prosím o kontrolu logu
Napsal: 18 kvě 2014 11:39
Logfile of random's system information tool 1.09 (written by random/random)
Run by Viktor at 2014-05-18 10:57:23
Microsoft Windows 8.1
System drive C: has 21 GB (17%) free of 122 GB
Total RAM: 8142 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:57:27, on 18. 5. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17037)
Boot mode: Normal
Running processes:
C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe
C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe
C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
C:\Games\World_of_Tanks\WOTLauncher.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\SysWOW64\cmd.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.5\ScriptHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Viktor.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mysearch.avg.com?cid={E49891FB-9 ... 2014-01-27 09:59:20&v=18.0.5.292&pid=safeguard&sg=&sap=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: WsSVRIEHelper - {54F73992-6549-4369-9A0D-84FD310A464A} - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O3 - Toolbar: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [BrowserPlugInHelper] C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHKE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX230"
O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [ABBYY Screenshot Reader Bonus] "C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ShowDesktopAsRun] C:\Users\Viktor\AppData\Roaming\StartMenu\desktop.scf
O4 - HKCU\..\Run: [StartMenu] C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe
O4 - HKCU\..\Run: [AVG-Secure-Search-Update_0414c] "C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" /PROMPT /CMPID=0414c
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: iSCTsysTray.lnk = C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe
O4 - Global Startup: SnugTV Quick Start.lnk = ?
O4 - Global Startup: Wi-Fi MediaConnect.lnk = C:\Program Files (x86)\Philips\Wi-Fi MediaConnect\Wi-Fi MediaConnect.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.5\ViProtocol.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AllShare Framework DMS - Samsung - C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe
O23 - Service: AllShare Play Service - Copyright 2013 SAMSUNG - C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: AVerUpdateServer - AVerMedia TECHNOLOGIES, Inc. - C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: ISCT Always Updated Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_OTPService - Unknown owner - C:\Program Files (x86)\MSI\OTPService\OTPService.exe
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: SnugTV Service - AVerMedia Technologies, Inc. - C:\Program Files (x86)\SnugTV\SnugTV Station\AMAServer.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.5 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15008 bytes
======Listing Processes======
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=80f33e0b-fc94-491f-bf01-fe287fa50467 /coreSdkOptions=4382 /logConfFile="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\0c7d8079-2263-4830-b573-da6f74066142-228-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\" /logPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\log\"
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe"
"C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe"
"C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkDMS.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe" "AllShare Play Service" __i4j_restart
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe"
"C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe"
dashost.exe {1d116908-bdb9-4b0e-91985c25520811bf}
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\MSI\OTPService\OTPService.exe"
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgemca.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\SnugTV\SnugTV Station\AMAServer.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe"
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\WINDOWS\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
taskeng.exe {0EFEC87F-4165-446B-84BA-0A9A868C05F1}
"C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" --RELAUNCH=1 --CMPID=0414c
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
atieclxx
C:\WINDOWS\Explorer.EXE
taskhostex.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe"
"C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" /PROMPT /CMPID=0414c
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe"
"C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
ctfmon.exe
"C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
"C:\Games\World_of_Tanks\WOTLauncher.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://worldoftanks.eu/cs/news/videos/8 ... per-games/
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4420.0.613097069\1011945411" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,28 --gpu-vendor-id=0x1002 --gpu-device-id=0x6819 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.1.1798478166\1420851695" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.2.1443217636\1197003165" /prefetch:673131151
C:\WINDOWS\system32\cmd.exe /c "C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.5\ScriptHelper.exe" --parent-window=0 chrome-extension://ndibdjnfmopecpmkdieinmbadjfpblof/ < \\.\pipe\chrome.nativeMessaging.in.eb09ecc072ef07c9 > \\.\pipe\chrome.nativeMessaging.out.eb09ecc072ef07c9
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.5\ScriptHelper.exe" --parent-window=0 chrome-extension://ndibdjnfmopecpmkdieinmbadjfpblof/
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.6.1237180640\2030752312" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4420.8.837794428\1026372716" --ppapi-flash-args --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.10.1870782101\219587003" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.12.1768316317\395319590" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.14.1137615768\1640536350" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.16.1928576250\314456642" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.18.275360874\521340455" /prefetch:673131151
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe43_ Global\UsGthrCtrlFltPipeMssGthrPipe43 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Users\Viktor\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rel.job
C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rmv.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1ce06f3402ac403.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Viktor\AppData\Roaming\Mozilla\Firefox\Profiles\9yosqzkc.default
