVGn+Rdld27liyEkH/rxLvgZEAX6c+Dk6CXlmKpXMjLtSIJBu8WQnLnC8p2sqyHUesKLgfzSri6Zs/bxT9wMsNBxPaAaksY6sgcdk8GGhshc6giTCQ82Fzk9QE4ZRn54VNtTdSIlR+3srhU5Bh1QNoisIf9fyjfsg6EQhCiQNtEbsv5qHD2A2/PjNWhsdKfAxivsW40lTCVS3BVN/CAZH0Cowvzhtakn+yNutgjp78GzbSAKYIwRvV2VuZjglzK13c7XFKlCJhbH3KQID81xAdAW/JHwlr2TgsTGyy4vae4tSC54fijmiksB5Po5mYjQVEwKfZsLNelfQRNBmdlJAnYUZ+iGcK8/LusgW7tQO2BAFInmZWiuYQ+J8aZZqyV/MVMjpXJJ3NgeDuAHGrgyTyS07S/oU4ouw8RJmHepCo51jEEdt2T3Dt4HQd7M99qrU0Gs10Xey7Dc7ufKOqx3Ij8xdMlsBJ8CIgCLzgmIbq0DkIpWNz/m4i0ekmTj9njrtWYsTIh2qAjdMS+i1lhnOaUO+Fq5Ze8QOZS7C+Vfe0Lj3VUTbND6p8+pEfrmrbWUZ721c4A4Q97uA5emgGqtWaWTPy5h9l1eOzfGilv8R3y975iQgDMSo7Zfk7TuZLyi60U3EqoycwMZpgBqbh53cjVg==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-4.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-4.exe /rawdata=tw37QcYb58YcPCNo3Ywzy3gNcG7mNjj4gQ9g8PgytL/VeJPmyH1VoUO2P4syYmRcnCsnKD7qldp8k4j+CzRTX4gt32HAxfH891Cm09KyDRJiNMq5l7VFk0wCk4uEfZ+hcgY0G+/3jA251SYaus0giz2Azzi/as68X7xVFTbnSwZa+PY36lFmW5Fi/7mmsVoEzPCqOUiIaCyQqzbtpDNxoMs0ePskGLX5cxMLhvP2P+woD6eCh+ZXlJqunmkjE7UoSfhwQLIiNvuamkaOSFy9Hz3XfxGOfxwd65mLBTSO3DVrw9j4j36bkP+6Zlh+Muxq5AD8PyrrfY0BFLRP6uhyAo6+gGQ9iuatGuHNnxUCWlb+YEbWHvqnY+Dtvi9J16saVvwiroccrvGYS4ktRWxlSoGc/+LTBzEHav+j3tFhHbhX+9/JK7aYv2DsrFgw/qFIT/DnhrHXsQvYwqv0OONbrdGYQ0uBuk8XnUjWv651yHS2aub3rj7HtOdWSA7o6er/k+9elN3okSwGkp0LIOIQFRHqK7InWqBdeLCvrgR5/L7phhNwMxeoC2fYr80miuDiZo2MqDvEXiboCL9A9T0lQv0sHYIzW3x2/VrKc3NbmZb03gkU/oSGdtBpY90MdsXWcI/OJO7iCqMYpIE/mHRWNaTyEuPEFj3Ch0RwvTKz0EsXZ93uo3sfQvNu1Rl5Un9Xab+L63Zwupvmb9MGzPbuLp2tUCrjUt8a1fBwCo6DhxW/oVFtjz7YkkO1Jrz6E8+YQ1toyMWiomRn3c7vnAu21v4VOoC09hgqNL8g7msMqn7KHkWp1Y/zgmxueVMnGHyLTnR6hj0tjSChaOp7TrWXCWzkrTTdMMS1hKkdatsMHSkMvikLPSvwg8R/p0V4pHoeJgKskz0VmHtDdWinKlLRQ7kpRiRySjDO5z7iNAW2hwqjSAgBS/FagLBcuTIP1SsH0ZALmTIzIoLOLZZ/mYrOsUJaos2pessHEqs4CMvqnoXDs0i4KugEjvsCXDus4wkYwLW+3uhSTv7QhE5DeprsL4cribJEZ2LMYgsiZUiGjdJgq0Nx1YlEsMMAjxwsYNtNPpnoaz3PEhrUHrA9Do4NKN8znqXdy8EAaSvxcYrs7LSfX7bRdziTwN/lsO2/K7wckp1G4zB77/lM9aI65CAtL+OwQxWN0FbJ264gIVB9t4IquJmyWtTXhygBFP5PG3zeDsrXmMV0DKlTW3ETBFL40FPSdC8D0Kvf1xCx76Ldoj9DjMVptOf1qT3D+jZsm2yOKxDjBdUOFtsZ/ZrRXUfL0HN2xVCFZnY75k6yG3gDUxB8xV+jPfdhYfvzhCnZgtSRY16KgWCjwuB+4KyAKqlfPw+2HM0Aft+c5PzuiyNfIzih//ZQQI/9YwP5AoHmSQdKpJaNKK7BfTuSsHlqTOeQxq/UywQCIs2Kz+pRkx8XAWj+L9pffgcBElvnTUGsE+z5ojb+qZd99ePX5HNmZPI2bDcpged5Zl6/fsQide3ieXIEB6Byqw5fF+JbyMbFbiqyFdAldS3901qU972hnD6CR4PV1n9mfU6k2b3pPQkZ+vsu6XS6M2krnYWHm56slpheRUN0LGLN/OE5L5VlszOPLIItgw6cUzR4GUYBOyqSWFsLAmqdEqvjEnxpnbVcHlpc6v0n5GyybwvEFOafsW6O5Wz9XIcQ8vPcVndIIQw7luR15KXmoXwPAYwKQRBfjXQAp4P3sSGbZ4Zn3ZaIZZm3msFde3AeDMmA4jpIu4heTMOmFBFw4wUezTd+SERijkbNzhSpzC3KT0UlO6tl17OYEf6wI0siJ6WYzB+LV09OtiGcvG1WZ3fjyeolphakbf8oAn6AMg78it0UAdBPqqzjIA==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-6.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-6.exe /rawdata=MyIFC1ve4f21pb/dR3Rn2DqqKpZh/Bi7BCALsrMa7xG3iDXHPMLaECu50ASzJxi/J1kJjB/+B6ZkVK2Iy/MmOJ6fu7ge2rA1Kt8Tw7mIi9AkzdEwvLVpb2RzXqoZLyby8tpE1wLnc4nqMP1WhbJVJL//IrLHEUa2oeo+uvgRWAqSIY/FuTe5daTNbThE649QuElcifI7SsnEXJPnyXsnMWtlJ4YWBLu5LXLL42BJ79a88/TUoDwEAz+yiuBkUK7mp1fc9YRTSg4J29zbtl4O0+6595bC6dnh0Lr20ikSN+ipMptNayYW24gywJUu3ziz0Pz4xIAR7iUWQp+k4rKvm1/gr72RUqzEk2C5UsNEfnrposCeHINw8gMd+00Fn1EzcbDyS1qcNxkF1G/qVVrvmpafGoO2QzUTEqOj+QVaSrR8UWXfR4CX7oU0OKu2yb65+iGX+iH7Wdp35CzmO0WpGkZbqbf4dU4FPuNqmi04skdNJTlAoz/K/Y6vTBv0VjMLRVS/B5eUWEtYKt6l+YJzMcfOIqPfZORRhvPRITfZoSwbvYfYJT6UQSWyLvaTC4Sdpg9CfOM3KIJHoYcq2KJEHhivYrkgyBBnKivHO8mwyHdr4w4E6TMWJFLzRH956dOZEBhRV8bHWiWwqEcOxBfCrlwmBnkjM2hqJRXTTk2q0a614914IQnuMud9lk3aqJmnqnWQdJW5lBpdJiH7/kcAhhLD5ie/58nXubb6+uOzz5osRXUcT3vsmSoPo2SZZzxc64Y5TOBVuHb1jOANnrHUSJ+kwq0R7cmcubhazTzjngxiwp0Hgy64jljJfcTcJPpL46l4VRrqJhg+rduBhVVD74ummhU1A2H2WRu1he3kxJd+FO3QqJJH/6WINRDcBI9Kp3OexUubzpgy+KbLLJrx3yYnvT2GdzsR803Sc2KW8pa8i7MckjaXxnggLjtitO0BRELw/eXoVqji24CDrwhmTbtgizR6HwCOGponRRDTGWlN+aBqI+1ozDVDhG08Bva4dB77oYLOe80tnK4R/gS67DNf5Dmwxo8UHp/ZA3M5XsVaxEl3hZS1eH2LkX0wnsTv2y96c+F6AkL8e/7BqHVd+beRF4mADfJxp6EVCDvVB4zDqZywkJMdTWafJVrC+3UFPYMwj5Wxw0Bel6x8lDUxUJ+RN+HrxWTlsxTbWA2gqvVsN7TtFV+/uuLDVCvgJBHRY7i2CO8Am189haL1PE6SGJfo/JU+3LoCMpa4/PC3l4V1qz8BBJiC+VLA6Ir0GvGNDMfM54H4ZFjZ2QU0Rr/reirEWIjqecii0DK1RFtFHKHLw+pQwMA9ohKHKyOaTl3nBcOdiMeMVfW00CwAEjW+IWfxgsRPn7MKOH01G9MAyBOTxxRe01WCPJhBALmZByCHbvSyaR+Fc6Hg4YbRtNor99k7XsBBhnL09U/keA2Tv6S/LkByc8izJnVcqnDSd3fuA7vqhK2rCCL9TBXwSKU8JOkuoJaqyyOACLHUfiAjSef/XV2chldNwq5xxHWc3Oihb7u7U0JVBQFe9EwlrNh/Wba7SboRxhvIlNliNdtgo4xFEo++uzpjPiTg52Z7Lsc1vTuACqD/ZOMaPMjmjDkEP5yNAE3TNaiSCheIuudCN5LsX5S9Xbnlw020i0IF6nddPIUtl+M/CUNPDnHPBwHrhQMx4PYRcs5dEjz/9wZtAJF8uak7/6ugdTbdmt+RK+E1404W1V5fY776w9OGKslHbxzd1fRaNjJa/J1xZ9mYb0owFlk8gGYOOjAr1690lJJKZVIMxPujJiuTpDnAEY8q7vWuYpmLFO2kXoajI05Akp4Oyfq1+vG7ML8eNuiOFxwJggjUOSUQGlS6QacW2Cu6kQ==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-7.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-7.exe /rawdata=yBXhCAlu2cALWig39dCPUvnuB94Yjyey6e3FQpYeyj3shHg3nx76gKaqTDzX13SRneE1lfBT7o2//V+aMK8AHdBr7jJptRRsK51iS3NugCtU5PKcLU775oNadUAp28M2ucQwoFW7/Oxvst4l1yMd7gZqR2rRi4wOOl4jYGCYqhwdU92SL/uG4D0vANetFc3nAnRv4HM7/xhnBP0Tm8EIHgZM8+DTjvLUfSANZDcyXjUzM1DzBC/tRmOHaL0jHH2T/1hpNU40Pa5jW7lPG5FlyHCpwhvrPS+kAR3vwM0F2eFo9AAeWH5lloTGp1FK2M19BcSXSZe0rFsFmnMW6gMJ7Kic7gO8Tv+2/+iegF6XrYangm2mqePYxAhREEajNcecv/tiBnlklFpPXhDXl6vx9tBVJJTTuECY+v7Xet04oFNJ/pfyDjlRVLljKO4By0TNZo0geoJaHcF0jistQlGMucDrIm9XSvmWO4nAU2119JKkc/CeQSlpIGRn2dxXfcTej8+l7m1yovC7cyAijGWyn94V9as6IaQ3pFrN3n/evTpb8J0BB1V8vOPcXgwYGmi4sVgusvVhuSOHtwLQ5bFOKOjeNfMtLkBdy/i3oi8wdx4E2RquFVsNM6fn8x/I+1KFl+mhqpLky3muH364EnXVmOz1ILK1xs4+aFEpNaFO7+ZXEXWUBelCTxOkLl+Ix/it9XGKFUAoYEFzaq9+7sWoTrTojJB2PsRHmrHXmV9YIQWVutlxR/yzVycK/UIGV4AQqSIymWwHRG3bf4mRwVTign+pL+UbndcoQ/D6tTeXsqvxLOPa3nBBhrKPTnhzYSJPX0OcPB+GXxQfpiLkZun80WELhrOn0Pk1vgcA7pXFYzd4AVzcv158Fktbs35yZXz2NhRPLn/DNpYXhMN4l0uI6G8IKp1jHuGUDgVHRfM27AxRpoLBZj3GpyaoYg3m9dMQCLifzW7jzaVC1nGiD21PK9wB9o/SZ8Ffbe2zH4vpD0jhB56Z78Y2mbvqrD5c1i3OHw1eLwXiAXhUpvd8torhdS4057Rk8sFQEmpoOlR5oo49DMRLitChwQtA3oLMFGNNYCYKwweN2oXoBARP2n0NjZkA0yWMgIm9diTcI5XXssoAmHrr9qnu5R1SvBP7qc65gzVo3QdsLXSrniX2dTc4ba4Tvq85TxZg8w6jNc2b3NQ276ZyW+97yo9KbRpPHiXqKrQ25fPP+jbvhniU+RXZKAeJvFghX2eyhY8BV4r16tGDpV7GPiB+EtU4fQY5GDNDcqvfmovZ2jGe2MyBjFsvSsG64YpoQYApyBbY8KvJuSyI8Z0VWGoViMDGkdo1CttYlK3Lwdxa13lfxNMeK0qBKYLMaE/3yDbDU8iRbwhfqctDU8DjEtBnE5PXYFeeRKkr8g/Y/Sx0Nsg5DBqNnI7pCWC2QNcMz/R1lL2bXsNjNJaNR8M3QmblurjWzFLKrnkkLIoBkURVwumjUytLB5RBeH8d2hPlQ+1EWRzXPqkP87hyFzcIt3iiWPqZu0HMYkVlZtvD62+IHt9QCn4Ok5YIrD+v1XGBKu2W11vhHv3/0g3fWlySheo6s+7wR1k9bU+yMS7EfgpKjkTl99dbRO8cmAqEmiebf+oaHywsCtqbgd/C/DhLpWaXB5ZqIo3+neEEUvpx9OIEdoSPt8lKwbxG8+LtmTWNp133cFw87N+SMc4=
C:\Windows\tasks\48_dresses_notification_service.job - C:\Program Files (x86)\48 dresses\48_dresses_notification_service.exe /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='48 dresses' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428343649' /runfrom='task' /brwtype='notbg' /postponedhours='6'
C:\Windows\tasks\48_dresses_updating_service.job - C:\Program Files (x86)\48 dresses\48_dresses_updating_service.exe /campid=2913 /verid=1 /url=http://cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=48_dresses_updating_service /funurl=http://stats.buildomserv.com
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /yYEHolYG /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-2.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-2.exe /DSIUmxCpW /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /GQTowmm=11111111-1111-1111-1111-110311551110 /aZJRhuSIm=ff /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-5.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-5.exe /yochGqlS /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /MLIMI=http://ipgeoapi.com/ /jXJieqAhe=http://update.clientstatsservice.com /HiJzz=2 /OmnqxP=http://logs.clientstatsservice.com /LWpHklfn='http://update.clientstatsservice.com/up ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-6.job - C:\Program Files (x86)\iWebar\iWebar-novainstaller.exe /UYfdKYRRC /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/no ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-7.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/no ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-1.job - C:\Program Files (x86)\Object Browser\Object Browser-codedownloader.exe /GiFbEM /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.exe /LRWiRR /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /YqoVZF=11111111-1111-1111-1111-110311281150 /bwgrJeg=ff /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.exe /PKXeqKRC /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /ALJkDN=http://ipgeoapi.com/ /TDNiHP=http://update.clientstatsservice.com /EVUDo=2 /mHmtsuHV=http://logs.clientstatsservice.com /fuiKVYjh='http://update.clientstatsservice.com/up ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-6.job - C:\Program Files (x86)\Object Browser\Object Browser-novainstaller.exe /LlhaGyRW /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/no ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-7.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/no ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\ext_coupons_notification_service.job - C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='ext coupons' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428043279' /runfrom='task' /brwtype='notbg' /postponedhours='6'
C:\Windows\tasks\ext_coupons_updating_service.job - C:\Program Files (x86)\ext coupons\ext_coupons_updating_service.exe /campid=2913 /verid=1 /url=http://cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=ext_coupons_updating_service /funurl=http://stats.buildomserv.com
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\HPCeeScheduleForPavel.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPavel (null)
C:\Windows\tasks\LAUNbFbBPC16B2.job - C:\Users\Pavel\AppData\Roaming\LAUNbFbBPC16B2.exe --c=oMAFrD801AXmNaTf2riQm64CQg/sJ45+zqDEmk+BMX31uMmiUZBNqQ749251lFdnw1tOy7sjmguPj2juc/7uhDhO0MCV7k09iPMdIdCXgAQQSRiqYbe3BZjcFMIHrZXQOJH+mvAQrO/QCea7GIEywDjdokLWukPkt+WUoAdG/PiUTwxJtdC5CaFHDT1NfhHC7lKsvJ4Qu3tadZN1hEN+YT7FXRwaqXmZyz2ZYyRRXdI/JxGbEiktTGUBXcmp/Wec5piHfB1xaXRb3Lm6/ul8w27Gzk/Tnd8/DEMOPu+Pttkv3VXOsYPeR4Z9HVgOj7O3YTEnN/kE15Jb03ajGiksmQ==
C:\Windows\tasks\RegClean Pro_DEFAULT.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -default
C:\Windows\tasks\RegClean Pro_UPDATES.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -updatecheck
C:\Windows\tasks\SpeedUpMyPC Maintenance.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -m
C:\Windows\tasks\SpeedUpMyPC Startup.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
C:\Windows\tasks\SpeedUpMyPC Subscription.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -l
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-06 662672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
LuckyTab Class - C:\Program Files (x86)\XTab\SupTab.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-06 565304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-01-06 170264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-01-06 398104]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-01-06 440600]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-01 2832168]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2012-01-04 1425408]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Browser Extensions]
C:\Users\Pavel\AppData\Roaming\Browser Extensions\CouponsHelper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
C:\Users\Pavel\AppData\Roaming\Search Protection\SP.EXE /autostart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefault]
C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [2011-12-19 44880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedItupFree]
C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YTDownloader]
C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-01-18 343168]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2011-12-05 291096]
"Easybits Recovery"=C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe []
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2011-11-29 576568]
"HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [2011-08-19 379960]
"HP CoolSense"=C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2011-08-26 1342008]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2010-03-12 49208]
""= []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-20 5515496]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-01-06 429056]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-05-24 16:47:47 ----D---- C:\Program Files\trend micro
2015-05-24 16:47:46 ----D---- C:\rsit
2015-05-20 19:24:49 ----A---- C:\Windows\system32\aswBoot.exe
2015-05-20 19:24:20 ----A---- C:\Windows\avastSS.scr
2015-05-18 21:52:11 ----D---- C:\Program Files (x86)\GUM30A3.tmp
2015-05-18 21:52:11 ----A---- C:\Program Files (x86)\GUT30A4.tmp
2015-05-14 03:03:24 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 03:03:24 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-05-13 10:37:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-05-13 10:37:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-13 10:37:41 ----A---- C:\Windows\system32\iernonce.dll
2015-05-13 10:37:41 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-13 10:37:40 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-13 10:37:39 ----A---- C:\Windows\system32\urlmon.dll
2015-05-13 10:37:39 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 10:37:38 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-13 10:37:37 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-13 10:37:37 ----A---- C:\Windows\system32\iesetup.dll
2015-05-13 10:37:37 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-13 10:37:36 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-05-13 10:37:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-13 10:37:36 ----A---- C:\Windows\system32\vbscript.dll
2015-05-13 10:37:36 ----A---- C:\Windows\system32\iertutil.dll
2015-05-13 10:37:35 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-13 10:37:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\jsproxy.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\ieUnatt.exe
2015-05-13 10:37:35 ----A---- C:\Windows\system32\ieui.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\jscript.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\ieframe.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\wininet.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\jscript9.dll
2015-05-13 10:37:32 ----A---- C:\Windows\system32\msrating.dll
2015-05-13 10:37:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-05-13 10:37:31 ----A---- C:\Windows\system32\mshtml.dll
2015-05-13 09:54:25 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-13 09:54:25 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 09:54:25 ----A---- C:\Windows\system32\schannel.dll
2015-05-13 09:54:25 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 09:49:23 ----A---- C:\Windows\system32\services.exe
2015-05-13 09:49:11 ----A---- C:\Windows\system32\UtcResources.dll
2015-05-13 09:49:11 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-05-13 09:49:11 ----A---- C:\Windows\system32\ntdll.dll
2015-05-13 09:49:11 ----A---- C:\Windows\system32\diagtrack.dll
2015-05-13 09:49:10 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-05-13 09:49:09 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-05-13 09:49:09 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-05-13 09:49:09 ----A---- C:\Windows\system32\tdh.dll
2015-05-13 09:49:09 ----A---- C:\Windows\system32\kernel32.dll
2015-05-13 09:49:09 ----A---- C:\Windows\system32\advapi32.dll
2015-05-13 09:49:08 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\wow64.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\winsrv.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\tracerpt.exe
