Pomalý ntb, prosím o kontrolu
Napsal: 01 dub 2014 23:46
Dobrý den, rád bych Vás poprosil o kontrolu mého ntb. Je to už starší ntb, ale nechce se mi ho celý reinstalvoat a rád bych ho dostal do nějakého použivatelného stavu. Starty systému trvají předlouho, vlastně všechno trvá tak dlouho, plus často pozoruji neobvyklé chování her a programů. Například jsem si všiml, že jsem měl několikrát zapnutý proces iexplorer.exe a po jeho vypnutí, mi přestal hučet větráček na celou místnost. Nicméně aplikace se zase znovu zapnula. Zkontrolujte mi prosím logy, jak jsem na tom. Děkuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Easy at 2014-04-02 00:49:30
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 13 GB (13%) free of 100 GB
Total RAM: 3830 MB (22% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:49:34, on 2.4.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16521)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe
C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Steam\Steam.exe
D:\Games\Dota 2\steamapps\common\dota 2 beta\dota.exe
C:\Program Files (x86)\Steam\GameOverlayUI.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera_crashreporter.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Easy.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=16194
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchsun.info/?pid=72 ... g=EN&cc=CZ
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MediaViewV1alpha6498 - {0e2cb2a4-35e4-4ab1-aa50-310aee21d7fb} - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha6498\ie\MediaViewV1alpha6498.dll
O2 - BHO: Microsoft Web Test Recorder 12.0 Helper - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: weBsaVe - {5C663553-2F86-28CB-04B6-ADBD67B6CE6B} - C:\Program Files (x86)\weBsaVe\4f2ujEts.dll
O2 - BHO: Search-NewTab - {6B48303E-1A81-E583-E093-3901A218CCDB} - C:\Program Files (x86)\Search-NewTab\Jm.dll
O2 - BHO: YoutubeAdblocker - {747BD38C-6E5E-BAEC-21E7-F9F5AAE99839} - C:\Program Files (x86)\YoutubeAdblocker\IhTIrymTp.dll
O2 - BHO: MediaWatchV1home2068 - {809bf73f-342d-4e85-9fa5-9c6b72aa245d} - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home2068\ie\MediaWatchV1home2068.dll
O2 - BHO: SeaRch-NewTab - {ABC43D27-3E84-03DA-5C71-36E92DD58006} - C:\Program Files (x86)\SeaRch-NewTab\Pk9dfsNBN.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: websave - {B85E8218-2998-6E43-39D7-9E8DC4BA219E} - C:\Program Files (x86)\websave\GrnL4Ta5.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - (no file)
O2 - BHO: MediaViewV1alpha2733 - {f539bd67-1f73-455e-a93b-fb30b517bc4a} - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2733\ie\MediaViewV1alpha2733.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [Aqalawsulytaila] C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Easy\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Easy\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [WmiPrv] C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe
O4 - HKCU\..\Run: [Ipsoft] regsvr32.exe C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll
O4 - HKCU\..\Run: [Aqalawsulytaila] C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files (x86)\Offline Explorer\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files (x86)\Offline Explorer\Add_AllO.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~3\assist~1\assist~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Automation License Manager Service (almservice) - SIEMENS AG - C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BR.AS.VersionChangerService - Bernecker + Rainer, Industrie-Elektronik Ges.m.b.H., A-5142 Austria, Europe - C:\Windows\SysWOW64\BR.AS.VersionChangerService.exe
O23 - Service: B&R Authorization (BrAuthorizationSvcx) - Bernecker + Rainer, Industrie-Elektronik Ges.m.b.H, A-5142, Austria, Europe - C:\BrAutomation\AsTools\BrAuthorization\BrAuthorizationSvc.exe
O23 - Service: B&R Disk Image (BrDiskImageSvcx) - Bernecker + Rainer, Industrie-Elektronik Ges.m.b.H, A-5142, Austria, Europe - C:\BrAutomation\PVI\V3.00.02\PVI\Tools\PviTransfer\BrDiskImageSvc.exe
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: ODMV3 - Hilscher GmbH - C:\Program Files (x86)\Common Files\Hilscher\ODMV3\ODMV3.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx64) - SIEMENS AG - C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe
O23 - Service: S7TraceServiceX - SIEMENS AG - C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 13473 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
"C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe"
"C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe"
atieclxx
"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 41354192
\??\C:\Windows\system32\conhost.exe "-2401861071530426128127239168-1557228804421813730-2056815248-1131096612-1043504793
C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\rundll32.exe" "c:\progra~3\assist~1\AssistantSvc.dll",service
"C:\Windows\system32\rundll32.exe" "c:\progra~3\assist~1\AssistantSvc.dll",service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\LSI SoftModem\agr64svc.exe"
"C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe"
C:\BrAutomation\AsTools\BrAuthorization\BrAuthorizationSvc.exe
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\PROGRAM FILES\COMMON FILES\SIEMENS\ALMPANELPLUGIN\ALMPANELPLUGIN.EXE" -Embedding
"taskhost.exe"
taskeng.exe {F9101A32-42DF-431D-897F-D63DD76173B6}
c:\programdata\hostit\ws-booster\WS-Booster.exe /schedule /profile "c:\programdata\hostit\ws-booster\1884037147.ini"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
"C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe"
"C:\Windows\System32\regsvr32.exe" C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files (x86)\Mobogenie\DaemonProcess.exe"
C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll
"C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe"
szndesktop.exe default start
"C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "-1270895207-165705909612247338887103968511439719502095407269636124374-193585130
"C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe"
"C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe"
"C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\PNIOMGR.exe" --start 0
\??\C:\Windows\system32\conhost.exe "737800342-4114725801929905632-1880639119742199778-261041774-1820006428-693477999
C:\Windows\SysWOW64\pniopcac.exe 0 {11D91DBA-4D98-4F43-8A39-1E3E2EE098A4}
C:\Windows\SysWOW64\pniopcac.exe 0 {3EA24257-41B0-49AB-8D7E-C42DCE87370F}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"D:\Games\Dota 2\steamapps\common\dota 2 beta\dota.exe" -game dota -steam -novid -console
C:\Program Files (x86)\Steam\GameOverlayUI.exe -pid 3932 -manuallyclearframes 0
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --ran-launcher /crash-reporter-parent-id=1012