prefs.js - "browser.startup.homepage" - "http://www.google.com/webhp?nord=1"
prefs.js - "keyword.URL" - ""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.5\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npwachk.dll
QuickTimePlugin.class
C:\Users\Viktor\AppData\Roaming\Mozilla\Firefox\Profiles\9yosqzkc.default\extensions\
foxmarks@kei.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54F73992-6549-4369-9A0D-84FD310A464A}]
Aimersoft Video Converter Ultimate - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRIEPlugin.dll [2012-11-23 275304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG SafeGuard toolbar - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll [2014-05-09 3592728]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG SafeGuard toolbar - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll [2014-05-09 3592728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-06-12 6548112]
"AllShare Play"=C:\Program Files\Samsung\AllShare Play\utils\AllShare Play Launcher.exe [2013-01-24 407384]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll,LogiFetch []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2013-04-23 1561968]
"OfficeSyncProcess"=C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [2010-03-16 718208]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]
"EPLTarget\P0000000000000000"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHKE.EXE [2013-02-13 283232]
""=C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2013-05-18 844168]
"ABBYY Screenshot Reader Bonus"=C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe [2009-11-25 939272]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2014-02-20 1822400]
"ShowDesktopAsRun"=C:\Users\Viktor\AppData\Roaming\StartMenu\desktop.scf [2013-02-17 81]
"StartMenu"=C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe [2013-11-08 3360000]
"AVG-Secure-Search-Update_0414c"=C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-25 2725912]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2013-02-18 774168]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2012-06-27 485944]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2010-12-09 74752]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2013-04-23 311152]
"BrowserPlugInHelper"=C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe [2012-11-23 400896]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2014-04-06 5180432]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"vProt"=C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2014-05-09 2561560]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-04-17 767200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
iSCTsysTray.lnk - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe
SnugTV Quick Start.lnk - C:\Windows\Installer\{33CFCB69-2FA5-43E8-B8A8-FAA155F870B5}\NewShortcut1_46FEF19C05F1475DAA14D9007DC15270_2.exe
Wi-Fi MediaConnect.lnk - C:\Program Files (x86)\Philips\Wi-Fi MediaConnect\Wi-Fi MediaConnect.exe
C:\Users\Viktor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-05-18 10:57:23 ----D---- C:\rsit
2014-05-18 10:57:23 ----D---- C:\Program Files\trend micro
2014-05-15 15:57:47 ----A---- C:\WINDOWS\SYSWOW64\wusa.exe
2014-05-15 15:57:47 ----A---- C:\WINDOWS\system32\wusa.exe
2014-05-15 15:57:46 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2014-05-15 15:57:46 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2014-05-15 15:57:46 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2014-05-15 15:57:37 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-05-15 15:57:37 ----A---- C:\WINDOWS\system32\twinui.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wups.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\WSReset.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\ubpm.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\storewuauth.dll
2014-05-15 15:57:32 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-05-15 15:57:31 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-05-15 15:57:31 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-05-15 15:57:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\SYSWOW64\mrt100.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\SYSWOW64\mrt_map.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\system32\mrt100.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\system32\mrt_map.dll
2014-05-15 15:56:55 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-05-15 15:56:54 ----A---- C:\WINDOWS\system32\shell32.dll
2014-05-14 16:34:46 ----D---- C:\WINDOWS\SYSWOW64\directx
2014-05-14 14:09:34 ----A---- C:\WINDOWS\system32\WPRO_41_2001woem.tmp
2014-05-13 15:36:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-05-12 16:35:51 ----RD---- C:\WINDOWS\BrowserChoice
2014-05-10 09:52:02 ----DC---- C:\WINDOWS\Panther
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlanhlp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlangpui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\w32tm.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\userenv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\tsgqec.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\sxproxy.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\spp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\SessEnv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\SensorsApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\ReInfo.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\pdh.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\LocationApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\l2gpstore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\kernel32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\FWPUCLNT.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\drvinst.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\davclnt.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\CredentialMigrationHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\WsmWmiPl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlidprov.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlanhlp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlangpui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\w32tm.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\userenv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\tsgqec.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\sxproxy.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\spp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SetNetworkLocation.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SessEnv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\RMapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ReInfo.