2015-05-13 09:49:07 ----A---- C:\Windows\system32\srcore.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\sechost.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\msv1_0.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\logman.exe
2015-05-13 09:49:07 ----A---- C:\Windows\system32\KernelBase.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-05-13 09:49:07 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-05-13 09:49:06 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-05-13 09:49:06 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-05-13 09:49:06 ----A---- C:\Windows\system32\conhost.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\wdigest.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\typeperf.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\TSpkg.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\sspicli.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\smss.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\rstrui.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\relog.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\ncrypt.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\lsass.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\kerberos.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\auditpol.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-05-13 09:49:04 ----A---- C:\Windows\system32\diskperf.exe
2015-05-13 09:49:04 ----A---- C:\Windows\system32\csrsrv.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\wow64win.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\wow64cpu.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\sspisrv.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\srclient.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\secur32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\ntvdm64.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\credssp.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\user.exe
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\system32\apisetschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\system32\adtschema.dll
2015-05-13 09:49:00 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-05-13 09:49:00 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-05-13 09:49:00 ----A---- C:\Windows\system32\msobjs.dll
2015-05-13 09:49:00 ----A---- C:\Windows\system32\msaudite.dll
2015-05-13 09:47:47 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 09:47:47 ----A---- C:\Windows\system32\win32k.sys
2015-05-13 09:47:47 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 09:47:47 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 09:42:31 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 09:42:31 ----A---- C:\Windows\system32\InkEd.dll
2015-05-13 09:36:29 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-13 09:36:29 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-13 09:35:13 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-13 09:35:13 ----A---- C:\Windows\system32\poqexec.exe
2015-05-13 09:26:52 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-13 09:26:52 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-13 09:26:52 ----A---- C:\Windows\system32\sdbinst.exe
2015-05-13 09:26:52 ----A---- C:\Windows\system32\apphelp.dll
2015-05-13 09:26:52 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-13 09:26:51 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-13 09:26:51 ----A---- C:\Windows\system32\shimeng.dll
======List of files/folders modified in the last 1 month======
2015-05-24 16:50:41 ----D---- C:\Windows\Temp
2015-05-24 16:47:47 ----RD---- C:\Program Files
2015-05-24 16:47:01 ----D---- C:\Windows\Prefetch
2015-05-24 16:35:08 ----D---- C:\Windows\system32\Tasks
2015-05-24 16:34:44 ----HD---- C:\ProgramData
2015-05-24 16:34:37 ----SHD---- C:\System Volume Information
2015-05-24 16:27:26 ----D---- C:\Windows\System32
2015-05-24 16:27:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-05-24 16:26:41 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-05-24 16:26:23 ----D---- C:\Program Files (x86)
2015-05-24 14:07:20 ----A---- C:\Windows\SYSWOW64\log.txt
2015-05-24 14:06:07 ----RD---- C:\Nepotřebné
2015-05-24 14:05:24 ----D---- C:\Windows\system32\config
2015-05-24 14:01:22 ----D---- C:\Games
2015-05-24 13:57:19 ----D---- C:\Program Files (x86)\Opera
2015-05-24 13:55:19 ----D---- C:\Windows\system32\drivers
2015-05-22 21:49:39 ----D---- C:\Windows\winsxs
2015-05-22 21:49:08 ----SD---- C:\Windows\SYSWOW64\GWX
2015-05-22 21:48:56 ----SD---- C:\Windows\system32\GWX
2015-05-21 18:10:01 ----D---- C:\Windows\SYSWOW64\en-US
2015-05-21 18:10:01 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-05-21 18:10:01 ----D---- C:\Windows\system32\en-US
2015-05-21 18:10:01 ----D---- C:\Windows\system32\cs-CZ
2015-05-21 18:08:19 ----D---- C:\Users\Pavel\AppData\Roaming\systweak
2015-05-21 18:08:19 ----D---- C:\Program Files (x86)\ext coupons
2015-05-21 18:08:15 ----D---- C:\Program Files (x86)\globalUpdate
2015-05-21 18:08:09 ----D---- C:\Windows\SysWOW64
2015-05-20 19:24:47 ----D---- C:\Windows
2015-05-20 19:23:34 ----D---- C:\Windows\Tasks
2015-05-15 01:09:51 ----D---- C:\Windows\rescache
2015-05-14 03:57:54 ----D---- C:\Windows\Microsoft.NET
2015-05-14 03:57:08 ----RSD---- C:\Windows\assembly
2015-05-14 03:42:33 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-14 03:42:31 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-14 03:39:39 ----D---- C:\Program Files\Internet Explorer
2015-05-14 03:39:36 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-14 03:39:31 ----D---- C:\Windows\AppPatch
2015-05-14 03:39:29 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-14 03:39:21 ----D---- C:\Windows\system32\DriverStore
2015-05-14 03:39:20 ----D---- C:\Windows\system32\drivers\UMDF
2015-05-14 03:18:48 ----SHD---- C:\Windows\Installer
2015-05-14 03:18:47 ----SHD---- C:\Config.Msi
2015-05-14 03:18:18 ----D---- C:\Windows\system32\MRT
2015-05-14 03:07:47 ----A---- C:\Windows\system32\MRT.exe
2015-05-13 09:26:38 ----D---- C:\Windows\system32\catroot2
2015-05-12 07:39:05 ----D---- C:\Windows\system32\NDF
2015-04-28 17:05:43 ----D---- C:\Program Files (x86)\WarThunder
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2012-01-18 31360]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-05-20 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-05-20 272248]
R0 hpdskflt;HP Filter; C:\Windows\system32\drivers\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2011-11-29 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3hcs.sys [2011-12-05 16152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-05-20 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-05-20 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-05-20 442264]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-09-02 50976]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2015-02-08 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-05-20 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-05-20 89944]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-05-20 137288]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\drivers\Accelerometer.sys [2011-05-13 43320]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-01-18 10729984]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-01-18 328192]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2011-11-03 134696]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2012-06-01 4746304]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2012-02-11 80384]
R3 btwampfl;btwampfl Bluetooth filter driver; \??\C:\Windows\system32\drivers\btwampfl.sys [2011-12-03 620584]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2011-07-07 167976]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2011-06-23 178728]
