Zdravím,
prosím o preventivku svého ntb, kdy do druhého se mi naboural hacker.
Děkuji.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Lenka at 2015-08-05 17:27:00
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 44 GB (15%) free of 286 GB
Total RAM: 2729 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:27:11, on 5.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Bluetooth Suite\BtvStack.exe
C:\Program Files\Bluetooth Suite\AthBtTray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
c:\program files\cmcm\Clean Master\cmtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Opera\31.0.1889.99\opera.exe
C:\Program Files\Opera\31.0.1889.99\opera_crashreporter.exe
C:\Program Files\Opera\31.0.1889.99\opera.exe
C:\Program Files\Opera\31.0.1889.99\opera.exe
C:\Program Files\Opera\31.0.1889.99\opera.exe
C:\Program Files\Opera\31.0.1889.99\opera.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Opera\31.0.1889.99\opera.exe
C:\Program Files\Opera\31.0.1889.99\opera.exe
C:\Users\Lenka\Desktop\RSIT.exe
C:\Windows\system32\UI0Detect.exe
C:\Users\Lenka\Desktop\RSIT.exe
C:\Program Files\trend micro\Lenka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [AtherosBtStack] "C:\Program Files\Bluetooth Suite\BtvStack.exe"
O4 - HKLM\..\Run: [AthBtTray] "C:\Program Files\Bluetooth Suite\AthBtTray.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [cmsc] "c:\program files\cmcm\Clean Master\cmtray.exe" -autorun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GRA32A~1.DLL
O20 - AppInit_DLLs: C:\Windows\system32\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files\Bluetooth Suite\adminservice.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Clean Master Core Service (cmcore) - Kingsoft Corporation - c:\program files\cmcm\Clean Master\cmcore.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update Banana Phone - Unknown owner - C:\Program Files\Banana Phone\updateBananaPhone.exe (file missing)
O23 - Service: Util Banana Phone - Unknown owner - C:\Program Files\Banana Phone\bin\utilBananaPhone.exe (file missing)
--
End of file - 8343 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job - C:\Windows\system32\Macromed\Flash\FlashUtil32_16_0_0_296_pepper.exe -check pepperplugin
C:\Windows\tasks\e2fdd633-023e-4ff4-bd77-024f4b061375.job - C:\Program Files\CinemaP-1.9cV16.03\e2fdd633-023e-4ff4-bd77-024f4b061375.exe 002661 463AB2CC7F764EC8B8CFA81628BB8983IE 71387 1438700753 93-0,102-0,178-288,179-288,180-288,223-288,263-24 CinemaP-1.9cV16.03
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.exe /rawdata=AsEEAD4Hzmn3tqHFLPm5W2JhFdi1fR5vJ+3HEcwzOiKNnymwt8okym0ZG8cWBfu55IMciXSQjWZ2CI7zTco5vuHD7ZR/LS16nwmwKUdrU32VKjNrWiaecb26ADh1Ggr4nD8CfMLVjgl1Ce/piDKLSLq5Ffo6xSIwA3uB84fz5+eFB3SZxctDBia1fyEHcBd/DIP0oDFchkUyovGxbo17MU2rXn/dLPBJFckowiPcdFom+Fn9hbGPo4rtLZhWjwGWQV5F2sURm6P8sLgOJGAgEX39yHb1yY/uWUMITBNsVpKy4mmSwSGuzAJQ14/B3RjXE5PIGI1FoeWA7ayAPIrBlTsNg5Pv9m2JNTwYrmJ/JTp4AQGrfRsag9OkX09E5gmYt2rbJXPZcSQxZybdVj8pRTfhpGfjHRS15oa38/rL4cSI8HFOx57cm5rzPqfLfETI/HSa2e1LS9N5e3q+a3Pdo20fRgNTjX8+SzPcl43720bQSESl2DZVcsXzD4DDVAmauVh18yv+eiJ24hInQYpnhwhyHgeOX/N1nJ4/1iJXm0fXtDT+2NdCpcYwGirhvsk3gIGgxZ0WtvqZvszonBVRxRHWpEdtWJOg3yF