Preventivní kontrola
Napsal: 10 čer 2013 18:05
Dobrý den,
žádám o preventivní kontrolu logu,
Děkuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Psyhcodelic at 2013-06-10 19:00:51
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 43 GB (26%) free of 167 GB
Total RAM: 4094 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:01:03, on 10.6.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Users\Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Psyhcodelic.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=113480 ... 43a405a405
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (file missing)
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Kerio VPN Client] "C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe" /tray
O4 - HKCU\..\Run: [Google Update] "C:\Users\Psyhcodelic\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Fences.lnk = C:\Program Files (x86)\Stardock\Fences\Fences.exe
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download video on this page - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/300
O8 - Extra context menu item: Download video this links to - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/301
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Psyhcodelic\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Download Video - {B4FECE59-6D0A-4EE6-A07F-E6A94F846E55} - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/300 (file missing)
O9 - Extra 'Tools' menuitem: Download video on this page - {B4FECE59-6D0A-4EE6-A07F-E6A94F846E55} - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/300 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{66F21A65-FBE5-4A37-A3F9-37C8DC463698}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{8DDE1AE4-40D0-4487-B768-E11376EA5E9D}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: DisplayFusionService - Binary Fortress Software - C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Kerio VPN Client Service (KVPNCSvc) - Kerio Technologies Inc. - C:\Program Files (x86)\Kerio\VPN Client\kvpncsvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Acronis OS Selector activator (OS Selector) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15137 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
winlogon.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000007c4
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-fbbb89e6-ed2e-4853-ac15-54e5fcfdaef4 -SystemEventPortName:HostProcess-d0accb78-166f-488c-9135-226525c012d1 -IoCancelEventPortName:HostProcess-fbac92b3-c588-49e3-bd2f-94c5c2439a75 -NonStateChangingEventPortName:HostProcess-b41ae9c7-6d8c-482a-b9e8-bb037e7cf0fc -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:69021318-9c08-463a-91c7-73ccf1964524 -DeviceGroupId:WpdFsGroup
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
"C:\Users\Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files\Rainmeter\Rainmeter.exe"
"C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\sppsvc.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe" "132038" "63d5518e-4d85-490f-9279-5794e02a455e" "C:\Program Files (x86)\DisplayFusion\Hooks\AppHookx86_71C2806E-68FE-487F-8235-4DA35D784DC2.dll"
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5068.0.331091443\246130257" --supports-dual-gpus=false --gpu-vendor-id=0x1002 --gpu-device-id=0x9440 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.7000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.1.1559735211\774972502" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.3.352738733\378143627" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.4.1897910011\1915414031" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.5.296721235\992412006" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.6.1221047984\778560119" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.7.1560771570\1225355924" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.8.386405905\546257560" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.9.1111382967\339552517" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.10.120165734\1802225275" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.11.443484784\392465614" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.12.759596119\822308053" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.13.2019580461\1634082702" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.14.1904240517\620429341" /prefetch:673131151
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
taskeng.exe {B494BF80-6E82-4C11-8AF8-A2F416A1DC19}
"C:\Program Files (x86)\Kerio\VPN Client\kvpncsvc.exe"
"C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe"
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwndDynamic/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.190.1835046435\1377170956" /prefetch:673131151
C:\Windows\splwow64.exe 8192
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
taskeng.exe {233282EA-3CB9-46DA-9D7A-AD0D28943B04}
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwndDynamic/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.215.1474976046\608120090" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe13_ Global\UsGthrCtrlFltPipeMssGthrPipe13 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwndDynamic/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.227.1794617910\286085244" /prefetch:673131151
"C:\Users\Psyhcodelic\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2857271893-2709921192-1482975336-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2857271893-2709921192-1482975336-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14 6307960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-06-03 462752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14 4531320]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
KMPlayer Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-06-03 171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - KMPlayer Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-03-11 9569096]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-03-27 12459112]
"Fences"=C:\Program Files (x86)\Stardock\Fences\Fences.exe [2012-10-29 4017368]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Psyhcodelic\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-03 116648]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2013-05-20 4284976]