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ReAgent.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\rasapi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\propsys.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\pdh.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ole32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\nshwfp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\netlogon.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\msxml6.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\msftedit.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\mfsvr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\MDEServer.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\LocationApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\localspl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\kernel32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\kerberos.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\gdi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dxgi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dwmcore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drvinst.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drvcfg.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\wof.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\tcpipreg.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\Classpnp.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dnsapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Display.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\DevPropMgr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dcomp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\davclnt.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dafWfdProvider.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\d3d11.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\cdd.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\BFE.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\authui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\audiosrv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AudioSes.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AudioEng.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\audiodg.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\adtschema.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\aclui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\explorer.exe
2014-05-10 09:50:55 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-05-10 09:50:55 ----AC---- C:\WINDOWS\system32\drivers\hidusb.sys
2014-05-10 09:50:55 ----AC---- C:\WINDOWS\system32\drivers\hidclass.sys
2014-05-10 09:50:55 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-05-10 09:50:55 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-05-10 09:50:55 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-05-10 09:50:08 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-05-10 09:50:08 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-05-10 09:48:54 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2014-05-10 09:48:54 ----D---- C:\WINDOWS\SYSWOW64\BestPractices
2014-05-10 09:48:54 ----D---- C:\WINDOWS\system32\BestPractices
2014-05-10 09:48:54 ----D---- C:\Program Files\Reference Assemblies
2014-05-10 09:48:54 ----D---- C:\Program Files\MSBuild
2014-05-10 09:48:54 ----D---- C:\Program Files (x86)\Reference Assemblies
2014-05-10 09:48:54 ----D---- C:\Program Files (x86)\MSBuild
2014-05-10 09:48:54 ----D---- C:\inetpub
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\wamregps.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\iisRtl.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\iisrstap.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\iisreset.exe
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\ahadmin.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\admwprox.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2014-05-10 09:48:39 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2014-05-10 09:48:39 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2014-05-10 08:58:32 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2014-05-10 08:55:15 ----SD---- C:\Users\Viktor\AppData\Roaming\Microsoft
2014-05-10 08:53:40 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2014-05-10 08:52:51 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2014-05-10 08:52:51 ----D---- C:\Program Files\Realtek
2014-05-10 08:52:44 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-05-10 08:52:43 ----D---- C:\Program Files\AMD
2014-05-10 08:52:27 ----D---- C:\WINDOWS\Prefetch
2014-05-09 15:59:40 ----D---- C:\ProgramData\AVG Secure Search
2014-05-01 02:56:14 ----D---- C:\Program Files (x86)\WOT Statistics 2.5
2014-04-30 17:35:29 ----D---- C:\ProgramData\ATI
2014-04-30 17:22:39 ----D---- C:\Users\Viktor\AppData\Roaming\library_dir
2014-04-30 17:22:29 ----D---- C:\Program Files (x86)\Raptr
2014-04-30 17:22:25 ----D---- C:\Program Files (x86)\AMD AVT
2014-04-30 17:21:32 ----D---- C:\ProgramData\Package Cache
2014-04-29 17:32:31 ----D---- C:\Users\Viktor\AppData\Roaming\TSNotifier
2014-04-25 19:37:15 ----D---- C:\Program Files (x86)\Avg Secure Update
2014-04-25 16:13:40 ----D---- C:\Program Files\TeamSpeak 3 Client
======List of files/folders modified in the last 1 month======
2014-05-18 10:57:23 ----RD---- C:\Program Files
2014-05-18 10:49:15 ----D---- C:\WINDOWS\Temp
2014-05-18 10:00:00 ----D---- C:\WINDOWS\system32\sru
2014-05-18 09:35:55 ----D---- C:\ProgramData\MFAData
2014-05-17 12:50:21 ----D---- C:\WINDOWS\system32\config
2014-05-17 12:02:54 ----D---- C:\WINDOWS\system32\DriverStore
2014-05-17 11:48:26 ----D---- C:\WINDOWS\Microsoft.NET
2014-05-17 11:48:26 ----D---- C:\WINDOWS\Logs
2014-05-17 10:33:04 ----RD---- C:\WINDOWS\System32
2014-05-17 10:33:04 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-17 10:30:53 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-05-16 16:39:38 ----D---- C:\Users\Viktor\AppData\Roaming\ActiveDossierUploader
2014-05-16 14:35:05 ----RD---- C:\WINDOWS\assembly
2014-05-16 14:34:59 ----D---- C:\WINDOWS\rescache
2014-05-16 13:32:02 ----D---- C:\WINDOWS\WinSxS
2014-05-16 13:32:01 ----D---- C:\WINDOWS\SysWOW64
2014-05-16 13:31:21 ----RD---- C:\WINDOWS\ToastData
2014-05-16 13:31:21 ----D---- C:\WINDOWS\WinStore
2014-05-16 13:31:21 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-05-16 13:31:21 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2014-05-16 13:31:21 ----D---- C:\WINDOWS\system32\drivers
2014-05-16 13:31:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-05-16 13:31:21 ----D---- C:\WINDOWS\Inf
2014-05-16 13:31:21 ----D---- C:\WINDOWS\apppatch