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=gpu-process --channel="1012.0.677848166\1474046533" --crash-reporter-pid=2160 --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,27 --reduce-gpu-sandbox --gpu-vendor-id=0x1002 --gpu-device-id=0x68e0 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.743.2.5000 --crash-reporter-pid=2160 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.2.1695485015\395935538" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.3.2058358066\1748816134" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.5.1360104926\632945521" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll" --lang=cs --channel="1012.11.2024505391\791149085" --crash-reporter-pid=2160 /prefetch:-390060480
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll" --lang=cs --channel="1012.12.556975529\1418030686" --crash-reporter-pid=2160 /prefetch:-390060480
C:\Windows\system32\msiexec.exe /V
C:\Windows\System32\svchost.exe -k swprv
taskmgr.exe /2
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.14.1601171979\1102178866" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.15.428588321\225793698" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.16.1201513420\1845819642" /prefetch:673131151
"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding -noframemerging -private
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4716 CREDAT:267521 /prefetch:2
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Users\Easy\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AmiUpdXp.job
C:\Windows\tasks\Driver Booster Update.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2378380575-1943291218-1237148033-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2378380575-1943291218-1237148033-1000UA.job
C:\Windows\tasks\Security Center Update - 3921653254.job
C:\Windows\tasks\WS-Booster-S-1884037147.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2014-01-07 2486592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C663553-2F86-28CB-04B6-ADBD67B6CE6B}]
weBsaVe - C:\Program Files (x86)\weBsaVe\4f2ujEts.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B48303E-1A81-E583-E093-3901A218CCDB}]
Search-NewTab - C:\Program Files (x86)\Search-NewTab\Jm.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{747BD38C-6E5E-BAEC-21E7-F9F5AAE99839}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\IhTIrymTp.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-08-03 553896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABC43D27-3E84-03DA-5C71-36E92DD58006}]
SeaRch-NewTab - C:\Program Files (x86)\SeaRch-NewTab\Pk9dfsNBN.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B85E8218-2998-6E43-39D7-9E8DC4BA219E}]
websave - C:\Program Files (x86)\websave\GrnL4Ta5.x64.dll [2014-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-08-03 211880]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0e2cb2a4-35e4-4ab1-aa50-310aee21d7fb}]
Media View - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha6498\ie\MediaViewV1alpha6498.dll [2014-02-27 87040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{432dd630-7e03-4c97-9d62-b99f52df4fc2}]
Microsoft Web Test Recorder 12.0 Helper - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2013-10-05 71520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C663553-2F86-28CB-04B6-ADBD67B6CE6B}]
weBsaVe - C:\Program Files (x86)\weBsaVe\4f2ujEts.dll [2014-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B48303E-1A81-E583-E093-3901A218CCDB}]
Search-NewTab - C:\Program Files (x86)\Search-NewTab\Jm.dll [2013-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{747BD38C-6E5E-BAEC-21E7-F9F5AAE99839}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\IhTIrymTp.dll [2014-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{809bf73f-342d-4e85-9fa5-9c6b72aa245d}]
Media Watch - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home2068\ie\MediaWatchV1home2068.dll [2014-03-20 87040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABC43D27-3E84-03DA-5C71-36E92DD58006}]
SeaRch-NewTab - C:\Program Files (x86)\SeaRch-NewTab\Pk9dfsNBN.dll [2013-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B85E8218-2998-6E43-39D7-9E8DC4BA219E}]
websave - C:\Program Files (x86)\websave\GrnL4Ta5.dll [2014-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-10-17 669504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f539bd67-1f73-455e-a93b-fb30b517bc4a}]
Media View - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2733\ie\MediaViewV1alpha2733.dll [2014-02-27 87040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-03 2174760]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"cz.seznam.software.autoupdate"=C:\Users\Easy\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"NextLive"=C:\Windows\SysWOW64\rundll32.exe [2009-07-14 44544]
"WmiPrv"=C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe [2014-03-04 580096]
"Ipsoft"=regsvr32.exe C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll []
"Aqalawsulytaila"=C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe [2014-02-07 280576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe [2013-11-21 959904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGupdate]
c:\program files (x86)\appgraffiti\agupdate.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cisco AnyConnect Secure Mobility Agent for Windows]
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\vpnui.exe [2013-07-19 703888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
c:\program files (x86)\daemon tools lite\dtlite.exe [2013-07-03 3673184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Printsrv]
c:\windows\system32\printing_admin_scripts\en-us\pubpr.vbs []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiemensAutomationFileStorage]
d:\portal v12\bin\siemens.automation.objectframe.filestorage.server.exe [2013-02-14 922112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files (x86)\steam\steam.exe [2014-02-25 1821888]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2013-08-26 1989920]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"mobilegeni daemon"=C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [2014-02-14 775872]
"Aqalawsulytaila"=C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe [2014-02-07 280576]
[HKEY_CURRENT_USER\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Aqalawsulytaila"=C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe [2014-02-07 280576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"
======List of files/folders created in the last 1 month======
2014-04-02 00:49:30 ----D---- C:\rsit
2014-04-02 00:49:30 ----D---- C:\Program Files\trend micro
2014-03-26 22:13:42 ----D---- C:\Program Files (x86)\Git
2014-03-23 22:23:34 ----D---- C:\ProgramData\Assistant
2014-03-23 15:44:42 ----D---- C:\Program Files (x86)\MediaWatchV1
2014-03-20 14:12:22 ----D---- C:\Users\Easy\AppData\Roaming\Offline Explorer
2014-03-20 14:12:07 ----D---- C:\download
2014-03-20 14:07:41 ----D---- C:\Program Files (x86)\Offline Explorer
2014-03-20 13:59:30 ----D---- C:\Program Files (x86)\WinHTTrack
2014-03-13 16:54:31 ----A---- C:\Windows\system32\wwansvc.dll
2014-03-13 16:54:30 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-03-13 16:54:30 ----A---- C:\Windows\system32\wer.dll
2014-03-13 16:54:28 ----A---- C:\Windows\system32\win32k.sys