"DisplayFusion"=C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [2013-04-26 7283072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2013-04-01 1719944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO]
C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe [2011-11-23 213304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPA]
C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe [2011-11-23 184120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvUpdater]
C:\Users\Psyhcodelic\AppData\Roaming\DRPSu\DrvUpdater.exe [2012-06-20 195256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
C:\Program Files (x86)\Origin\Origin.exe [2013-04-24 3497552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Psyhcodelic\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-03 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesAirMessage]
C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [2012-06-08 958392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2012-06-08 21432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2012-06-08 3521464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-05-03 17355912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files (x86)\uTorrent\uTorrent.exe [2013-05-08 802136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
C:\PROGRA~2\MCAFEE~1\30937D~1.207\SSSCHE~1.EXE [2011-06-17 272528]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"Driver Genius"= []
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2013-04-01 1719944]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-05-23 345312]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5.5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]
"Kerio VPN Client"=C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe [2010-03-02 4986728]
C:\Users\Psyhcodelic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe
Fences.lnk - C:\Program Files (x86)\Stardock\Fences\Fences.exe
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2012-10-29 551640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=0
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe"="C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe:*:Enabled:YouTube Video Downloader"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"VIDC.XFR1"=xfcodec64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-06-10 19:00:51 ----D---- C:\rsit
2013-06-10 19:00:51 ----D---- C:\Program Files\trend micro
2013-06-10 17:01:16 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.technic
2013-06-10 16:39:39 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.minecraft
2013-06-10 16:09:08 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Kerio
2013-06-10 16:08:17 ----D---- C:\Program Files (x86)\Kerio
2013-06-06 19:29:55 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.minecraft_2012.7.4_13.12.48
2013-06-06 19:27:18 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.techniclauncher
2013-06-05 20:37:25 ----A---- C:\Windows\system32\drivers\VBoxDrv.sys
2013-06-05 20:36:47 ----A---- C:\Windows\system32\drivers\VBoxUSBMon.sys
2013-06-05 20:36:46 ----DC---- C:\Windows\system32\DRVSTORE
2013-06-05 20:36:43 ----D---- C:\Program Files\Oracle
2013-06-05 19:36:55 ----D---- C:\ProgramData\ATI
2013-06-05 19:36:52 ----D---- C:\Program Files (x86)\AMD AVT
2013-06-05 19:36:41 ----D---- C:\Program Files (x86)\AMD APP
2013-06-05 14:50:13 ----D---- C:\Program Files (x86)\FinalWire
2013-06-05 14:46:56 ----D---- C:\Program Files\PeerBlock
2013-06-04 20:39:23 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\TeamViewer
2013-06-04 17:14:00 ----SHD---- C:\Users\Psyhcodelic\AppData\Roaming\Common
2013-06-04 17:13:57 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\DisplayFusion
2013-06-04 17:13:31 ----D---- C:\ProgramData\Binary Fortress Software
2013-06-04 17:13:24 ----D---- C:\Program Files (x86)\DisplayFusion
2013-06-04 02:33:53 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Dropbox
2013-06-03 20:12:38 ----D---- C:\Program Files (x86)\T-Mobile
2013-06-03 20:12:31 ----D---- C:\ProgramData\Gemfor
2013-06-03 18:53:10 ----D---- C:\videooutput
2013-06-03 18:53:07 ----D---- C:\Program Files (x86)\Smallvideosoft
2013-06-03 18:53:07 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2013-06-03 18:53:07 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2013-06-03 18:53:07 ----A---- C:\Windows\SYSWOW64\NCMedia2.dll
2013-06-03 18:46:12 ----D---- C:\Program Files (x86)\FreeTime
2013-06-03 18:32:04 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Tomabo
2013-06-03 18:32:03 ----D---- C:\Program Files (x86)\Tomabo
2013-06-03 16:49:17 ----D---- C:\ProgramData\Sun
2013-06-03 16:49:10 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-06-03 16:49:09 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2013-06-03 16:49:09 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-06-03 16:48:54 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-06-03 16:48:54 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-06-03 16:48:54 ----A---- C:\Windows\SYSWOW64\java.exe
2013-06-03 16:48:46 ----D---- C:\Program Files (x86)\Java
2013-06-03 00:32:37 ----D---- C:\Program Files (x86)\Valve
2013-05-30 15:48:21 ----D---- C:\Program Files\Google
2013-05-30 15:41:07 ----A---- C:\Windows\system32\Wdfres.dll
2013-05-30 15:41:07 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2013-05-30 15:41:07 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-05-30 15:20:30 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-05-30 15:20:29 ----A---- C:\Windows\system32\mshtml.dll
2013-05-30 15:19:13 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-05-30 15:19:13 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-05-30 15:19:13 ----A---- C:\Windows\system32\atmlib.dll
2013-05-30 15:19:13 ----A---- C:\Windows\system32\atmfd.dll
2013-05-30 15:18:28 ----A---- C:\Windows\system32\WUDFSvc.dll
2013-05-30 15:18:28 ----A---- C:\Windows\system32\WUDFPlatform.dll
2013-05-30 15:18:28 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2013-05-30 15:18:28 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2013-05-30 15:18:27 ----A---- C:\Windows\system32\WUDFx.dll
2013-05-30 15:18:27 ----A---- C:\Windows\system32\WUDFHost.exe