2014-05-16 13:31:21 ----D---- C:\Program Files\Windows Defender
2014-05-16 13:31:21 ----D---- C:\Program Files (x86)\Windows Defender
2014-05-16 13:31:20 ----D---- C:\WINDOWS\CbsTemp
2014-05-16 13:30:41 ----D---- C:\WINDOWS\system32\MRT
2014-05-16 13:29:44 ----A---- C:\WINDOWS\system32\MRT.exe
2014-05-16 06:15:18 ----SHD---- C:\WINDOWS\Installer
2014-05-16 06:15:14 ----D---- C:\Program Files (x86)\Internet Explorer
2014-05-15 22:18:23 ----D---- C:\Users\Viktor\AppData\Roaming\Winamp
2014-05-15 16:12:55 ----HD---- C:\Program Files\WindowsApps
2014-05-15 16:12:55 ----D---- C:\WINDOWS\AppReadiness
2014-05-15 15:56:25 ----D---- C:\WINDOWS\system32\catroot2
2014-05-15 06:59:39 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-14 16:34:44 ----D---- C:\Games
2014-05-14 16:28:30 ----SHD---- C:\System Volume Information
2014-05-14 16:28:09 ----AD---- C:\ProgramData\TEMP
2014-05-14 16:10:27 ----D---- C:\WINDOWS\system32\drivers\UMDF
2014-05-14 14:16:17 ----RD---- C:\Program Files (x86)
2014-05-13 23:14:16 ----D---- C:\Users\Viktor\AppData\Roaming\TS3Client
2014-05-12 16:35:51 ----D---- C:\Windows
2014-05-12 16:35:34 ----D---- C:\WINDOWS\system32\restore
2014-05-11 18:58:34 ----D---- C:\WINDOWS\SYSWOW64\config
2014-05-11 10:23:55 ----D---- C:\WINDOWS\system32\wdi
2014-05-10 11:14:27 ----D---- C:\WINDOWS\debug
2014-05-10 10:36:31 ----HD---- C:\WINDOWS\ELAMBKUP
2014-05-10 10:35:58 ----HD---- C:\ProgramData\Common Files
2014-05-10 09:51:18 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2014-05-10 09:51:18 ----D---- C:\WINDOWS\system32\inetsrv
2014-05-10 09:51:09 ----D---- C:\WINDOWS\system32\wbem
2014-05-10 09:51:09 ----D---- C:\WINDOWS\system32\setup
2014-05-10 09:48:54 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-05-10 09:48:54 ----D---- C:\WINDOWS\system32\migration
2014-05-10 09:10:36 ----D---- C:\WINDOWS\system32\LogFiles
2014-05-10 09:06:34 ----SHD---- C:\$Recycle.Bin
2014-05-10 09:06:21 ----D---- C:\WINDOWS\SoftwareDistribution
2014-05-10 08:59:09 ----D---- C:\Program Files\Windows NT
2014-05-10 08:59:04 ----D---- C:\WINDOWS\Registration
2014-05-10 08:58:38 ----D---- C:\WINDOWS\system32\Tasks
2014-05-10 08:58:15 ----RSD---- C:\WINDOWS\Media
2014-05-10 08:57:16 ----D---- C:\WINDOWS\system32\Sysprep
2014-05-10 08:57:15 ----RSD---- C:\WINDOWS\Fonts
2014-05-10 08:57:15 ----D---- C:\WINDOWS\Tasks
2014-05-10 08:57:15 ----D---- C:\WINDOWS\ShellNew
2014-05-10 08:56:53 ----D---- C:\WINDOWS\twain_32
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\xlive
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\WCN
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\sysprep
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\SMI
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\MUI
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\migwiz
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\LogFiles
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\IME
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\catroot
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\WCN
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\spool
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\oobe
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\NDF
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\MUI
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\IME
2014-05-10 08:56:42 ----RD---- C:\Users
2014-05-10 08:56:42 ----HD---- C:\ProgramData
2014-05-10 08:56:42 ----D---- C:\WINDOWS\IME
2014-05-10 08:56:42 ----D---- C:\WINDOWS\Help
2014-05-10 08:56:42 ----D---- C:\WINDOWS\DigitalLocker
2014-05-10 08:56:41 ----SD---- C:\ProgramData\Microsoft
2014-05-10 08:56:41 ----D---- C:\ProgramData\PRICache
2014-05-10 08:56:39 ----SHD---- C:\Program Files (x86)\Windows Sidebar
2014-05-10 08:56:39 ----D---- C:\Program Files (x86)\Windows Media Player
2014-05-10 08:56:38 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-05-10 08:56:38 ----D---- C:\Program Files (x86)\Common Files
2014-05-10 08:56:37 ----SHD---- C:\Program Files\Windows Sidebar
2014-05-10 08:56:37 ----D---- C:\Program Files\Windows Media Player
2014-05-10 08:56:37 ----D---- C:\Program Files\Internet Explorer
2014-05-10 08:56:37 ----D---- C:\Program Files\Common Files\microsoft shared
2014-05-10 08:56:36 ----D---- C:\Program Files\Common Files
2014-05-10 08:55:32 ----D---- C:\WINDOWS\system32\Recovery
2014-05-10 08:52:45 ----D---- C:\AMD
2014-05-10 08:34:14 ----D---- C:\WINDOWS\AUInstallAgent
2014-05-09 15:59:39 ----D---- C:\Program Files (x86)\AVG SafeGuard toolbar
2014-05-01 22:30:26 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-04-30 20:48:14 ----D---- C:\Users\Viktor\AppData\Roaming\StartMenu
2014-04-30 17:22:26 ----D---- C:\ProgramData\AMD
2014-04-30 17:22:20 ----D---- C:\Program Files\ATI Technologies
2014-04-24 17:21:20 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
Run by Viktor at 2014-05-18 10:57:23
Microsoft Windows 8.1
System drive C: has 21 GB (17%) free of 122 GB
Total RAM: 8142 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:57:27, on 18. 5. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17037)
Boot mode: Normal
Running processes:
C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe
C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe
C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe
C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
C:\Games\World_of_Tanks\WOTLauncher.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\SysWOW64\cmd.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.5\ScriptHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Viktor.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mysearch.avg.com?cid={E49891FB-9 ... 2014-01-27 09:59:20&v=18.0.5.292&pid=safeguard&sg=&sap=hp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: WsSVRIEHelper - {54F73992-6549-4369-9A0D-84FD310A464A} - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O3 - Toolbar: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [BrowserPlugInHelper] C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHKE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX230"
O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [ABBYY Screenshot Reader Bonus] "C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ShowDesktopAsRun] C:\Users\Viktor\AppData\Roaming\StartMenu\desktop.scf
O4 - HKCU\..\Run: [StartMenu] C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe
O4 - HKCU\..\Run: [AVG-Secure-Search-Update_0414c] "C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" /PROMPT /CMPID=0414c
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: iSCTsysTray.lnk = C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe
O4 - Global Startup: SnugTV Quick Start.lnk = ?