9Gj93fqzjsFRZ7jBP9kBsnIrIOqjVZku0m7yoXvOf3tq7Wu0/nsyKAKdJJgBnB+hNcf7pkJunkTl+Ye2MF1DZz+H0E1KLQn1gTffj0wZ2slUil2mEa6hNSxDf/WmtozPau4SmyshE+u85uefcRtWfQBYv03MdfRkKVUzngrjw0nKVXHkUjjRXK98aHEukqYh7y2CtMclrp8fhgH8ZvO7Gm8bJwr4TRXaMXidOSXjTA145EJdT+2fDRhxsYRK8PdQ8Caam3QPc/m7XgYVXW6+E73ukybZ5aRaqrbtGqKsuXSbI1rvOz8Wu6T2cl/koCHL4N/z18pUJT2j+i51kp5VnIYgZfsdqNwWavdVw4W+HvJc8WhT8QY5xdFKaFXvPRFooHIOZlM+icPXqSF9HDTsd/BGGXTqJM0692hYIxzck+M98XBZelGwroQQav0EqR4YDSjSdicGuvoQhG6/Zwa5CPvI44CcyyFjQT+tslmw34vmMtvYOnzsprSsLxi2SH60Et5cxrgv49LH3py6ng8FrdjjNzYGEf5QhsQPrDKAf6RP5jXvDR9v/esSGOIAhROsPFXpJn/IMK8oHSOZFbu8qkz5I9xXDQI4j+8cdbsNqZe20dsMqQtfasEdayW/cwGo5Bu8jINHtXMtF2bvXt4Of3LVDQ5aDWngC6AjHq3ZEQVOsyC0JP9xhbFTWfwyw5NWUFLgW/jeJKDvTRQtqEXFNVMZQaY6/zYtqUfJc3YnTF8ZSkxAwXg==
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-7.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-7.exe /rawdata=UKQjXniniO+OEjJ05kv4aKYrGxWTyajti4dBiJtck+med0t1NH+xR6eqHpBx627CWFRofeVxzKUzfKrl+s3U3wCL2Av033eiiHWKgxuQ4I94mkg4aUsPGZo0l6qyBAo90mt+HBh8gcMpF2j8xqQfLQrO0veZquO38wqUbPpkrIfCpwsqLhB/dwmbZiBMRKD+rR2LTn6Edq//iwS0WTdUU7HX3RpLiJDHUmehse1j5UhihAKnFbEDSyelMgGukTAIOEG3KrdAwyB46OvlySAJMT2Kh5qmlVC7rO4lqpTG68Q+DXgRwVcVNBenTWND42U+MOliFR2MreJJs9sB5Pt6DwBXrs3nb+cfZeRLZ14Dj5l29wBEuQI8bO6rv+cf+iag2LIRnejEBD7XnjM5qOHX2YMdvi8iz9zetdTVz5669G60Mlcr30iNZdjZsE+q+dEo4qogj9mvzvC5DTJefW7YKKNHpI67cdGoNhoOP/zhABWGwFkbLXOOw0HzIsel00Odmn2mgL1yZ8yxQ8sGFtFoY48MfnSNCatJeUyX7WtUv33kI1gcR/GTpgATrJWj2jmwQVdKefqsEkvwMprPRLwpOOYpry7FX7UQgE8QQvNnofMhKUB6rwmeB/etUSdx35nSeTUDyS1mcegbQATY6/wNQSdjy+eV3lQ5sTZXjPqAbTNhbqyY14Q96MgrKcAd2xErHz9ULMIfBXofcUn1HWM8yzgrhCZ6VgmKN730eOLu09fICAL0+EWyLluvVuTTfUGEvkprLoJcTPEvrAlcSmVUJ6eNmtNP3sZ7jtHbIiUo/x6GWGW0amLSV9Fh8L9XT1/s7dQTOdsLHJlH6j4aeqjfibNRMC/A8EvaHtWJPe/5S+tT2jnkj8FjI79JpxeceFKA7RTyR5K5h+K1MqdNwktow6boKAMHGZrBodb/Zd2d3CCuCe8LR9XVBGuPkg6PlQGgvz/pAWt076RVCyW7HKc2d8G1F/teFuHlbX5YpSXfaG6wr3EN57NeKRhxT83nADasNyVCzD0ktJiZDVHrbrFiT52hIJjSWD322x2KCmzf7bJxaIVdfiBPzYLSeL9a0FDlMDtNAIDZynJh/0TkiPAZPeBN0Ruox9zLYagH1TGGO+6jOyko3Crivk/dS7PcTvYu1JA6A6yezESIEhy+8Zkze0a2UfYCI6xiqDDArpXdqwszw3pUgLBARnwKtY0GLmL3RPSjxw6fgWbSD7grgrVOfBdOmkPaNsPTw9NHtR8lBH7m+Yq5uK+Ajgzh2AabvkB8BQHzJfEvFqQrh1aPLL1Dmfcr1mZet5lyylOAMxUkJfx0EyfUIVotl9euhn8ULnNOGPZxDTVid0jmoxDL0F0dxZMYdkiKDsx0JSXz7OxE0zmktvcRQwR7prVSPSA/wZ1ScLh+5EVfsepUJT3tCbdF2rG0mLe2kj27dkOpMQPTqHOYQlU1Dbw09OMY+F6XL2O7Ywx+Q2XsayjHq2yVDQYZuD8FDjvUMMLAhDXAFFH19Su6gHZKyAyh4ic6h6CGsgZE
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-11.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-11.exe /rawdata=h43H8fSM1ZJCGFWgMjq1rJi/dxb+5RUEJZhxh+Wb89haTdz0S23TccvSA1EwnU1pMh3SvGqqfqIB0Ok1E301rb6Cofb2YUyKupG80U6PG9G1903V5J5iE7XWa6alpfx8nHN830SxRGHO8DQXdq7Ivfz8UfzbrmLPDKnh06enuA5udvw11C1JC2dAzrWpAFk+9n9jJIyjrR6TjeY2K6wewGfjayt8Y4iD6m+zJqt7FEzE8nt1K4cAIymVyyXkYI7f4NKvoNYXQRpD0H/oHvqaDxyMlWIndg6zSyoyWU5cJNP2dutFQJ3q+ojSSn63rZt+AfqrfwSBMqNfDuKoDInSdyaiq8WjWToDTys0afeEVlo9CcRrOGbNv4ViK/lfkQl1HK2Mn8/jhWCDvNvN3TkPZMv7Y9IURViOQxczQaueXq78oCyIajb/2kLl9qNC5LBxLyjH/X+EHVCdZ3b9rT7oEob46eigRq31Qr7vwlRU8T4KO8XTw6yyGGQS350Lk4z9Lc+3m/v8F2n5VvRndt6yNivD5ebWtWb4Swx/VU5byCrEV1YDQw5mlQmKSQGHWkPox/yqYISvSYf0SAGSIqVA62Ot/xhjs72EIaNlAMptBXAXB6XevBRr4cR7OMcIF1o9eFuTpsATrSnE0iZpmw3zuzXy3Sd73CJWjar7CTbuSKFcD9I+UZSqLvYw3LRWn3zbauNNzr9pkZzb1ydbtXipi0G1Sbqvp6x+u8i1EVJpq+OhDnx8anvQdYa0fb5a0VmZuR7cPj/KzqAqRqz126Lb9VlaOuIo2ATW+KFjmEs3/XuY0nAj04oPLYMHaborhCWOB1mDd8dZTO53v6dU1nhu/o0aRAMTg+VgR1wU5BG7DrghKA1JZt542fQw5hXCxiPZX2zE54aWeXvLsDdjFZWqRKSkW9fvfnL3H0NJ7OyNzo/Slgbepp3mmTXT3eiB25066amKsHJ9dhNgb1LNWFjKqx0UsGgXD36yYgqt3Ul9P6tuvlH5N2e80rY1RKpv/K2gqLVd07jlK5SOMlA39u3ekT9KtfjQ7wrWPxZF1g9YOOZ6r58aSyRNcetmjf06si5pBdYuLKQBk5LZr8/hwAqYpIXCj8yrYhrWbWtJEsHC4/hzvlrFPMOspOKX6nwBOiAHnLgsyEnHOXRZ4q25JxxVzjwYTR0S8wwB/GTEHvZgH0eBecPVN9M1Ng622TjNJYcahg0M7xQeIXAggTFNsQxrgM4nXIvKnYhZnXMzUlf6B9acBOgRbxIsmDuOz5AD0+ZuanU2SgcZ90sWJhtMCKtabGE65nSFnwrsGP68q6pBwpTj7wnwZ9rVdoVtItqxrbpznKEq5XiMSmpgE36Q9CbhrlWLEscRu3Y2iux2W6s8B+nAjTclDxKSCMX8LNDofVyhV/xlGNm8nxcSCVq1YzllXR7S+1G+S9NS/WoJmoP0SASghmYOth35qcTQf5t7n+aVcfj41uw7adGqbnnC5LeIlcq/LvWisL6udttkO1DbmY7UwkR1RxWnYYdeA/ne+hksvgVPT994tKEuaqiXnDlnF3h58zSr2IsQR0lj8lm5054+no1Tv9fud1LeJNL6A1iXMHGRX8HLdMfZ4dc7HBL18ti8tM9k2FvPatnVYN18OOBw/gLIaqu95L0SSMJNNQ+8BzXZJg2ALi1kX7pDiHnygp/3aGLzhxqzpB+zOrui5SW2r9qnbSXBu5opdDM6ujzbykEcc0mBC4OBWopGNULQeK0KcAbMhK+FaEseB/VBawGu78IZMVL7t+L9gu72bD/6xt0iiF1hGEvtWh/v4z0UAlRnkL1vevITY66kwEGVMSCFRwmgzt5eSeLzRIHZnBgDLuUZt+oeShiB/EX0z6VMtqOxwrVEBIXc0VcooglMyUleGG5geA85BIkcFJGA7ZT3n52RftPquGw65MasYIOVJZsIkEbm26CnEQ5I4cvIN9WjZyEaS69plOnv7So1iru/9K6KCXqyGtuIa7j/1zNl9Z2egB36Q/QprQ1qCAVRqUXMd4WnTi0UrvEx459uOGaSqfkE+WvRSAnKKYUpfiuXGaKNgzfMQZz5nR/h7jJNdnYzQk62a0H0eTtEl/bNth6RM5wnbcD1lH+/Y4D9uGEzduP0LjADTS2zdAba2Yhjf+rg37M2cZmSDvdfKM1VFLIkaOvTxzkxgGSFxxgednDVspsQ0lC+02d1Oke6QYrOHD06WZ5GV+BSZjJDdyfIEsB7f6wQVj5/46ILg7RT8Mri+eQ1ReHyQg+hXWgCLn4Sm+mcXqmHL99w55DPyhL7lsYClNs64l1KCa0LKgTymhm6K2PjHiEPxLkEbZJajIS1eSdb4G8CtvVEcpje8oCslAky8W6CMNkwelHNc4emymT+7Q==
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-3.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-3.exe /rawdata=Ff06aR3aK/x/1br+jxIL/q+pZkOnoHQOJIP4p5mrQQswckwzZZ2HSt1oUas6pDQjMk6cjmqHlqp+e0wBGdGHYvmzPa+jzDEFxfMjknlq90Tk/LNGyGf7Yr303G5xzPXDAiKu8tld0oCF/3wdnBTHtmjhWq1bb88MxFnziIT6Zkas2s+jSb/JTBu1ohZsNefVJYi8otad+SbLVheqyEAmy8BoI/4TbfDU/4Uu4dMXgIYmWlfpEYjYZnrGDHsFU0u42rldeg4Jz72V0CappzB+bTNbO5YNwricViPeWECfkCswPJ9zX5+qmlIQGVdpQrwX46oWgo8OB0wJtef7Hwiz2wDgSKw54SOX0ivRwhZW69YVfNfxlt/qWaBZ0ScoSOE+JXQYJij9JXL7gf072uYyYl9HbVFFb3y9lbHXFjz/gR2anPdPeC9oZEDH5rm3PqJFwvtmWOeQep5/Vvg3Vk9/n0zw20oEt+uNLMIktgztZKcv6JL5W01DJpkJ1uPUymEZT2TyaSUaOcz3fQkiFUSuu381zWHFWc/b71H7GSE/T+/o9YbSoVv0uwuGNcBEJuPE8vdptV6I970Y0etoRg1ue82XO/92TVrGmpSofRdcRMjEqxneS0eK3Y2PV+Cf8oRicr7jVqXa6vtv0Wen/nxvcFNOZ+CJDNY0QzsFbKeFRNU0yVIKr9ZAa+8wlHU+/yFQCYqTuSbr7oEFdJxpgyKhEXBJ2PfM+Mqf530Zr4/CRDmlhAYI3B2CZWRHEyvxCFTggm5obgunlDICsSjpiL6DW1SZmdcCLm98DpRJRq6ztj3RX82uYnM4LJKfgW09DHebH3MsVYzRiUSE1LzXaV76klgJTu7p+CqANisPwvfZORhF817fXkMGsiNWsjzxEfFSZyf/ShzIeGtu5wAwDP6jlM8z3qd2QB+rTKA9ccl1QhBvme2o04yDKlCXeAGVvh3LX9Fh4kVeoIjloMGSLfySJKbVTQnYG+uhAUiHQvz34hXCXDTR/AxwZFHITZNYQpreWxYfARUPpVVPNpYdJOY/dcP5Y8NmzfysBYntuwAFGrueX3gXT4iHwh/CJivyBk0tH+BQC/vNUR60ITZTUoalbeT2y6TLf/T+rDHJkZDYBNaBvBZ6oMWUVEhk5gUvNpHhXTUdAg+M5bFEyILrKYqwyvF/gpbkn/RFt6rnuewwHSU0EaRL6QlBaRx4bkAJ3BSw3oa1eIo2oUM+p4Emw9CpSFZYNYOoUsxT+V1EyNSTMQ2GoBoRveKwCWa+dmUzB7pNQPbicCZnmryD061tvJL4tGPGX9yl2hxzAACFi8hLclFWkDLH2SKnmbUX1b2M3OllxqwftI/l0R2MiqJv60CC+pJYC3JFcVqMbK7ka/S4SvoeIrsY/XofMjHsOJXQUxd7X8GxxjLMBR2nWdUgIVXtuNWgTUoeOiWim9i5P7HAOdb0K3SfmH0iK5x9uIROdKoLvi7gtEoxVWFavWt7zyuWGBJqdbpvjM6QySVrQjzDU4BlsYeSLHQ67q4dFnqc9OqnD6UJptjV52wiE+vnlFTXEhzwJP7qVlNCfX1R+Qexk2/b8ShJcrS/wdolTpBQcr1ajmCcBgNgQySqMh/a1OjTuCj35dNb6niA4zBtFc3WGEDLe3f/d6xPXDjDrRoVM1ceG5q40+av5jw8+jvGGCdrBJRRXHRnDhNVD4cpBjEvaFo1BmxtUZFoewDZMOo6EgiImvKH1ET40EoLVuTi4g8N+W7FkNiTY+jFgvRhZvr/PZSlt/GCm0JV5uoq5wzNn8oxz+v5ZvuV7D4Mc9Kl6IESxhf/Zcpely0XrNibdf19pE4FNVmVrNyJx+nK/dN2VZMXUdu0x2ZA6Utdtb/Fy1D7LA==
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.exe /rawdata=Ymn85pN85PkM5Ofgn8rPPSGI14c9WnRT358lR3GF3J3oY15hWEcvdNTvH0QKhqiQKrbNDoKplJazJR+9XNrdnOq8BbXF47z6oYTSLuzNcgdCb1qRG9N629hJSfcXI/zvMH8CCO0ph6B00c+/ubLXhejXyvX2/+BMbkaFGlbJ0WCtpJtmpRiJ2VSBGMTtFse03P+TmZvCf9jiZ0Ca7efO2RpPjTF6HBkEsfXGzvqnZvTV/PtzeddRyQvMAHbow2BSJnZHZhNBb/FPAUlTu7PMPmx4yTqi3lPJN2OqGCRk2aUOKwllHasaM4Q91HOfTSgWahB+Ml+GTBrX9g+tylK7EW5Www1YnzSzqQNchKqjkSyfv7ySy3+aWq6oBkckDAJeiau6Eajs4R6eKvtQjVtPRX66+MUKHBQtGlNYCeu4jLrUIHJyNVl+0RGB1AF+bpOlasDNNiBey1R7LU42hAJ5LxFpah51fHxoPaxEjCH8iUDfezlryJmHEBqlU4M446whpvAtox+HetgJQ1TNiCSqhg2/TvQFeFiHGNhgoaWecsjwGf3xKfFPgZ4tZPb4cPRFN0ferJ3J1p6vh9OOdpCPX6g9gozNiu1lH3QAhAGHh9+Fn0Fy6HRgYviVh1Y3MzQlK4LeazUAW4s7/d5/Q6hzXP/UxZBmcwDNbLMpt5yxw9OBErAQVTCm3iAPSaSES+SVVIEFaMWVF6c6frinAFMu3Pigl38ewg0zEqZSxpyMmhFpLoxmuNb89TNgFfSv5nnDOUUQtfI89XMKmIriWP7gJSbWujoXqbUhW5lmWtew6MDvYz1Y+3OPzckWDchvBW5W6CDcD7ATOjZTJv4LzZgyBoPpBOW3q4O7JeHtRjsKp8hyjuWMiAAgdIEB1S+OiLziX0IksNFqVoaOQDadunNsdjLV5CeAGkOd5+mKd89BIMSrv3UEVQJ1JmoWFIkoYuJUXqDD6Ylvvr07vLulM91XUwPtEbL3zyA36PESsdAV5yrooNGXvX5gV/ChiNwYhaDZ
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5_user.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.exe /rawdata=Ymn85pN85PkM5Ofgn8rPPSGI14c9WnRT358lR3GF3J3oY15hWEcvdNTvH0QKhqiQKrbNDoKplJazJR+9XNrdnOq8BbXF47z6oYTSLuzNcgdCb1qRG9N629hJSfcXI/zvMH8CCO0ph6B00c+/ubLXhejXyvX2/+BMbkaFGlbJ0WCtpJtmpRiJ2VSBGMTtFse03P+TmZvCf9jiZ0Ca7efO2RpPjTF6HBkEsfXGzvqnZvTV/PtzeddRyQvMAHbow2BSJnZHZhNBb/FPAUlTu7PMPmx4yTqi3lPJN2OqGCRk2aUOKwllHasaM4Q91HOfTSgWahB+Ml+GTBrX9g+tylK7EW5Www1YnzSzqQNchKqjkSyfv7ySy3+aWq6oBkckDAJeiau6Eajs4R6eKvtQjVtPRX66+MUKHBQtGlNYCeu4jLrUIHJyNVl+0RGB1AF+bpOlasDNNiBey1R7LU42hAJ5LxFpah51fHxoPaxEjCH8iUDfezlryJmHEBqlU4M446whpvAtox+HetgJQ1TNiCSqhg2/TvQFeFiHGNhgoaWecsjwGf3xKfFPgZ4tZPb4cPRFN0ferJ3J1p6vh9OOdpCPX6g9gozNiu1lH3QAhAGHh9+Fn0Fy6HRgYviVh1Y3MzQlK4LeazUAW4s7/d5/Q6hzXP/UxZBmcwDNbLMpt5yxw9OBErAQVTCm3iAPSaSES+SVVIEFaMWVF6c6frinAFMu3Pigl38ewg0zEqZSxpyMmhFpLoxmuNb89TNgFfSv5nnDOUUQtfI89XMKmIriWP7gJSbWujoXqbUhW5lmWtew6MDvYz1Y+3OPzckWDchvBW5W6CDcD7ATOjZTJv4LzZgyBo4zzDfaeN2knLUhfdbEESZ+leZ0pVHHJoINM2mYCg+nUu3klkaxwRiWPDLjMeUF2XJ+bnd8PshErF8POyn4q4MqHnarna81ntbQt+Z/w3WP9wGVZtiQhXmlL1z+oYwi4YD8Fqt3DZc0E50lFAkLMBydcXxjCaBeYrUalk1HWddb