2013-05-30 15:18:27 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2013-05-30 15:17:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-05-30 15:17:02 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-05-30 15:17:02 ----A---- C:\Windows\system32\mshtmled.dll
2013-05-30 15:17:02 ----A---- C:\Windows\system32\iertutil.dll
2013-05-30 15:17:01 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-05-30 15:17:01 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-05-30 15:17:01 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-05-30 15:17:01 ----A---- C:\Windows\system32\ieUnatt.exe
2013-05-30 15:17:01 ----A---- C:\Windows\system32\ieui.dll
2013-05-30 15:17:00 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-05-30 15:17:00 ----A---- C:\Windows\SYSWOW64\url.dll
2013-05-30 15:17:00 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\urlmon.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\url.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\msfeeds.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\jscript9.dll
2013-05-30 15:16:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-05-30 15:16:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-05-30 15:16:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\wininet.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\vbscript.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\jscript.dll
2013-05-30 15:16:58 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-05-30 15:16:55 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-05-30 15:16:55 ----A---- C:\Windows\system32\ieframe.dll
2013-05-30 15:14:58 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-05-30 15:14:58 ----A---- C:\Windows\system32\Wpc.dll
2013-05-30 15:14:58 ----A---- C:\Windows\system32\gameux.dll
2013-05-30 15:14:57 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-05-30 15:14:42 ----A---- C:\Windows\system32\KernelBase.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 15:14:41 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-05-30 15:14:41 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\wow64win.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\wow64.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\kernel32.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\conhost.exe
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 15:14:40 ----A---- C:\Windows\system32\wow64cpu.dll
2013-05-30 15:14:40 ----A---- C:\Windows\system32\ntvdm64.dll
2013-05-30 15:14:39 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 15:14:39 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-05-30 15:13:20 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-05-30 15:13:20 ----A---- C:\Windows\system32\drivers\netio.sys
2013-05-30 15:13:19 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-05-30 15:13:16 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-05-30 15:13:02 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-05-30 15:13:02 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-05-30 15:13:02 ----A---- C:\Windows\system32\winsrv.dll
2013-05-30 15:13:01 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-05-30 15:13:01 ----A---- C:\Windows\SYSWOW64\user.exe
2013-05-30 15:13:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-05-30 15:12:52 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-05-30 15:12:52 ----A---- C:\Windows\system32\tzres.dll
2013-05-30 15:12:44 ----A---- C:\Windows\system32\mstscax.dll
2013-05-30 15:12:43 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-05-30 15:12:43 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-05-30 15:12:43 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-05-30 15:12:43 ----A---- C:\Windows\system32\tsgqec.dll
2013-05-30 15:12:43 ----A---- C:\Windows\system32\aaclient.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\netevent.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\nlasvc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\nlaapi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\netevent.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\netcorehc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\ncsi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-05-30 15:12:29 ----A---- C:\Windows\system32\shell32.dll
2013-05-30 15:12:28 ----A---- C:\Windows\SYSWOW64\shell32.dll
2013-05-30 15:12:28 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2013-05-30 15:12:28 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-05-30 15:12:28 ----A---- C:\Windows\system32\shdocvw.dll
2013-05-30 15:12:28 ----A---- C:\Windows\system32\consent.exe
2013-05-30 15:12:28 ----A---- C:\Windows\system32\authui.dll
2013-05-30 15:12:28 ----A---- C:\Windows\system32\appinfo.dll
2013-05-30 15:12:21 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-05-30 15:12:18 ----A---- C:\Windows\system32\msxml6.dll
2013-05-30 15:12:18 ----A---- C:\Windows\system32\msxml3.dll
2013-05-30 15:12:17 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-05-30 15:12:17 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-05-30 15:12:16 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2013-05-30 15:12:16 ----A---- C:\Windows\SYSWOW64\browcli.dll
2013-05-30 15:12:16 ----A---- C:\Windows\system32\netapi32.dll
2013-05-30 15:12:16 ----A---- C:\Windows\system32\browser.dll
2013-05-30 15:12:16 ----A---- C:\Windows\system32\browcli.dll
2013-05-30 15:12:14 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2013-05-30 15:12:14 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2013-05-30 15:12:14 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-05-30 15:12:14 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-05-30 15:12:11 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-05-30 15:12:10 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-05-30 15:12:09 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2013-05-30 15:12:09 ----A---- C:\Windows\system32\kerberos.dll
2013-05-30 15:12:08 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-05-30 15:12:08 ----A---- C:\Windows\system32\win32spl.dll
2013-05-30 15:12:08 ----A---- C:\Windows\system32\usp10.dll
2013-05-30 15:12:07 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-05-30 15:12:06 ----A---- C:\Windows\SYSWOW64\srclient.dll
