Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosím o kontrolu logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
SkrdletaP
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 24 kvě 2015 15:44

prosím o kontrolu logu

#1 Příspěvek od SkrdletaP »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Pavel at 2015-05-24 16:50:40
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 587 GB (85%) free of 692 GB
Total RAM: 3996 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:50:41, on 24.5.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17801)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Pavel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: Browser Extensions - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons.dll (file missing)
O2 - BHO: (no name) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file)
O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files (x86)\XTab\SupTab.dll (file missing)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\3.2.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12968 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 2136496
\??\C:\Windows\system32\conhost.exe "-3069511431305431118-120848313-730844470964887319-49216216115589764022034971870
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\Windows\SysWOW64\ssins.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2920
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
taskeng.exe {2F7F4E0C-A9BB-40B0-BD10-6C5E0C9F2AD9}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" -byrunkey
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5476.0.2134417513\1867929143" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,19,42 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x6840 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.933.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.2.2074235932\1733496971" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.14.1822436942\363580951" /prefetch:673131151
"C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe" /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='ext coupons' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428043279' /runfrom='task' /brwtype='notbg' /postponedhours='6'
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.22.1525135076\783793556" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Extension (public)/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/PP_Ethersuggest_A4_Stable_R8/*PasswordGeneration/Disabled/*PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*ShowAppLauncherPromo/ShowPromoUntilDismissed/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group5/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_55/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*V8CacheOptions/default/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=5476 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --disable-accelerated-video-decode --channel="5476.23.228611272\259547357" /prefetch:673131151
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Pavel\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-11.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-11.exe /rawdata=Vu+6/C7XPB/wN4Bpsy3l28XKHTEWq0z/Ob90bue0dUiZn1nePk6j2wZRdJTfS5DSFUVxcY4CA1uuVVATMxPnsDKrln/pEJL1aYCXVTMzQzEGppBvrluN8ddybBfTLzDeCc0HupWGYtaafCoc6RlBGMAYkZ69W1wZlD051zJ3080iLUa4Hw/ZKUJzr3KCAHlHZAFe4Po984Fk56kGX3kB65H3s5IR8YWpy/VPkaVU7G7tC+rA2a/Jia2sH6tt1ukQowqSeCSKJ3q8NiwsTq7eD2ZQJvUZtwf1l/je2jRiey4BXb99vH0QnAuljSUp2kETuAy1v4+nn/U5W9c0Y0wc17V9fdwIz/9SZY++pxnmoHRW2k/Sxd2sU0O148ZsXYzqCA/gOLWPKY6bzoXdKODAy7Bsl4BFcjSgpRHx+1J9uCAtkXCYxOIPQwX5c03pYmEYAq0N3mP//GIfiQ57rFywPNiq1jXus3ZgyTEUk1Ld0IlyXl4G0S/dNxwNuEIl3rT/qkGtgCGWzNgBkYnmBvsUWev3ktzEm7Cu5awaZwfDcTrvYSsYnO2UgMEq/6NM31dG4a3lkGEcclUrXLBOTah5uk4xlwEv9vl0du5YpRqHHKIQFO3ttTI63FLm1892m4DMzr/8ZmQalsZ3w5dX26q6P7S8xEMOed8IfZ0C8jBg8+5f1NaCm2/KDlJZtfmlZ5R1q9o+tGzkoBY1+p5PyS1imVe+vBasooM87h7e4jTnbd8F4F5s1E4d1Q9qTn2Xgrco120yi5U1bpX+qTLiJP1yVW1zjEeuTeK9QpeBL9//MRT4nWUKN8u4Uk0ZhXNxMn5rhtVwBXCGVNHpdI1XcYJoiG6ReI/J5qGQ5hHyykmp0rWDK6ULh7l+93lFnh+ZeL6e2VHqSd5rQpoF9mkZ8Z00AmDC3hqnCnCNTbPG4l9wOGf1jS/z+HjYpV+pN+VubGPD/bg2nzn1vw65X66ayy8jFbx7mxqdb+LOlnQTJ4MwJYxTEfHoi0xm0aMpEH2MH0rlamhBtnj2Yv9sxIac7fdGzUWBiH2EKpevn040UKAqrWyXqenvtGTZRAND8dnyllkkFQb2YOIWoTv9/0FYsC3Pz/w65