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.exe /rawdata=XM6KblEPWx04VuNC6QAdDDxIxsKQfa6HyD0Xvmet4WF4tYbWN599iJTuBhsCk4z5NweLil7jp6xFyCZWZq4yG8eRgRzpxBadU8WUGj25y1QM2q6C/udY2tIYrEv7cJdRN+hCUGvcZ+HC2GlEqgW8+/iToMqmTKwl7/QPXJFkPmZDeNbIE0f3N0X7SjU+tHqCdmnROEwnO+f35Mn4T0OO6HKFsxTNCyb5sbr9ItP4/jXXcgD+PylCcHMebirMy+2wJ+GxOKY0ZMfyukoLRKJtKJCMXlQD82p8+Mhk9+LlOYgOyxeaCIkdSKR8ofhWJWUHdeUmS3Mvsoqo2U1ROu/+Oi1iNchJH98Fp9wFoxiTkOkeZq48ZMIgoWfKJHTXkWHCF/XnABDp7MOAsXDoRhcaw8IsMiqwE3qeW6dCulQkc5IpQxLuADg6dM9Ke3LXetZc1ravdcSrCQbV9RYHQ4729taCPJPNNI9HKliC+Us4R6YmvSvEszmlgK4qAXrQgszuQyaVk4iX1EydLihtSdj3HuoU8+kZamA6t5aGXLOMAEn0mnErG4wzg7q+KvFTqzYg0puHO8PmJHGqrS4HIyP6puD2z+dZuMVMKBFyWQ0FAYJT5rzHFr4ET5zrIH0CAG0m8qLofGEDJSLZfaNc12mYKN5MzbOadZNVVopNc6Hy9WW1V1vrDvwKo32VBPyNmpHG6GITBYGnD5eVXsSmYsW4JRoQ8Fto0DRuJbI+UX/ViL0UfPbllrnxXtDVAQ4GB+rtWni140MiaM4sC+CaPHyEix8vnz3E3nbzkQzIoYzXIXkER5aiP8E9NNItaZYN9hKLrd5IXkvuTD/dhXmY46Oe7pPQ+ptNGQrQ4meP06nvqnLktRtY/tG6dlgv0KConcelZJnNhk1Mu3IFnQk9ot2FVt4EObQ2ooknMCrPiA8QO8EBJ55d+90fbsRlWKyk/4YRcKCaTOABKQJImNLNX4wL00gXtFsUyg5rm26sw1qyCvDS+GizTSAzFzsXi+cywBGSQxUDS3yojKeZaZ61dneCPOVlCrX+FvsFBowy0AD87FdP0BWvvsavClukl0iKpmDj5WKj1J/FkQYlMuReIgb7wE2HEKZopS/HQij72qcsFvj/oR6Bl+4hU5PYbVOimvyq/33ABYxyk+M5eR44XzSIuvWI2rNZFGESI+unxvoZbG0CO3jHuHSZIMASuxWYpbV6YXeunZvOBiA0pMWySErTJdi7i5+dUOUbS4RLqRxQI1KRl95AnuPTC9RwuWGZ3Vrj795YyASlkuw7X16fm7NI12/p99spspolzluniis/3oze3JqIdu//mqn34mVTr558NBPIVeiugadv5gtuttvrH7YRQNdVaJpyfIkl7kDhsTZdUHqMVUeKLj9SUp9NvdW6Cq0q8vQZ9wz15TLIdvztWwQAD8JWI9JcV5Sml2dYuX2pWYcvuNmkDT0MI/MU18OrPLkaES84d4Yy+ZKv9aAAePn+FLWhTjvpAzkuh+RqTKEXUdNOeXaRwuwV9J+Cw2rJTn63NX8x7dPxfKM/BT3tBleTT4b3fU3q2uOpmZSgQKfqVxN7kdqqmbXUMZbXt0HZ/rfHR86i3ob5kCfvbxHaFL9TPI1nFjPnDx3ukPZR/FN7siHNXBXhwzzPbr8DD/DRgktQBTPaCm7PAY6WSUB9c7Ahe6ZrXw2vBaJG3PLd95xIhCXawEYbzpFjtkagiijcEDmWo7ZJ8eTPBhzXxiijP31jtpEvY6m2LYFYU6qZ+fP5339PT8iqatgU8xCEOxzDD/B5YcXOHIo+TVPYA1JY2s4ew3stGrRAcx2pih5yrVVIF7iA4uvWF+M16uBnRado+IxpQcE+HR90xC8ejWeCywSkCOQ/02yQefRB6X3jAXy37vpSY5468ZN1N1Ddnq5Ttqcwi4+xpIwcvVVo3XR5sN/LsvkmwdmMlZVSLZDHpy1ymjg2Hev9cc2udrkSOrBsbdWBv+1Y4R+RfjPN4sSUoTdPmMeoXl/xSqqbUaOSRbpXs8tGf3mB1tmYLa1xAi8kP7P2VMeq4LmEt+K5yJGdiF/vreU1877elmSs9xCPWycFrSrQT4JjVnrCQzXtFg5BcMf3mjKEpLOsx21+rkix965dWu+F0uy/PuDtRVOLqoMH2vDXxZqi7e6SXs/oWigCsPIgA9LRNZEw2buZjvhaxHc4B5Jy1VPlv+SUKd/Ht89PVXbDExwU0JYL0Ys0Qo6K2ZmFom3zUp6ff979BjfqCSGUcmVIJdpac/OE2sBIJS8LINCIXkIKNgskb0+HKYprESYzSeyP84fxJa+rfzYrlk1/z+ML64FZcEDi9/GzGQs07AB2eWsrGGflApKy1r+fbluTOiLXXKx0OQ4bTWgXTJEgwSrVd3Nfsrhcvry5Z0In5UJhtX5BocQayVScWv/rRa8okEnVuk7lhP4osr0//lYnwzroGQmnkBaTDP472XsGY5Vi86SfH2jkvpWTik9XIvM0+IaxyEO9cMkLPDY4E0tJLBlDOi2ZwbYNbUQcCj4g4+l/LrXSsdG1eztZpdBd
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-7.job - C:\Program Files\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-7.exe /rawdata=nBjoQ14cC24zlFiMn3lpeC4lAqIdjtFquCLBCDFZXWfJ68sodE8cWpI3IL4H1ENQsjTCO4Nv69XDUsXFAema0QpdUlK4mn4FWNjKe5mEWDr/Zw8X1clpXsnWrA7OeQCaCwUy2BYXzWQfpSD9qQIPqKIWxnOFNHhUEEu8AFCv8a2MOOw1DGivaf624LeynAbqC2IWfRDrd35OhlnNIWPUb30/IfTcBgt9Nk+nvXYP+pmplbdOydEJ0rqYeQFMKrs8OlkKof6bI89EQx0KEV/jVuXc8qY7MxzxIN1dt7HOLVD3Bn7c/Wsa5Nz85SVB6yY55IvXo0s/lMAqcZ6OgdIbpaEXV5iwmlP6vuG2wIN4fJSpR1joyHUnWNwgpuJU5i5J709jEz9wrhb2z8dPvErNXg38yyTrWbKmg8dJhAYOl9ZrfdaNx8sHOOGYFrZmnngrMpme3NA2dJJ/iWNbrSEPCH/dWigmIylPMEAn/Io3b/NA/PzHhIW7umzlR/YyU6qZel4FGew/0SYBZlFBdYA5ZiqcN9/JKUy8iD7NoStEzfHBfhHKTqu4FnYH3684hFLPxiNX7dUxRqJqfdeUF4YkOUBMleSUTh95GOI8ZhbRD4OTrcfJdoEiVuP6n3F3YrSkyT/kyV6hgIZS0sa4HuI1yxf9Pv+GGhUltblGq1GcQgMxLW2ivVyaiZyDcqbyHgK/ycEEzyMOiwO8i1x/PT4MMtUeaSk1P7vHqieDP