2013-05-30 15:12:06 ----A---- C:\Windows\system32\srcore.dll
2013-05-30 15:12:02 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-05-30 15:12:02 ----A---- C:\Windows\system32\ncrypt.dll
2013-05-30 15:12:01 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-05-30 15:12:01 ----A---- C:\Windows\system32\wintrust.dll
2013-05-30 15:11:58 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-05-30 15:11:57 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-05-30 15:11:57 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-30 15:11:57 ----A---- C:\Windows\system32\cdd.dll
2013-05-30 15:11:56 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2013-05-30 15:11:56 ----A---- C:\Windows\system32\dpnet.dll
2013-05-30 15:11:54 ----A---- C:\Windows\system32\drivers\fvevol.sys
2013-05-30 15:11:53 ----A---- C:\Windows\system32\wwansvc.dll
2013-05-30 15:11:53 ----A---- C:\Windows\system32\wwanprotdim.dll
2013-05-30 15:11:53 ----A---- C:\Windows\system32\taskhost.exe
2013-05-30 15:11:52 ----A---- C:\Windows\SYSWOW64\synceng.dll
2013-05-30 15:11:52 ----A---- C:\Windows\system32\synceng.dll
2013-05-30 15:11:45 ----A---- C:\Windows\system32\win32k.sys
2013-05-30 15:11:43 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-05-30 15:11:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-05-30 15:11:41 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-05-30 15:11:41 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2013-05-30 15:11:41 ----A---- C:\Windows\system32\smss.exe
2013-05-30 15:11:41 ----A---- C:\Windows\system32\csrsrv.dll
2013-05-30 15:11:38 ----A---- C:\Windows\system32\localspl.dll
2013-05-30 15:11:32 ----A---- C:\Windows\system32\crypt32.dll
2013-05-30 15:11:31 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-05-30 15:11:31 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-05-30 15:11:31 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-05-30 15:11:31 ----A---- C:\Windows\system32\cryptsvc.dll
2013-05-30 15:11:31 ----A---- C:\Windows\system32\cryptnet.dll
2013-05-30 15:03:47 ----A---- C:\Windows\system32\spoolsv.exe
2013-05-30 15:03:47 ----A---- C:\Windows\splwow64.exe
2013-05-29 18:09:20 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\XUSSoft
2013-05-29 15:15:36 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Opera
2013-05-29 15:15:27 ----D---- C:\Program Files (x86)\Opera
2013-05-28 21:46:18 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Google
2013-05-23 19:25:27 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Avira
2013-05-23 19:21:03 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2013-05-23 19:19:55 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2013-05-23 19:19:55 ----A---- C:\Windows\system32\drivers\avipbb.sys
2013-05-23 19:19:55 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2013-05-23 19:19:49 ----D---- C:\ProgramData\Avira
2013-05-23 19:19:49 ----D---- C:\Program Files (x86)\Avira
2013-05-23 18:58:22 ----D---- C:\Program Files\Common Files\Adobe
2013-05-23 18:57:37 ----D---- C:\Program Files\Adobe
2013-05-23 14:58:43 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Apple Computer
2013-05-22 21:13:50 ----D---- C:\Program Files (x86)\CR2 Converter
2013-05-22 14:04:23 ----D---- C:\ProgramData\Apple Computer
2013-05-22 14:04:23 ----D---- C:\Program Files (x86)\QuickTime
2013-05-22 14:04:01 ----D---- C:\ProgramData\Apple
2013-05-22 14:04:01 ----D---- C:\Program Files (x86)\Apple Software Update
2013-05-22 13:54:51 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Publish Providers
2013-05-21 22:04:55 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Xfire
2013-05-21 22:04:50 ----D---- C:\ProgramData\Xfire
2013-05-21 22:04:50 ----D---- C:\Program Files (x86)\Xfire2
2013-05-20 03:52:41 ----D---- C:\T3Fun
2013-05-20 02:39:25 ----D---- C:\ProgramData\PMB Files
2013-05-20 02:39:15 ----D---- C:\Program Files (x86)\Pando Networks
2013-05-20 00:12:36 ----D---- C:\Program Files (x86)\Ask.com
2013-05-19 23:11:44 ----D---- C:\Fraps
2013-05-16 22:28:13 ----D---- C:\Program Files\Rainmeter
2013-05-16 22:28:07 ----D---- C:\ProgramData\Package Cache
2013-05-16 22:19:48 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Rainmeter
2013-05-16 20:36:42 ----D---- C:\Program Files (x86)\Halo Combat Evolved
2013-05-15 15:56:11 ----D---- C:\fastboot
2013-05-14 18:59:03 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Leadertech
2013-05-14 18:55:00 ----D---- C:\Program Files (x86)\EA Sports
2013-05-13 22:33:39 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2013-05-13 22:33:22 ----D---- C:\Windows\PCHEALTH
2013-05-13 22:33:22 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2013-05-13 22:33:22 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-05-13 22:32:03 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-05-13 22:31:50 ----D---- C:\Program Files\Microsoft Office
2013-05-13 22:31:40 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2013-05-13 22:31:16 ----D---- C:\Program Files (x86)\Microsoft Office
2013-05-13 22:31:15 ----D---- C:\ProgramData\Microsoft Help
2013-05-13 22:30:55 ----RHD---- C:\MSOCache
2013-05-13 21:16:04 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\LibreOffice
2013-05-13 21:12:33 ----D---- C:\Program Files (x86)\LibreOffice 4.0
2013-05-13 21:05:04 ----D---- C:\ProgramData\id Software
2013-05-13 20:18:33 ----D---- C:\Windows\SYSWOW64\directx
2013-05-13 18:35:36 ----D---- C:\ProgramData\WarThunder
2013-05-13 18:34:55 ----D---- C:\Program Files (x86)\War Thunder
2013-05-13 17:41:40 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Trillian
žádám o preventivní kontrolu logu,
Děkuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Psyhcodelic at 2013-06-10 19:00:51
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 43 GB (26%) free of 167 GB
Total RAM: 4094 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:01:03, on 10.6.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16483)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Users\Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Ask.com\Updater\Updater.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Psyhcodelic.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=113480 ... 43a405a405
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (file missing)