R3 BTWDPAN;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\btwdpan.sys [2011-05-21 89640]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2011-02-14 39976]
R3 btwrchid;btwrchid; C:\Windows\system32\drivers\btwrchid.sys [2011-06-23 21544]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2012-01-06 14652768]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3hub.sys [2011-12-05 355096]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3xhc.sys [2011-12-05 785688]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\drivers\HECIx64.sys [2011-11-10 60184]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2012-01-04 535552]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\drivers\SynTP.sys [2011-10-01 393264]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 cpuz134;cpuz134; \??\C:\Users\Pavel\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [2011-09-22 258664]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-01-18 235520]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-05-20 343336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2011-12-05 1084192]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-11-29 34872]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-08 607456]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2011-12-16 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2011-12-16 161560]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-12-16 277784]
R2 ssinstall;SInstalátor; C:\Windows\SysWOW64\ssins.exe [2015-02-02 2324216]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2012-01-04 311808]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-12-16 363800]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15 268464]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-21 114688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-09-06 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
Run by Pavel at 2015-05-24 16:50:40
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 587 GB (85%) free of 692 GB
Total RAM: 3996 MB (36% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:50:41, on 24.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17801)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Pavel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: Browser Extensions - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons.dll (file missing)
O2 - BHO: (no name) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file)
O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files (x86)\XTab\SupTab.dll (file missing)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12968 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 2136496
\??\C:\Windows\system32\conhost.exe "-3069511431305431118-120848313-730844470964887319-49216216115589764022034971870
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\Windows\SysWOW64\ssins.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2920
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
taskeng.exe {2F7F4E0C-A9BB-40B0-BD10-6C5E0C9F2AD9}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" -byrunkey
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5476.0.2134417513\1867929143" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,19,42 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x6840 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.933.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.2.2074235932\1733496971" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.14.1822436942\363580951" /prefetch:673131151
"C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe" /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='ext coupons' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428043279' /runfrom='task' /brwtype='notbg' /postponedhours='6'
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.22.1525135076\783793556" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.23.228611272\259547357" /prefetch:673131151
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Pavel\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-11.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-11.exe /rawdata=Vu+6/C7XPB/wN4Bpsy3l28XKHTEWq0z/Ob90bue0dUiZn1nePk6j2wZRdJTfS5DSFUVxcY4CA1uuVVATMxPnsDKrln/pEJL1aYCXVTMzQzEGppBvrluN8ddybBfTLzDeCc0HupWGYtaafCoc6RlBGMAYkZ69W1wZlD051zJ3080iLUa4Hw/ZKUJzr3KCAHlHZAFe4Po984Fk56kGX3kB65H3s5IR8YWpy/VPkaVU7G7tC+rA2a/Jia2sH6tt1ukQowqSeCSKJ3q8NiwsTq7eD2ZQJvUZtwf1l/je2jRiey4BXb99vH0QnAuljSUp2kETuAy1v4+nn/U5W9c0Y0wc17V9fdwIz/9SZY++pxnmoHRW2k/Sxd2sU0O148ZsXYzqCA/gOLWPKY6bzoXdKODAy7Bsl4BFcjSgpRHx+1J9uCAtkXCYxOIPQwX5c03pYmEYAq0N3mP//GIfiQ57rFywPNiq1jXus3ZgyTEUk1Ld0IlyXl4G0S/dNxwNuEIl3rT/qkGtgCGWzNgBkYnmBvsUWev3ktzEm7Cu5awaZwfDcTrvYSsYnO2UgMEq/6NM31dG4a3lkGEcclUrXLBOTah5uk4xlwEv9vl0du5YpRqHHKIQFO3ttTI63FLm1892m4DMzr/8ZmQalsZ3w5dX26q6P7S8xEMOed8IfZ0C8jBg8+5f1NaCm2/KDlJZtfmlZ5R1q9o+tGzkoBY1+p5PyS1imVe+vBasooM87h7e4jTnbd8F4F5s1E4d1Q9qTn2Xgrco120yi5U1bpX+qTLiJP1yVW1zjEeuTeK9QpeBL9//MRT4nWUKN8u4Uk0ZhXNxMn5rhtVwBXCGVNHpdI1XcYJoiG6ReI/J5qGQ5hHyykmp0rWDK6ULh7l+93lFnh+ZeL6e2VHqSd5rQpoF9mkZ8Z00AmDC3hqnCnCNTbPG4l9wOGf1jS/z+HjYpV+pN+VubGPD/bg2nzn1vw65X66ayy8jFbx7mxqdb+LOlnQTJ4MwJYxTEfHoi0xm0aMpEH2MH0rlamhBtnj2Yv9sxIac7fdGzUWBiH2EKpevn040UKAqrWyXqenvtGTZRAND8dnyllkkFQb2YOIWoTv9/0FYsC3Pz/w65WZ+zF6I7V9Df976JcljCvqgn+8q/FY3TKkOYdl4YgA2Sl9htBrxQW/qPP/mQ4g1108CgC8izHtjroCVB7Sb/kbPdZLoRGO6lf7dguXvmiAer6HsqKDyXw+uF7JXoq9dCRqqhpvHnX7/HkzAJAXCZPSKRp/nbzGcCrK/Q+X2/1G80UMviMKb+r6+82aCfq8uMVGQJ+c9jQSgLrErwmO5ZLZmOYnscmc5MLqCxhiGRzZ5k9V2OX0N4QK5BXKy7B1lPPLI2d5uN+3MyFVtCZmwqTs7Fq1GQ0DelyeM57WNdNoWRdf4hpFoG0u6AcVkC7XH5UCaofOBeJvC0bYcYHZ7a1kTxgXHrhp00D/u8Ql0DslxDS320+gMeyO9Z20t/c3um0PWMfpGLRGeEghv18EMOc1oKR/+1WJOQU1hNfCeEAdZJJzQDY+ZbfYoKbaL8z8SPYKJxKC0KFU1YETcLVsig1hCgLR8icVP/vbXDI02JMALUuKliU4Jhy5S/J6GXeuITG+diMCvHcXdyJ7fKUPmiflXrP7NmiACjcfY1q1g88b1trZKlxYvJFdoDEXcTExtHZckOX4hUJFH4ifpr6eMach+Z1zOBHOQhJHC+QLVGn+Rdld27liyEkH/rxLvgZEAX6c+Dk6CXlmKpXMjLtSIJBu8WQnLnC8p2sqyHUesKLgfzSri6Zs/bxT9wMsNBxPaAaksY6sgcdk8GGhshc6giTCQ82Fzk9QE4ZRn54VNtTdSIlR+3srhU5Bh1QNoisIf9fyjfsg6EQhCiQNtEbsv5qHD2A2/PjNWhsdKfAxivsW40lTCVS3BVN/CAZH0Cowvzhtakn+yNutgjp78GzbSAKYIwRvV2VuZjglzK13c7XFKlCJhbH3KQID81xAdAW/JHwlr2TgsTGyy4vae4tSC54fijmiksB5Po5mYjQVEwKfZsLNelfQRNBmdlJAnYUZ+iGcK8/LusgW7tQO2BAFInmZWiuYQ+J8aZZqyV/MVMjpXJJ3NgeDuAHGrgyTyS07S/oU4ouw8RJmHepCo51jEEdt2T3Dt4HQd7M99qrU0Gs10Xey7Dc7ufKOqx3Ij8xdMlsBJ8CIgCLzgmIbq0DkIpWNz/m4i0ekmTj9njrtWYsTIh2qAjdMS+i1lhnOaUO+Fq5Ze8QOZS7C+Vfe0Lj3VUTbND6p8+pEfrmrbWUZ721c4A4Q97uA5emgGqtWaWTPy5h9l1eOzfGilv8R3y975iQgDMSo7Zfk7TuZLyi60U3EqoycwMZpgBqbh53cjVg==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-4.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-4.exe /rawdata=tw37QcYb58YcPCNo3Ywzy3gNcG7mNjj4gQ9g8PgytL/VeJPmyH1VoUO2P4syYmRcnCsnKD7qldp8k4j+CzRTX4gt32HAxfH891Cm09KyDRJiNMq5l7VFk0wCk4uEfZ+hcgY0G+/3jA251SYaus0giz2Azzi/as68X7xVFTbnSwZa+PY36lFmW5Fi/7mmsVoEzPCqOUiIaCyQqzbtpDNxoMs0ePskGLX5cxMLhvP2P+woD6eCh+ZXlJqunmkjE7UoSfhwQLIiNvuamkaOSFy9Hz3XfxGOfxwd65mLBTSO3DVrw9j4j36bkP+6Zlh+Muxq5AD8PyrrfY0BFLRP6uhyAo6+gGQ9iuatGuHNnxUCWlb+YEbWHvqnY+Dtvi9J16saVvwiroccrvGYS4ktRWxlSoGc/+LTBzEHav+j3tFhHbhX+9/JK7aYv2DsrFgw/qFIT/DnhrHXsQvYwqv0OONbrdGYQ0uBuk8XnUjWv651yHS2aub3rj7HtOdWSA7o6er/k+9elN3okSwGkp0LIOIQFRHqK7InWqBdeLCvrgR5/L7phhNwMxeoC2fYr80miuDiZo2MqDvEXiboCL9A9T0lQv0sHYIzW3x2/VrKc3NbmZb03gkU/oSGdtBpY90MdsXWcI/OJO7iCqMYpIE/mHRWNaTyEuPEFj3Ch0RwvTKz0EsXZ93uo3sfQvNu1Rl5Un9Xab+L63Zwupvmb9MGzPbuLp2tUCrjUt8a1fBwCo6DhxW/oVFtjz7YkkO1Jrz6E8+YQ1toyMWiomRn3c7vnAu21v4VOoC09hgqNL8g7msMqn7KHkWp1Y/zgmxueVMnGHyLTnR6hj0tjSChaOp7TrWXCWzkrTTdMMS1hKkdatsMHSkMvikLPSvwg8R/p0V4pHoeJgKskz0VmHtDdWinKlLRQ7kpRiRySjDO5z7iNAW2hwqjSAgBS/FagLBcuTIP1SsH0ZALmTIzIoLOLZZ/mYrOsUJaos2pessHEqs4CMvqnoXDs0i4KugEjvsCXDus4wkYwLW+3uhSTv7QhE5DeprsL4cribJEZ2LMYgsiZUiGjdJgq0Nx1YlEsMMAjxwsYNtNPpnoaz3PEhrUHrA9Do4NKN8znqXdy8EAaSvxcYrs7LSfX7bRdziTwN/lsO2/K7wckp1G4zB77/lM9aI65CAtL+OwQxWN0FbJ264gIVB9t4IquJmyWtTXhygBFP5PG3zeDsrXmMV0DKlTW3ETBFL40FPSdC8D0Kvf1xCx76Ldoj9DjMVptOf1qT3D+jZsm2yOKxDjBdUOFtsZ/ZrRXUfL0HN2xVCFZnY75k6yG3gDUxB8xV+jPfdhYfvzhCnZgtSRY16KgWCjwuB+4KyAKqlfPw+2HM0Aft+c5PzuiyNfIzih//ZQQI/9YwP5AoHmSQdKpJaNKK7BfTuSsHlqTOeQxq/UywQCIs2Kz+pRkx8XAWj+L9pffgcBElvnTUGsE+z5ojb+qZd99ePX5HNmZPI2bDcpged5Zl6/fsQide3ieXIEB6Byqw5fF+JbyMbFbiqyFdAldS3901qU972hnD6CR4PV1n9mfU6k2b3pPQkZ+vsu6XS6M2krnYWHm56slpheRUN0LGLN/OE5L5VlszOPLIItgw6cUzR4GUYBOyqSWFsLAmqdEqvjEnxpnbVcHlpc6v0n5GyybwvEFOafsW6O5Wz9XIcQ8vPcVndIIQw7luR15KXmoXwPAYwKQRBfjXQAp4P3sSGbZ4Zn3ZaIZZm3msFde3AeDMmA4jpIu4heTMOmFBFw4wUezTd+SERijkbNzhSpzC3KT0UlO6tl17OYEf6wI0siJ6WYzB+LV09OtiGcvG1WZ3fjyeolphakbf8oAn6AMg78it0UAdBPqqzjIA==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-6.