1XizaDNvRnaXcAZZCfZX8wKPwfFIntVRjCLo+xNUe4AZ61qGWDTV3hNqwLLnTb2iyQuLuqhiaXISxAEwKtTgW7C1reESWUsIcWWAE6/XSUNTv1dw7ygv6DAhL7ri0oCeIQtFXK7FrshjvyNAN6P3LalFLfv6CkbXJphiGfsG7bclPUCdJA23fBawrdADCO8lcmdp4bFhTLJSzgkeQkKKvVn9pbDF7wMgU6usj/IQ5MSAStoo26D/Ve64wkLdQ+KDm75EdDLj8BFyD6csYsdQUmlFcMBAOv1m3wYBCnvy0PGORx+hOUW6jMVFgJ0VVSXVo+tg4id7ZmTGjGZu6c6RP9Npp8ZUVutze/Mbh/eBp5L2D2d0mQvBTt2dvB1EggBWiRuXsqfFf4Kgc3j3C1kthGdd9dyxlT9TdsNMArmTDiVlpYYsKOigRx0mxS6U5r9WZwiPZqBqbJJG+XUmEuvZv7J9rn+x6idHQlBZIb3p5Ut3NyY5DhJCEecYqf1czKRZ3RBMn6NCi/JXsv5FGSUFR8HVSxzbn72o0oCReb8slDYfehzmvesnYSBk74yv82UPsrGwiazKp6yhOb98WSRZjPId0zbwWJHVDJM3b8mukxyoC93J6cUfBVzU1mvCYD638d7jPZIEl4FX++T8baGhsPD5+eiP1HtJhYSXFfYkzBJuVBkhWGhgT8zZMf+2FwHbrhq2eezczLj4jGOmuIKucL6jVmFH2HI7F2UjevkMuH2RsDsRMkb0CGiLXUJYWLT2mKynIog5i0ns+eRYjFbu9mCvQb4DkKruTPhWkpoD+CvtUqGGc9uV79U1woqw/bqD7P5bzU30EYfUY6OBz8gi3PZDU6j/oZh5EJOWnmHhR3zuFv23uIKK70Vcc4LRVFrZq+iHMlJOnPrIyN49i0ZGBynl+9qRdQKCTndOLu41IO/JWsKawL/Z3UV4szK/japFpSePX8GOsF1rmtZkCI5mTcAdzykwzt4HVAXsE7UZH/KgWhESvz5cjbFTnfc5Ou+XUbYplLbOnsNODTmyiTGf1W60VH9pIlS/RDieMIa8lOh7PWSBnCwKMf0GHi0AgCQ8XuktD3sdb8SLFPvYVBoJx6WWar3KgkOUE9jKJaPxV6Zp1G8f6OhI69Elekj/sHBBH8Tt9uIQ6361+4ai1MJ09uCoJZ3tsJY6lyp+8H/YUYwLTFnn8nv6FQwQXpeek2Q7jNHtAKXUSfzCA2+zpkngTYS7yV2xu9DQXLqfQyBHa6hRlB0lXEy3jfa+N364GEVyQHaxgE+mcBhSWFALy62bnH5vwnlmFej/ugiP3maaMV6gEKNRbzPbcml9gERISuK2Sm1dFawdbOI4LM0Htgfum/Peftt2zUFdJ1OoNqMW1xP0uetFu/FBxAsdFUgsFwoyzg3E6Cxk011c6aCo9tIVaATOtMkVpzQerYOhOzE9bM3FJckTAfK40rvpT6W0KDTHvh7If+8xSTSb2pjKojfI3SxYA0hDnyzXk1PKuGpIHG9iQMBudEzd04tCjjZv2u2OhLX8ZfLpXaJLV6wui67XFMz+vgeaFZshp18JGKma8WoqrDq1f6QAoet1ebrgu2aBy+0Y0t3Bhq4NcoAWokd4lmH14Jv9GqCtna0ztlWvDkc5zzF/A==
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files\Bluetooth Suite\IEPlugIn.dll [2011-03-13 60576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-20 559624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-22 194504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-22 194504]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-10 143384]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-10 176664]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-10 178200]
"NvBackend"=C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2014-04-30 2199840]
"AtherosBtStack"=C:\Program Files\Bluetooth Suite\BtvStack.exe [2011-03-13 490656]
"AthBtTray"=C:\Program Files\Bluetooth Suite\AthBtTray.exe [2011-03-13 302240]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-07-20 6109776]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"cmsc"=c:\program files\cmcm\Clean Master\cmtray.exe [2015-06-18 479080]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinit.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-01-27 288768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"VIDC.IV41"=IR41_32.AX
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-08-05 17:16:27 ----D---- C:\rsit
2015-08-05 17:16:27 ----D---- C:\Program Files\trend micro
2015-08-04 17:57:18 ----D---- C:\Program Files\gmsd_re_002020050
2015-08-04 17:16:48 ----SHD---- C:\Config.Msi
2015-08-04 17:06:57 ----D---- C:\Program Files\69dc8177-a574-4dff-8461-b3267b078dcf
2015-08-04 17:06:38 ----D---- C:\ProgramData\BlueStacksSetup