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Kerio VPN Client] "C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe" /tray
O4 - HKCU\..\Run: [Google Update] "C:\Users\Psyhcodelic\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Fences.lnk = C:\Program Files (x86)\Stardock\Fences\Fences.exe
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download video on this page - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/300
O8 - Extra context menu item: Download video this links to - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/301
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Psyhcodelic\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Download Video - {B4FECE59-6D0A-4EE6-A07F-E6A94F846E55} - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/300 (file missing)
O9 - Extra 'Tools' menuitem: Download video on this page - {B4FECE59-6D0A-4EE6-A07F-E6A94F846E55} - res://C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YVD_IEX.dll/300 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{66F21A65-FBE5-4A37-A3F9-37C8DC463698}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{8DDE1AE4-40D0-4487-B768-E11376EA5E9D}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: DisplayFusionService - Binary Fortress Software - C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Kerio VPN Client Service (KVPNCSvc) - Kerio Technologies Inc. - C:\Program Files (x86)\Kerio\VPN Client\kvpncsvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Acronis OS Selector activator (OS Selector) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15137 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
winlogon.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000007c4
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-fbbb89e6-ed2e-4853-ac15-54e5fcfdaef4 -SystemEventPortName:HostProcess-d0accb78-166f-488c-9135-226525c012d1 -IoCancelEventPortName:HostProcess-fbac92b3-c588-49e3-bd2f-94c5c2439a75 -NonStateChangingEventPortName:HostProcess-b41ae9c7-6d8c-482a-b9e8-bb037e7cf0fc -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:69021318-9c08-463a-91c7-73ccf1964524 -DeviceGroupId:WpdFsGroup
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
"C:\Users\Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files\Rainmeter\Rainmeter.exe"
"C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\sppsvc.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe" "132038" "63d5518e-4d85-490f-9279-5794e02a455e" "C:\Program Files (x86)\DisplayFusion\Hooks\AppHookx86_71C2806E-68FE-487F-8235-4DA35D784DC2.dll"
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5068.0.331091443\246130257" --supports-dual-gpus=false --gpu-vendor-id=0x1002 --gpu-device-id=0x9440 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.7000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.1.1559735211\774972502" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.3.352738733\378143627" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.4.1897910011\1915414031" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.5.296721235\992412006" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.6.1221047984\778560119" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.7.1560771570\1225355924" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.8.386405905\546257560" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.9.1111382967\339552517" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.10.120165734\1802225275" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.11.443484784\392465614" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.12.759596119\822308053" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.13.2019580461\1634082702" /prefetch:673131151
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --extension-process --renderer-print-preview --enable-threaded-compositing --channel="5068.14.1904240517\620429341" /prefetch:673131151
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
taskeng.exe {B494BF80-6E82-4C11-8AF8-A2F416A1DC19}
"C:\Program Files (x86)\Kerio\VPN Client\kvpncsvc.exe"
"C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe"
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwndDynamic/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.190.1835046435\1377170956" /prefetch:673131151
C:\Windows\splwow64.exe 8192
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
taskeng.exe {233282EA-3CB9-46DA-9D7A-AD0D28943B04}
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwndDynamic/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.215.1474976046\608120090" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe13_ Global\UsGthrCtrlFltPipeMssGthrPipe13 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Psyhcodelic\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_1/DisabledProviders_16/ForceCompositingMode/thread/InfiniteCache/No/InstantDummy/DummyGroup5 channel:stable mods:9/InstantExtended/Control2 channel:stable/OmniboxHQPReplaceHUPProhibitTrumpingInlineableResult/Standard/OmniboxSearchSuggestTrialStarted2013Q1/19/OneClickSignIn/Standard/OverlappedReadImpact/OverlappedReadEnabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SpdyCwnd/cwndDynamic/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/" --renderer-print-preview --enable-threaded-compositing --channel="5068.227.1794617910\286085244" /prefetch:673131151
"C:\Users\Psyhcodelic\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2857271893-2709921192-1482975336-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2857271893-2709921192-1482975336-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-05-14 6307960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-06-03 462752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14 4531320]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
KMPlayer Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-06-03 171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - KMPlayer Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll []
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-03-11 9569096]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-03-27 12459112]