2014-03-13 16:54:27 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-03-13 16:54:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-03-13 16:54:27 ----A---- C:\Windows\system32\iertutil.dll
2014-03-13 16:54:27 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-03-13 16:54:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-03-13 16:54:25 ----A---- C:\Windows\system32\iernonce.dll
2014-03-13 16:54:24 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-03-13 16:54:24 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-03-13 16:54:24 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-03-13 16:54:24 ----A---- C:\Windows\system32\urlmon.dll
2014-03-13 16:54:24 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-03-13 16:54:23 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-03-13 16:54:23 ----A---- C:\Windows\system32\msfeeds.dll
2014-03-13 16:54:23 ----A---- C:\Windows\system32\iesetup.dll
2014-03-13 16:54:23 ----A---- C:\Windows\system32\ie4uinit.exe
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-03-13 16:54:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\jsproxy.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\ieui.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\ieframe.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-03-13 16:54:20 ----A---- C:\Windows\system32\wininet.dll
2014-03-13 16:54:20 ----A---- C:\Windows\system32\jscript9diag.dll
2014-03-13 16:54:20 ----A---- C:\Windows\system32\jscript9.dll
2014-03-13 16:54:20 ----A---- C:\Windows\system32\ieUnatt.exe
2014-03-13 16:54:20 ----A---- C:\Windows\system32\ieapfltr.dll
2014-03-13 16:54:19 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 16:54:19 ----A---- C:\Windows\system32\msrating.dll
2014-03-13 16:54:19 ----A---- C:\Windows\system32\mshtml.dll
2014-03-13 16:54:18 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-03-13 16:54:18 ----A---- C:\Windows\system32\qedit.dll
2014-03-13 16:54:17 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-03-13 16:54:17 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-03-10 17:49:58 ----ASH---- C:\pagefile.sys
2014-03-10 00:44:41 ----SHD---- C:\Config.Msi
2014-03-10 00:43:28 ----A---- C:\AVScanner.ini
2014-03-07 02:43:26 ----D---- C:\ProgramData\SeaRch-NewTab
2014-03-07 02:43:25 ----D---- C:\Program Files (x86)\SeaRch-NewTab
2014-03-07 02:42:45 ----D---- C:\ProgramData\HostIt
2014-03-07 02:42:40 ----D---- C:\Program Files (x86)\WS-Booster
2014-03-07 02:42:24 ----D---- C:\ProgramData\YoutubeAdblocker
2014-03-07 02:42:24 ----D---- C:\Program Files (x86)\YoutubeAdblocker
2014-03-07 02:42:18 ----D---- C:\ProgramData\websave
2014-03-07 02:42:17 ----D---- C:\Program Files (x86)\websave
2014-03-07 02:42:11 ----D---- C:\ProgramData\3222838959d7ca7c
2014-03-05 22:23:37 ----D---- C:\Users\Easy\AppData\Roaming\Capyqiu
2014-03-03 10:16:33 ----SHD---- C:\found.002
======List of files/folders modified in the last 1 month======
2014-04-02 00:49:32 ----D---- C:\Windows\Temp
2014-04-02 00:49:30 ----RD---- C:\Program Files
2014-04-02 00:45:58 ----SHD---- C:\Windows\Installer
2014-04-02 00:45:58 ----D---- C:\Program Files (x86)
2014-04-02 00:45:56 ----D---- C:\Windows\system32\Tasks
2014-04-02 00:44:05 ----SHD---- C:\System Volume Information
2014-04-02 00:23:32 ----D---- C:\Program Files (x86)\Steam
2014-04-02 00:19:40 ----D---- C:\Windows\System32
2014-04-02 00:19:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-04-02 00:16:23 ----D---- C:\Users\Easy\AppData\Roaming\Seznam.cz
2014-04-02 00:13:11 ----D---- C:\Windows\debug
2014-04-02 00:12:21 ----D---- C:\Windows\Prefetch
2014-04-02 00:11:13 ----D---- C:\Users\Easy\AppData\Roaming\newnext.me
2014-04-02 00:10:50 ----D---- C:\Users\Easy\AppData\Roaming\Adobe
2014-04-01 23:17:50 ----D---- C:\Users\Easy\AppData\Roaming\uTorrent
2014-04-01 14:23:10 ----D---- C:\Windows\system32\catroot2
2014-04-01 14:18:28 ----D---- C:\Windows\inf
2014-04-01 14:18:16 ----D---- C:\Windows
2014-04-01 14:18:09 ----D---- C:\Windows\SoftwareDistribution
2014-03-31 07:56:07 ----D---- C:\Users\Easy\AppData\Roaming\AIMP3
2014-03-26 22:06:50 ----D---- C:\Windows\system32\drivers\etc
2014-03-25 10:09:36 ----D---- C:\Windows\system32\config
2014-03-23 22:23:34 ----HD---- C:\ProgramData
2014-03-23 16:51:28 ----D---- C:\Windows\system32\MRT
2014-03-23 16:51:24 ----A---- C:\Windows\system32\MRT.exe
2014-03-23 15:45:43 ----A---- C:\extensions.ini
2014-03-21 16:56:53 ----D---- C:\Program Files (x86)\Opera
2014-03-20 14:07:45 ----D---- C:\Users
2014-03-19 17:20:51 ----D---- C:\Users\Easy\AppData\Roaming\Notepad++
2014-03-16 18:58:29 ----D---- C:\Users\Easy\AppData\Roaming\Skype
2014-03-16 15:32:00 ----D---- C:\Windows\winsxs
2014-03-16 15:27:10 ----D---- C:\Windows\SysWOW64
2014-03-16 15:27:09 ----D---- C:\Program Files\Internet Explorer
2014-03-16 15:27:09 ----D---- C:\Program Files (x86)\Internet Explorer
2014-03-16 04:03:54 ----D---- C:\ProgramData\Microsoft Help
2014-03-16 02:16:16 ----D---- C:\Program Files (x86)\MediaViewV1
2014-03-15 12:55:08 ----D---- C:\Program Files (x86)\Notepad++
2014-03-14 04:11:03 ----D---- C:\Program Files\Microsoft Silverlight
2014-03-14 04:11:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-03-13 16:54:13 ----D---- C:\Windows\system32\catroot
2014-03-12 16:27:28 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-03-10 15:18:23 ----D---- C:\Windows\Microsoft.NET
2014-03-10 15:18:21 ----RSD---- C:\Windows\assembly
2014-03-10 00:47:23 ----D---- C:\Program Files\Microsoft Office
2014-03-10 00:47:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-03-10 00:47:06 ----D---- C:\Program Files (x86)\Microsoft Office
2014-03-10 00:47:02 ----RSD---- C:\Windows\Fonts
2014-03-10 00:47:00 ----D---- C:\Windows\ShellNew
2014-03-10 00:47:00 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-03-10 00:46:52 ----D---- C:\Program Files\Common Files
2014-03-10 00:46:51 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-03-10 00:45:36 ----D---- C:\Program Files\Common Files\System
2014-03-10 00:45:36 ----A---- C:\Windows\win.ini
2014-03-07 02:45:54 ----D---- C:\ProgramData\InstallMate
2014-03-07 02:45:45 ----D---- C:\Windows\Tasks
2014-03-04 01:50:42 ----HD---- C:\Program Files\Uninstall Information
2014-03-04 01:50:42 ----D---- C:\Program Files\WinRAR
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Sidebar
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Portable Devices
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Photo Viewer
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows NT
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Media Player
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Mail
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Journal
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Identity Foundation
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Defender
2014-03-04 01:50:42 ----D---- C:\Program Files\Synaptics
2014-03-04 01:50:42 ----D---- C:\Program Files\SharePoint Client Components
2014-03-04 01:50:42 ----D---- C:\Program Files\Reference Assemblies
2014-03-04 01:50:42 ----D---- C:\Program Files\NetBeans 7.3.1
2014-03-04 01:50:42 ----D---- C:\Program Files\MSBuild
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft.NET