O4 - Global Startup: Wi-Fi MediaConnect.lnk = C:\Program Files (x86)\Philips\Wi-Fi MediaConnect\Wi-Fi MediaConnect.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.5\ViProtocol.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AllShare Framework DMS - Samsung - C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe
O23 - Service: AllShare Play Service - Copyright 2013 SAMSUNG - C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AVerRemote - AVerMedia - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: AVerUpdateServer - AVerMedia TECHNOLOGIES, Inc. - C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: ISCT Always Updated Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_OTPService - Unknown owner - C:\Program Files (x86)\MSI\OTPService\OTPService.exe
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: SnugTV Service - AVerMedia Technologies, Inc. - C:\Program Files (x86)\SnugTV\SnugTV Station\AMAServer.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.5 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15008 bytes
======Listing Processes======
c:\PROGRA~2\AVG\AVG2014\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe /pipeName=80f33e0b-fc94-491f-bf01-fe287fa50467 /coreSdkOptions=4382 /logConfFile="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\0c7d8079-2263-4830-b573-da6f74066142-228-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2014\" /tempPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\temp\" /logPath="C:\WINDOWS\system32\config\systemprofile\AppData\Local\Avg2014\log\"
wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkManagerDMS.exe"
"C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe"
"C:\Program Files\Samsung\AllShare Framework DMS\1.3.06\AllShareFrameworkDMS.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Samsung\AllShare Play\AllShare Play Service.exe" "AllShare Play Service" __i4j_restart
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe"
"C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe"
"C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe"
dashost.exe {1d116908-bdb9-4b0e-91985c25520811bf}
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\MSI\OTPService\OTPService.exe"
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgemca.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\SnugTV\SnugTV Station\AMAServer.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe"
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\loggingserver.exe" 72648 "C:\ProgramData\AVG Secure Search\Logger\logger.properties"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\WINDOWS\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
taskeng.exe {0EFEC87F-4165-446B-84BA-0A9A868C05F1}
"C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" --RELAUNCH=1 --CMPID=0414c
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
atieclxx
C:\WINDOWS\Explorer.EXE
taskhostex.exe
C:\Windows\System32\skydrive.exe -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe"
"C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" /PROMPT /CMPID=0414c
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe"
"C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe"
"C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
ctfmon.exe
"C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
"C:\Games\World_of_Tanks\WOTLauncher.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://worldoftanks.eu/cs/news/videos/8 ... per-games/
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4420.0.613097069\1011945411" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,28 --gpu-vendor-id=0x1002 --gpu-device-id=0x6819 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.1.1798478166\1420851695" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.2.1443217636\1197003165" /prefetch:673131151
C:\WINDOWS\system32\cmd.exe /c "C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.5\ScriptHelper.exe" --parent-window=0 chrome-extension://ndibdjnfmopecpmkdieinmbadjfpblof/ < \\.\pipe\chrome.nativeMessaging.in.eb09ecc072ef07c9 > \\.\pipe\chrome.nativeMessaging.out.eb09ecc072ef07c9
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.5\ScriptHelper.exe" --parent-window=0 chrome-extension://ndibdjnfmopecpmkdieinmbadjfpblof/
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.6.1237180640\2030752312" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4420.8.837794428\1026372716" --ppapi-flash-args --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.10.1870782101\219587003" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.12.1768316317\395319590" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.14.1137615768\1640536350" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.16.1928576250\314456642" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Default/EmbeddedSearch/Group7 pct:10g stable:pp1 use_cacheable_ntp:1 espv:210 suppress_on_srp:1/ExtensionInstallVerification/Bootstrap/FlashHardwareVideoDecode/Disabled/GoogleNow/Default/OmniboxBundledExperimentV1/POSTPERIOD_StableReorderHoldbackControlR4/OmniboxStopTimer/Standard/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_34/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-pinch --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --enable-software-compositing --channel="4420.18.275360874\521340455" /prefetch:673131151
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe43_ Global\UsGthrCtrlFltPipeMssGthrPipe43 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Users\Viktor\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rel.job
C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rmv.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1ce06f3402ac403.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Viktor\AppData\Roaming\Mozilla\Firefox\Profiles\9yosqzkc.default
prefs.js - "browser.startup.homepage" - "http://www.google.com/webhp?nord=1"
prefs.js - "keyword.URL" - ""
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.5\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.214 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npwachk.dll
QuickTimePlugin.class
C:\Users\Viktor\AppData\Roaming\Mozilla\Firefox\Profiles\9yosqzkc.default\extensions\
foxmarks@kei.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54F73992-6549-4369-9A0D-84FD310A464A}]