"Fences"=C:\Program Files (x86)\Stardock\Fences\Fences.exe [2012-10-29 4017368]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Psyhcodelic\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-03 116648]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2013-05-20 4284976]
"DisplayFusion"=C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [2013-04-26 7283072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMD AVT]
Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2013-04-01 1719944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO]
C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe [2011-11-23 213304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPA]
C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe [2011-11-23 184120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvUpdater]
C:\Users\Psyhcodelic\AppData\Roaming\DRPSu\DrvUpdater.exe [2012-06-20 195256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
C:\Program Files (x86)\Origin\Origin.exe [2013-04-24 3497552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Psyhcodelic\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-03 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesAirMessage]
C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [2012-06-08 958392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2012-06-08 21432]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2012-06-08 3521464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2012-05-03 17355912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files (x86)\uTorrent\uTorrent.exe [2013-05-08 802136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
C:\PROGRA~2\MCAFEE~1\30937D~1.207\SSSCHE~1.EXE [2011-06-17 272528]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"Driver Genius"= []
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2013-04-01 1719944]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-05-23 345312]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-11-16 641704]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe aml []
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5.5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]
"Kerio VPN Client"=C:\Program Files (x86)\Kerio\VPN Client\kvpncgui.exe [2010-03-02 4986728]
C:\Users\Psyhcodelic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Psyhcodelic\AppData\Roaming\Dropbox\bin\Dropbox.exe
Fences.lnk - C:\Program Files (x86)\Stardock\Fences\Fences.exe
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2012-10-29 551640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=0
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe"="C:\Program Files (x86)\Tomabo\YouTube Video Downloader\YouTubeVideoDownloader.exe:*:Enabled:YouTube Video Downloader"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"VIDC.XFR1"=xfcodec64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-06-10 19:00:51 ----D---- C:\rsit
2013-06-10 19:00:51 ----D---- C:\Program Files\trend micro
2013-06-10 17:01:16 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.technic
2013-06-10 16:39:39 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.minecraft
2013-06-10 16:09:08 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Kerio
2013-06-10 16:08:17 ----D---- C:\Program Files (x86)\Kerio
2013-06-06 19:29:55 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.minecraft_2012.7.4_13.12.48
2013-06-06 19:27:18 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\.techniclauncher
2013-06-05 20:37:25 ----A---- C:\Windows\system32\drivers\VBoxDrv.sys
2013-06-05 20:36:47 ----A---- C:\Windows\system32\drivers\VBoxUSBMon.sys
2013-06-05 20:36:46 ----DC---- C:\Windows\system32\DRVSTORE
2013-06-05 20:36:43 ----D---- C:\Program Files\Oracle
2013-06-05 19:36:55 ----D---- C:\ProgramData\ATI
2013-06-05 19:36:52 ----D---- C:\Program Files (x86)\AMD AVT
2013-06-05 19:36:41 ----D---- C:\Program Files (x86)\AMD APP
2013-06-05 14:50:13 ----D---- C:\Program Files (x86)\FinalWire
2013-06-05 14:46:56 ----D---- C:\Program Files\PeerBlock
2013-06-04 20:39:23 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\TeamViewer
2013-06-04 17:14:00 ----SHD---- C:\Users\Psyhcodelic\AppData\Roaming\Common
2013-06-04 17:13:57 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\DisplayFusion
2013-06-04 17:13:31 ----D---- C:\ProgramData\Binary Fortress Software
2013-06-04 17:13:24 ----D---- C:\Program Files (x86)\DisplayFusion
2013-06-04 02:33:53 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Dropbox
2013-06-03 20:12:38 ----D---- C:\Program Files (x86)\T-Mobile
2013-06-03 20:12:31 ----D---- C:\ProgramData\Gemfor
2013-06-03 18:53:10 ----D---- C:\videooutput
2013-06-03 18:53:07 ----D---- C:\Program Files (x86)\Smallvideosoft
2013-06-03 18:53:07 ----A---- C:\Windows\SYSWOW64\xvidvfw.dll
2013-06-03 18:53:07 ----A---- C:\Windows\SYSWOW64\xvidcore.dll
2013-06-03 18:53:07 ----A---- C:\Windows\SYSWOW64\NCMedia2.dll
2013-06-03 18:46:12 ----D---- C:\Program Files (x86)\FreeTime
2013-06-03 18:32:04 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Tomabo
2013-06-03 18:32:03 ----D---- C:\Program Files (x86)\Tomabo
2013-06-03 16:49:17 ----D---- C:\ProgramData\Sun
2013-06-03 16:49:10 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-06-03 16:49:09 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2013-06-03 16:49:09 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-06-03 16:48:54 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-06-03 16:48:54 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-06-03 16:48:54 ----A---- C:\Windows\SYSWOW64\java.exe
2013-06-03 16:48:46 ----D---- C:\Program Files (x86)\Java
2013-06-03 00:32:37 ----D---- C:\Program Files (x86)\Valve
2013-05-30 15:48:21 ----D---- C:\Program Files\Google
2013-05-30 15:41:07 ----A---- C:\Windows\system32\Wdfres.dll
2013-05-30 15:41:07 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2013-05-30 15:41:07 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-05-30 15:20:30 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-05-30 15:20:29 ----A---- C:\Windows\system32\mshtml.dll
2013-05-30 15:19:13 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-05-30 15:19:13 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-05-30 15:19:13 ----A---- C:\Windows\system32\atmlib.dll
2013-05-30 15:19:13 ----A---- C:\Windows\system32\atmfd.dll