WZ+zF6I7V9Df976JcljCvqgn+8q/FY3TKkOYdl4YgA2Sl9htBrxQW/qPP/mQ4g1108CgC8izHtjroCVB7Sb/kbPdZLoRGO6lf7dguXvmiAer6HsqKDyXw+uF7JXoq9dCRqqhpvHnX7/HkzAJAXCZPSKRp/nbzGcCrK/Q+X2/1G80UMviMKb+r6+82aCfq8uMVGQJ+c9jQSgLrErwmO5ZLZmOYnscmc5MLqCxhiGRzZ5k9V2OX0N4QK5BXKy7B1lPPLI2d5uN+3MyFVtCZmwqTs7Fq1GQ0DelyeM57WNdNoWRdf4hpFoG0u6AcVkC7XH5UCaofOBeJvC0bYcYHZ7a1kTxgXHrhp00D/u8Ql0DslxDS320+gMeyO9Z20t/c3um0PWMfpGLRGeEghv18EMOc1oKR/+1WJOQU1hNfCeEAdZJJzQDY+ZbfYoKbaL8z8SPYKJxKC0KFU1YETcLVsig1hCgLR8icVP/vbXDI02JMALUuKliU4Jhy5S/J6GXeuITG+diMCvHcXdyJ7fKUPmiflXrP7NmiACjcfY1q1g88b1trZKlxYvJFdoDEXcTExtHZckOX4hUJFH4ifpr6eMach+Z1zOBHOQhJHC+QLVGn+Rdld27liyEkH/rxLvgZEAX6c+Dk6CXlmKpXMjLtSIJBu8WQnLnC8p2sqyHUesKLgfzSri6Zs/bxT9wMsNBxPaAaksY6sgcdk8GGhshc6giTCQ82Fzk9QE4ZRn54VNtTdSIlR+3srhU5Bh1QNoisIf9fyjfsg6EQhCiQNtEbsv5qHD2A2/PjNWhsdKfAxivsW40lTCVS3BVN/CAZH0Cowvzhtakn+yNutgjp78GzbSAKYIwRvV2VuZjglzK13c7XFKlCJhbH3KQID81xAdAW/JHwlr2TgsTGyy4vae4tSC54fijmiksB5Po5mYjQVEwKfZsLNelfQRNBmdlJAnYUZ+iGcK8/LusgW7tQO2BAFInmZWiuYQ+J8aZZqyV/MVMjpXJJ3NgeDuAHGrgyTyS07S/oU4ouw8RJmHepCo51jEEdt2T3Dt4HQd7M99qrU0Gs10Xey7Dc7ufKOqx3Ij8xdMlsBJ8CIgCLzgmIbq0DkIpWNz/m4i0ekmTj9njrtWYsTIh2qAjdMS+i1lhnOaUO+Fq5Ze8QOZS7C+Vfe0Lj3VUTbND6p8+pEfrmrbWUZ721c4A4Q97uA5emgGqtWaWTPy5h9l1eOzfGilv8R3y975iQgDMSo7Zfk7TuZLyi60U3EqoycwMZpgBqbh53cjVg==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-4.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-4.exe /rawdata=tw37QcYb58YcPCNo3Ywzy3gNcG7mNjj4gQ9g8PgytL/VeJPmyH1VoUO2P4syYmRcnCsnKD7qldp8k4j+CzRTX4gt32HAxfH891Cm09KyDRJiNMq5l7VFk0wCk4uEfZ+hcgY0G+/3jA251SYaus0giz2Azzi/as68X7xVFTbnSwZa+PY36lFmW5Fi/7mmsVoEzPCqOUiIaCyQqzbtpDNxoMs0ePskGLX5cxMLhvP2P+woD6eCh+ZXlJqunmkjE7UoSfhwQLIiNvuamkaOSFy9Hz3XfxGOfxwd65mLBTSO3DVrw9j4j36bkP+6Zlh+Muxq5AD8PyrrfY0BFLRP6uhyAo6+gGQ9iuatGuHNnxUCWlb+YEbWHvqnY+Dtvi9J16saVvwiroccrvGYS4ktRWxlSoGc/+LTBzEHav+j3tFhHbhX+9/JK7aYv2DsrFgw/qFIT/DnhrHXsQvYwqv0OONbrdGYQ0uBuk8XnUjWv651yHS2aub3rj7HtOdWSA7o6er/k+9elN3okSwGkp0LIOIQFRHqK7InWqBdeLCvrgR5/L7phhNwMxeoC2fYr80miuDiZo2MqDvEXiboCL9A9T0lQv0sHYIzW3x2/VrKc3NbmZb03gkU/oSGdtBpY90MdsXWcI/OJO7iCqMYpIE/mHRWNaTyEuPEFj3Ch0RwvTKz0EsXZ93uo3sfQvNu1Rl5Un9Xab+L63Zwupvmb9MGzPbuLp2tUCrjUt8a1fBwCo6DhxW/oVFtjz7YkkO1Jrz6E8+YQ1toyMWiomRn3c7vnAu21v4VOoC09hgqNL8g7msMqn7KHkWp1Y/zgmxueVMnGHyLTnR6hj0tjSChaOp7TrWXCWzkrTTdMMS1hKkdatsMHSkMvikLPSvwg8R/p0V4pHoeJgKskz0VmHtDdWinKlLRQ7kpRiRySjDO5z7iNAW2hwqjSAgBS/FagLBcuTIP1SsH0ZALmTIzIoLOLZZ/mYrOsUJaos2pessHEqs4CMvqnoXDs0i4KugEjvsCXDus4wkYwLW+3uhSTv7QhE5DeprsL4cribJEZ2LMYgsiZUiGjdJgq0Nx1YlEsMMAjxwsYNtNPpnoaz3PEhrUHrA9Do4NKN8znqXdy8EAaSvxcYrs7LSfX7bRdziTwN/lsO2/K7wckp1G4zB77/lM9aI65CAtL+OwQxWN0FbJ264gIVB9t4IquJmyWtTXhygBFP5PG3zeDsrXmMV0DKlTW3ETBFL40FPSdC8D0Kvf1xCx76Ldoj9DjMVptOf1qT3D+jZsm2yOKxDjBdUOFtsZ/ZrRXUfL0HN2xVCFZnY75k6yG3gDUxB8xV+jPfdhYfvzhCnZgtSRY16KgWCjwuB+4KyAKqlfPw+2HM0Aft+c5PzuiyNfIzih//ZQQI/9YwP5AoHmSQdKpJaNKK7BfTuSsHlqTOeQxq/UywQCIs2Kz+pRkx8XAWj+L9pffgcBElvnTUGsE+z5ojb+qZd99ePX5HNmZPI2bDcpged5Zl6/fsQide3ieXIEB6Byqw5fF+JbyMbFbiqyFdAldS3901qU972hnD6CR4PV1n9mfU6k2b3pPQkZ+vsu6XS6M2krnYWHm56slpheRUN0LGLN/OE5L5VlszOPLIItgw6cUzR4GUYBOyqSWFsLAmqdEqvjEnxpnbVcHlpc6v0n5GyybwvEFOafsW6O5Wz9XIcQ8vPcVndIIQw7luR15KXmoXwPAYwKQRBfjXQAp4P3sSGbZ4Zn3ZaIZZm3msFde3AeDMmA4jpIu4heTMOmFBFw4wUezTd+SERijkbNzhSpzC3KT0UlO6tl17OYEf6wI0siJ6WYzB+LV09OtiGcvG1WZ3fjyeolphakbf8oAn6AMg78it0UAdBPqqzjIA==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-6.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-6.exe /rawdata=MyIFC1ve4f21pb/dR3Rn2DqqKpZh/Bi7BCALsrMa7xG3iDXHPMLaECu50ASzJxi/J1kJjB/+B6ZkVK2Iy/MmOJ6fu7ge2rA1Kt8Tw7mIi9AkzdEwvLVpb2RzXqoZLyby8tpE1wLnc4nqMP1WhbJVJL//IrLHEUa2oeo+uvgRWAqSIY/FuTe5daTNbThE649QuElcifI7SsnEXJPnyXsnMWtlJ4YWBLu5LXLL42BJ79a88/TUoDwEAz+yiuBkUK7mp1fc9YRTSg4J29zbtl4O0+6595bC6dnh0Lr20ikSN+ipMptNayYW24gywJUu3ziz0Pz4xIAR7iUWQp+k4rKvm1/gr72RUqzEk2C5UsNEfnrposCeHINw8gMd+00Fn1EzcbDyS1qcNxkF1G/qVVrvmpafGoO2QzUTEqOj+QVaSrR8UWXfR4CX7oU0OKu2yb65+iGX+iH7Wdp35CzmO0WpGkZbqbf4dU4FPuNqmi04skdNJTlAoz/K/Y6vTBv0VjMLRVS/B5eUWEtYKt6l+YJzMcfOIqPfZORRhvPRITfZoSwbvYfYJT6UQSWyLvaTC4Sdpg9CfOM3KIJHoYcq2KJEHhivYrkgyBBnKivHO8mwyHdr4w4E6TMWJFLzRH956dOZEBhRV8bHWiWwqEcOxBfCrlwmBnkjM2hqJRXTTk2q0a614914IQnuMud9lk3aqJmnqnWQdJW5lBpdJiH7/kcAhhLD5ie/58nXubb6+uOzz5osRXUcT3vsmSoPo2SZZzxc64Y5TOBVuHb1jOANnrHUSJ+kwq0R7cmcubhazTzjngxiwp0Hgy64jljJfcTcJPpL46l4VRrqJhg+rduBhVVD74ummhU1A2H2WRu1he3kxJd+FO3QqJJH/6WINRDcBI9Kp3OexUubzpgy+KbLLJrx3yYnvT2GdzsR803Sc2KW8pa8i7MckjaXxnggLjtitO0BRELw/eXoVqji24CDrwhmTbtgizR6HwCOGponRRDTGWlN+aBqI+1ozDVDhG08Bva4dB77oYLOe80tnK4R/gS67DNf5Dmwxo8UHp/ZA3M5XsVaxEl3hZS1eH2LkX0wnsTv2y96c+F6AkL8e/7BqHVd+beRF4mADfJxp6EVCDvVB4zDqZywkJMdTWafJVrC+3UFPYMwj5Wxw0Bel6x8lDUxUJ+RN+HrxWTlsxTbWA2gqvVsN7TtFV+/uuLDVCvgJBHRY7i2CO8Am189haL1PE6SGJfo/JU+3LoCMpa4/PC3l4V1qz8BBJiC+VLA6Ir0GvGNDMfM54H4ZFjZ2QU0Rr/reirEWIjqecii0DK1RFtFHKHLw+pQwMA9ohKHKyOaTl3nBcOdiMeMVfW00CwAEjW+IWfxgsRPn7MKOH01G9MAyBOTxxRe01WCPJhBALmZByCHbvSyaR+Fc6Hg4YbRtNor99k7XsBBhnL09U/keA2Tv6S/LkByc8izJnVcqnDSd3fuA7vqhK2rCCL9TBXwSKU8JOkuoJaqyyOACLHUfiAjSef/XV2chldNwq5xxHWc3Oihb7u7U0JVBQFe9EwlrNh/Wba7SboRxhvIlNliNdtgo4xFEo++uzpjPiTg52Z7Lsc1vTuACqD/ZOMaPMjmjDkEP5yNAE3TNaiSCheIuudCN5LsX5S9Xbnlw020i0IF6nddPIUtl+M/CUNPDnHPBwHrhQMx4PYRcs5dEjz/9wZtAJF8uak7/6ugdTbdmt+RK+E1404W1V5fY776w9OGKslHbxzd1fRaNjJa/J1xZ9mYb0owFlk8gGYOOjAr1690lJJKZVIMxPujJiuTpDnAEY8q7vWuYpmLFO2kXoajI05Akp4Oyfq1+vG7ML8eNuiOFxwJggjUOSUQGlS6QacW2Cu6kQ==
C:\Windows\tasks\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-7.job - C:\Program Files (x86)\GoHD\1a27847f-91bf-4f4a-9f6e-c8a687e76aa8-7.exe /rawdata=yBXhCAlu2cALWig39dCPUvnuB94Yjyey6e3FQpYeyj3shHg3nx76gKaqTDzX13SRneE1lfBT7o2//V+aMK8AHdBr7jJptRRsK51iS3NugCtU5PKcLU775oNadUAp28M2ucQwoFW7/Oxvst4l1yMd7gZqR2rRi4wOOl4jYGCYqhwdU92SL/uG4D0vANetFc3nAnRv4HM7/xhnBP0Tm8EIHgZM8+DTjvLUfSANZDcyXjUzM1DzBC/tRmOHaL0jHH2T/1hpNU40Pa5jW7lPG5FlyHCpwhvrPS+kAR3vwM0F2eFo9AAeWH5lloTGp1FK2M19BcSXSZe0rFsFmnMW6gMJ7Kic7gO8Tv+2/+iegF6XrYangm2mqePYxAhREEajNcecv/tiBnlklFpPXhDXl6vx9tBVJJTTuECY+v7Xet04oFNJ/pfyDjlRVLljKO4By0TNZo0geoJaHcF0jistQlGMucDrIm9XSvmWO4nAU2119JKkc/CeQSlpIGRn2dxXfcTej8+l7m1yovC7cyAijGWyn94V9as6IaQ3pFrN3n/evTpb8J0BB1V8vOPcXgwYGmi4sVgusvVhuSOHtwLQ5bFOKOjeNfMtLkBdy/i3oi8wdx4E2RquFVsNM6fn8x/I+1KFl+mhqpLky3muH364EnXVmOz1ILK1xs4+aFEpNaFO7+ZXEXWUBelCTxOkLl+Ix/it9XGKFUAoYEFzaq9+7sWoTrTojJB2PsRHmrHXmV9YIQWVutlxR/yzVycK/UIGV4AQqSIymWwHRG3bf4mRwVTign+pL+UbndcoQ/D6tTeXsqvxLOPa3nBBhrKPTnhzYSJPX0OcPB+GXxQfpiLkZun80WELhrOn0Pk1vgcA7pXFYzd4AVzcv158Fktbs35yZXz2NhRPLn/DNpYXhMN4l0uI6G8IKp1jHuGUDgVHRfM27AxRpoLBZj3GpyaoYg3m9dMQCLifzW7jzaVC1nGiD21PK9wB9o/SZ8Ffbe2zH4vpD0jhB56Z78Y2mbvqrD5c1i3OHw1eLwXiAXhUpvd8torhdS4057Rk8sFQEmpoOlR5oo49DMRLitChwQtA3oLMFGNNYCYKwweN2oXoBARP2n0NjZkA0yWMgIm9diTcI5XXssoAmHrr9qnu5R1SvBP7qc65gzVo3QdsLXSrniX2dTc4ba4Tvq85TxZg8w6jNc2b3NQ276ZyW+97yo9KbRpPHiXqKrQ25fPP+jbvhniU+RXZKAeJvFghX2eyhY8BV4r16tGDpV7GPiB+EtU4fQY5GDNDcqvfmovZ2jGe2MyBjFsvSsG64YpoQYApyBbY8KvJuSyI8Z0VWGoViMDGkdo1CttYlK3Lwdxa13lfxNMeK0qBKYLMaE/3yDbDU8iRbwhfqctDU8DjEtBnE5PXYFeeRKkr8g/Y/Sx0Nsg5DBqNnI7pCWC2QNcMz/R1lL2bXsNjNJaNR8M3QmblurjWzFLKrnkkLIoBkURVwumjUytLB5RBeH8d2hPlQ+1EWRzXPqkP87hyFzcIt3iiWPqZu0HMYkVlZtvD62+IHt9QCn4Ok5YIrD+v1XGBKu2W11vhHv3/0g3fWlySheo6s+7wR1k9bU+yMS7EfgpKjkTl99dbRO8cmAqEmiebf+oaHywsCtqbgd/C/DhLpWaXB5ZqIo3+neEEUvpx9OIEdoSPt8lKwbxG8+LtmTWNp133cFw87N+SMc4=
C:\Windows\tasks\48_dresses_notification_service.job - C:\Program Files (x86)\48 dresses\48_dresses_notification_service.exe /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='48 dresses' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428343649' /runfrom='task' /brwtype='notbg' /postponedhours='6'
C:\Windows\tasks\48_dresses_updating_service.job - C:\Program Files (x86)\48 dresses\48_dresses_updating_service.exe /campid=2913 /verid=1 /url=http://cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=48_dresses_updating_service /funurl=http://stats.buildomserv.com
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /yYEHolYG /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-2.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-2.exe /DSIUmxCpW /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /GQTowmm=11111111-1111-1111-1111-110311551110 /aZJRhuSIm=ff /mZOxglpw /LWpHklfn='http://update.clientstatsservice.com/ie ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-5.job - C:\Program Files (x86)\iWebar\74275bdc-96a9-440e-8569-aaf52624e348-5.exe /yochGqlS /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /MLIMI=http://ipgeoapi.com/ /jXJieqAhe=http://update.clientstatsservice.com /HiJzz=2 /OmnqxP=http://logs.clientstatsservice.com /LWpHklfn='http://update.clientstatsservice.com/up ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-6.job - C:\Program Files (x86)\iWebar\iWebar-novainstaller.exe /UYfdKYRRC /rgtdh=task /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/no ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\74275bdc-96a9-440e-8569-aaf52624e348-7.