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-6.exe /rawdata=MyIFC1ve4f21pb/dR3Rn2DqqKpZh/Bi7BCALsrMa7xG3iDXHPMLaECu50ASzJxi/J1kJjB/+B6ZkVK2Iy/MmOJ6fu7ge2rA1Kt8Tw7mIi9AkzdEwvLVpb2RzXqoZLyby8tpE1wLnc4nqMP1WhbJVJL//IrLHEUa2oeo+uvgRWAqSIY/FuTe5daTNbThE649QuElcifI7SsnEXJPnyXsnMWtlJ4YWBLu5LXLL42BJ79a88/TUoDwEAz+yiuBkUK7mp1fc9YRTSg4J29zbtl4O0+6595bC6dnh0Lr20ikSN+ipMptNayYW24gywJUu3ziz0Pz4xIAR7iUWQp+k4rKvm1/gr72RUqzEk2C5UsNEfnrposCeHINw8gMd+00Fn1EzcbDyS1qcNxkF1G/qVVrvmpafGoO2QzUTEqOj+QVaSrR8UWXfR4CX7oU0OKu2yb65+iGX+iH7Wdp35CzmO0WpGkZbqbf4dU4FPuNqmi04skdNJTlAoz/K/Y6vTBv0VjMLRVS/B5eUWEtYKt6l+YJzMcfOIqPfZORRhvPRITfZoSwbvYfYJT6UQSWyLvaTC4Sdpg9CfOM3KIJHoYcq2KJEHhivYrkgyBBnKivHO8mwyHdr4w4E6TMWJFLzRH956dOZEBhRV8bHWiWwqEcOxBfCrlwmBnkjM2hqJRXTTk2q0a614914IQnuMud9lk3aqJmnqnWQdJW5lBpdJiH7/kcAhhLD5ie/58nXubb6+uOzz5osRXUcT3vsmSoPo2SZZzxc64Y5TOBVuHb1jOANnrHUSJ+kwq0R7cmcubhazTzjngxiwp0Hgy64jljJfcTcJPpL46l4VRrqJhg+rduBhVVD74ummhU1A2H2WRu1he3kxJd+FO3QqJJH/6WINRDcBI9Kp3OexUubzpgy+KbLLJrx3yYnvT2GdzsR803Sc2KW8pa8i7MckjaXxnggLjtitO0BRELw/eXoVqji24CDrwhmTbtgizR6HwCOGponRRDTGWlN+aBqI+1ozDVDhG08Bva4dB77oYLOe80tnK4R/gS67DNf5Dmwxo8UHp/ZA3M5XsVaxEl3hZS1eH2LkX0wnsTv2y96c+F6AkL8e/7BqHVd+beRF4mADfJxp6EVCDvVB4zDqZywkJMdTWafJVrC+3UFPYMwj5Wxw0Bel6x8lDUxUJ+RN+HrxWTlsxTbWA2gqvVsN7TtFV+/uuLDVCvgJBHRY7i2CO8Am189haL1PE6SGJfo/JU+3LoCMpa4/PC3l4V1qz8BBJiC+VLA6Ir0GvGNDMfM54H4ZFjZ2QU0Rr/reirEWIjqecii0DK1RFtFHKHLw+pQwMA9ohKHKyOaTl3nBcOdiMeMVfW00CwAEjW+IWfxgsRPn7MKOH01G9MAyBOTxxRe01WCPJhBALmZByCHbvSyaR+Fc6Hg4YbRtNor99k7XsBBhnL09U/keA2Tv6S/LkByc8izJnVcqnDSd3fuA7vqhK2rCCL9TBXwSKU8JOkuoJaqyyOACLHUfiAjSef/XV2chldNwq5xxHWc3Oihb7u7U0JVBQFe9EwlrNh/Wba7SboRxhvIlNliNdtgo4xFEo++uzpjPiTg52Z7Lsc1vTuACqD/ZOMaPMjmjDkEP5yNAE3TNaiSCheIuudCN5LsX5S9Xbnlw020i0IF6nddPIUtl+M/CUNPDnHPBwHrhQMx4PYRcs5dEjz/9wZtAJF8uak7/6ugdTbdmt+RK+E1404W1V5fY776w9OGKslHbxzd1fRaNjJa/J1xZ9mYb0owFlk8gGYOOjAr1690lJJKZVIMxPujJiuTpDnAEY8q7vWuYpmLFO2kXoajI05Akp4Oyfq1+vG7ML8eNuiOFxwJggjUOSUQGlS6QacW2Cu6kQ==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-7.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-7.exe /rawdata=yBXhCAlu2cALWig39dCPUvnuB94Yjyey6e3FQpYeyj3shHg3nx76gKaqTDzX13SRneE1lfBT7o2//V+aMK8AHdBr7jJptRRsK51iS3NugCtU5PKcLU775oNadUAp28M2ucQwoFW7/Oxvst4l1yMd7gZqR2rRi4wOOl4jYGCYqhwdU92SL/uG4D0vANetFc3nAnRv4HM7/xhnBP0Tm8EIHgZM8+DTjvLUfSANZDcyXjUzM1DzBC/tRmOHaL0jHH2T/1hpNU40Pa5jW7lPG5FlyHCpwhvrPS+kAR3vwM0F2eFo9AAeWH5lloTGp1FK2M19BcSXSZe0rFsFmnMW6gMJ7Kic7gO8Tv+2/+iegF6XrYangm2mqePYxAhREEajNcecv/tiBnlklFpPXhDXl6vx9tBVJJTTuECY+v7Xet04oFNJ/pfyDjlRVLljKO4By0TNZo0geoJaHcF0jistQlGMucDrIm9XSvmWO4nAU2119JKkc/CeQSlpIGRn2dxXfcTej8+l7m1yovC7cyAijGWyn94V9as6IaQ3pFrN3n/evTpb8J0BB1V8vOPcXgwYGmi4sVgusvVhuSOHtwLQ5bFOKOjeNfMtLkBdy/i3oi8wdx4E2RquFVsNM6fn8x/I+1KFl+mhqpLky3muH364EnXVmOz1ILK1xs4+aFEpNaFO7+ZXEXWUBelCTxOkLl+Ix/it9XGKFUAoYEFzaq9+7sWoTrTojJB2PsRHmrHXmV9YIQWVutlxR/yzVycK/UIGV4AQqSIymWwHRG3bf4mRwVTign+pL+UbndcoQ/D6tTeXsqvxLOPa3nBBhrKPTnhzYSJPX0OcPB+GXxQfpiLkZun80WELhrOn0Pk1vgcA7pXFYzd4AVzcv158Fktbs35yZXz2NhRPLn/DNpYXhMN4l0uI6G8IKp1jHuGUDgVHRfM27AxRpoLBZj3GpyaoYg3m9dMQCLifzW7jzaVC1nGiD21PK9wB9o/SZ8Ffbe2zH4vpD0jhB56Z78Y2mbvqrD5c1i3OHw1eLwXiAXhUpvd8torhdS4057Rk8sFQEmpoOlR5oo49DMRLitChwQtA3oLMFGNNYCYKwweN2oXoBARP2n0NjZkA0yWMgIm9diTcI5XXssoAmHrr9qnu5R1SvBP7qc65gzVo3QdsLXSrniX2dTc4ba4Tvq85TxZg8w6jNc2b3NQ276ZyW+97yo9KbRpPHiXqKrQ25fPP+jbvhniU+RXZKAeJvFghX2eyhY8BV4r16tGDpV7GPiB+EtU4fQY5GDNDcqvfmovZ2jGe2MyBjFsvSsG64YpoQYApyBbY8KvJuSyI8Z0VWGoViMDGkdo1CttYlK3Lwdxa13lfxNMeK0qBKYLMaE/3yDbDU8iRbwhfqctDU8DjEtBnE5PXYFeeRKkr8g/Y/Sx0Nsg5DBqNnI7pCWC2QNcMz/R1lL2bXsNjNJaNR8M3QmblurjWzFLKrnkkLIoBkURVwumjUytLB5RBeH8d2hPlQ+1EWRzXPqkP87hyFzcIt3iiWPqZu0HMYkVlZtvD62+IHt9QCn4Ok5YIrD+v1XGBKu2W11vhHv3/0g3fWlySheo6s+7wR1k9bU+yMS7EfgpKjkTl99dbRO8cmAqEmiebf+oaHywsCtqbgd/C/DhLpWaXB5ZqIo3+neEEUvpx9OIEdoSPt8lKwbxG8+LtmTWNp133cFw87N+SMc4=
C:\Windows\tasks\48_dresses_notification_service.job - C:\Program Files (x86)\48 dresses\48_dresses_notification_service.exe /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='48 dresses' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428343649' /runfrom='task' /brwtype='notbg' /postponedhours='6'
C:\Windows\tasks\48_dresses_updating_service.job - C:\Program Files (x86)\48 dresses\48_dresses_updating_service.exe /campid=2913 /verid=1 /url=http://cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=48_dresses_updating_service /funurl=http://stats.buildomserv.com
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /yYEHolYG /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-2.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-2.exe /DSIUmxCpW /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /GQTowmm=11111111-1111-1111-1111-110311551110 /aZJRhuSIm=ff /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-5.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-5.exe /yochGqlS /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /MLIMI=http://ipgeoapi.com/ /jXJieqAhe=http://update.clientstatsservice.com /HiJzz=2 /OmnqxP=http://logs.clientstatsservice.com /LWpHklfn='http://update.clientstatsservice.com/up ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-6.job - C:\Program Files (x86)\iWebar\iWebar-novainstaller.exe /UYfdKYRRC /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/no ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-7.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/no ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-1.job - C:\Program Files (x86)\Object Browser\Object Browser-codedownloader.exe /GiFbEM /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.exe /LRWiRR /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /YqoVZF=11111111-1111-1111-1111-110311281150 /bwgrJeg=ff /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.exe /PKXeqKRC /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /ALJkDN=http://ipgeoapi.com/ /TDNiHP=http://update.clientstatsservice.com /EVUDo=2 /mHmtsuHV=http://logs.clientstatsservice.com /fuiKVYjh='http://update.clientstatsservice.com/up ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-6.job - C:\Program Files (x86)\Object Browser\Object Browser-novainstaller.exe /LlhaGyRW /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/no ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-7.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/no ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\ext_coupons_notification_service.job - C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='ext coupons' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428043279' /runfrom='task' /brwtype='notbg' /postponedhours='6'
C:\Windows\tasks\ext_coupons_updating_service.job - C:\Program Files (x86)\ext coupons\ext_coupons_updating_service.exe /campid=2913 /verid=1 /url=http://cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=ext_coupons_updating_service /funurl=http://stats.buildomserv.com
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\HPCeeScheduleForPavel.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPavel (null)