2015-08-04 17:06:34 ----D---- C:\Program Files\globalUpdate
2015-08-04 17:06:14 ----D---- C:\Program Files\CinemaP-1.9cV16.03
2015-08-04 17:03:41 ----A---- C:\Windows\system32\drivers\{db75d149-c22d-401d-a1df-e7ebf4c48d4b}Gw.sys
2015-08-04 17:01:58 ----D---- C:\Program Files\Seznam.cz
2015-08-04 17:01:10 ----D---- C:\Program Files\Banana Phone
2015-08-04 17:00:20 ----D---- C:\Users\Lenka\AppData\Roaming\Seznam.cz
2015-08-04 16:59:53 ----D---- C:\Program Files\GUPlayer
2015-07-28 19:27:20 ----A---- C:\Program Files\Common Files\Deployer.dll
2015-07-20 15:46:29 ----A---- C:\Windows\system32\aswBoot.exe
2015-07-20 15:45:46 ----A---- C:\Windows\avastSS.scr
2015-07-11 07:27:14 ----A---- C:\Windows\system32\FNTCACHE.DAT
======List of files/folders modified in the last 1 month======
2015-08-05 17:27:08 ----D---- C:\Windows\Temp
2015-08-05 17:24:58 ----D---- C:\Windows\Prefetch
2015-08-05 17:16:27 ----RD---- C:\Program Files
2015-08-05 17:12:23 ----D---- C:\Program Files\Common Files
2015-08-05 17:12:21 ----SHD---- C:\Windows\Installer
2015-08-05 17:12:11 ----D---- C:\Windows\System32
2015-08-05 17:12:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-08-05 17:12:10 ----D---- C:\Windows\inf
2015-08-05 16:08:51 ----D---- C:\Windows\system32\Tasks
2015-08-05 16:08:51 ----D---- C:\Program Files\Opera
2015-08-05 15:59:50 ----A---- C:\Windows\system32\log.txt
2015-08-05 15:57:33 ----D---- C:\ProgramData\NVIDIA
2015-08-04 21:50:04 ----D---- C:\Windows\system32\config
2015-08-04 18:06:05 ----D---- C:\Windows\Tasks
2015-08-04 17:55:29 ----D---- C:\Program Files\PSPad editor
2015-08-04 17:55:07 ----D---- C:\Program Files\EDDICA
2015-08-04 17:19:29 ----D---- C:\Windows\winsxs
2015-08-04 17:10:37 ----SHD---- C:\System Volume Information
2015-08-04 17:10:10 ----HD---- C:\Program Files\InstallShield Installation Information
2015-08-04 17:08:42 ----SD---- C:\Users\Lenka\AppData\Roaming\Microsoft
2015-08-04 17:06:38 ----HD---- C:\ProgramData
2015-08-04 17:03:41 ----D---- C:\Windows\system32\drivers
2015-08-04 17:03:41 ----A---- C:\Windows\win.ini
2015-08-02 21:36:33 ----D---- C:\Users\Lenka\AppData\Roaming\Skype
2015-07-24 08:52:00 ----D---- C:\Windows\system32\catroot2
2015-07-22 09:00:21 ----D---- C:\Users\Lenka\AppData\Roaming\Mumble
2015-07-22 07:20:28 ----D---- C:\Windows\system32\drivers\UMDF
2015-07-21 06:30:03 ----SHD---- C:\$Recycle.Bin
2015-07-21 06:24:17 ----D---- C:\Windows
2015-07-10 09:37:13 ----D---- C:\ProgramData\Skype
2015-07-09 15:02:06 ----D---- C:\Users\Lenka\AppData\Roaming\TS3Client
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-07-20 49776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-07-20 208664]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 461080]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2014-05-20 29128]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-07-20 81728]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-07-20 788784]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-07-20 433264]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2015-02-08 243128]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-07-20 24016]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-07-20 76000]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2011-02-24 100328]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2011-02-24 308200]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2011-03-13 34976]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2011-03-13 259232]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2011-03-13 24736]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2011-03-13 175776]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2011-03-13 49312]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2011-03-13 141088]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-01-27 10551296]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 269824]
R3 ksapi;ksapi; \??\C:\Windows\system32\drivers\ksapi.sys [2015-06-18 81768]
R3 MEI;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECI.sys [2010-10-19 41088]
R3 NETwNs32;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 7 32 Bit; C:\Windows\system32\DRIVERS\NETwNs32.sys [2011-05-01 7513088]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad32v.sys [2014-03-31 34080]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-01-13 328808]
S0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2015-02-08 717296]
S2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-07-20 113592]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393728]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RTSUVSTOR.sys [2010-08-03 215144]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe [2011-03-13 138400]
R2 AtherosSvc;AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [2011-03-13 68768]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-20 146600]
R2 cmcore;Clean Master Core Service; c:\program files\cmcm\Clean Master\cmcore.exe [2015-06-18 315240]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2015-08-04 68608]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-04-30 1617696]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-05-20 668104]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-05-20 410968]
R2 TeamViewer;TeamViewer 10; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-01-25 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-03 327296]
S2 Update Banana Phone;Update Banana Phone; C:\Program Files\Banana Phone\updateBananaPhone.exe []
S2 Util Banana Phone;Util Banana Phone; C:\Program Files\Banana Phone\bin\utilBananaPhone.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2015-08-04 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-01-25 116648]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2015-01-25 194032]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 102912]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o preventivku
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o preventivku
ahoj,
doporucujem prebentivne prescanovat a vycistit s MBAM a AVPTool
doporucujem prebentivne prescanovat a vycistit s MBAM a AVPTool
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
-
- Návštěvník
- Příspěvky: 26
- Registrován: 10 srp 2007 09:46
Re: Prosím o preventivku
Děkuji 

Re: Prosím o preventivku
zamalicko 

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/