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe /dyqGeJy='iWebar' /hhBQjVc=35510 /JGSkT='000170' /YTHbNkmX='0' /ciHdRpSZ='eyJkYXRhIjp7ImRhdGUiOiJFNVJ6YWRrY0FnMCxjNzEwMTE5Yy1kNDNiLTRhNjMtYjBiMC01ZDBmOGQyYzMyOTEsIiwidW5xIjoiYzcxMDExOWMtZDQzYi00YTYzLWIwYjAtNWQwZjhkMmMzMjkxIn19' /rluRGxYUp=C69B13D5DEF8437AB20BE081468DF04DIE /WJOPj=3ffe7ff34d99b3a01e1d230d2397627b /WMSqXF=1_34_05_12 /iFUNYeEm=1.34.5.12 /CRFsAs=1401209893 /xqzkUn=http://stats.clientstatsservice.com /ZYlkDu=http://errors.clientstatsservice.com /PxGcIm=http://js.clientstatsservice.com /aZJRhuSIm=ff /cHuOpTi /BrMsvOZoV='nova' /LWpHklfn='http://update.clientstatsservice.com/no ... pdate.json' /rgtdh='task' /mxrJU=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-1.job - C:\Program Files (x86)\Object Browser\Object Browser-codedownloader.exe /GiFbEM /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-2.exe /LRWiRR /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /YqoVZF=11111111-1111-1111-1111-110311281150 /bwgrJeg=ff /tAsDXB /fuiKVYjh='http://update.clientstatsservice.com/ie ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.job - C:\Program Files (x86)\Object Browser\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-5.exe /PKXeqKRC /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /ALJkDN=http://ipgeoapi.com/ /TDNiHP=http://update.clientstatsservice.com /EVUDo=2 /mHmtsuHV=http://logs.clientstatsservice.com /fuiKVYjh='http://update.clientstatsservice.com/up ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-6.job - C:\Program Files (x86)\Object Browser\Object Browser-novainstaller.exe /LlhaGyRW /XIFwaOI=task /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/no ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\e659c2f6-b592-4eb3-89e8-8b6d7e4656ed-7.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe /OTDrBJeO='Object Browser' /FiNnKVw=32850 /hiGfn='000037' /GBYJEqn='0' /DlhsjeRKG='0' /Cpqhya=95BD3BA621924835A58B71D87BA96369IE /nMtcQaJf=cb2e83946a499d72683b6652ecad71d1 /XPEVjTXx=1_34_05_12 /eQsHsX=1.34.5.12 /rZLnUVXZZ=1401721098 /fmdZyhSkc=http://stats.clientstatsservice.com /fhGWIh=http://errors.clientstatsservice.com /LElwNE=http://js.clientstatsservice.com /bwgrJeg=ff /frXtlSs /uDfjTU='nova' /fuiKVYjh='http://update.clientstatsservice.com/no ... pdate.json' /XIFwaOI='task' /xGDsvkK=''
C:\Windows\tasks\ext_coupons_notification_service.job - C:\Program Files (x86)\ext coupons\ext_coupons_notification_service.exe /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='ext coupons' /appid='73143' /srcid='2913' /bic='55b6ac250ef91b7ff3cd14797aa8fff7' /verifier='65f02db9100a8a1339b0bcdd940ae6f1' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1428043279' /runfrom='task' /brwtype='notbg' /postponedhours='6'
C:\Windows\tasks\ext_coupons_updating_service.job - C:\Program Files (x86)\ext coupons\ext_coupons_updating_service.exe /campid=2913 /verid=1 /url=http://cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=ext_coupons_updating_service /funurl=http://stats.buildomserv.com
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\HPCeeScheduleForPavel.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForPavel (null)
C:\Windows\tasks\LAUNbFbBPC16B2.job - C:\Users\Pavel\AppData\Roaming\LAUNbFbBPC16B2.exe --c=oMAFrD801AXmNaTf2riQm64CQg/sJ45+zqDEmk+BMX31uMmiUZBNqQ749251lFdnw1tOy7sjmguPj2juc/7uhDhO0MCV7k09iPMdIdCXgAQQSRiqYbe3BZjcFMIHrZXQOJH+mvAQrO/QCea7GIEywDjdokLWukPkt+WUoAdG/PiUTwxJtdC5CaFHDT1NfhHC7lKsvJ4Qu3tadZN1hEN+YT7FXRwaqXmZyz2ZYyRRXdI/JxGbEiktTGUBXcmp/Wec5piHfB1xaXRb3Lm6/ul8w27Gzk/Tnd8/DEMOPu+Pttkv3VXOsYPeR4Z9HVgOj7O3YTEnN/kE15Jb03ajGiksmQ==
C:\Windows\tasks\RegClean Pro_DEFAULT.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -default
C:\Windows\tasks\RegClean Pro_UPDATES.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -updatecheck
C:\Windows\tasks\SpeedUpMyPC Maintenance.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -m
C:\Windows\tasks\SpeedUpMyPC Startup.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
C:\Windows\tasks\SpeedUpMyPC Subscription.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -l