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Visual Studio 12.0
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft SQL Server
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Identity Extensions
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Help Viewer
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Analysis Services
2014-03-04 01:50:42 ----D---- C:\Program Files\MATLAB
2014-03-04 01:50:42 ----D---- C:\Program Files\LSI SoftModem
2014-03-04 01:50:42 ----D---- C:\Program Files\Java
2014-03-04 01:50:42 ----D---- C:\Program Files\IIS Express
2014-03-04 01:50:42 ----D---- C:\Program Files\IIS
2014-03-04 01:50:42 ----D---- C:\Program Files\IDT
2014-03-04 01:50:42 ----D---- C:\Program Files\HP USB Docking Video
2014-03-04 01:50:42 ----D---- C:\Program Files\GIMP 2
2014-03-04 01:50:42 ----D---- C:\Program Files\DVD Maker
2014-03-04 01:50:42 ----D---- C:\Program Files\DisplayLink Core Software
2014-03-04 01:50:42 ----D---- C:\Program Files\Broadcom
2014-03-04 01:50:42 ----D---- C:\Program Files\ATI Technologies
2014-03-04 01:50:42 ----D---- C:\Program Files\ATI
2014-03-04 01:50:42 ----D---- C:\Program Files\Application Verifier
2014-03-03 18:56:01 ----SD---- C:\Users\Easy\AppData\Roaming\Microsoft
2014-03-03 18:15:07 ----D---- C:\Users\Easy\AppData\Roaming\Media Player Classic
2014-03-03 13:40:03 ----D---- C:\projects
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-03-09 16440]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-07-05 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2013-07-05 35344]
R2 s7ousbu64x;SIMATIC USB Service; C:\Windows\system32\DRIVERS\s7ousbu64x.sys [2012-12-19 213504]
R2 s7sn2srtx;PROFINET IO RT-Protocol V2.0; C:\Windows\system32\DRIVERS\s7sn2srtx.sys [2012-05-09 83032]
R2 SNTIE;SIMATIC Industrial Ethernet (ISO); C:\Windows\system32\DRIVERS\sntie.sys [2012-09-06 287016]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-08-13 1209856]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-03-16 6862848]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-03-16 264192]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2013-07-05 22632]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2014-01-29 4749008]
R3 dpmconv;SIMATIC NET DP Driver; C:\Windows\system32\DRIVERS\dpmconv.sys [2012-07-05 259072]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-01-29 888536]
R3 s7odpx2x64;SIMATIC Knotentaufe; C:\Windows\system32\DRIVERS\s7odpx2x64.sys [2012-12-19 71168]
R3 s7oppinx64;SIMATIC PPI Transport; C:\Windows\system32\DRIVERS\s7oppinx64.sys [2012-07-24 107520]
R3 s7oserix64;Siemens PC Serial Cable; C:\Windows\System32\Drivers\s7oserix64.sys [2012-07-24 121856]
R3 s7osmcax64;SIMATIC PC Adapter RS232; C:\Windows\system32\DRIVERS\s7osmcax64.sys [2012-07-24 199680]
R3 s7osobux64;SIMATIC SoftBus; C:\Windows\system32\DRIVERS\s7osobux64.sys [2012-07-24 153600]
R3 s7otmcd64x;SIMATIC Memory Cards; C:\Windows\System32\Drivers\s7otmcd64x.sys [2012-07-24 199680]
R3 s7otranx64;SIMATIC Transport; C:\Windows\system32\DRIVERS\s7otranx64.sys [2012-07-24 260096]
R3 s7otsadx64;SIMATIC TS Adapter RS232; C:\Windows\system32\DRIVERS\s7otsadx64.sys [2012-07-24 196096]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2011-05-09 1803904]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-03 1379376]
R3 vsnl2ada;SIMATIC NET FDL Driver; C:\Windows\system32\DRIVERS\vsnl2ada.sys [2012-05-09 126976]
S1 FileDisk;FileDisk; C:\Windows\system32\drivers\FileDisk.sys []
S3 acsock;acsock; C:\Windows\system32\DRIVERS\acsock64.sys [2013-07-19 112080]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-01-08 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-08 239136]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 127488]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 18944]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 161280]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver; C:\Windows\system32\DRIVERS\ss_bserd.sys [2009-09-19 128000]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-01-08 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-01-08 30208]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 vpnva;Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64; C:\Windows\system32\DRIVERS\vpnva64-6.sys [2013-07-19 52080]
S4 RsFx0300;RsFx0300 Driver; C:\Windows\system32\DRIVERS\RsFx0300.sys [2013-10-04 247488]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 699fd52f;Assistant; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agr64svc.exe [2009-03-27 16896]
R2 almservice;Automation License Manager Service; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [2013-01-08 1608568]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-03-16 203264]
R2 BrAuthorizationSvcx;B&R Authorization; C:\BrAutomation\AsTools\BrAuthorization\BrAuthorizationSvc.exe [2008-12-18 40960]
R2 DisplayLinkService;DisplayLinkManager; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2011-08-09 8329576]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 s7oiehsx64;SIMATIC IEPG Help Service; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [2013-01-07 141688]
R2 S7TraceServiceX;S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe [2013-01-07 472440]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2013-10-04 134336]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
R2 vpnagent;Cisco AnyConnect Secure Mobility Agent; C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2013-07-19 557968]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-25 568512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MSSQLSERVER;SQL Server (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [2013-10-04 370368]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12 257928]
S3 BR.AS.VersionChangerService;BR.AS.VersionChangerService; C:\Windows\SysWOW64\BR.AS.VersionChangerService.exe [2009-07-15 155648]
S3 BrDiskImageSvcx;B&R Disk Image; C:\BrAutomation\PVI\V3.00.02\PVI\Tools\PviTransfer\BrDiskImageSvc.exe [2010-11-11 61952]
S3 c2wts;@%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2010-02-03 15768]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2013-08-22 142336]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-01 111616]
S3 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [2013-10-04 50880]
S3 ODMV3;ODMV3; C:\Program Files (x86)\Common Files\Hilscher\ODMV3\ODMV3.exe [2011-04-26 364544]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 SQLSERVERAGENT;SQL Server Agent (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [2013-10-04 612544]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 VsEtwService120;Visual Studio ETW Event Collection Service; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [2013-10-05 87728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-07-06 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2013-10-04 270016]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Easy at 2014-04-02 00:49:30
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 13 GB (13%) free of 100 GB