Aimersoft Video Converter Ultimate - C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\SVRIEPlugin.dll [2012-11-23 275304]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG SafeGuard toolbar - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll [2014-05-09 3592728]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG SafeGuard toolbar - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.512\AVG SafeGuard toolbar_toolbar.dll [2014-05-09 3592728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-06-12 6548112]
"AllShare Play"=C:\Program Files\Samsung\AllShare Play\utils\AllShare Play Launcher.exe [2013-01-24 407384]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll,LogiFetch []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2013-04-23 1561968]
"OfficeSyncProcess"=C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [2010-03-16 718208]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]
"EPLTarget\P0000000000000000"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHKE.EXE [2013-02-13 283232]
""=C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2013-05-18 844168]
"ABBYY Screenshot Reader Bonus"=C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe [2009-11-25 939272]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2014-02-20 1822400]
"ShowDesktopAsRun"=C:\Users\Viktor\AppData\Roaming\StartMenu\desktop.scf [2013-02-17 81]
"StartMenu"=C:\Users\Viktor\AppData\Roaming\StartMenu\StartMenu.exe [2013-11-08 3360000]
"AVG-Secure-Search-Update_0414c"=C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-25 2725912]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2013-02-18 774168]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2012-06-27 485944]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2010-12-09 74752]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2013-04-23 311152]
"BrowserPlugInHelper"=C:\Program Files (x86)\Aimersoft\Video Converter Ultimate\BrowserPlugInHelper.exe [2012-11-23 400896]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2014\avgui.exe [2014-04-06 5180432]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"vProt"=C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2014-05-09 2561560]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-04-17 767200]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AVer HID Receiver.lnk - C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
iSCTsysTray.lnk - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe
SnugTV Quick Start.lnk - C:\Windows\Installer\{33CFCB69-2FA5-43E8-B8A8-FAA155F870B5}\NewShortcut1_46FEF19C05F1475DAA14D9007DC15270_2.exe
Wi-Fi MediaConnect.lnk - C:\Program Files (x86)\Philips\Wi-Fi MediaConnect\Wi-Fi MediaConnect.exe
C:\Users\Viktor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-05-18 10:57:23 ----D---- C:\rsit
2014-05-18 10:57:23 ----D---- C:\Program Files\trend micro
2014-05-15 15:57:47 ----A---- C:\WINDOWS\SYSWOW64\wusa.exe
2014-05-15 15:57:47 ----A---- C:\WINDOWS\system32\wusa.exe
2014-05-15 15:57:46 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2014-05-15 15:57:46 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2014-05-15 15:57:46 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2014-05-15 15:57:37 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-05-15 15:57:37 ----A---- C:\WINDOWS\system32\twinui.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wups.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\WSReset.exe
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\ubpm.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2014-05-15 15:57:36 ----A---- C:\WINDOWS\system32\storewuauth.dll
2014-05-15 15:57:32 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-05-15 15:57:31 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-05-15 15:57:31 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-05-15 15:57:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\SYSWOW64\mrt100.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\SYSWOW64\mrt_map.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\system32\mrt100.dll
2014-05-15 15:57:00 ----A---- C:\WINDOWS\system32\mrt_map.dll
2014-05-15 15:56:55 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-05-15 15:56:54 ----A---- C:\WINDOWS\system32\shell32.dll
2014-05-14 16:34:46 ----D---- C:\WINDOWS\SYSWOW64\directx
2014-05-14 14:09:34 ----A---- C:\WINDOWS\system32\WPRO_41_2001woem.tmp
2014-05-13 15:36:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-05-12 16:35:51 ----RD---- C:\WINDOWS\BrowserChoice
2014-05-10 09:52:02 ----DC---- C:\WINDOWS\Panther
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlanmsm.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlanhlp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlangpui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\wlanapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\w32tm.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\userenv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\tsgqec.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\sxproxy.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\spp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\SessEnv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\SensorsApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\ReInfo.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\pdh.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\LocationApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\l2gpstore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\kernel32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\FWPUCLNT.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\drvinst.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\Display.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\davclnt.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\CredentialMigrationHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\WsmWmiPl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\WSDMon.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlidprov.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlansec.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlanhlp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlangpui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\wlanapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\w32tm.