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-06 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Pavel\AppData\Roaming\Browser Extensions\Coupons.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
LuckyTab Class - C:\Program Files (x86)\XTab\SupTab.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-06 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-01-06 170264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-01-06 398104]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-01-06 440600]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-01 2832168]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2012-01-04 1425408]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Browser Extensions]
C:\Users\Pavel\AppData\Roaming\Browser Extensions\CouponsHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
C:\Users\Pavel\AppData\Roaming\Search Protection\SP.EXE /autostart []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefault]
C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [2011-12-19 44880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedItupFree]
C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YTDownloader]
C:\Program Files (x86)\YTDownloader\YTDownloader.exe /boot []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-01-18 343168]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2011-12-05 291096]
"Easybits Recovery"=C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe []
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2011-11-29 576568]
"HPOSD"=C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [2011-08-19 379960]
"HP CoolSense"=C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2011-08-26 1342008]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1425\jsdrv.exe []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2010-03-12 49208]
""= []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-20 5515496]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-01-06 429056]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-05-24 16:47:47 ----D---- C:\Program Files\trend micro
2015-05-24 16:47:46 ----D---- C:\rsit
2015-05-20 19:24:49 ----A---- C:\Windows\system32\aswBoot.exe
2015-05-20 19:24:20 ----A---- C:\Windows\avastSS.scr
2015-05-18 21:52:11 ----D---- C:\Program Files (x86)\GUM30A3.tmp
2015-05-18 21:52:11 ----A---- C:\Program Files (x86)\GUT30A4.tmp
2015-05-14 03:03:24 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 03:03:24 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-05-13 10:37:42 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-05-13 10:37:42 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-05-13 10:37:42 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-05-13 10:37:41 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-13 10:37:41 ----A---- C:\Windows\system32\iernonce.dll
2015-05-13 10:37:41 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-13 10:37:40 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-13 10:37:40 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-13 10:37:39 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-13 10:37:39 ----A---- C:\Windows\system32\urlmon.dll
2015-05-13 10:37:39 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-05-13 10:37:38 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 10:37:38 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 10:37:38 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-13 10:37:37 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-13 10:37:37 ----A---- C:\Windows\system32\iesetup.dll
2015-05-13 10:37:37 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-13 10:37:36 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-05-13 10:37:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-13 10:37:36 ----A---- C:\Windows\system32\vbscript.dll
2015-05-13 10:37:36 ----A---- C:\Windows\system32\iertutil.dll
2015-05-13 10:37:35 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-13 10:37:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\jsproxy.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\ieUnatt.exe
2015-05-13 10:37:35 ----A---- C:\Windows\system32\ieui.dll
2015-05-13 10:37:35 ----A---- C:\Windows\system32\dxtmsft.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\jscript.dll
2015-05-13 10:37:34 ----A---- C:\Windows\system32\ieframe.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\wininet.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\jscript9diag.dll
2015-05-13 10:37:33 ----A---- C:\Windows\system32\jscript9.dll
2015-05-13 10:37:32 ----A---- C:\Windows\system32\msrating.dll
2015-05-13 10:37:32 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-05-13 10:37:31 ----A---- C:\Windows\system32\mshtml.dll
2015-05-13 09:54:25 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-13 09:54:25 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 09:54:25 ----A---- C:\Windows\system32\schannel.dll
2015-05-13 09:54:25 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 09:49:23 ----A---- C:\Windows\system32\services.exe
2015-05-13 09:49:11 ----A---- C:\Windows\system32\UtcResources.dll
2015-05-13 09:49:11 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-05-13 09:49:11 ----A---- C:\Windows\system32\ntdll.dll
2015-05-13 09:49:11 ----A---- C:\Windows\system32\diagtrack.dll
2015-05-13 09:49:10 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-05-13 09:49:09 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-05-13 09:49:09 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-05-13 09:49:09 ----A---- C:\Windows\system32\tdh.dll
2015-05-13 09:49:09 ----A---- C:\Windows\system32\kernel32.dll
2015-05-13 09:49:09 ----A---- C:\Windows\system32\advapi32.dll
2015-05-13 09:49:08 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-05-13 09:49:07 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\wow64.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\winsrv.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\tracerpt.exe
2015-05-13 09:49:07 ----A---- C:\Windows\system32\srcore.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\sechost.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\msv1_0.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\logman.exe
2015-05-13 09:49:07 ----A---- C:\Windows\system32\KernelBase.dll
2015-05-13 09:49:07 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-05-13 09:49:07 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-05-13 09:49:06 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-05-13 09:49:06 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-05-13 09:49:06 ----A---- C:\Windows\system32\conhost.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-05-13 09:49:05 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\wdigest.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\typeperf.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\TSpkg.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\sspicli.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\smss.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\rstrui.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\relog.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\ncrypt.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\lsass.exe
2015-05-13 09:49:05 ----A---- C:\Windows\system32\kerberos.dll
2015-05-13 09:49:05 ----A---- C:\Windows\system32\auditpol.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-05-13 09:49:04 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-05-13 09:49:04 ----A---- C:\Windows\system32\diskperf.exe
2015-05-13 09:49:04 ----A---- C:\Windows\system32\csrsrv.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 09:49:03 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-05-13 09:49:03 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\wow64win.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\wow64cpu.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\sspisrv.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\srclient.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\secur32.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\ntvdm64.dll
2015-05-13 09:49:03 ----A---- C:\Windows\system32\credssp.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 09:49:02 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 09:49:01 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\user.exe
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\system32\apisetschema.dll
2015-05-13 09:49:01 ----A---- C:\Windows\system32\adtschema.dll
2015-05-13 09:49:00 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-05-13 09:49:00 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-05-13 09:49:00 ----A---- C:\Windows\system32\msobjs.dll
2015-05-13 09:49:00 ----A---- C:\Windows\system32\msaudite.dll
2015-05-13 09:47:47 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 09:47:47 ----A---- C:\Windows\system32\win32k.sys
2015-05-13 09:47:47 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 09:47:47 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 09:42:31 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 09:42:31 ----A---- C:\Windows\system32\InkEd.dll
2015-05-13 09:36:29 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-13 09:36:29 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-13 09:35:13 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-13 09:35:13 ----A---- C:\Windows\system32\poqexec.exe
2015-05-13 09:26:52 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-13 09:26:52 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-13 09:26:52 ----A---- C:\Windows\system32\sdbinst.exe
2015-05-13 09:26:52 ----A---- C:\Windows\system32\apphelp.dll
2015-05-13 09:26:52 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-13 09:26:51 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-13 09:26:51 ----A---- C:\Windows\system32\shimeng.dll