2013-05-30 15:18:28 ----A---- C:\Windows\system32\WUDFSvc.dll
2013-05-30 15:18:28 ----A---- C:\Windows\system32\WUDFPlatform.dll
2013-05-30 15:18:28 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2013-05-30 15:18:28 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2013-05-30 15:18:27 ----A---- C:\Windows\system32\WUDFx.dll
2013-05-30 15:18:27 ----A---- C:\Windows\system32\WUDFHost.exe
2013-05-30 15:18:27 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2013-05-30 15:17:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-05-30 15:17:02 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-05-30 15:17:02 ----A---- C:\Windows\system32\mshtmled.dll
2013-05-30 15:17:02 ----A---- C:\Windows\system32\iertutil.dll
2013-05-30 15:17:01 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-05-30 15:17:01 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-05-30 15:17:01 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-05-30 15:17:01 ----A---- C:\Windows\system32\ieUnatt.exe
2013-05-30 15:17:01 ----A---- C:\Windows\system32\ieui.dll
2013-05-30 15:17:00 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-05-30 15:17:00 ----A---- C:\Windows\SYSWOW64\url.dll
2013-05-30 15:17:00 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\urlmon.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\url.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\msfeeds.dll
2013-05-30 15:17:00 ----A---- C:\Windows\system32\jscript9.dll
2013-05-30 15:16:59 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-05-30 15:16:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-05-30 15:16:59 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\wininet.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\vbscript.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\jsproxy.dll
2013-05-30 15:16:59 ----A---- C:\Windows\system32\jscript.dll
2013-05-30 15:16:58 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-05-30 15:16:55 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-05-30 15:16:55 ----A---- C:\Windows\system32\ieframe.dll
2013-05-30 15:14:58 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-05-30 15:14:58 ----A---- C:\Windows\system32\Wpc.dll
2013-05-30 15:14:58 ----A---- C:\Windows\system32\gameux.dll
2013-05-30 15:14:57 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-05-30 15:14:42 ----A---- C:\Windows\system32\KernelBase.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 15:14:41 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 15:14:41 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-05-30 15:14:41 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\wow64win.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\wow64.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\kernel32.dll
2013-05-30 15:14:41 ----A---- C:\Windows\system32\conhost.exe
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-05-30 15:14:40 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-05-30 15:14:40 ----A---- C:\Windows\system32\wow64cpu.dll
2013-05-30 15:14:40 ----A---- C:\Windows\system32\ntvdm64.dll
2013-05-30 15:14:39 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-05-30 15:14:39 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-05-30 15:13:20 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-05-30 15:13:20 ----A---- C:\Windows\system32\drivers\netio.sys
2013-05-30 15:13:19 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-05-30 15:13:16 ----A---- C:\Windows\system32\drivers\ntfs.sys
2013-05-30 15:13:02 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-05-30 15:13:02 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-05-30 15:13:02 ----A---- C:\Windows\system32\winsrv.dll
2013-05-30 15:13:01 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-05-30 15:13:01 ----A---- C:\Windows\SYSWOW64\user.exe
2013-05-30 15:13:01 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-05-30 15:12:52 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-05-30 15:12:52 ----A---- C:\Windows\system32\tzres.dll
2013-05-30 15:12:44 ----A---- C:\Windows\system32\mstscax.dll
2013-05-30 15:12:43 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2013-05-30 15:12:43 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2013-05-30 15:12:43 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2013-05-30 15:12:43 ----A---- C:\Windows\system32\tsgqec.dll
2013-05-30 15:12:43 ----A---- C:\Windows\system32\aaclient.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\netevent.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\nlasvc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\nlaapi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\netevent.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\netcorehc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\ncsi.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\iphlpsvc.dll
2013-05-30 15:12:36 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-05-30 15:12:29 ----A---- C:\Windows\system32\shell32.dll
2013-05-30 15:12:28 ----A---- C:\Windows\SYSWOW64\shell32.dll
2013-05-30 15:12:28 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2013-05-30 15:12:28 ----A---- C:\Windows\SYSWOW64\authui.dll
2013-05-30 15:12:28 ----A---- C:\Windows\system32\shdocvw.dll
2013-05-30 15:12:28 ----A---- C:\Windows\system32\consent.exe
2013-05-30 15:12:28 ----A---- C:\Windows\system32\authui.dll
2013-05-30 15:12:28 ----A---- C:\Windows\system32\appinfo.dll
2013-05-30 15:12:21 ----A---- C:\Windows\system32\OxpsConverter.exe
2013-05-30 15:12:18 ----A---- C:\Windows\system32\msxml6.dll
2013-05-30 15:12:18 ----A---- C:\Windows\system32\msxml3.dll
2013-05-30 15:12:17 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-05-30 15:12:17 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-05-30 15:12:16 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2013-05-30 15:12:16 ----A---- C:\Windows\SYSWOW64\browcli.dll
2013-05-30 15:12:16 ----A---- C:\Windows\system32\netapi32.dll
2013-05-30 15:12:16 ----A---- C:\Windows\system32\browser.dll
2013-05-30 15:12:16 ----A---- C:\Windows\system32\browcli.dll
2013-05-30 15:12:14 ----A---- C:\Windows\SYSWOW64\dhcpcsvc6.dll
2013-05-30 15:12:14 ----A---- C:\Windows\SYSWOW64\dhcpcore6.dll