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\userenv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\tsgqec.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\sxproxy.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\spp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SetNetworkLocation.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SessEnv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\RMapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ReInfo.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ReAgent.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\rasapi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\propsys.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\profsvc.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\pdh.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ole32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\nshwfp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\netlogon.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\netcfgx.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\msxml6.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\msftedit.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\mfsvr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\MDEServer.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\LocationApi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\localspl.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\kernel32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\kerberos.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\gdi32.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dxgi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dwmcore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drvinst.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drvcfg.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\wof.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\tcpipreg.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\drivers\Classpnp.sys
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dnsapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\Display.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\DevPropMgr.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dcomp.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\davclnt.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\dafWfdProvider.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\d3d11.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\CredentialMigrationHandler.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\clusapi.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\cdd.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\BFE.DLL
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\authui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\audiosrv.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AudioSes.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AudioEng.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\audiodg.exe
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\adtschema.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\system32\aclui.dll
2014-05-10 09:50:56 ----A---- C:\WINDOWS\explorer.exe
2014-05-10 09:50:55 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2014-05-10 09:50:55 ----AC---- C:\WINDOWS\system32\drivers\hidusb.sys
2014-05-10 09:50:55 ----AC---- C:\WINDOWS\system32\drivers\hidclass.sys
2014-05-10 09:50:55 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-05-10 09:50:55 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-05-10 09:50:55 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2014-05-10 09:50:08 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-05-10 09:50:08 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-05-10 09:48:54 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2014-05-10 09:48:54 ----D---- C:\WINDOWS\SYSWOW64\BestPractices
2014-05-10 09:48:54 ----D---- C:\WINDOWS\system32\BestPractices
2014-05-10 09:48:54 ----D---- C:\Program Files\Reference Assemblies
2014-05-10 09:48:54 ----D---- C:\Program Files\MSBuild
2014-05-10 09:48:54 ----D---- C:\Program Files (x86)\Reference Assemblies
2014-05-10 09:48:54 ----D---- C:\Program Files (x86)\MSBuild
2014-05-10 09:48:54 ----D---- C:\inetpub
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\wamregps.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\iisRtl.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\iisrstap.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\iisreset.exe
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\ahadmin.dll
2014-05-10 09:48:52 ----A---- C:\WINDOWS\system32\admwprox.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2014-05-10 09:48:39 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2014-05-10 09:48:39 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2014-05-10 09:48:39 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2014-05-10 08:58:32 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2014-05-10 08:55:15 ----SD---- C:\Users\Viktor\AppData\Roaming\Microsoft
2014-05-10 08:53:40 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2014-05-10 08:52:51 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2014-05-10 08:52:51 ----D---- C:\Program Files\Realtek
2014-05-10 08:52:44 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-05-10 08:52:43 ----D---- C:\Program Files\AMD
2014-05-10 08:52:27 ----D---- C:\WINDOWS\Prefetch
2014-05-09 15:59:40 ----D---- C:\ProgramData\AVG Secure Search
2014-05-01 02:56:14 ----D---- C:\Program Files (x86)\WOT Statistics 2.5
2014-04-30 17:35:29 ----D---- C:\ProgramData\ATI
2014-04-30 17:22:39 ----D---- C:\Users\Viktor\AppData\Roaming\library_dir
2014-04-30 17:22:29 ----D---- C:\Program Files (x86)\Raptr
2014-04-30 17:22:25 ----D---- C:\Program Files (x86)\AMD AVT
2014-04-30 17:21:32 ----D---- C:\ProgramData\Package Cache
2014-04-29 17:32:31 ----D---- C:\Users\Viktor\AppData\Roaming\TSNotifier
2014-04-25 19:37:15 ----D---- C:\Program Files (x86)\Avg Secure Update
2014-04-25 16:13:40 ----D---- C:\Program Files\TeamSpeak 3 Client
======List of files/folders modified in the last 1 month======