======List of files/folders modified in the last 1 month======

2015-05-24 16:50:41 ----D---- C:\Windows\Temp
2015-05-24 16:47:47 ----RD---- C:\Program Files
2015-05-24 16:47:01 ----D---- C:\Windows\Prefetch
2015-05-24 16:35:08 ----D---- C:\Windows\system32\Tasks
2015-05-24 16:34:44 ----HD---- C:\ProgramData
2015-05-24 16:34:37 ----SHD---- C:\System Volume Information
2015-05-24 16:27:26 ----D---- C:\Windows\System32
2015-05-24 16:27:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-05-24 16:26:41 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2015-05-24 16:26:23 ----D---- C:\Program Files (x86)
2015-05-24 14:07:20 ----A---- C:\Windows\SYSWOW64\log.txt
2015-05-24 14:06:07 ----RD---- C:\Nepotřebné
2015-05-24 14:05:24 ----D---- C:\Windows\system32\config
2015-05-24 14:01:22 ----D---- C:\Games
2015-05-24 13:57:19 ----D---- C:\Program Files (x86)\Opera
2015-05-24 13:55:19 ----D---- C:\Windows\system32\drivers
2015-05-22 21:49:39 ----D---- C:\Windows\winsxs
2015-05-22 21:49:08 ----SD---- C:\Windows\SYSWOW64\GWX
2015-05-22 21:48:56 ----SD---- C:\Windows\system32\GWX
2015-05-21 18:10:01 ----D---- C:\Windows\SYSWOW64\en-US
2015-05-21 18:10:01 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-05-21 18:10:01 ----D---- C:\Windows\system32\en-US
2015-05-21 18:10:01 ----D---- C:\Windows\system32\cs-CZ
2015-05-21 18:08:19 ----D---- C:\Users\Pavel\AppData\Roaming\systweak
2015-05-21 18:08:19 ----D---- C:\Program Files (x86)\ext coupons
2015-05-21 18:08:15 ----D---- C:\Program Files (x86)\globalUpdate
2015-05-21 18:08:09 ----D---- C:\Windows\SysWOW64
2015-05-20 19:24:47 ----D---- C:\Windows
2015-05-20 19:23:34 ----D---- C:\Windows\Tasks
2015-05-15 01:09:51 ----D---- C:\Windows\rescache
2015-05-14 03:57:54 ----D---- C:\Windows\Microsoft.NET
2015-05-14 03:57:08 ----RSD---- C:\Windows\assembly
2015-05-14 03:42:33 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-14 03:42:31 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-14 03:39:39 ----D---- C:\Program Files\Internet Explorer
2015-05-14 03:39:36 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-14 03:39:31 ----D---- C:\Windows\AppPatch
2015-05-14 03:39:29 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-14 03:39:21 ----D---- C:\Windows\system32\DriverStore
2015-05-14 03:39:20 ----D---- C:\Windows\system32\drivers\UMDF
2015-05-14 03:18:48 ----SHD---- C:\Windows\Installer
2015-05-14 03:18:47 ----SHD---- C:\Config.Msi
2015-05-14 03:18:18 ----D---- C:\Windows\system32\MRT
2015-05-14 03:07:47 ----A---- C:\Windows\system32\MRT.exe
2015-05-13 09:26:38 ----D---- C:\Windows\system32\catroot2
2015-05-12 07:39:05 ----D---- C:\Windows\system32\NDF
2015-04-28 17:05:43 ----D---- C:\Program Files (x86)\WarThunder