Total RAM: 3830 MB (22% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:49:34, on 2.4.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16521)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe
C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Steam\Steam.exe
D:\Games\Dota 2\steamapps\common\dota 2 beta\dota.exe
C:\Program Files (x86)\Steam\GameOverlayUI.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera_crashreporter.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\trend micro\Easy.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=16194
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchsun.info/?pid=72 ... g=EN&cc=CZ
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MediaViewV1alpha6498 - {0e2cb2a4-35e4-4ab1-aa50-310aee21d7fb} - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha6498\ie\MediaViewV1alpha6498.dll
O2 - BHO: Microsoft Web Test Recorder 12.0 Helper - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: weBsaVe - {5C663553-2F86-28CB-04B6-ADBD67B6CE6B} - C:\Program Files (x86)\weBsaVe\4f2ujEts.dll
O2 - BHO: Search-NewTab - {6B48303E-1A81-E583-E093-3901A218CCDB} - C:\Program Files (x86)\Search-NewTab\Jm.dll
O2 - BHO: YoutubeAdblocker - {747BD38C-6E5E-BAEC-21E7-F9F5AAE99839} - C:\Program Files (x86)\YoutubeAdblocker\IhTIrymTp.dll
O2 - BHO: MediaWatchV1home2068 - {809bf73f-342d-4e85-9fa5-9c6b72aa245d} - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home2068\ie\MediaWatchV1home2068.dll
O2 - BHO: SeaRch-NewTab - {ABC43D27-3E84-03DA-5C71-36E92DD58006} - C:\Program Files (x86)\SeaRch-NewTab\Pk9dfsNBN.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: websave - {B85E8218-2998-6E43-39D7-9E8DC4BA219E} - C:\Program Files (x86)\websave\GrnL4Ta5.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - (no file)
O2 - BHO: MediaViewV1alpha2733 - {f539bd67-1f73-455e-a93b-fb30b517bc4a} - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2733\ie\MediaViewV1alpha2733.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [Aqalawsulytaila] C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Easy\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Easy\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [WmiPrv] C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe
O4 - HKCU\..\Run: [Ipsoft] regsvr32.exe C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll
O4 - HKCU\..\Run: [Aqalawsulytaila] C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files (x86)\Offline Explorer\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files (x86)\Offline Explorer\Add_AllO.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~4\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~3\assist~1\assist~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Automation License Manager Service (almservice) - SIEMENS AG - C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BR.AS.VersionChangerService - Bernecker + Rainer, Industrie-Elektronik Ges.m.b.H., A-5142 Austria, Europe - C:\Windows\SysWOW64\BR.AS.VersionChangerService.exe
O23 - Service: B&R Authorization (BrAuthorizationSvcx) - Bernecker + Rainer, Industrie-Elektronik Ges.m.b.H, A-5142, Austria, Europe - C:\BrAutomation\AsTools\BrAuthorization\BrAuthorizationSvc.exe
O23 - Service: B&R Disk Image (BrDiskImageSvcx) - Bernecker + Rainer, Industrie-Elektronik Ges.m.b.H, A-5142, Austria, Europe - C:\BrAutomation\PVI\V3.00.02\PVI\Tools\PviTransfer\BrDiskImageSvc.exe
O23 - Service: @%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000 (c2wts) - Unknown owner - C:\Program Files (x86)\Windows Identity Foundation\v3.5\c2wtshost.exe (file missing)
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: ODMV3 - Hilscher GmbH - C:\Program Files (x86)\Common Files\Hilscher\ODMV3\ODMV3.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx64) - SIEMENS AG - C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe
O23 - Service: S7TraceServiceX - SIEMENS AG - C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 13473 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
"C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe"
"C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe"
atieclxx
"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 41354192
\??\C:\Windows\system32\conhost.exe "-2401861071530426128127239168-1557228804421813730-2056815248-1131096612-1043504793
C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\rundll32.exe" "c:\progra~3\assist~1\AssistantSvc.dll",service
"C:\Windows\system32\rundll32.exe" "c:\progra~3\assist~1\AssistantSvc.dll",service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\LSI SoftModem\agr64svc.exe"
"C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe"
C:\BrAutomation\AsTools\BrAuthorization\BrAuthorizationSvc.exe
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\PROGRAM FILES\COMMON FILES\SIEMENS\ALMPANELPLUGIN\ALMPANELPLUGIN.EXE" -Embedding
"taskhost.exe"
taskeng.exe {F9101A32-42DF-431D-897F-D63DD76173B6}
c:\programdata\hostit\ws-booster\WS-Booster.exe /schedule /profile "c:\programdata\hostit\ws-booster\1884037147.ini"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
"C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe"
"C:\Windows\System32\regsvr32.exe" C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files (x86)\Mobogenie\DaemonProcess.exe"
C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll
"C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe"
szndesktop.exe default start
"C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "-1270895207-165705909612247338887103968511439719502095407269636124374-193585130
"C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe"
"C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe"
"C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\PNIOMGR.exe" --start 0
\??\C:\Windows\system32\conhost.exe "737800342-4114725801929905632-1880639119742199778-261041774-1820006428-693477999
C:\Windows\SysWOW64\pniopcac.exe 0 {11D91DBA-4D98-4F43-8A39-1E3E2EE098A4}
C:\Windows\SysWOW64\pniopcac.exe 0 {3EA24257-41B0-49AB-8D7E-C42DCE87370F}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"D:\Games\Dota 2\steamapps\common\dota 2 beta\dota.exe" -game dota -steam -novid -console
C:\Program Files (x86)\Steam\GameOverlayUI.exe -pid 3932 -manuallyclearframes 0
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --ran-launcher /crash-reporter-parent-id=1012
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=gpu-process --channel="1012.0.677848166\1474046533" --crash-reporter-pid=2160 --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,27 --reduce-gpu-sandbox --gpu-vendor-id=0x1002 --gpu-device-id=0x68e0 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.743.2.5000 --crash-reporter-pid=2160 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.2.1695485015\395935538" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.3.2058358066\1748816134" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.5.1360104926\632945521" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll" --lang=cs --channel="1012.11.2024505391\791149085" --crash-reporter-pid=2160 /prefetch:-390060480
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll" --lang=cs --channel="1012.12.556975529\1418030686" --crash-reporter-pid=2160 /prefetch:-390060480
C:\Windows\system32\msiexec.exe /V
C:\Windows\System32\svchost.exe -k swprv
taskmgr.exe /2
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.14.1601171979\1102178866" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.15.428588321\225793698" /prefetch:673131151
"C:\Program Files (x86)\Opera\20.0.1387.82\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --enable-threaded-compositing --enable-deadline-scheduling --disable-client-side-phishing-detection --enable-ignore-autocomplete-off --disable-delegated-renderer --crash-reporter-pid=2160 --channel="1012.16.1201513420\1845819642" /prefetch:673131151
"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding -noframemerging -private
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4716 CREDAT:267521 /prefetch:2
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Users\Easy\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AmiUpdXp.job
C:\Windows\tasks\Driver Booster Update.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2378380575-1943291218-1237148033-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2378380575-1943291218-1237148033-1000UA.job
C:\Windows\tasks\Security Center Update - 3921653254.job
C:\Windows\tasks\WS-Booster-S-1884037147.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2014-01-07 2486592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C663553-2F86-28CB-04B6-ADBD67B6CE6B}]
weBsaVe - C:\Program Files (x86)\weBsaVe\4f2ujEts.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B48303E-1A81-E583-E093-3901A218CCDB}]
Search-NewTab - C:\Program Files (x86)\Search-NewTab\Jm.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{747BD38C-6E5E-BAEC-21E7-F9F5AAE99839}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\IhTIrymTp.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-08-03 553896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABC43D27-3E84-03DA-5C71-36E92DD58006}]
SeaRch-NewTab - C:\Program Files (x86)\SeaRch-NewTab\Pk9dfsNBN.x64.dll [2013-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B85E8218-2998-6E43-39D7-9E8DC4BA219E}]
websave - C:\Program Files (x86)\websave\GrnL4Ta5.x64.dll [2014-03-07 472064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-08-03 211880]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0e2cb2a4-35e4-4ab1-aa50-310aee21d7fb}]
Media View - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha6498\ie\MediaViewV1alpha6498.dll [2014-02-27 87040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{432dd630-7e03-4c97-9d62-b99f52df4fc2}]
Microsoft Web Test Recorder 12.0 Helper - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2013-10-05 71520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C663553-2F86-28CB-04B6-ADBD67B6CE6B}]
weBsaVe - C:\Program Files (x86)\weBsaVe\4f2ujEts.dll [2014-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B48303E-1A81-E583-E093-3901A218CCDB}]
Search-NewTab - C:\Program Files (x86)\Search-NewTab\Jm.dll [2013-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{747BD38C-6E5E-BAEC-21E7-F9F5AAE99839}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\IhTIrymTp.dll [2014-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{809bf73f-342d-4e85-9fa5-9c6b72aa245d}]
Media Watch - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home2068\ie\MediaWatchV1home2068.dll [2014-03-20 87040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ABC43D27-3E84-03DA-5C71-36E92DD58006}]
SeaRch-NewTab - C:\Program Files (x86)\SeaRch-NewTab\Pk9dfsNBN.dll [2013-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B85E8218-2998-6E43-39D7-9E8DC4BA219E}]
websave - C:\Program Files (x86)\websave\GrnL4Ta5.dll [2014-03-07 423936]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-10-17 669504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f539bd67-1f73-455e-a93b-fb30b517bc4a}]
Media View - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha2733\ie\MediaViewV1alpha2733.dll [2014-02-27 87040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-03 2174760]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"cz.seznam.software.autoupdate"=C:\Users\Easy\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Easy\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"NextLive"=C:\Windows\SysWOW64\rundll32.exe [2009-07-14 44544]
"WmiPrv"=C:\Users\Easy\AppData\Roaming\Adobe\WmiPrv\WmiPrvSE.exe [2014-03-04 580096]
"Ipsoft"=regsvr32.exe C:\Users\Easy\AppData\Local\Ipsoft\lsvxd.dll []
"Aqalawsulytaila"=C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe [2014-02-07 280576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe [2013-11-21 959904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGupdate]
c:\program files (x86)\appgraffiti\agupdate.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cisco AnyConnect Secure Mobility Agent for Windows]
c:\program files (x86)\cisco\cisco anyconnect secure mobility client\vpnui.exe [2013-07-19 703888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
c:\program files (x86)\daemon tools lite\dtlite.exe [2013-07-03 3673184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Printsrv]
c:\windows\system32\printing_admin_scripts\en-us\pubpr.vbs []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiemensAutomationFileStorage]
d:\portal v12\bin\siemens.automation.objectframe.filestorage.server.exe [2013-02-14 922112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files (x86)\steam\steam.exe [2014-02-25 1821888]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2013-08-26 1989920]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"mobilegeni daemon"=C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [2014-02-14 775872]
"Aqalawsulytaila"=C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe [2014-02-07 280576]
[HKEY_CURRENT_USER\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Aqalawsulytaila"=C:\Users\Easy\AppData\Roaming\Capyqiu\ewufoz.exe [2014-02-07 280576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"
======List of files/folders created in the last 1 month======
2014-04-02 00:49:30 ----D---- C:\rsit
2014-04-02 00:49:30 ----D---- C:\Program Files\trend micro
2014-03-26 22:13:42 ----D---- C:\Program Files (x86)\Git
2014-03-23 22:23:34 ----D---- C:\ProgramData\Assistant
2014-03-23 15:44:42 ----D---- C:\Program Files (x86)\MediaWatchV1
2014-03-20 14:12:22 ----D---- C:\Users\Easy\AppData\Roaming\Offline Explorer
2014-03-20 14:12:07 ----D---- C:\download
2014-03-20 14:07:41 ----D---- C:\Program Files (x86)\Offline Explorer
2014-03-20 13:59:30 ----D---- C:\Program Files (x86)\WinHTTrack
2014-03-13 16:54:31 ----A---- C:\Windows\system32\wwansvc.dll
2014-03-13 16:54:30 ----A---- C:\Windows\SYSWOW64\wer.dll
2014-03-13 16:54:30 ----A---- C:\Windows\system32\wer.dll
2014-03-13 16:54:28 ----A---- C:\Windows\system32\win32k.sys
2014-03-13 16:54:27 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-03-13 16:54:27 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-03-13 16:54:27 ----A---- C:\Windows\system32\iertutil.dll