C:\Windows\tasks\LAUNbFbBPC16B2.job - C:\Users\Pavel\AppData\Roaming\LAUNbFbBPC16B2.exe --c=oMAFrD801AXmNaTf2riQm64CQg/sJ45+zqDEmk+BMX31uMmiUZBNqQ749251lFdnw1tOy7sjmguPj2juc/7uhDhO0MCV7k09iPMdIdCXgAQQSRiqYbe3BZjcFMIHrZXQOJH+mvAQrO/QCea7GIEywDjdokLWukPkt+WUoAdG/PiUTwxJtdC5CaFHDT1NfhHC7lKsvJ4Qu3tadZN1hEN+YT7FXRwaqXmZyz2ZYyRRXdI/JxGbEiktTGUBXcmp/Wec5piHfB1xaXRb3Lm6/ul8w27Gzk/Tnd8/DEMOPu+Pttkv3VXOsYPeR4Z9HVgOj7O3YTEnN/kE15Jb03ajGiksmQ==
C:\Windows\tasks\RegClean Pro_DEFAULT.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -default
C:\Windows\tasks\RegClean Pro_UPDATES.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -updatecheck
C:\Windows\tasks\SpeedUpMyPC Maintenance.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -m
C:\Windows\tasks\SpeedUpMyPC Startup.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
C:\Windows\tasks\SpeedUpMyPC Subscription.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -l
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-06 662672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
LuckyTab Class - C:\Program Files (x86)\XTab\SupTab.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-06 565304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-01-06 170264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-01-06 398104]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-01-06 440600]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-01 2832168]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2012-01-04 1425408]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Browser Extensions]
C:\Users\Pavel\AppData\Roaming\Browser Extensions\CouponsHelper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
C:\Users\Pavel\AppData\Roaming\Search Protection\SP.EXE /autostart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefault]
C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [2011-12-19 44880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedItupFree]
C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YTDownloader]
C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-01-18 343168]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2011-12-05 291096]
"Easybits Recovery"=C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe []
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2011-11-29 576568]
"HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [2011-08-19 379960]
"HP CoolSense"=C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2011-08-26 1342008]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2010-03-12 49208]
""= []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-20 5515496]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-01-06 429056]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-05-24 16:47:47 ----D---- C:\Program Files\trend micro
2015-05-24 16:47:46 ----D---- C:\rsit
2015-05-20 19:24:49 ----A---- C:\Windows\system32\aswBoot.exe
2015-05-20 19:24:20 ----A---- C:\Windows\avastSS.scr
2015-05-18 21:52:11 ----D---- C:\Program Files (x86)\GUM30A3.tmp
2015-05-18 21:52:11 ----A---- C:\Program Files (x86)\GUT30A4.tmp
2015-05-14 03:03:24 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 03:03:24 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-05-13 10:37:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-05-13 10:37:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-13 10:37:41 ----A---- C:\Windows\system32\iernonce.dll
2015-05-13 10:37:41 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-13 10:37:40 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-13 10:37:39 ----A---- C:\Windows\system32\urlmon.dll
2015-05-13 10:37:39 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 10:37:38 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-13 10:37:37 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-13 10:37:37 ----A---- C:\Windows\system32\iesetup.dll
2015-05-13 10:37:37 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-13 10:37:36 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-05-13 10:37:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-13 10:37:36 ----A---- C:\Windows\system32\vbscript.dll
2015-05-13 10:37:36 ----A---- C:\Windows\system32\iertutil.dll
2015-05-13 10:37:35 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-13 10:37:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\jsproxy.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\ieUnatt.exe
2015-05-13 10:37:35 ----A---- C:\Windows\system32\ieui.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\jscript.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\ieframe.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\wininet.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\jscript9.dll
2015-05-13 10:37:32 ----A---- C:\Windows\system32\msrating.dll
2015-05-13 10:37:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-05-13 10:37:31 ----A---- C:\Windows\system32\mshtml.dll
2015-05-13 09:54:25 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-13 09:54:25 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 09:54:25 ----A---- C:\Windows\system32\schannel.dll
2015-05-13 09:54:25 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 09:49:23 ----A---- C:\Windows\system32\services.exe
2015-05-13 09:49:11 ----A---- C:\Windows\system32\UtcResources.dll
2015-05-13 09:49:11 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-05-13 09:49:11 ----A---- C:\Windows\system32\ntdll.dll
2015-05-13 09:49:11 ----A---- C:\Windows\system32\diagtrack.dll
2015-05-13 09:49:10 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-05-13 09:49:09 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-05-13 09:49:09 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-05-13 09:49:09 ----A---- C:\Windows\system32\tdh.dll
2015-05-13 09:49:09 ----A---- C:\Windows\system32\kernel32.dll
2015-05-13 09:49:09 ----A---- C:\Windows\system32\advapi32.dll
2015-05-13 09:49:08 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\wow64.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\winsrv.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\tracerpt.exe
2015-05-13 09:49:07 ----A---- C:\Windows\system32\srcore.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\sechost.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\msv1_0.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\logman.exe
2015-05-13 09:49:07 ----A---- C:\Windows\system32\KernelBase.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-05-13 09:49:07 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-05-13 09:49:06 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-05-13 09:49:06 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-05-13 09:49:06 ----A---- C:\Windows\system32\conhost.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\wdigest.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\typeperf.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\TSpkg.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\sspicli.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\smss.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\rstrui.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\relog.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\ncrypt.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\lsass.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\kerberos.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\auditpol.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-05-13 09:49:04 ----A---- C:\Windows\system32\diskperf.exe
2015-05-13 09:49:04 ----A---- C:\Windows\system32\csrsrv.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\wow64win.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\wow64cpu.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\sspisrv.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\srclient.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\secur32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\ntvdm64.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\credssp.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\user.exe