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amdkmpfd;AMD PCI Root Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmpfd.sys [2012-01-18 31360]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-05-20 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-05-20 272248]
R0 hpdskflt;HP Filter; C:\Windows\system32\drivers\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2011-11-29 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3hcs.sys [2011-12-05 16152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-05-20 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-05-20 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-05-20 442264]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-09-02 50976]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2015-02-08 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-05-20 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-05-20 89944]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-05-20 137288]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\drivers\Accelerometer.sys [2011-05-13 43320]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-01-18 10729984]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-01-18 328192]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2011-11-03 134696]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2012-06-01 4746304]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2012-02-11 80384]
R3 btwampfl;btwampfl Bluetooth filter driver; \??\C:\Windows\system32\drivers\btwampfl.sys [2011-12-03 620584]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2011-07-07 167976]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2011-06-23 178728]
R3 BTWDPAN;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\btwdpan.sys [2011-05-21 89640]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2011-02-14 39976]
R3 btwrchid;btwrchid; C:\Windows\system32\drivers\btwrchid.sys [2011-06-23 21544]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2012-01-06 14652768]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3hub.sys [2011-12-05 355096]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\drivers\iusb3xhc.sys [2011-12-05 785688]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\drivers\HECIx64.sys [2011-11-10 60184]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2012-01-04 535552]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\drivers\SynTP.sys [2011-10-01 393264]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 cpuz134;cpuz134; \??\C:\Users\Pavel\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [2011-09-22 258664]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\drivers\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-01-18 235520]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-05-20 343336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2011-12-05 1084192]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-11-29 34872]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2011-12-08 607456]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2011-12-16 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2011-12-16 161560]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-12-16 277784]
R2 ssinstall;SInstalátor; C:\Windows\SysWOW64\ssins.exe [2015-02-02 2324216]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2012-01-04 311808]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-12-16 363800]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15 268464]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-27 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-04-21 114688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-09-06 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: prosím o kontrolu logu

#2 Příspěvek od altrok »

Krasny den Vam preju :bye:


:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).


:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi

:arrow: Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm
  • spustte jako spravce
  • do velkeho okna zkopirujte script uvedeny nize
  • kliknete na Run script
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi

    Kód: Vybrat vše

    autoclean;
    emptyclsid;
    emptyalltemp;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

SkrdletaP
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 24 kvě 2015 15:44

Re: prosím o kontrolu logu

#3 Příspěvek od SkrdletaP »

# AdwCleaner v4.205 - Log vytvořen 25/05/2015 v 15:22:02
# Aktualizováno 21/05/2015 by Xplode
# Databáze : 2015-05-24.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : Pavel - PAVEL-HP
# Spuštěno z : C:\Users\Pavel\Documents\Downloads\adwcleaner_4.205.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\AVG Secure Search
Složka Smazáno : C:\ProgramData\AVG Security Toolbar
Složka Smazáno : C:\ProgramData\ShopperPro
Složka Smazáno : C:\ProgramData\IHProtectUpDate
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
Složka Smazáno : C:\Program Files (x86)\globalUpdate
Složka Smazáno : C:\Program Files (x86)\ext coupons
Složka Smazáno : C:\Program Files (x86)\48 dresses
Složka Smazáno : C:\Program Files (x86)\Common Files\AVG Secure Search
Složka Smazáno : C:\Users\Pavel\AppData\Local\Temp\apn
Složka Smazáno : C:\Program Files\PC Optimizer Pro
Složka Smazáno : C:\Program Files\Reimage
Složka Smazáno : C:\Program Files\Common Files\ShopperPro
Složka Smazáno : C:\Users\Pavel\AppData\Local\globalUpdate
Složka Smazáno : C:\Users\Pavel\AppData\LocalLow\iWebar
Složka Smazáno : C:\Users\Pavel\AppData\LocalLow\Object Browser
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Systweak
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Uniblue
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
Složka Smazáno : C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default\Extensions\z5cC9@gmail.com
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal
Soubor Smazáno : C:\Windows\Reimage.ini
Soubor Smazáno : C:\Windows\SpeedItup Free Setup Log.txt
Soubor Smazáno : C:\Users\Pavel\AppData\Local\Temp\DriverDetective.exe
Soubor Smazáno : C:\Windows\System32\roboot64.exe
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\LAUNbFbBPC16B2
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\speedupmypc.lnk
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Soubor Smazáno : C:\Program Files (x86)\Mozilla Firefox\my.cfg
Soubor Smazáno : C:\Program Files (x86)\Mozilla Firefox\browser\defaults\preferences\my-prefs.js
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_mail-bomber.en.softonic.com_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_mail-bomber.en.softonic.com_0.localstorage-journal
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.istartsurf.com_0.localstorage
Soubor Smazáno : C:\Users\Pavel\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.istartsurf.com_0.localstorage-journal