2014-03-13 16:54:27 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-03-13 16:54:26 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-03-13 16:54:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-03-13 16:54:25 ----A---- C:\Windows\system32\iernonce.dll
2014-03-13 16:54:24 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-03-13 16:54:24 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-03-13 16:54:24 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-03-13 16:54:24 ----A---- C:\Windows\system32\urlmon.dll
2014-03-13 16:54:24 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-03-13 16:54:23 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-03-13 16:54:23 ----A---- C:\Windows\system32\msfeeds.dll
2014-03-13 16:54:23 ----A---- C:\Windows\system32\iesetup.dll
2014-03-13 16:54:23 ----A---- C:\Windows\system32\ie4uinit.exe
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-03-13 16:54:22 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-03-13 16:54:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\jsproxy.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\ieui.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\ieframe.dll
2014-03-13 16:54:21 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-03-13 16:54:20 ----A---- C:\Windows\system32\wininet.dll
2014-03-13 16:54:20 ----A---- C:\Windows\system32\jscript9diag.dll
2014-03-13 16:54:20 ----A---- C:\Windows\system32\jscript9.dll
2014-03-13 16:54:20 ----A---- C:\Windows\system32\ieUnatt.exe
2014-03-13 16:54:20 ----A---- C:\Windows\system32\ieapfltr.dll
2014-03-13 16:54:19 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 16:54:19 ----A---- C:\Windows\system32\msrating.dll
2014-03-13 16:54:19 ----A---- C:\Windows\system32\mshtml.dll
2014-03-13 16:54:18 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-03-13 16:54:18 ----A---- C:\Windows\system32\qedit.dll
2014-03-13 16:54:17 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-03-13 16:54:17 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-03-10 17:49:58 ----ASH---- C:\pagefile.sys
2014-03-10 00:44:41 ----SHD---- C:\Config.Msi
2014-03-10 00:43:28 ----A---- C:\AVScanner.ini
2014-03-07 02:43:26 ----D---- C:\ProgramData\SeaRch-NewTab
2014-03-07 02:43:25 ----D---- C:\Program Files (x86)\SeaRch-NewTab
2014-03-07 02:42:45 ----D---- C:\ProgramData\HostIt
2014-03-07 02:42:40 ----D---- C:\Program Files (x86)\WS-Booster
2014-03-07 02:42:24 ----D---- C:\ProgramData\YoutubeAdblocker
2014-03-07 02:42:24 ----D---- C:\Program Files (x86)\YoutubeAdblocker
2014-03-07 02:42:18 ----D---- C:\ProgramData\websave
2014-03-07 02:42:17 ----D---- C:\Program Files (x86)\websave
2014-03-07 02:42:11 ----D---- C:\ProgramData\3222838959d7ca7c
2014-03-05 22:23:37 ----D---- C:\Users\Easy\AppData\Roaming\Capyqiu
2014-03-03 10:16:33 ----SHD---- C:\found.002
======List of files/folders modified in the last 1 month======
2014-04-02 00:49:32 ----D---- C:\Windows\Temp
2014-04-02 00:49:30 ----RD---- C:\Program Files
2014-04-02 00:45:58 ----SHD---- C:\Windows\Installer
2014-04-02 00:45:58 ----D---- C:\Program Files (x86)
2014-04-02 00:45:56 ----D---- C:\Windows\system32\Tasks
2014-04-02 00:44:05 ----SHD---- C:\System Volume Information
2014-04-02 00:23:32 ----D---- C:\Program Files (x86)\Steam
2014-04-02 00:19:40 ----D---- C:\Windows\System32
2014-04-02 00:19:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-04-02 00:16:23 ----D---- C:\Users\Easy\AppData\Roaming\Seznam.cz
2014-04-02 00:13:11 ----D---- C:\Windows\debug
2014-04-02 00:12:21 ----D---- C:\Windows\Prefetch
2014-04-02 00:11:13 ----D---- C:\Users\Easy\AppData\Roaming\newnext.me
2014-04-02 00:10:50 ----D---- C:\Users\Easy\AppData\Roaming\Adobe
2014-04-01 23:17:50 ----D---- C:\Users\Easy\AppData\Roaming\uTorrent
2014-04-01 14:23:10 ----D---- C:\Windows\system32\catroot2
2014-04-01 14:18:28 ----D---- C:\Windows\inf
2014-04-01 14:18:16 ----D---- C:\Windows
2014-04-01 14:18:09 ----D---- C:\Windows\SoftwareDistribution
2014-03-31 07:56:07 ----D---- C:\Users\Easy\AppData\Roaming\AIMP3
2014-03-26 22:06:50 ----D---- C:\Windows\system32\drivers\etc
2014-03-25 10:09:36 ----D---- C:\Windows\system32\config
2014-03-23 22:23:34 ----HD---- C:\ProgramData
2014-03-23 16:51:28 ----D---- C:\Windows\system32\MRT
2014-03-23 16:51:24 ----A---- C:\Windows\system32\MRT.exe
2014-03-23 15:45:43 ----A---- C:\extensions.ini
2014-03-21 16:56:53 ----D---- C:\Program Files (x86)\Opera
2014-03-20 14:07:45 ----D---- C:\Users
2014-03-19 17:20:51 ----D---- C:\Users\Easy\AppData\Roaming\Notepad++
2014-03-16 18:58:29 ----D---- C:\Users\Easy\AppData\Roaming\Skype
2014-03-16 15:32:00 ----D---- C:\Windows\winsxs
2014-03-16 15:27:10 ----D---- C:\Windows\SysWOW64
2014-03-16 15:27:09 ----D---- C:\Program Files\Internet Explorer
2014-03-16 15:27:09 ----D---- C:\Program Files (x86)\Internet Explorer
2014-03-16 04:03:54 ----D---- C:\ProgramData\Microsoft Help
2014-03-16 02:16:16 ----D---- C:\Program Files (x86)\MediaViewV1
2014-03-15 12:55:08 ----D---- C:\Program Files (x86)\Notepad++
2014-03-14 04:11:03 ----D---- C:\Program Files\Microsoft Silverlight
2014-03-14 04:11:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-03-13 16:54:13 ----D---- C:\Windows\system32\catroot
2014-03-12 16:27:28 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-03-10 15:18:23 ----D---- C:\Windows\Microsoft.NET
2014-03-10 15:18:21 ----RSD---- C:\Windows\assembly
2014-03-10 00:47:23 ----D---- C:\Program Files\Microsoft Office
2014-03-10 00:47:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-03-10 00:47:06 ----D---- C:\Program Files (x86)\Microsoft Office
2014-03-10 00:47:02 ----RSD---- C:\Windows\Fonts
2014-03-10 00:47:00 ----D---- C:\Windows\ShellNew
2014-03-10 00:47:00 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-03-10 00:46:52 ----D---- C:\Program Files\Common Files
2014-03-10 00:46:51 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-03-10 00:45:36 ----D---- C:\Program Files\Common Files\System
2014-03-10 00:45:36 ----A---- C:\Windows\win.ini
2014-03-07 02:45:54 ----D---- C:\ProgramData\InstallMate
2014-03-07 02:45:45 ----D---- C:\Windows\Tasks
2014-03-04 01:50:42 ----HD---- C:\Program Files\Uninstall Information
2014-03-04 01:50:42 ----D---- C:\Program Files\WinRAR
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Sidebar
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Portable Devices
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Photo Viewer
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows NT
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Media Player
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Mail
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Journal
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Identity Foundation
2014-03-04 01:50:42 ----D---- C:\Program Files\Windows Defender
2014-03-04 01:50:42 ----D---- C:\Program Files\Synaptics
2014-03-04 01:50:42 ----D---- C:\Program Files\SharePoint Client Components
2014-03-04 01:50:42 ----D---- C:\Program Files\Reference Assemblies
2014-03-04 01:50:42 ----D---- C:\Program Files\NetBeans 7.3.1
2014-03-04 01:50:42 ----D---- C:\Program Files\MSBuild
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft.NET
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Visual Studio 12.0