2014-05-18 10:57:23 ----RD---- C:\Program Files
2014-05-18 10:49:15 ----D---- C:\WINDOWS\Temp
2014-05-18 10:00:00 ----D---- C:\WINDOWS\system32\sru
2014-05-18 09:35:55 ----D---- C:\ProgramData\MFAData
2014-05-17 12:50:21 ----D---- C:\WINDOWS\system32\config
2014-05-17 12:02:54 ----D---- C:\WINDOWS\system32\DriverStore
2014-05-17 11:48:26 ----D---- C:\WINDOWS\Microsoft.NET
2014-05-17 11:48:26 ----D---- C:\WINDOWS\Logs
2014-05-17 10:33:04 ----RD---- C:\WINDOWS\System32
2014-05-17 10:33:04 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-17 10:30:53 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-05-16 16:39:38 ----D---- C:\Users\Viktor\AppData\Roaming\ActiveDossierUploader
2014-05-16 14:35:05 ----RD---- C:\WINDOWS\assembly
2014-05-16 14:34:59 ----D---- C:\WINDOWS\rescache
2014-05-16 13:32:02 ----D---- C:\WINDOWS\WinSxS
2014-05-16 13:32:01 ----D---- C:\WINDOWS\SysWOW64
2014-05-16 13:31:21 ----RD---- C:\WINDOWS\ToastData
2014-05-16 13:31:21 ----D---- C:\WINDOWS\WinStore
2014-05-16 13:31:21 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-05-16 13:31:21 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2014-05-16 13:31:21 ----D---- C:\WINDOWS\system32\drivers
2014-05-16 13:31:21 ----D---- C:\WINDOWS\system32\cs-CZ
2014-05-16 13:31:21 ----D---- C:\WINDOWS\Inf
2014-05-16 13:31:21 ----D---- C:\WINDOWS\apppatch
2014-05-16 13:31:21 ----D---- C:\Program Files\Windows Defender
2014-05-16 13:31:21 ----D---- C:\Program Files (x86)\Windows Defender
2014-05-16 13:31:20 ----D---- C:\WINDOWS\CbsTemp
2014-05-16 13:30:41 ----D---- C:\WINDOWS\system32\MRT
2014-05-16 13:29:44 ----A---- C:\WINDOWS\system32\MRT.exe
2014-05-16 06:15:18 ----SHD---- C:\WINDOWS\Installer
2014-05-16 06:15:14 ----D---- C:\Program Files (x86)\Internet Explorer
2014-05-15 22:18:23 ----D---- C:\Users\Viktor\AppData\Roaming\Winamp
2014-05-15 16:12:55 ----HD---- C:\Program Files\WindowsApps
2014-05-15 16:12:55 ----D---- C:\WINDOWS\AppReadiness
2014-05-15 15:56:25 ----D---- C:\WINDOWS\system32\catroot2
2014-05-15 06:59:39 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-14 16:34:44 ----D---- C:\Games
2014-05-14 16:28:30 ----SHD---- C:\System Volume Information
2014-05-14 16:28:09 ----AD---- C:\ProgramData\TEMP
2014-05-14 16:10:27 ----D---- C:\WINDOWS\system32\drivers\UMDF
2014-05-14 14:16:17 ----RD---- C:\Program Files (x86)
2014-05-13 23:14:16 ----D---- C:\Users\Viktor\AppData\Roaming\TS3Client
2014-05-12 16:35:51 ----D---- C:\Windows
2014-05-12 16:35:34 ----D---- C:\WINDOWS\system32\restore
2014-05-11 18:58:34 ----D---- C:\WINDOWS\SYSWOW64\config
2014-05-11 10:23:55 ----D---- C:\WINDOWS\system32\wdi
2014-05-10 11:14:27 ----D---- C:\WINDOWS\debug
2014-05-10 10:36:31 ----HD---- C:\WINDOWS\ELAMBKUP
2014-05-10 10:35:58 ----HD---- C:\ProgramData\Common Files
2014-05-10 09:51:18 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2014-05-10 09:51:18 ----D---- C:\WINDOWS\system32\inetsrv
2014-05-10 09:51:09 ----D---- C:\WINDOWS\system32\wbem
2014-05-10 09:51:09 ----D---- C:\WINDOWS\system32\setup
2014-05-10 09:48:54 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-05-10 09:48:54 ----D---- C:\WINDOWS\system32\migration
2014-05-10 09:10:36 ----D---- C:\WINDOWS\system32\LogFiles
2014-05-10 09:06:34 ----SHD---- C:\$Recycle.Bin
2014-05-10 09:06:21 ----D---- C:\WINDOWS\SoftwareDistribution
2014-05-10 08:59:09 ----D---- C:\Program Files\Windows NT
2014-05-10 08:59:04 ----D---- C:\WINDOWS\Registration
2014-05-10 08:58:38 ----D---- C:\WINDOWS\system32\Tasks
2014-05-10 08:58:15 ----RSD---- C:\WINDOWS\Media
2014-05-10 08:57:16 ----D---- C:\WINDOWS\system32\Sysprep
2014-05-10 08:57:15 ----RSD---- C:\WINDOWS\Fonts
2014-05-10 08:57:15 ----D---- C:\WINDOWS\Tasks
2014-05-10 08:57:15 ----D---- C:\WINDOWS\ShellNew
2014-05-10 08:56:53 ----D---- C:\WINDOWS\twain_32
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\xlive
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\WCN
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\sysprep
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\SMI
2014-05-10 08:56:53 ----D---- C:\WINDOWS\SYSWOW64\MUI
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\migwiz
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\LogFiles
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\IME
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2014-05-10 08:56:52 ----D---- C:\WINDOWS\SYSWOW64\catroot
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\WCN
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\spool
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\oobe
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\NDF
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\MUI
2014-05-10 08:56:51 ----D---- C:\WINDOWS\system32\IME
2014-05-10 08:56:42 ----RD---- C:\Users
2014-05-10 08:56:42 ----HD---- C:\ProgramData
2014-05-10 08:56:42 ----D---- C:\WINDOWS\IME
2014-05-10 08:56:42 ----D---- C:\WINDOWS\Help
2014-05-10 08:56:42 ----D---- C:\WINDOWS\DigitalLocker
2014-05-10 08:56:41 ----SD---- C:\ProgramData\Microsoft
2014-05-10 08:56:41 ----D---- C:\ProgramData\PRICache
2014-05-10 08:56:39 ----SHD---- C:\Program Files (x86)\Windows Sidebar
2014-05-10 08:56:39 ----D---- C:\Program Files (x86)\Windows Media Player
2014-05-10 08:56:38 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-05-10 08:56:38 ----D---- C:\Program Files (x86)\Common Files
2014-05-10 08:56:37 ----SHD---- C:\Program Files\Windows Sidebar
2014-05-10 08:56:37 ----D---- C:\Program Files\Windows Media Player
2014-05-10 08:56:37 ----D---- C:\Program Files\Internet Explorer
2014-05-10 08:56:37 ----D---- C:\Program Files\Common Files\microsoft shared
2014-05-10 08:56:36 ----D---- C:\Program Files\Common Files
2014-05-10 08:55:32 ----D---- C:\WINDOWS\system32\Recovery
2014-05-10 08:52:45 ----D---- C:\AMD
2014-05-10 08:34:14 ----D---- C:\WINDOWS\AUInstallAgent
2014-05-09 15:59:39 ----D---- C:\Program Files (x86)\AVG SafeGuard toolbar
2014-05-01 22:30:26 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-04-30 20:48:14 ----D---- C:\Users\Viktor\AppData\Roaming\StartMenu
2014-04-30 17:22:26 ----D---- C:\ProgramData\AMD
2014-04-30 17:22:20 ----D---- C:\Program Files\ATI Technologies
2014-04-24 17:21:20 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client