2013-05-30 15:12:14 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2013-05-30 15:12:14 ----A---- C:\Windows\system32\dhcpcore6.dll
2013-05-30 15:12:11 ----A---- C:\Windows\system32\drivers\ndis.sys
2013-05-30 15:12:10 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2013-05-30 15:12:09 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2013-05-30 15:12:09 ----A---- C:\Windows\system32\kerberos.dll
2013-05-30 15:12:08 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-05-30 15:12:08 ----A---- C:\Windows\system32\win32spl.dll
2013-05-30 15:12:08 ----A---- C:\Windows\system32\usp10.dll
2013-05-30 15:12:07 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-05-30 15:12:06 ----A---- C:\Windows\SYSWOW64\srclient.dll
2013-05-30 15:12:06 ----A---- C:\Windows\system32\srcore.dll
2013-05-30 15:12:02 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-05-30 15:12:02 ----A---- C:\Windows\system32\ncrypt.dll
2013-05-30 15:12:01 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-05-30 15:12:01 ----A---- C:\Windows\system32\wintrust.dll
2013-05-30 15:11:58 ----A---- C:\Windows\system32\drivers\usb8023.sys
2013-05-30 15:11:57 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2013-05-30 15:11:57 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-30 15:11:57 ----A---- C:\Windows\system32\cdd.dll
2013-05-30 15:11:56 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2013-05-30 15:11:56 ----A---- C:\Windows\system32\dpnet.dll
2013-05-30 15:11:54 ----A---- C:\Windows\system32\drivers\fvevol.sys
2013-05-30 15:11:53 ----A---- C:\Windows\system32\wwansvc.dll
2013-05-30 15:11:53 ----A---- C:\Windows\system32\wwanprotdim.dll
2013-05-30 15:11:53 ----A---- C:\Windows\system32\taskhost.exe
2013-05-30 15:11:52 ----A---- C:\Windows\SYSWOW64\synceng.dll
2013-05-30 15:11:52 ----A---- C:\Windows\system32\synceng.dll
2013-05-30 15:11:45 ----A---- C:\Windows\system32\win32k.sys
2013-05-30 15:11:43 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-05-30 15:11:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-05-30 15:11:41 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-05-30 15:11:41 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2013-05-30 15:11:41 ----A---- C:\Windows\system32\smss.exe
2013-05-30 15:11:41 ----A---- C:\Windows\system32\csrsrv.dll
2013-05-30 15:11:38 ----A---- C:\Windows\system32\localspl.dll
2013-05-30 15:11:32 ----A---- C:\Windows\system32\crypt32.dll
2013-05-30 15:11:31 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-05-30 15:11:31 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-05-30 15:11:31 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-05-30 15:11:31 ----A---- C:\Windows\system32\cryptsvc.dll
2013-05-30 15:11:31 ----A---- C:\Windows\system32\cryptnet.dll
2013-05-30 15:03:47 ----A---- C:\Windows\system32\spoolsv.exe
2013-05-30 15:03:47 ----A---- C:\Windows\splwow64.exe
2013-05-29 18:09:20 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\XUSSoft
2013-05-29 15:15:36 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Opera
2013-05-29 15:15:27 ----D---- C:\Program Files (x86)\Opera
2013-05-28 21:46:18 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Google
2013-05-23 19:25:27 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Avira
2013-05-23 19:21:03 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2013-05-23 19:19:55 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2013-05-23 19:19:55 ----A---- C:\Windows\system32\drivers\avipbb.sys
2013-05-23 19:19:55 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2013-05-23 19:19:49 ----D---- C:\ProgramData\Avira
2013-05-23 19:19:49 ----D---- C:\Program Files (x86)\Avira
2013-05-23 18:58:22 ----D---- C:\Program Files\Common Files\Adobe
2013-05-23 18:57:37 ----D---- C:\Program Files\Adobe
2013-05-23 14:58:43 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Apple Computer
2013-05-22 21:13:50 ----D---- C:\Program Files (x86)\CR2 Converter
2013-05-22 14:04:23 ----D---- C:\ProgramData\Apple Computer
2013-05-22 14:04:23 ----D---- C:\Program Files (x86)\QuickTime
2013-05-22 14:04:01 ----D---- C:\ProgramData\Apple
2013-05-22 14:04:01 ----D---- C:\Program Files (x86)\Apple Software Update
2013-05-22 13:54:51 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Publish Providers
2013-05-21 22:04:55 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Xfire
2013-05-21 22:04:50 ----D---- C:\ProgramData\Xfire
2013-05-21 22:04:50 ----D---- C:\Program Files (x86)\Xfire2
2013-05-20 03:52:41 ----D---- C:\T3Fun
2013-05-20 02:39:25 ----D---- C:\ProgramData\PMB Files
2013-05-20 02:39:15 ----D---- C:\Program Files (x86)\Pando Networks
2013-05-20 00:12:36 ----D---- C:\Program Files (x86)\Ask.com
2013-05-19 23:11:44 ----D---- C:\Fraps
2013-05-16 22:28:13 ----D---- C:\Program Files\Rainmeter
2013-05-16 22:28:07 ----D---- C:\ProgramData\Package Cache
2013-05-16 22:19:48 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Rainmeter
2013-05-16 20:36:42 ----D---- C:\Program Files (x86)\Halo Combat Evolved
2013-05-15 15:56:11 ----D---- C:\fastboot
2013-05-14 18:59:03 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Leadertech
2013-05-14 18:55:00 ----D---- C:\Program Files (x86)\EA Sports
2013-05-13 22:33:39 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2013-05-13 22:33:22 ----D---- C:\Windows\PCHEALTH
2013-05-13 22:33:22 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2013-05-13 22:33:22 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-05-13 22:32:03 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-05-13 22:31:50 ----D---- C:\Program Files\Microsoft Office
2013-05-13 22:31:40 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2013-05-13 22:31:16 ----D---- C:\Program Files (x86)\Microsoft Office
2013-05-13 22:31:15 ----D---- C:\ProgramData\Microsoft Help
2013-05-13 22:30:55 ----RHD---- C:\MSOCache
2013-05-13 21:16:04 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\LibreOffice
2013-05-13 21:12:33 ----D---- C:\Program Files (x86)\LibreOffice 4.0
2013-05-13 21:05:04 ----D---- C:\ProgramData\id Software
2013-05-13 20:18:33 ----D---- C:\Windows\SYSWOW64\directx
2013-05-13 18:35:36 ----D---- C:\ProgramData\WarThunder
2013-05-13 18:34:55 ----D---- C:\Program Files (x86)\War Thunder
2013-05-13 17:41:40 ----D---- C:\Users\Psyhcodelic\AppData\Roaming\Trillian