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft SQL Server
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Identity Extensions
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Help Viewer
2014-03-04 01:50:42 ----D---- C:\Program Files\Microsoft Analysis Services
2014-03-04 01:50:42 ----D---- C:\Program Files\MATLAB
2014-03-04 01:50:42 ----D---- C:\Program Files\LSI SoftModem
2014-03-04 01:50:42 ----D---- C:\Program Files\Java
2014-03-04 01:50:42 ----D---- C:\Program Files\IIS Express
2014-03-04 01:50:42 ----D---- C:\Program Files\IIS
2014-03-04 01:50:42 ----D---- C:\Program Files\IDT
2014-03-04 01:50:42 ----D---- C:\Program Files\HP USB Docking Video
2014-03-04 01:50:42 ----D---- C:\Program Files\GIMP 2
2014-03-04 01:50:42 ----D---- C:\Program Files\DVD Maker
2014-03-04 01:50:42 ----D---- C:\Program Files\DisplayLink Core Software
2014-03-04 01:50:42 ----D---- C:\Program Files\Broadcom
2014-03-04 01:50:42 ----D---- C:\Program Files\ATI Technologies
2014-03-04 01:50:42 ----D---- C:\Program Files\ATI
2014-03-04 01:50:42 ----D---- C:\Program Files\Application Verifier
2014-03-03 18:56:01 ----SD---- C:\Users\Easy\AppData\Roaming\Microsoft
2014-03-03 18:15:07 ----D---- C:\Users\Easy\AppData\Roaming\Media Player Classic
2014-03-03 13:40:03 ----D---- C:\projects
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-03-09 16440]
R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-07-05 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2013-07-05 35344]
R2 s7ousbu64x;SIMATIC USB Service; C:\Windows\system32\DRIVERS\s7ousbu64x.sys [2012-12-19 213504]
R2 s7sn2srtx;PROFINET IO RT-Protocol V2.0; C:\Windows\system32\DRIVERS\s7sn2srtx.sys [2012-05-09 83032]
R2 SNTIE;SIMATIC Industrial Ethernet (ISO); C:\Windows\system32\DRIVERS\sntie.sys [2012-09-06 287016]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-08-13 1209856]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-03-16 6862848]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-03-16 264192]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2013-07-05 22632]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2014-01-29 4749008]
R3 dpmconv;SIMATIC NET DP Driver; C:\Windows\system32\DRIVERS\dpmconv.sys [2012-07-05 259072]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-01-29 888536]
R3 s7odpx2x64;SIMATIC Knotentaufe; C:\Windows\system32\DRIVERS\s7odpx2x64.sys [2012-12-19 71168]
R3 s7oppinx64;SIMATIC PPI Transport; C:\Windows\system32\DRIVERS\s7oppinx64.sys [2012-07-24 107520]
R3 s7oserix64;Siemens PC Serial Cable; C:\Windows\System32\Drivers\s7oserix64.sys [2012-07-24 121856]
R3 s7osmcax64;SIMATIC PC Adapter RS232; C:\Windows\system32\DRIVERS\s7osmcax64.sys [2012-07-24 199680]
R3 s7osobux64;SIMATIC SoftBus; C:\Windows\system32\DRIVERS\s7osobux64.sys [2012-07-24 153600]
R3 s7otmcd64x;SIMATIC Memory Cards; C:\Windows\System32\Drivers\s7otmcd64x.sys [2012-07-24 199680]
R3 s7otranx64;SIMATIC Transport; C:\Windows\system32\DRIVERS\s7otranx64.sys [2012-07-24 260096]
R3 s7otsadx64;SIMATIC TS Adapter RS232; C:\Windows\system32\DRIVERS\s7otsadx64.sys [2012-07-24 196096]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2011-05-09 1803904]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-09-08 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-06-03 1379376]
R3 vsnl2ada;SIMATIC NET FDL Driver; C:\Windows\system32\DRIVERS\vsnl2ada.sys [2012-05-09 126976]
S1 FileDisk;FileDisk; C:\Windows\system32\drivers\FileDisk.sys []
S3 acsock;acsock; C:\Windows\system32\DRIVERS\acsock64.sys [2013-07-19 112080]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 clwvd;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-01-08 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-08 239136]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 127488]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 18944]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 161280]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver; C:\Windows\system32\DRIVERS\ss_bserd.sys [2009-09-19 128000]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-01-08 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-01-08 30208]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 vpnva;Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64; C:\Windows\system32\DRIVERS\vpnva64-6.sys [2013-07-19 52080]
S4 RsFx0300;RsFx0300 Driver; C:\Windows\system32\DRIVERS\RsFx0300.sys [2013-10-04 247488]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 699fd52f;Assistant; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agr64svc.exe [2009-03-27 16896]
R2 almservice;Automation License Manager Service; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [2013-01-08 1608568]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-03-16 203264]
R2 BrAuthorizationSvcx;B&R Authorization; C:\BrAutomation\AsTools\BrAuthorization\BrAuthorizationSvc.exe [2008-12-18 40960]
R2 DisplayLinkService;DisplayLinkManager; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [2011-08-09 8329576]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 s7oiehsx64;SIMATIC IEPG Help Service; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [2013-01-07 141688]
R2 S7TraceServiceX;S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe [2013-01-07 472440]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2013-10-04 134336]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2010-09-08 271360]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2013-12-17 5341536]
R2 vpnagent;Cisco AnyConnect Secure Mobility Agent; C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2013-07-19 557968]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-25 568512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 MSSQLSERVER;SQL Server (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [2013-10-04 370368]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12 257928]
S3 BR.AS.VersionChangerService;BR.AS.VersionChangerService; C:\Windows\SysWOW64\BR.AS.VersionChangerService.exe [2009-07-15 155648]
S3 BrDiskImageSvcx;B&R Disk Image; C:\BrAutomation\PVI\V3.00.02\PVI\Tools\PviTransfer\BrDiskImageSvc.exe [2010-11-11 61952]
S3 c2wts;@%ProgramFiles%\Windows Identity Foundation\v3.5\c2wtsres.dll,-1000; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [2010-02-03 15768]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2013-08-22 142336]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-01 111616]
S3 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [2013-10-04 50880]
S3 ODMV3;ODMV3; C:\Program Files (x86)\Common Files\Hilscher\ODMV3\ODMV3.exe [2011-04-26 364544]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 SQLSERVERAGENT;SQL Server Agent (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [2013-10-04 612544]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 VsEtwService120;Visual Studio ETW Event Collection Service; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [2013-10-05 87728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-07-06 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2013-10-04 270016]
-----------------EOF-----------------