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\system32\apisetschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\system32\adtschema.dll
2015-05-13 09:49:00 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-05-13 09:49:00 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-05-13 09:49:00 ----A---- C:\Windows\system32\msobjs.dll
2015-05-13 09:49:00 ----A---- C:\Windows\system32\msaudite.dll
2015-05-13 09:47:47 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 09:47:47 ----A---- C:\Windows\system32\win32k.sys
2015-05-13 09:47:47 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 09:47:47 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 09:42:31 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 09:42:31 ----A---- C:\Windows\system32\InkEd.dll
2015-05-13 09:36:29 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-13 09:36:29 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-13 09:35:13 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-13 09:35:13 ----A---- C:\Windows\system32\poqexec.exe
2015-05-13 09:26:52 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-13 09:26:52 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-13 09:26:52 ----A---- C:\Windows\system32\sdbinst.exe
2015-05-13 09:26:52 ----A---- C:\Windows\system32\apphelp.dll
2015-05-13 09:26:52 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-13 09:26:51 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-13 09:26:51 ----A---- C:\Windows\system32\shimeng.dll
======List of files/folders modified in the last 1 month======
2015-05-24 16:50:41 ----D---- C:\Windows\Temp
2015-05-24 16:47:47 ----RD---- C:\Program Files
2015-05-24 16:47:01 ----D---- C:\Windows\Prefetch
2015-05-24 16:35:08 ----D---- C:\Windows\system32\Tasks
2015-05-24 16:34:44 ----HD---- C:\ProgramData
2015-05-24 16:34:37 ----SHD---- C:\System Volume Information
2015-05-24 16:27:26 ----D---- C:\Windows\System32
2015-05-24 16:27:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-05-24 16:26:41 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-05-24 16:26:23 ----D---- C:\Program Files (x86)
2015-05-24 14:07:20 ----A---- C:\Windows\SYSWOW64\log.txt
2015-05-24 14:06:07 ----RD---- C:\Nepotřebné
2015-05-24 14:05:24 ----D---- C:\Windows\system32\config
2015-05-24 14:01:22 ----D---- C:\Games
2015-05-24 13:57:19 ----D---- C:\Program Files (x86)\Opera
2015-05-24 13:55:19 ----D---- C:\Windows\system32\drivers
2015-05-22 21:49:39 ----D---- C:\Windows\winsxs
2015-05-22 21:49:08 ----SD---- C:\Windows\SYSWOW64\GWX
2015-05-22 21:48:56 ----SD---- C:\Windows\system32\GWX
2015-05-21 18:10:01 ----D---- C:\Windows\SYSWOW64\en-US
2015-05-21 18:10:01 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-05-21 18:10:01 ----D---- C:\Windows\system32\en-US
2015-05-21 18:10:01 ----D---- C:\Windows\system32\cs-CZ
2015-05-21 18:08:19 ----D---- C:\Users\Pavel\AppData\Roaming\systweak
2015-05-21 18:08:19 ----D---- C:\Program Files (x86)\ext coupons
2015-05-21 18:08:15 ----D---- C:\Program Files (x86)\globalUpdate
2015-05-21 18:08:09 ----D---- C:\Windows\SysWOW64
2015-05-20 19:24:47 ----D---- C:\Windows
2015-05-20 19:23:34 ----D---- C:\Windows\Tasks
2015-05-15 01:09:51 ----D---- C:\Windows\rescache
2015-05-14 03:57:54 ----D---- C:\Windows\Microsoft.NET
2015-05-14 03:57:08 ----RSD---- C:\Windows\assembly
2015-05-14 03:42:33 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-14 03:42:31 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-14 03:39:39 ----D---- C:\Program Files\Internet Explorer
2015-05-14 03:39:36 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-14 03:39:31 ----D---- C:\Windows\AppPatch
2015-05-14 03:39:29 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-14 03:39:21 ----D---- C:\Windows\system32\DriverStore
2015-05-14 03:39:20 ----D---- C:\Windows\system32\drivers\UMDF
2015-05-14 03:18:48 ----SHD---- C:\Windows\Installer
2015-05-14 03:18:47 ----SHD---- C:\Config.Msi
2015-05-14 03:18:18 ----D---- C:\Windows\system32\MRT
2015-05-14 03:07:47 ----A---- C:\Windows\system32\MRT.exe
2015-05-13 09:26:38 ----D---- C:\Windows\system32\catroot2
2015-05-12 07:39:05 ----D---- C:\Windows\system32\NDF
2015-04-28 17:05:43 ----D---- C:\Program Files (x86)\WarThunder
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2012-01-18 31360]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-05-20 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-05-20 272248]
R0 hpdskflt;HP Filter; C:\Windows\system32\drivers\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2011-11-29 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3hcs.sys [2011-12-05 16152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-05-20 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-05-20 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-05-20 442264]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-09-02 50976]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2015-02-08 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-05-20 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-05-20 89944]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-05-20 137288]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\drivers\Accelerometer.sys [2011-05-13 43320]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-01-18 10729984]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-01-18 328192]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2011-11-03 134696]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2012-06-01 4746304]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2012-02-11 80384]
R3 btwampfl;btwampfl Bluetooth filter driver; \??\C:\Windows\system32\drivers\btwampfl.sys [2011-12-03 620584]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2011-07-07 167976]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2011-06-23 178728]
R3 BTWDPAN;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\btwdpan.sys [2011-05-21 89640]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2011-02-14 39976]
R3 btwrchid;btwrchid; C:\Windows\system32\drivers\btwrchid.sys [2011-06-23 21544]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2012-01-06 14652768]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3hub.sys [2011-12-05 355096]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3xhc.sys [2011-12-05 785688]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\drivers\HECIx64.sys [2011-11-10 60184]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2012-01-04 535552]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\drivers\SynTP.sys [2011-10-01 393264]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 cpuz134;cpuz134; \??\C:\Users\Pavel\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [2011-09-22 258664]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-01-18 235520]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-05-20 343336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2011-12-05 1084192]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-11-29 34872]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-08 607456]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2011-12-16 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2011-12-16 161560]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-12-16 277784]
R2 ssinstall;SInstalátor; C:\Windows\SysWOW64\ssins.exe [2015-02-02 2324216]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2012-01-04 311808]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-12-16 363800]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15 268464]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-21 114688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-09-06 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
Re: prosím o kontrolu logu
Krasny den Vam preju 
V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).
Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm



- ukoncete vsechny programy
- kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
- kliknete na Scan, pote na Cleaning
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi

- spustte jako spravce
- do velkeho okna zkopirujte script uvedeny nize
- kliknete na Run script
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi
Kód: Vybrat vše
autoclean; emptyclsid; emptyalltemp;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: prosím o kontrolu logu
# AdwCleaner v4.205 - Log vytvořen 25/05/2015 v 15:22:02
# Aktualizováno 21/05/2015 by Xplode
# Databáze : 2015-05-24.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : Pavel - PAVEL-HP
# Spuštěno z : C:\Users\Pavel\Documents\Downloads\adwcleaner_4.205.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
Složka Smazáno : C:\ProgramData\AVG Secure Search
Složka Smazáno : C:\ProgramData\AVG Security Toolbar
Složka Smazáno : C:\ProgramData\ShopperPro
Složka Smazáno : C:\ProgramData\IHProtectUpDate
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\Program Files (x86)\ext coupons
Složka Smazáno : C:\Program Files (x86)\48 dresses
Složka Smazáno : C:\Program Files (x86)\Common Files\AVG Secure Search
Složka Smazáno : C:\Users\Pavel\AppData\Local\Temp\apn
Složka Smazáno : C:\Program Files\PC Optimizer Pro
Složka Smazáno : C:\Program Files\Reimage
Složka Smazáno : C:\Program Files\Common Files\ShopperPro
Složka Smazáno : C:\Users\Pavel\AppData\Local\globalUpdate
Složka Smazáno : C:\Users\Pavel\AppData\LocalLow\iWebar
Složka Smazáno : C:\Users\Pavel\AppData\LocalLow\Object Browser
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Systweak
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Uniblue
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\z5cC9@gmail.com
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal
Soubor Smazáno : C:\Windows\Reimage.ini
Soubor Smazáno : C:\Windows\SpeedItup Free Setup Log.txt
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Temp\DriverDetective.exe
Soubor Smazáno : C:\Windows\System32\roboot64.exe
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\LAUNbFbBPC16B2
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\speedupmypc.lnk
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Soubor Smazáno : C:\Program Files (x86)\Mozilla Firefox\my.cfg
Soubor Smazáno : C:\Program Files (x86)\Mozilla Firefox\browser\defaults\preferences\my-prefs.js
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_mail-bomber.en.softonic.com_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_mail-bomber.en.softonic.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.istartsurf.com_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.istartsurf.com_0.localstorage-journal
***** [ Naplánované úlohy ] *****
Úloha Smazáno : LaunchSignup
Úloha Smazáno : RegClean Pro
Úloha Smazáno : RegClean Pro_DEFAULT
Úloha Smazáno : RegClean Pro_UPDATES
Úloha Smazáno : ReimageUpdater
Úloha Smazáno : SPDriver
Úloha Smazáno : SpeedUpMyPC Maintenance
Úloha Smazáno : SpeedUpMyPC Startup
Úloha Smazáno : SpeedUpMyPC Subscription
Úloha Smazáno : YTDownloader
Úloha Smazáno : ext_coupons_updating_service
Úloha Smazáno : ext_coupons_notification_service
# Aktualizováno 21/05/2015 by Xplode
# Databáze : 2015-05-24.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : Pavel - PAVEL-HP
# Spuštěno z : C:\Users\Pavel\Documents\Downloads\adwcleaner_4.205.exe
# Nastavení : Čištění
***** [ Služby ] *****
***** [ Soubory / Složky ] *****
Složka Smazáno : C:\ProgramData\AVG Secure Search
Složka Smazáno : C:\ProgramData\AVG Security Toolbar
Složka Smazáno : C:\ProgramData\ShopperPro
Složka Smazáno : C:\ProgramData\IHProtectUpDate
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\Program Files (x86)\ext coupons
Složka Smazáno : C:\Program Files (x86)\48 dresses
Složka Smazáno : C:\Program Files (x86)\Common Files\AVG Secure Search
Složka Smazáno : C:\Users\Pavel\AppData\Local\Temp\apn
Složka Smazáno : C:\Program Files\PC Optimizer Pro
Složka Smazáno : C:\Program Files\Reimage
Složka Smazáno : C:\Program Files\Common Files\ShopperPro
Složka Smazáno : C:\Users\Pavel\AppData\Local\globalUpdate
Složka Smazáno : C:\Users\Pavel\AppData\LocalLow\iWebar
Složka Smazáno : C:\Users\Pavel\AppData\LocalLow\Object Browser
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Systweak
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Uniblue
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\z5cC9@gmail.com
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal
Soubor Smazáno : C:\Windows\Reimage.ini
Soubor Smazáno : C:\Windows\SpeedItup Free Setup Log.txt
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Temp\DriverDetective.exe
Soubor Smazáno : C:\Windows\System32\roboot64.exe
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\LAUNbFbBPC16B2
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\speedupmypc.lnk
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Soubor Smazáno : C:\Program Files (x86)\Mozilla Firefox\my.cfg
Soubor Smazáno : C:\Program Files (x86)\Mozilla Firefox\browser\defaults\preferences\my-prefs.js
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_mail-bomber.en.softonic.com_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_mail-bomber.en.softonic.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.istartsurf.com_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.istartsurf.com_0.localstorage-journal
***** [ Naplánované úlohy ] *****
Úloha Smazáno : LaunchSignup
Úloha Smazáno : RegClean Pro
Úloha Smazáno : RegClean Pro_DEFAULT
Úloha Smazáno : RegClean Pro_UPDATES
Úloha Smazáno : ReimageUpdater
Úloha Smazáno : SPDriver
Úloha Smazáno : SpeedUpMyPC Maintenance
Úloha Smazáno : SpeedUpMyPC Startup
Úloha Smazáno : SpeedUpMyPC Subscription
Úloha Smazáno : YTDownloader
Úloha Smazáno : ext_coupons_updating_service
Úloha Smazáno : ext_coupons_notification_service
Re: prosím o kontrolu logu
Děkuji za kontrolu







Re: prosím o kontrolu logu


Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: prosím o kontrolu logu
Ano děkuji a co nejdříve vám sem další log odešlu
Re: prosím o kontrolu logu
OK, jak budete mit cas, ozvete se a poradne Vam PC procistime 

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: prosím o kontrolu logu
Zoek.exe is still running.
Do not start any browser windows, they may get closed automatically.
Please wait! This window will close when finished.
A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log
Do not start any browser windows, they may get closed automatically.
Please wait! This window will close when finished.
A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log
Re: prosím o kontrolu logu
Zoek Vam v anglictine vzkazuje, abyste ho nechal bezet - prelozim radky logu:
Pokud jste jej ukoncil, spustte jej znovu se stejnym skriptem 
Kód: Vybrat vše
Zoek stale bezi.
Nespoustejte prohlizece, protoze muze dojit k jejich ukonceni.
Pockejte prosim! Toto okno bude ukonceno, jakmile zoek svou praci dokonci.
Nasledne bude otevren vysledny log nebo jej lze najit v C:\zoek-results.log

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: prosím o kontrolu logu
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Pavel on st 27.05.2015 at 15:45:28,23.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Pavel\Desktop\zoek.exe [Scan all users] [Quick Scan] [Auto Clean]
===== Runcheck 15:45:46,08 =====
--- Create Environment Variables 15:45:48,51
--- Checking Input 15:46:04,46
--- AU AppData Check 15:46:28,25
--- Remove From Windows Installer 15:46:37,90
--- Empty Folders Check 15:49:36,72
--- Registry HKLM Software Check 15:49:36,88
--- Quick Launch Shortcut Check 15:50:50,53
--- IE Startpage Check 15:50:57,75
--- Program Files DB Check 15:51:40,90
--- C:\Users\Default\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Default User\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Pavel\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Pavel DB Check 15:58:52,82
--- C:\PROGRA~3 DB Check 15:59:33,80
--- C:\Users\Default\AppData\Local DB Check 15:59:45,89
--- C:\Users\Default User\AppData\Local DB Check 15:59:45,89
--- C:\Users\Pavel\AppData\Local DB Check 15:59:45,89
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 15:59:45,89
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 15:59:45,89
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 15:59:45,89
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 15:59:45,89
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 16:03:29,69
--- C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 16:03:53,51
--- Tasks DB Check 16:04:08,61
--- Downloads DB Check 16:04:17,67
--- C:\Users\Pavel\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 16:04:27,80
--- Tasks2 DB Check 16:06:29,29
--- Documents DB Check 16:07:38,09
--- C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default DB Check 16:07:56,42
--- C:\Users\Public\Desktop DB Check 16:08:01,92
--- C:\Users\Pavel\Desktop DB Check 16:08:12,36
--- Services DB Check 16:08:33,70
--- FF prefs.js DB Check 16:09:16,16
--- Emptyclsid 16:10:56,46
--- Del by CLSID 16:11:00,33
Tool run by Pavel on st 27.05.2015 at 15:45:28,23.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Pavel\Desktop\zoek.exe [Scan all users] [Quick Scan] [Auto Clean]
===== Runcheck 15:45:46,08 =====
--- Create Environment Variables 15:45:48,51
--- Checking Input 15:46:04,46
--- AU AppData Check 15:46:28,25
--- Remove From Windows Installer 15:46:37,90
--- Empty Folders Check 15:49:36,72
--- Registry HKLM Software Check 15:49:36,88
--- Quick Launch Shortcut Check 15:50:50,53
--- IE Startpage Check 15:50:57,75
--- Program Files DB Check 15:51:40,90
--- C:\Users\Default\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Default User\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Pavel\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Pavel DB Check 15:58:52,82
--- C:\PROGRA~3 DB Check 15:59:33,80
--- C:\Users\Default\AppData\Local DB Check 15:59:45,89
--- C:\Users\Default User\AppData\Local DB Check 15:59:45,89
--- C:\Users\Pavel\AppData\Local DB Check 15:59:45,89
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 15:59:45,89
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 15:59:45,89
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 15:59:45,89
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 15:59:45,89
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 16:03:29,69
--- C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 16:03:53,51
--- Tasks DB Check 16:04:08,61
--- Downloads DB Check 16:04:17,67
--- C:\Users\Pavel\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 16:04:27,80
--- Tasks2 DB Check 16:06:29,29
--- Documents DB Check 16:07:38,09
--- C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default DB Check 16:07:56,42
--- C:\Users\Public\Desktop DB Check 16:08:01,92
--- C:\Users\Pavel\Desktop DB Check 16:08:12,36
--- Services DB Check 16:08:33,70
--- FF prefs.js DB Check 16:09:16,16
--- Emptyclsid 16:10:56,46
--- Del by CLSID 16:11:00,33
Re: prosím o kontrolu logu

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: prosím o kontrolu logu
Více mi to neukázalo pak mi tento program nešel vypnout vyplo se to až po restartaci asi sem to vypnul dříve jak dlouho asi tak trvá toto čištění děkuji








Re: prosím o kontrolu logu


Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.