***** [ Naplánované úlohy ] *****

Úloha Smazáno : LaunchSignup
Úloha Smazáno : RegClean Pro
Úloha Smazáno : RegClean Pro_DEFAULT
Úloha Smazáno : RegClean Pro_UPDATES
Úloha Smazáno : ReimageUpdater
Úloha Smazáno : SPDriver
Úloha Smazáno : SpeedUpMyPC Maintenance
Úloha Smazáno : SpeedUpMyPC Startup
Úloha Smazáno : SpeedUpMyPC Subscription
Úloha Smazáno : YTDownloader
Úloha Smazáno : ext_coupons_updating_service
Úloha Smazáno : ext_coupons_notification_service

SkrdletaP
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 24 kvě 2015 15:44

Re: prosím o kontrolu logu

#4 Příspěvek od SkrdletaP »

Děkuji za kontrolu :) :) :) :) :thumbsup: :idea:

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: prosím o kontrolu logu

#5 Příspěvek od altrok »

:arrow: Haveti tam mate stale spoustu, takze pouzijte jeste zoek viz muj predchazejici prispevek :)
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

SkrdletaP
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 24 kvě 2015 15:44

Re: prosím o kontrolu logu

#6 Příspěvek od SkrdletaP »

Ano děkuji a co nejdříve vám sem další log odešlu

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: prosím o kontrolu logu

#7 Příspěvek od altrok »

OK, jak budete mit cas, ozvete se a poradne Vam PC procistime :)
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

SkrdletaP
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 24 kvě 2015 15:44

Re: prosím o kontrolu logu

#8 Příspěvek od SkrdletaP »

Zoek.exe is still running.
Do not start any browser windows, they may get closed automatically.
Please wait! This window will close when finished.
A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: prosím o kontrolu logu

#9 Příspěvek od altrok »

Zoek Vam v anglictine vzkazuje, abyste ho nechal bezet - prelozim radky logu:

Kód: Vybrat vše

Zoek stale bezi.
Nespoustejte prohlizece, protoze muze dojit k jejich ukonceni.
Pockejte prosim! Toto okno bude ukonceno, jakmile zoek svou praci dokonci.
Nasledne bude otevren vysledny log nebo jej lze najit v C:\zoek-results.log
Pokud jste jej ukoncil, spustte jej znovu se stejnym skriptem :)
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

SkrdletaP
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 24 kvě 2015 15:44

Re: prosím o kontrolu logu

#10 Příspěvek od SkrdletaP »

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Pavel on st 27.05.2015 at 15:45:28,23.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Pavel\Desktop\zoek.exe [Scan all users] [Quick Scan] [Auto Clean]

===== Runcheck 15:45:46,08 =====

--- Create Environment Variables 15:45:48,51
--- Checking Input 15:46:04,46
--- AU AppData Check 15:46:28,25
--- Remove From Windows Installer 15:46:37,90
--- Empty Folders Check 15:49:36,72
--- Registry HKLM Software Check 15:49:36,88
--- Quick Launch Shortcut Check 15:50:50,53
--- IE Startpage Check 15:50:57,75
--- Program Files DB Check 15:51:40,90
--- C:\Users\Default\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Default User\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Pavel\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 15:53:31,19
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 15:53:31,19
--- C:\Users\Pavel DB Check 15:58:52,82
--- C:\PROGRA~3 DB Check 15:59:33,80
--- C:\Users\Default\AppData\Local DB Check 15:59:45,89
--- C:\Users\Default User\AppData\Local DB Check 15:59:45,89
--- C:\Users\Pavel\AppData\Local DB Check 15:59:45,89
--- C:\Windows\SysNative\config\systemprofile\AppData\Local DB Check 15:59:45,89
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Local DB Check 15:59:45,89
--- C:\Windows\serviceprofiles\networkservice\AppData\Local DB Check 15:59:45,89
--- C:\Windows\serviceprofiles\Localservice\AppData\Local DB Check 15:59:45,89
--- C:\ProgramData\Microsoft\Windows\Start Menu\Programs DB Check 16:03:29,69
--- C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs DB Check 16:03:53,51
--- Tasks DB Check 16:04:08,61
--- Downloads DB Check 16:04:17,67
--- C:\Users\Pavel\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\SysNative\config\systemprofile\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\serviceprofiles\networkservice\AppData\LocalLow DB Check 16:04:27,80
--- C:\Windows\serviceprofiles\Localservice\AppData\LocalLow DB Check 16:04:27,80
--- Tasks2 DB Check 16:06:29,29
--- Documents DB Check 16:07:38,09
--- C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\xs9ng2ob.default DB Check 16:07:56,42
--- C:\Users\Public\Desktop DB Check 16:08:01,92
--- C:\Users\Pavel\Desktop DB Check 16:08:12,36
--- Services DB Check 16:08:33,70
--- FF prefs.js DB Check 16:09:16,16
--- Emptyclsid 16:10:56,46
--- Del by CLSID 16:11:00,33

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: prosím o kontrolu logu

#11 Příspěvek od altrok »

:arrow: Dejte log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

SkrdletaP
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 24 kvě 2015 15:44

Re: prosím o kontrolu logu

#12 Příspěvek od SkrdletaP »

Více mi to neukázalo pak mi tento program nešel vypnout vyplo se to až po restartaci asi sem to vypnul dříve jak dlouho asi tak trvá toto čištění děkuji :worship: :worship: :worship: :) :) :) :thumbsup:

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: prosím o kontrolu logu

#13 Příspěvek od altrok »

:arrow: Zoek pravdepodobne jeste pracoval. Proces zoeku s timto skriptem trva cca 30-60 minut. Pokud jste ho prerusil, nic se nedeje. Vlozte logy z FRST (viz muj predesly prispevek) a odvirujeme to rucne :)
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět