Preventivní Kontrola, Děkuji
Napsal: 01 srp 2014 19:56
Logfile of random's system information tool 1.10 (written by random/random)
Run by Wareza at 2014-08-01 20:53:13
Microsoft Windows 7 Home Premium
System drive C: has 26 GB (11%) free of 238 GB
Total RAM: 4091 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:53:19, on 1.8.2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Normal
Running processes:
C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe
C:\Windows\System32\PrintDisp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Users\Wareza\AppData\Local\VNT\vntldr.exe
C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe
C:\Users\Wareza\AppData\Local\Temp\SkyMonkAM__2155_il2428.exe
C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Wareza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5250
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: CrossriderApp0057050 - {11111111-1111-1111-1111-110511701150} - C:\Program Files (x86)\SavePass\SavePass-bho.dll
O2 - BHO: CrossriderApp0061762 - {11111111-1111-1111-1111-110611171162} - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O3 - Toolbar: (no name) - {828DC97A-2277-4E10-92A9-4907FA0922A9} - (no file)
O4 - HKLM\..\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [FontExpertType1Loader] C:\Program Files (x86)\FontExpert\Type1Loader.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Nástroj WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
O4 - HKLM\..\Run: [VNT] C:\Program Files (x86)\VNT\vntldr.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKCU\..\Run: [DriveCrypt Startup] C:\Program Files (x86)\DriveCrypt\DriveCrypt.exe /WS
O4 - HKCU\..\Run: [SmartSerialMail Sending] C:\Program Files (x86)\JAM Software\SmartSerialMail\SmartSerialMailServiceApp.exe /delayedstart
O4 - HKCU\..\Run: [tedcgtelwn] wscript.exe //B "C:\Users\Wareza\AppData\Local\Temp\tedcgtelwn..vbs"
O4 - HKCU\..\Run: [qrnvvhxtfg] wscript.exe //B "C:\Users\Wareza\AppData\Local\Temp\qrnvvhxtfg..vbs"
O4 - HKCU\..\Run: [Pokki] C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Wareza\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: qrnvvhxtfg..vbs
O4 - Startup: tedcgtelwn..vbs
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Atomic Email Hunter - C:\Program Files (x86)\AtomPark\Atomic Email Hunter\ie.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Extract e-mail addresses - C:\Program Files (x86)\AtomPark\Atomic Email Studio\modules\Hunter\ie.htm
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Extract e-mail addresses - {491A6C2B-1046-486b-8A8F-7D26BCB79A9B} - C:\Program Files (x86)\AtomPark\Atomic Email Studio\modules\Hunter\ie.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Extract e-mail addresses - {491A6C2B-1046-486b-8A8F-7D26BCB79A9B} - C:\Program Files (x86)\AtomPark\Atomic Email Studio\modules\Hunter\ie.htm (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{32C913EE-9640-4023-93A9-F7A94D537652}: NameServer = 4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: CrypKey License - Unknown owner - C:\Windows\system32\crypserv.exe (file missing)
O23 - Service: DriveCrypt Service (DriveCryptService) - Unknown owner - C:\Program Files (x86)\DriveCrypt\DcrServ.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Sentinel Local License Manager (hasplms) - Unknown owner - C:\Windows\system32\hasplms.exe (file missing)
O23 - Service: HDRExpose3Service - Unknown owner - C:\Program Files\UCT\HDR Expose 3\HDRExpose3Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\nlssrv32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Printer Control - Unknown owner - C:\Windows\system32\PrintCtrl.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCDApp\StartHelp.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\SysWOW64\PSIService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD Backup (WDBackup) - Western Digital - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: WD Rules (WDRulesService) - Western Digital - C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 18745 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 32165920
\??\C:\Windows\system32\conhost.exe "-1469446462-24901943-1795427553-5770267731418599919-452001495794982546-802203594
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
taskeng.exe {97D335DC-D15A-4589-97BE-CB431B498041}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
taskeng.exe {E5CDF462-01ED-468B-9D7F-DA1133FA936B}
"C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe"
"C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-10.exe" /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /awdJubQ='SavePass' /iwZphDOV=1000 /WlUVNkF=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /AUrZlSbRE=http://logs.genstatsnet.com /strmlzPp='task' /MluqbclGU=''
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\crypserv.exe
"C:\Program Files (x86)\DriveCrypt\DcrServ.exe"
C:\Windows\system32\hasplms.exe -run
"C:\Program Files\UCT\HDR Expose 3\HDRExpose3Service.exe"
"C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\SysWOW64\nlssrv32.exe
"C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PrintCtrl.exe
"C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe"
"C:\Windows\System32\PrintDisp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
"C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
"C:\Users\Wareza\AppData\Local\VNT\vntldr.exe" /EXEC
C:\Windows\SysWOW64\PSIService.exe
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe"
"C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe"
"C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe" /TUStart /pid:4072
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe"
WLIDSvcM.exe 4256
"C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/Yes/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/9/OneClickSignIn/BlueOnWhite/Prefetch/ContentPrefetchPrefetchOff/Prerender/PrerenderMulti/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_01/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="888.2.1482929081\1833150136" /prefetch:3
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
TosBtBty.exe
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\tosBtProc.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe"
"taskhost.exe"
"C:\Users\Wareza\AppData\Local\Temp\SkyMonkAM__2155_il2428.exe"
"C:\Program Files (x86)\HD-V1.9\b82486d5-bb46-4c3f-bb97-2f0f41a249b0.exe" /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /UfxezKjj='Information' /OpCDRWC=1000 /sQjIxQ=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /XlOtcfFVl=http://logs.infogenservice.com
"C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe" /c
"C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe" default restart
"C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "533950929201358046615222617-778379726-17209728441562265620-4034199261756067456
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
"C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-6.exe" /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /coNJs /iUogpmnmb=HD-V1.9 /CgnmDlFbf84380d-77a2-4bc9-a2e7-5540de71071e.dll /rPhBrxCfX925a6da0-08c2-4cac-b63c-87e7d905d204.dll /hfgFCwMmqf7a4cc7e-9a86-4d86-a37b-ee13c88ab168-64.exe /lGCHTpn='nova' /QaZWS=http://js.clientdemocloud.com /HaSZZW='{"asw":[32770, -1602223867, 0]}' /tUhLI='http://update.infogenservice.com/novaru ... pdate.json' /IXonsqn='task' /mcmUK=''
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="8952.0.473162999\833892306" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x9553 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.2.1000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.2.604224725\1082397893" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.3.48905474\277079206" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.4.1374615775\1260337540" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.5.314646503\1324081633" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="8952.10.82561523\1488683136" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.11.221832232\824587545" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/NetworkConnectivity/disable_network_stats/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.14.515600331\135007853" /prefetch:673131151
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/NetworkConnectivity/disable_network_stats/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.33.842534985\570612996" /prefetch:673131151
C:\Windows\system32\vssvc.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe58_ Global\UsGthrCtrlFltPipeMssGthrPipe58 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 504 508 516 65536 512
"C:\Users\Wareza\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-1.job - C:\Program Files (x86)\SavePass\SavePass-codedownloader.exe /pqEPCzi /strmlzPp=task /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /tIDoOVcLd=1.34.7.1 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /SbfFnn=http://js.genstatsnet.com /PWGNFnVAw=ch /llaXMtNA='SavePass' /DNSYbH=http://js.clientdemocloud.com /BCgfKDZqT /XRQmuSjbS='{"asw":[32770, 536870917, 0]}' /JeVlF='http://update.genstatsnet.com/ie_code_a ... pdate.json' /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-10.job - C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-10.exe /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /awdJubQ='SavePass' /iwZphDOV=1000 /WlUVNkF=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /AUrZlSbRE=http://logs.genstatsnet.com /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-11.job - C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-11.exe 001504 6F26FD6331EF42CC8A0AC13B8B685718IE 57050 1405846363 93-0,102-0,104-0,178-288,179-288,180-288,223-288
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-4.job - C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-4.exe /mfoOei /ivGKDm='SavePass' /YroxogYLU='C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53.xpi' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /tIDoOVcLd=1.34.7.1 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /TDlbtL=300 /omxhrzmX=587fea1b-1c76-43c0-8b29-3c3da78e2485@2309207e-4ba6-42d8-b8a2-3b0a22e052b5.com /ncagNs=0.95 /wMkepiDvb=a587fea1b1c7643c08b293c3da78e24852309207e4ba642d8b8a23b0a22e052b5com57050 /iibxsGtwM=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /57050.rdf /awdJubQ='SavePass' /ulVKHxcBF='Just Save!' /xPCOk='OutBrowse' /PWGNFnVAw=ch /XRQmuSjbS='{"asw":[32770, 536870917, 0]}' /BCgfKDZqT /GxINeoL /UFDleiqq /JeVlF='http://update.genstatsnet.com/ff_agent_ ... pdate.json' /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-6.job - C:\Program Files (x86)\SavePass\SavePass-novainstaller.exe /CPJPf /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /tIDoOVcLd=1.34.7.1 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /SbfFnn=http://js.genstatsnet.com /PWGNFnVAw=ch /fZDrKku /llaXMtNA=SavePass /VkkIIyg='nova' /DNSYbH=http://js.clientdemocloud.com /XRQmuSjbS='{"asw":[32770, 536870917, 0]}' /strmlzPp=task /JeVlF='http://update.genstatsnet.com/novacode/ ... pdate.json' /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\aa7a3f39-302c-46f7-8819-f4f38634d18c.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-4.exe /qzWkN=gbbuLTNWVgOfB52rUgxi2Qu8nOtb7I960rFYPBFx21/jNbgYQU8n5s/J7nqXfhidb2mZnjwpHWdZPkRUnibl2M8SlQtILU5znmfS6TkhMMaFFBhdoFsNrS4FcfnPbpnHZFDDRV2C8GNHHnL9mAXofOnAL/RpU+2cG7vjNz8M9jUqG3B4JMeUVV2Ac5LADYCr922hnU6eTxPEuyBtwYB3D97XeJXsbF1MMOwV5OnWIJPViubP2WCLxdqHzd+KrWBPM6X26He7nvJf8ROqt2nbXmkFQdXINnR91os3ftqDYEpp3++yHCAHyU7bCVAP7ZDE9Ur673jadoywQAe7OEk9IqbCBPDmgeXHY7IC6peI503G8RM3QPyr77I6/qMMsgrr6d/5ocebRgzbDd3xCie1C8HX5fvuw/j3lQgjT9hDIKOOnYs2ZNVj4KH6q75Zj8uBJKq2ZzPBuvRNT2/+PoQATeMjruQP3Rvj+UjKY6WugLsI7nvtClNow2HX4VmrlbL1bcFStL6RiEjwVRujXVB+aXC8xiFuo4tRASjTJDPdX0JGHjd0q6oHtaeNTB3kcCJY+l9EgFkoHdh1191X9COGtyRiEbmGnzV+M4hbSNwm5TJ5wl4XKIfH6bFp32YSA/RuQdFUS1jR+q0mcf9EUYz35Gy/FgKSJCUvtxLJbKH6wleMLpbLMfBuygkWMhExiVYlVjrfzkbnOdrKF6Qsf1FljXYma7G/J9VzPhcAMM11fJZh/Vj2pIVyidCSm8uSu8GcYoJxO39+3WHwBmqV5fKCByD9iVsOhBgLjTzZuelyd4fjUvqcm0BFyEf8WEiWckD8T638DIk4rKdqm9l3w17jTEfnbfrjmb9rgcbVQ+2fzVX9H6Bwc0KZc32QYhahoJFA+Rr+9DEhqcxBllxseiRmb5910JOL7xJzJluk4YHT0b4uwFZx6wP0HE5e/yjnCM4OjHu2454Bw+jKANlArXuJIAexneAmAqxpgxdyy+8ccD5K0r9cviDujCcrJhehsfPxbzy7UpD22VLNXbNDC5T1doUSfzhPlgj3Yul03A2Qfw3eHtHOpbU8rI1fnzsvKLky+V9eLjbGBqxgR0+xHp9jYJsmKbBUyJ5ky4CHNZUjzkE0Z5BB+Rxuw5c6+FdwfEoFWTABPQRqOfis8teaWav1A5xr3Rsrzci10UqbwKD9uIoNXRaEPXq5ZzsH+aThO4vJVzh0bmnBrVdTCJoZqrqkcJAUICBgBF0UpmlQ5WB99SS6vui7hP+3vxUFxDMn7Ttihc2oGU0PaiqZ2H1QSIvH5uTg64ofoRhmbAKpn45Gp5xj6B8bmGZZ65DVgXzgkXe3HbsvoPDXwUSIf05RSU5G75XxdROo60cDy/3xbY4cpIk3nqL/YZlDjpoUluGV8Qd1UHtTUGl3CRIG6fTxpTlsXSMnf7gWIdHqVFptv0DaMHuRLpsNpSFExAla3g6DoBYSrCvCY3fcKWiIYsKK1Kf/Iq6CoxwtBFfuNIzwlyzx9pUDhmAdSXP9UlNSxarDqZ6s
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\b82486d5-bb46-4c3f-bb97-2f0f41a249b0.job - C:\Program Files (x86)\HD-V1.9\b82486d5-bb46-4c3f-bb97-2f0f41a249b0.exe /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /UfxezKjj='Information' /OpCDRWC=1000 /sQjIxQ=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /XlOtcfFVl=http://logs.infogenservice.com /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\bdeae81b-09ea-4fc8-93ce-7d0c70c48698.job - C:\Program Files (x86)\HD-V1.9\bdeae81b-09ea-4fc8-93ce-7d0c70c48698.exe 001859 6F26FD6331EF42CC8A0AC13B8B685718IE 61762 1406913860 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 HD-V1.9
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-1.job - C:\Program Files (x86)\HD-V1.9\HD-V1.9-codedownloader.exe /OtYwaHiV /IXonsqn=task /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /iUogpmnmb='HD-V1.9' /QaZWS=http://js.clientdemocloud.com /WOWkiqR /HaSZZW='{"asw":[32770, -1602223867, 0]}' /tUhLI='http://update.infogenservice.com/ie_cod ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-11.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-11.exe /qzWkN=iSkpzKtRrSQagkURWHwN2vjBAUsL5MdUwslLwoFPmpll7pY3Blapym9LNbTBkv1EOE9MrVndKHgi82A+ilnqQt/ie+SaEYp9+Axe+ErzwkXY9Bf+QVwZDS/Qrc7VrMHQjennKIDTwYcjJywe5paBq2WpkMPprHwZMSkXsXFcV+aGnMNqHZpE2c/At912PIEhnp2mB1U7U8+KK8LkYDpX0E4UnUZ3OFtmrf0EuZ5IP92E9Q9tAy2a/KZLDztNxQycGmQvVi6rgEEUGh1b1p9RTWqrxcO2K/HRZFvSFhTF4kczGgFn8NsH3Yb8yszfq2t5PIQHa5w/0h9LGZwAcaxlOwIDqsANcNDwntrPD6zA+v6nnUp0Ehhn6KIttFHbJBWymP38MNY6omaReuJlSzyZ2DUHUYEJUBVYZOm24/+T2zQBaz4UcSy6L3vjWn/u0n/8Smc62ABVVW4vJB8+zgIw9Z9+oJUVLVvY2sGtSWXTHzUDRIgw1wbR4qJ69SSt5mpJMbJTTFPbq5dcDsJBptFaI+Kx/o9blzwZZFxo+uuEpYdGtxhWxOoHR4m0r5lk37cmDLzlL8j3Km5TlsLH+6hYJdONk5nn+BumyITJzW+M1S887JMrGSKJrAh0Nt915jturhcejst8XoluXwOquFehvmVxyjVOLi3aUQiPogGJt78ui3VfKl8Z9tKKJ8HmLgXH1EiAwGhw0D6/YZdXp1eUWfLj2oxCQZH1mAQenE2rHK2JyFwy1zTd1iaeBZLeSs0JZyc+T8VChuvSNAy9f15NN1cN5mvGrMMHkFYwhIDhBOXbFX2kap0UCnTKPISK716D9t8D+Kxsm9vM6KlO4a2iIGppjBUNVwgcRfiAYWfITBi1Wg0oQK53VDxWii8CV/P2ioVu35D/duJ5l5xXzXLmsuKHSedRHEIsbFFSkqe2RlbDORMwkJxRIcLvOJZRB2JjbOSt/Nzvn7ScRznUKtrBq++WV/DlUB7YFGebBrDoFVJlme6Ybffo7rTlMyPYe7XonSkz2hP5FhArRbbMoQdDcF5Z7akWHNCF5SwPsWA+roHpeElsTSZyzxPl72DuamZmY+1pTg3XZJUKN1n52w7+e8aK2St15T0ZJ9SuzGhA9u/aPQ8RzetRWQD3wFoCUuMBwTm/Nj0QgZZA+aPVuMVoZ73r79v6V415Rh/x/w4e+txzRyalfy02quEXqQubdrH1pXGAseMRRY1ccon7U1NcZ3UGkbVhdlf6o6Ds/ujGxKNmk8Cgd36tgnthIqoMCCHIHZI0s5IaJ+VkjyE/CKeqIKouuY1hyxGWwMZlVzRaQD5c2pnc9y3MvPMXRyf4zukUEqsA3mYXdKFy/uYkDjKTSFY+x80EdXNO2vJM7jyd6RUJpzcXQaTWDy4AxngnMr/H1P40TUUpooFetLW5ZwaFMy9vrQ7NcfvKRuJGKGjVLqMlzDVjCAoCWdL19XjBRmCEiDZuQSL0fnbIYXecAOtj+JcAQphKvjDVTAlXgbFMvkks+3JQkQGhqGjuZGtr7kC+CFcU6gZQYR/PNKAuREIUXnJGM0+405nqy5djJz9obtGNH7C9EMiXDOPVcrXRWsFgrRvB5y9WoSqy8TWhfBDEF1brW88fnHdVOiUzIiriasThUzdl/yLA0Tg13HN7+uBgixZvOMQLsUng8NGEvolJm9+gXhzY6ekVKG2FsBhGxQE=
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-3.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-3.exe /qzWkN=g+BL3EpxqZYb7DfId15Gh2FTk+ng52onGgaAeL7zISkXNT1xEKNd2s03YqnmzUBIIFHL53iUygvM031uzHI/VQDrRh3pHRG8WRc3Ou7X56XQf2Dcd5nY8Xs1ieUOjm+/a7/vwYmChKhsG+1688knGtnn8QAAgnEW2e3t2UtxWYFCtocv2cLYZkdyA1ZLKW1oy0/blFJBewI33APpojDF8bNMtkV7A0Ft1KcNrr4H3wXn31PfWFnDnahMiSe6YYln12dPQZCgMiYGkiKMDcppXZUFxPBxxhhVr9Oc44AHL+w94Wp7VwGe5FRLOoNY6j5fsDB1vcu6J66Z44v3nX+99bn1K3MrTjBiAUcMA+HrCcADtH8qqbqeP4juFa0luiCNsKnvjDAzOV2JYDJwEq4ClCU52E6p1H6PQtiWs9Kae04Dux5zX23GjqQ3jaAtNegv3Gmw5iyr7YvjsmUXPY+c70/Nu77jxYWuX6pU8Bd2VS9coL5CONeEDLdCOnAbPrCTfaR3WSg3BOAq6n7G7oIQuGMDrq/bCUVqvSLWb0+hdBxqE4TCoPQ0bhUG7FGf4MDx7HwHo4wEYjOYa16JSypgHIoMfGXJZDlomJS8G6iDJCRVw4nXo4zwmuDdsGN6/scyhI393AJX5LiHVLV3rLrCKowiij1pEXVTcv+caFWwAC8WmI95HfESP3RQZgsvQsrA68ihotCFQXniFtxdrqokcjJ1xOKXiS555I9O/AftQl7f0UyrnfMOdQ0hfgFoPBXkHLnC7sWcwS2LxnmnqJoIisu1zvtSWTXeuw7rRUidaJshUU8B/CIMo1lhHqGVdrB+zUXdL4FDVDrpM7w5xzSBUVLPXnlBC7PGISlkcypgZ1F88TII+zwbg1ZK3E5rHImL9YNiaxwZS3OS1qnjkihb3gxbFiaT973b9X3PrmLwj8VwZT44gFUQmP70p3dflWsMr4Ot/aUR6M8bNNua29Xz4JyUiwk5qlk3xUqvpVpktjZqSJ/xLZJqvOX3hzb2597PmCgxAcgL+4lzWPhZNRdLiUuADpW8YMGykh1T5in0xiDEUOfDDQb8VDWxzmMQoTdl+9ieJ2/r1nJ5SNZEYB2visukyoubwDFcT68pBaSsGpmEV4YcfzLTwjG9HIOPJuMzLEN1NdzHsCHbkkyQ0Z7xv+eQE/pmwvrL18Yu3CWCKsWfHfXAhCYANmOjPEffvBq+nJu3V1Oqn+pGbwpWymSlIqx2kEim0RYmYzzO7zI3jjVLg66sNtoO9ctdUHv15UUsCdr1CWUWhHqr9i+s+kcME7BTR7Np6LxylWv7IFjJtupVophhM26C93S/aSG6RRg7BZbJtzPz2veG6K0GqluwyQ==
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-4.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-4.exe /zUDYVOfKZ /czeXVoVH='HD-V1.9' /guLuXGk='C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168.xpi' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /MBxxWezKH=300 /rQqUqB=0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com /BPldBcs=0.95 /cMtnkAeX=a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762 /JPBSDf=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /61762.rdf /UfxezKjj='HD-V1.9' /BykEld='Turn YouTube videos to High Definition by default' /OlsHtY='InfoHD-V1.8' /aaDFWNW=ch /HaSZZW='{"asw":[32770, -1602223867, 0]}' /WOWkiqR /GjatKFEvu /ouFRYqTVd /tUhLI='http://update.infogenservice.com/ff_age ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5.exe /jkAyfrw /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /RugkKYbJC=http://ipgeoapi.com/ /WTHMYHf=http://update.infogenservice.com /lvDfMb=2 /XlOtcfFVl=http://logs.infogenservice.com /tUhLI='http://update.infogenservice.com/update ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5_user.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5.exe /jkAyfrw /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /RugkKYbJC=http://ipgeoapi.com/ /WTHMYHf=http://update.infogenservice.com /lvDfMb=2 /XlOtcfFVl=http://logs.infogenservice.com /tUhLI='http://update.infogenservice.com/update ... pdate.json' /RwcRQamFg /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-6.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-6.exe /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /coNJs /iUogpmnmb=HD-V1.9 /CgnmDlFbf84380d-77a2-4bc9-a2e7-5540de71071e.dll /rPhBrxCfX925a6da0-08c2-4cac-b63c-87e7d905d204.dll /hfgFCwMmqf7a4cc7e-9a86-4d86-a37b-ee13c88ab168-64.exe /lGCHTpn='nova' /QaZWS=http://js.clientdemocloud.com /HaSZZW='{"asw":[32770, -1602223867, 0]}' /tUhLI='http://update.infogenservice.com/novaru ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-7.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-7.exe /eYUadnJG /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /coNJs /iUogpmnmb=HD-V1.9 /CgnmDlFbf84380d-77a2-4bc9-a2e7-5540de71071e.dll /rPhBrxCfX925a6da0-08c2-4cac-b63c-87e7d905d204.dll /hfgFCwMmqf7a4cc7e-9a86-4d86-a37b-ee13c88ab168-64.exe /lGCHTpn='nova' /QaZWS=http://js.clientdemocloud.com /HaSZZW='{"asw":[32770, -1602223867, 0]}' /IXonsqn=task /tUhLI='http://update.infogenservice.com/novaco ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3893988867-3537961221-3907201996-1000Core.job - C:\Users\Wareza\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3893988867-3537961221-3907201996-1000UA.job - C:\Users\Wareza\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Wareza\AppData\Roaming\Mozilla\Firefox\Profiles\7x9so9sh.default
prefs.js - "browser.search.useDBForOrder" - true
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.60.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@protectdisc.com/NPMPDRM]
"Description"=MPDRM License Acquisition Plugin
"Path"=C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198]
"Description"=15.0.0.198
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
nprjplug.dll
nprpjplug.dll
nsjsrealplayerplugin.xpt
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Users\Wareza\AppData\Roaming\Mozilla\Firefox\Profiles\7x9so9sh.default\extensions\
0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com
39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com
587fea1b-1c76-43c0-8b29-3c3da78e2485@2309207e-4ba6-42d8-b8a2-3b0a22e052b5.com
ffxtlbr@buenosearch.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Wareza\AppData\Roaming\Mozilla\Firefox\Profiles\7x9so9sh.default\searchplugins\
Ask.xml
buenosearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}]
SavePass - C:\Program Files (x86)\SavePass\SavePass-bho64.dll [2014-07-20 796696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171162}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho64.dll [2014-08-01 774000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-16 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}]
SavePass - C:\Program Files (x86)\SavePass\SavePass-bho.dll [2014-07-20 587288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171162}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll [2014-08-01 573296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-15 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-05-07 436600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-15 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-03-19 529784]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{828DC97A-2277-4E10-92A9-4907FA0922A9}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"SmartFaceVWatcher"=C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2010-03-03 35672]
"TosNC"=C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2010-03-09 595816]
"Toshiba TEMPRO"=C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2010-02-11 1050072]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2009-08-13 570680]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2010-02-23 705368]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2010-04-19 136136]
"CanonSolutionMenu"=C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]
"PrintDisp"=C:\Windows\system32\PrintDisp.exe [2011-01-03 976896]
"tedcgtelwn"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\tedcgtelwn..vbs []
"qrnvvhxtfg"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\qrnvvhxtfg..vbs []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DriveCrypt Startup"=C:\Program Files (x86)\DriveCrypt\DriveCrypt.exe [2013-05-09 1249280]
"SmartSerialMail Sending"=C:\Program Files (x86)\JAM Software\SmartSerialMail\SmartSerialMailServiceApp.exe [2011-11-10 12234136]
"tedcgtelwn"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\tedcgtelwn..vbs []
"qrnvvhxtfg"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\qrnvvhxtfg..vbs []
"Pokki"=C:\Users\Wareza\AppData\Local\Pokki\Engine\Launcher.dll [2013-12-05 1271064]
"SUPERAntiSpyware"=C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe [2010-10-25 2408688]
"cz.seznam.software.autoupdate"=C:\Users\Wareza\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TWebCamera"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2009-10-06 1294136]
"FontExpertType1Loader"=C:\Program Files (x86)\FontExpert\Type1Loader.exe [2010-05-14 294208]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-01-20 43848]
"Nástroj WD Quick View"=C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [2012-09-19 5236664]
"VNT"=C:\Program Files (x86)\VNT\vntldr.exe [2014-03-19 196048]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-04 3890208]
"TkBellExe"=C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [2011-12-10 296056]
[HKEY_CURRENT_USER\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Acdiacra"=C:\Users\Wareza\AppData\Roaming\Ebefno\vopow.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Users\Wareza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
qrnvvhxtfg..vbs
tedcgtelwn..vbs
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"C:\Users\Wareza\AppData\Roaming\wind.exe"="C:\Users\Wareza\AppData\Roaming\wind.exe:*:Enabled:Windows Messanger"
"C:\Users\Wareza\AppData\Local\Temp\wind.exe"="C:\Users\Wareza\AppData\Local\Temp\wind.exe:*:Enabled:Windows Messanger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.txt - open -
======List of files/folders created in the last 1 month======
2014-08-01 20:53:13 ----D---- C:\rsit
2014-08-01 20:44:39 ----D---- C:\FRST
2014-08-01 20:18:47 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-08-01 19:41:43 ----D---- C:\Program Files (x86)\Seznam.cz
2014-08-01 19:24:33 ----D---- C:\Program Files (x86)\HD-V1.9
2014-07-20 16:01:47 ----N---- C:\bootsqm.dat
2014-07-20 10:56:04 ----D---- C:\Program Files (x86)\7-Zip
2014-07-20 10:52:50 ----D---- C:\Program Files (x86)\SavePass
2014-07-19 14:55:55 ----A---- C:\Windows\ETKINST.INI
2014-07-18 20:59:50 ----A---- C:\Windows\system32\drivers\aksdf.sys
2014-07-18 20:59:46 ----A---- C:\Windows\SYSWOW64\UNWISE.EXE
2014-07-18 20:04:10 ----D---- C:\ProgramData\ALI213
2014-07-18 17:25:03 ----A---- C:\Windows\system32\hasplms.exe
2014-07-18 17:25:03 ----A---- C:\Windows\system32\aksllmtp.exe
2014-07-18 17:25:02 ----A---- C:\Windows\system32\drivers\aksfridge.sys
2014-07-18 17:24:26 ----A---- C:\Windows\system32\drivers\akshhl.sys
2014-07-18 17:24:26 ----A---- C:\Windows\system32\aksusb4.dll
2014-07-18 17:24:26 ----A---- C:\Windows\system32\akshsp52.dll
2014-07-18 17:24:26 ----A---- C:\Windows\system32\akshhl30.dll
2014-07-18 16:10:19 ----A---- C:\Windows\system32\drivers\multikey.sys
2014-07-18 16:10:16 ----RA---- C:\Windows\SYSWOW64\drivers\nshe.sys
2014-07-17 16:15:20 ----D---- C:\Users\Wareza\AppData\Roaming\proxyeverysvr
2014-07-16 18:34:03 ----A---- C:\Windows\avastSS.scr
2014-07-16 18:32:20 ----A---- C:\Windows\system32\drivers\aswNdisFlt.sys
2014-07-15 20:20:44 ----A---- C:\Windows\system32\TURegOpt.exe
2014-07-15 20:20:40 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2014-07-15 20:20:40 ----A---- C:\Windows\system32\authuitu.dll
2014-07-15 20:20:31 ----D---- C:\ProgramData\AVG Secure Search
2014-07-15 20:18:26 ----D---- C:\Program Files (x86)\TuneUp Utilities 2013
2014-07-15 19:09:28 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-07-15 19:08:58 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-07-08 23:35:17 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-07-06 23:19:50 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2014-07-06 23:19:19 ----D---- C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX
======List of files/folders modified in the last 1 month======
2014-08-01 20:53:17 ----D---- C:\Program Files\trend micro
2014-08-01 20:51:24 ----AD---- C:\Windows
2014-08-01 20:21:24 ----RD---- C:\Program Files (x86)
2014-08-01 20:21:24 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-01 20:20:38 ----D---- C:\Windows\temp
2014-08-01 20:20:17 ----D---- C:\Program Files (x86)\Google
2014-08-01 19:51:32 ----D---- C:\Users\Wareza\AppData\Roaming\Seznam.cz
2014-08-01 19:41:52 ----D---- C:\Windows\Tasks
2014-08-01 19:41:52 ----D---- C:\Windows\system32\Tasks
2014-08-01 19:34:50 ----D---- C:\Users\Wareza\AppData\Roaming\QuickScan
2014-08-01 19:25:14 ----SHD---- C:\Windows\Installer
2014-08-01 19:25:14 ----D---- C:\Config.Msi
2014-08-01 12:55:33 ----D---- C:\Windows\system32\config
2014-08-01 12:37:15 ----D---- C:\Program Files\PCDApp
2014-07-30 22:49:22 ----D---- C:\Users\Wareza\AppData\Roaming\vlc
2014-07-30 20:44:04 ----D---- C:\Users\Wareza\AppData\Roaming\uTorrent
2014-07-29 12:53:30 ----SHD---- C:\System Volume Information
2014-07-26 09:10:09 ----D---- C:\Program Files\Microsoft Silverlight
2014-07-26 09:10:07 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-07-26 09:07:12 ----D---- C:\Windows\system32\MRT
2014-07-26 09:07:07 ----A---- C:\Windows\system32\MRT.exe
2014-07-26 09:06:38 ----D---- C:\ProgramData\Microsoft Help
2014-07-23 13:27:02 ----AD---- C:\Windows\System32
2014-07-23 13:27:01 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-23 13:26:56 ----D---- C:\Windows\inf
2014-07-21 12:57:04 ----D---- C:\Windows\system32\drivers
2014-07-21 12:57:03 ----D---- C:\Windows\system32\DriverStore
2014-07-21 12:57:03 ----D---- C:\Windows\system32\catroot
2014-07-19 20:07:26 ----D---- C:\Windows\SysWOW64
2014-07-19 16:16:38 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-07-19 16:16:35 ----D---- C:\Windows\system32\cs-CZ
2014-07-19 12:54:10 ----D---- C:\Windows\SYSWOW64\drivers
2014-07-19 12:54:10 ----D---- C:\Windows\system
2014-07-18 21:10:35 ----D---- C:\Hry
2014-07-18 20:59:49 ----D---- C:\Windows\system32\Setup
2014-07-18 20:44:50 ----D---- C:\Users\Wareza\AppData\Roaming\DAEMON Tools Lite
2014-07-18 20:44:49 ----D---- C:\ProgramData\DAEMON Tools Lite
2014-07-18 20:04:10 ----D---- C:\ProgramData
2014-07-18 20:00:25 ----D---- C:\Windows\Logs
2014-07-18 17:24:16 ----D---- C:\Program Files (x86)\Common Files
2014-07-16 18:34:12 ----A---- C:\Windows\system32\aswBoot.exe
2014-07-15 20:48:58 ----SHD---- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2014-07-15 20:48:58 ----HDC---- C:\ProgramData\{81083967-5051-4F49-910E-70164AD89C2D}
2014-07-15 20:18:37 ----D---- C:\ProgramData\TuneUp Software
2014-07-15 19:10:24 ----D---- C:\ProgramData\Oracle
2014-07-15 19:08:48 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-07-15 19:08:48 ----A---- C:\Windows\SYSWOW64\java.exe
2014-07-15 18:55:11 ----D---- C:\ProgramData\IObit
2014-07-15 18:55:11 ----D---- C:\Program Files (x86)\IObit
2014-07-09 09:05:23 ----D---- C:\Windows\system32\catroot2
2014-07-09 09:05:17 ----D---- C:\Windows\winsxs
2014-07-08 23:36:17 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-07-02 00:18:15 ----D---- C:\Windows\debug
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2014-07-16 448400]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-16 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-16 224896]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 PCTCore;PCTools KDS; C:\Windows\system32\drivers\PCTCore64.sys [2011-11-14 367912]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2014-07-16 28184]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-16 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-16 1041168]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-17 427360]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R1 NetworkX;NetworkX; C:\Windows\System32\ckldrv.sys [2010-03-19 30272]
R1 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [2012-07-15 55384]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-07-28 81768]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aksdf;aksdf; C:\Windows\system32\DRIVERS\aksdf.sys [2006-12-13 65024]
R2 aksfridge;aksfridge; \??\C:\Windows\system32\drivers\aksfridge.sys [2013-02-19 141064]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-16 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-16 79184]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-16 92008]
R2 hardlock;hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2006-12-04 314368]
R2 multikey;Virtual USB MultiKey; C:\Windows\system32\DRIVERS\multikey.sys [2014-07-18 67584]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 akshasp;SafeNet Inc. HASP Key; C:\Windows\system32\DRIVERS\akshasp.sys [2013-01-14 60488]
R3 aksusb;SafeNet Inc. USB Key; C:\Windows\system32\DRIVERS\aksusb.sys [2013-03-05 303368]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2010-08-07 3058168]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-04-20 169584]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
R3 toshidpt;Bluetooth HID Port; C:\Windows\system32\drivers\Toshidpt.sys [2009-06-19 9608]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2009-09-24 212072]
R3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-06-19 50664]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2009-07-13 19824]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-06-19 94336]
R3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2010-02-03 60408]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [2012-08-28 11880]
S0 TfFsMon;TfFsMon; C:\Windows\system32\drivers\TfFsMon.sys []
S0 TFSysMon;TfSysMon; C:\Windows\system32\drivers\TfSysMon.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SASKUTIL.SYS [2010-05-10 67656]
S2 NSHE;Guardant Emulator Driver; \??\C:\Windows\system32\Drivers\NSHE.SYS []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files (x86)\MediaCoder\SysInfoX64.sys []
S3 DCR;DCR; \??\C:\Program Files (x86)\DriveCrypt\DCR.Sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 48488]
S3 hmhrwoiz;hmhrwoiz; C:\Windows\system32\drivers\hmhrwoiz.sys []
S3 PCTBD;PC Tools Browser Defender Driver; C:\Windows\System32\Drivers\PCTBD64.sys [2011-09-28 70760]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 tap0901;avast! SecureLine TAP Adapter; C:\Windows\system32\DRIVERS\tap0901.sys [2013-04-30 40616]
S3 TfNetMon;TfNetMon; \??\C:\Windows\system32\drivers\TfNetMon.sys []
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2009-08-05 63856]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-01-07 43336]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-05-07 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-05-07 109048]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 CrypKey License;CrypKey License; C:\Windows\system32\crypserv.exe [2010-03-18 126976]
R2 DriveCryptService;DriveCrypt Service; C:\Program Files (x86)\DriveCrypt\DcrServ.exe [2013-05-09 202112]
R2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-04 136176]
R2 hasplms;Sentinel Local License Manager; C:\Windows\system32\hasplms.exe [2013-01-11 4466120]
R2 HDRExpose3Service;HDRExpose3Service; C:\Program Files\UCT\HDR Expose 3\HDRExpose3Service.exe [2013-10-13 65656]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\SysWOW64\nlssrv32.exe [2012-12-21 66560]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-04-24 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2011-04-24 107832]
R2 Printer Control;Printer Control; C:\Windows\system32\PrintCtrl.exe [2009-10-28 65536]
R2 ProtexisLicensing;ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [2007-06-05 177704]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-11-30 336824]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2012-09-17 2365792]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2010-02-25 196464]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-01 68608]
S2 ProtectMonitor;Protect Monitor; C:\Program Files\PCDApp\StartHelp.exe [2014-06-09 77705]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08 262320]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-01 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-04 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-01-20 641352]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-08-01 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-07 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Wareza at 2014-08-01 20:53:13
Microsoft Windows 7 Home Premium
System drive C: has 26 GB (11%) free of 238 GB
Total RAM: 4091 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:53:19, on 1.8.2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16476)
Boot mode: Normal
Running processes:
C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe
C:\Windows\System32\PrintDisp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Users\Wareza\AppData\Local\VNT\vntldr.exe
C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe
C:\Users\Wareza\AppData\Local\Temp\SkyMonkAM__2155_il2428.exe
C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Wareza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 2&tsp=5250
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: CrossriderApp0057050 - {11111111-1111-1111-1111-110511701150} - C:\Program Files (x86)\SavePass\SavePass-bho.dll
O2 - BHO: CrossriderApp0061762 - {11111111-1111-1111-1111-110611171162} - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O3 - Toolbar: (no name) - {828DC97A-2277-4E10-92A9-4907FA0922A9} - (no file)
O4 - HKLM\..\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [FontExpertType1Loader] C:\Program Files (x86)\FontExpert\Type1Loader.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Nástroj WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
O4 - HKLM\..\Run: [VNT] C:\Program Files (x86)\VNT\vntldr.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKCU\..\Run: [DriveCrypt Startup] C:\Program Files (x86)\DriveCrypt\DriveCrypt.exe /WS
O4 - HKCU\..\Run: [SmartSerialMail Sending] C:\Program Files (x86)\JAM Software\SmartSerialMail\SmartSerialMailServiceApp.exe /delayedstart
O4 - HKCU\..\Run: [tedcgtelwn] wscript.exe //B "C:\Users\Wareza\AppData\Local\Temp\tedcgtelwn..vbs"
O4 - HKCU\..\Run: [qrnvvhxtfg] wscript.exe //B "C:\Users\Wareza\AppData\Local\Temp\qrnvvhxtfg..vbs"
O4 - HKCU\..\Run: [Pokki] C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Wareza\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: qrnvvhxtfg..vbs
O4 - Startup: tedcgtelwn..vbs
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Atomic Email Hunter - C:\Program Files (x86)\AtomPark\Atomic Email Hunter\ie.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Extract e-mail addresses - C:\Program Files (x86)\AtomPark\Atomic Email Studio\modules\Hunter\ie.htm
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Extract e-mail addresses - {491A6C2B-1046-486b-8A8F-7D26BCB79A9B} - C:\Program Files (x86)\AtomPark\Atomic Email Studio\modules\Hunter\ie.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Extract e-mail addresses - {491A6C2B-1046-486b-8A8F-7D26BCB79A9B} - C:\Program Files (x86)\AtomPark\Atomic Email Studio\modules\Hunter\ie.htm (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\ip hider pro\iphiderlib.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{32C913EE-9640-4023-93A9-F7A94D537652}: NameServer = 4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: CrypKey License - Unknown owner - C:\Windows\system32\crypserv.exe (file missing)
O23 - Service: DriveCrypt Service (DriveCryptService) - Unknown owner - C:\Program Files (x86)\DriveCrypt\DcrServ.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Sentinel Local License Manager (hasplms) - Unknown owner - C:\Windows\system32\hasplms.exe (file missing)
O23 - Service: HDRExpose3Service - Unknown owner - C:\Program Files\UCT\HDR Expose 3\HDRExpose3Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\nlssrv32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Printer Control - Unknown owner - C:\Windows\system32\PrintCtrl.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCDApp\StartHelp.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\SysWOW64\PSIService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD Backup (WDBackup) - Western Digital - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: WD Rules (WDRulesService) - Western Digital - C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 18745 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 32165920
\??\C:\Windows\system32\conhost.exe "-1469446462-24901943-1795427553-5770267731418599919-452001495794982546-802203594
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
taskeng.exe {97D335DC-D15A-4589-97BE-CB431B498041}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
taskeng.exe {E5CDF462-01ED-468B-9D7F-DA1133FA936B}
"C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe"
"C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-10.exe" /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /awdJubQ='SavePass' /iwZphDOV=1000 /WlUVNkF=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /AUrZlSbRE=http://logs.genstatsnet.com /strmlzPp='task' /MluqbclGU=''
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\crypserv.exe
"C:\Program Files (x86)\DriveCrypt\DcrServ.exe"
C:\Windows\system32\hasplms.exe -run
"C:\Program Files\UCT\HDR Expose 3\HDRExpose3Service.exe"
"C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\SysWOW64\nlssrv32.exe
"C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe"
"C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
"C:\Program Files\TOSHIBA\TECO\Teco.exe" /r
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PrintCtrl.exe
"C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe"
"C:\Windows\System32\PrintDisp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
"C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
"C:\Users\Wareza\AppData\Local\VNT\vntldr.exe" /EXEC
C:\Windows\SysWOW64\PSIService.exe
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
"C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe"
"C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe"
"C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe" /TUStart /pid:4072
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe"
WLIDSvcM.exe 4256
"C:\Users\Wareza\AppData\Local\Pokki\Engine\pokki.exe" --type=renderer --disable-breakpad --disable-desktop-notifications --disable-logging --disable-speech-input --lang=en-US --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/Yes/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/9/OneClickSignIn/BlueOnWhite/Prefetch/ContentPrefetchPrefetchOff/Prerender/PrerenderMulti/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V1/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingLearningEnabled/Test0PercentDefault/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-1-Percent/group_01/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --noerrdialogs --disable-client-side-phishing-detection --disable-bundled-ppapi-flash --channel="888.2.1482929081\1833150136" /prefetch:3
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
TosBtBty.exe
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\tosBtProc.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe"
"taskhost.exe"
"C:\Users\Wareza\AppData\Local\Temp\SkyMonkAM__2155_il2428.exe"
"C:\Program Files (x86)\HD-V1.9\b82486d5-bb46-4c3f-bb97-2f0f41a249b0.exe" /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /UfxezKjj='Information' /OpCDRWC=1000 /sQjIxQ=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /XlOtcfFVl=http://logs.infogenservice.com
"C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe" /c
"C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe" default restart
"C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "533950929201358046615222617-778379726-17209728441562265620-4034199261756067456
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
"C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-6.exe" /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /coNJs /iUogpmnmb=HD-V1.9 /CgnmDlFbf84380d-77a2-4bc9-a2e7-5540de71071e.dll /rPhBrxCfX925a6da0-08c2-4cac-b63c-87e7d905d204.dll /hfgFCwMmqf7a4cc7e-9a86-4d86-a37b-ee13c88ab168-64.exe /lGCHTpn='nova' /QaZWS=http://js.clientdemocloud.com /HaSZZW='{"asw":[32770, -1602223867, 0]}' /tUhLI='http://update.infogenservice.com/novaru ... pdate.json' /IXonsqn='task' /mcmUK=''
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="8952.0.473162999\833892306" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x9553 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.2.1000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.2.604224725\1082397893" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.3.48905474\277079206" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.4.1374615775\1260337540" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.5.314646503\1324081633" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="8952.10.82561523\1488683136" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.11.221832232\824587545" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/NetworkConnectivity/disable_network_stats/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.14.515600331\135007853" /prefetch:673131151
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/NetworkConnectivity/disable_network_stats/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Control/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_72/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="8952.33.842534985\570612996" /prefetch:673131151
C:\Windows\system32\vssvc.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe58_ Global\UsGthrCtrlFltPipeMssGthrPipe58 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 504 508 516 65536 512
"C:\Users\Wareza\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-1.job - C:\Program Files (x86)\SavePass\SavePass-codedownloader.exe /pqEPCzi /strmlzPp=task /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /tIDoOVcLd=1.34.7.1 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /SbfFnn=http://js.genstatsnet.com /PWGNFnVAw=ch /llaXMtNA='SavePass' /DNSYbH=http://js.clientdemocloud.com /BCgfKDZqT /XRQmuSjbS='{"asw":[32770, 536870917, 0]}' /JeVlF='http://update.genstatsnet.com/ie_code_a ... pdate.json' /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-10.job - C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-10.exe /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /awdJubQ='SavePass' /iwZphDOV=1000 /WlUVNkF=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /AUrZlSbRE=http://logs.genstatsnet.com /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-11.job - C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-11.exe 001504 6F26FD6331EF42CC8A0AC13B8B685718IE 57050 1405846363 93-0,102-0,104-0,178-288,179-288,180-288,223-288
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-4.job - C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53-4.exe /mfoOei /ivGKDm='SavePass' /YroxogYLU='C:\Program Files (x86)\SavePass\7dd07b49-00e3-43fc-aa78-d59d31542b53.xpi' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /tIDoOVcLd=1.34.7.1 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /TDlbtL=300 /omxhrzmX=587fea1b-1c76-43c0-8b29-3c3da78e2485@2309207e-4ba6-42d8-b8a2-3b0a22e052b5.com /ncagNs=0.95 /wMkepiDvb=a587fea1b1c7643c08b293c3da78e24852309207e4ba642d8b8a23b0a22e052b5com57050 /iibxsGtwM=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /57050.rdf /awdJubQ='SavePass' /ulVKHxcBF='Just Save!' /xPCOk='OutBrowse' /PWGNFnVAw=ch /XRQmuSjbS='{"asw":[32770, 536870917, 0]}' /BCgfKDZqT /GxINeoL /UFDleiqq /JeVlF='http://update.genstatsnet.com/ff_agent_ ... pdate.json' /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\7dd07b49-00e3-43fc-aa78-d59d31542b53-6.job - C:\Program Files (x86)\SavePass\SavePass-novainstaller.exe /CPJPf /ivGKDm='SavePass' /sywcXNlqN=57050 /ipMQcVy='001504' /tGavZZ='0' /jqrbnHI='0' /yZtwz=6F26FD6331EF42CC8A0AC13B8B685718IE /sdOcnejp=152a0c218bc945671311e216b106ec62 /Mpuww=1_34_07_01 /tIDoOVcLd=1.34.7.1 /THRfeM=1405846363 /jbEPe=http://stats.genstatsnet.com /AOqMEMKFI=http://errors.genstatsnet.com /SbfFnn=http://js.genstatsnet.com /PWGNFnVAw=ch /fZDrKku /llaXMtNA=SavePass /VkkIIyg='nova' /DNSYbH=http://js.clientdemocloud.com /XRQmuSjbS='{"asw":[32770, 536870917, 0]}' /strmlzPp=task /JeVlF='http://update.genstatsnet.com/novacode/ ... pdate.json' /strmlzPp='task' /MluqbclGU=''
C:\Windows\tasks\aa7a3f39-302c-46f7-8819-f4f38634d18c.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-4.exe /qzWkN=gbbuLTNWVgOfB52rUgxi2Qu8nOtb7I960rFYPBFx21/jNbgYQU8n5s/J7nqXfhidb2mZnjwpHWdZPkRUnibl2M8SlQtILU5znmfS6TkhMMaFFBhdoFsNrS4FcfnPbpnHZFDDRV2C8GNHHnL9mAXofOnAL/RpU+2cG7vjNz8M9jUqG3B4JMeUVV2Ac5LADYCr922hnU6eTxPEuyBtwYB3D97XeJXsbF1MMOwV5OnWIJPViubP2WCLxdqHzd+KrWBPM6X26He7nvJf8ROqt2nbXmkFQdXINnR91os3ftqDYEpp3++yHCAHyU7bCVAP7ZDE9Ur673jadoywQAe7OEk9IqbCBPDmgeXHY7IC6peI503G8RM3QPyr77I6/qMMsgrr6d/5ocebRgzbDd3xCie1C8HX5fvuw/j3lQgjT9hDIKOOnYs2ZNVj4KH6q75Zj8uBJKq2ZzPBuvRNT2/+PoQATeMjruQP3Rvj+UjKY6WugLsI7nvtClNow2HX4VmrlbL1bcFStL6RiEjwVRujXVB+aXC8xiFuo4tRASjTJDPdX0JGHjd0q6oHtaeNTB3kcCJY+l9EgFkoHdh1191X9COGtyRiEbmGnzV+M4hbSNwm5TJ5wl4XKIfH6bFp32YSA/RuQdFUS1jR+q0mcf9EUYz35Gy/FgKSJCUvtxLJbKH6wleMLpbLMfBuygkWMhExiVYlVjrfzkbnOdrKF6Qsf1FljXYma7G/J9VzPhcAMM11fJZh/Vj2pIVyidCSm8uSu8GcYoJxO39+3WHwBmqV5fKCByD9iVsOhBgLjTzZuelyd4fjUvqcm0BFyEf8WEiWckD8T638DIk4rKdqm9l3w17jTEfnbfrjmb9rgcbVQ+2fzVX9H6Bwc0KZc32QYhahoJFA+Rr+9DEhqcxBllxseiRmb5910JOL7xJzJluk4YHT0b4uwFZx6wP0HE5e/yjnCM4OjHu2454Bw+jKANlArXuJIAexneAmAqxpgxdyy+8ccD5K0r9cviDujCcrJhehsfPxbzy7UpD22VLNXbNDC5T1doUSfzhPlgj3Yul03A2Qfw3eHtHOpbU8rI1fnzsvKLky+V9eLjbGBqxgR0+xHp9jYJsmKbBUyJ5ky4CHNZUjzkE0Z5BB+Rxuw5c6+FdwfEoFWTABPQRqOfis8teaWav1A5xr3Rsrzci10UqbwKD9uIoNXRaEPXq5ZzsH+aThO4vJVzh0bmnBrVdTCJoZqrqkcJAUICBgBF0UpmlQ5WB99SS6vui7hP+3vxUFxDMn7Ttihc2oGU0PaiqZ2H1QSIvH5uTg64ofoRhmbAKpn45Gp5xj6B8bmGZZ65DVgXzgkXe3HbsvoPDXwUSIf05RSU5G75XxdROo60cDy/3xbY4cpIk3nqL/YZlDjpoUluGV8Qd1UHtTUGl3CRIG6fTxpTlsXSMnf7gWIdHqVFptv0DaMHuRLpsNpSFExAla3g6DoBYSrCvCY3fcKWiIYsKK1Kf/Iq6CoxwtBFfuNIzwlyzx9pUDhmAdSXP9UlNSxarDqZ6s
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\b82486d5-bb46-4c3f-bb97-2f0f41a249b0.job - C:\Program Files (x86)\HD-V1.9\b82486d5-bb46-4c3f-bb97-2f0f41a249b0.exe /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /UfxezKjj='Information' /OpCDRWC=1000 /sQjIxQ=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /XlOtcfFVl=http://logs.infogenservice.com /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\bdeae81b-09ea-4fc8-93ce-7d0c70c48698.job - C:\Program Files (x86)\HD-V1.9\bdeae81b-09ea-4fc8-93ce-7d0c70c48698.exe 001859 6F26FD6331EF42CC8A0AC13B8B685718IE 61762 1406913860 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 HD-V1.9
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-1.job - C:\Program Files (x86)\HD-V1.9\HD-V1.9-codedownloader.exe /OtYwaHiV /IXonsqn=task /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /iUogpmnmb='HD-V1.9' /QaZWS=http://js.clientdemocloud.com /WOWkiqR /HaSZZW='{"asw":[32770, -1602223867, 0]}' /tUhLI='http://update.infogenservice.com/ie_cod ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-11.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-11.exe /qzWkN=iSkpzKtRrSQagkURWHwN2vjBAUsL5MdUwslLwoFPmpll7pY3Blapym9LNbTBkv1EOE9MrVndKHgi82A+ilnqQt/ie+SaEYp9+Axe+ErzwkXY9Bf+QVwZDS/Qrc7VrMHQjennKIDTwYcjJywe5paBq2WpkMPprHwZMSkXsXFcV+aGnMNqHZpE2c/At912PIEhnp2mB1U7U8+KK8LkYDpX0E4UnUZ3OFtmrf0EuZ5IP92E9Q9tAy2a/KZLDztNxQycGmQvVi6rgEEUGh1b1p9RTWqrxcO2K/HRZFvSFhTF4kczGgFn8NsH3Yb8yszfq2t5PIQHa5w/0h9LGZwAcaxlOwIDqsANcNDwntrPD6zA+v6nnUp0Ehhn6KIttFHbJBWymP38MNY6omaReuJlSzyZ2DUHUYEJUBVYZOm24/+T2zQBaz4UcSy6L3vjWn/u0n/8Smc62ABVVW4vJB8+zgIw9Z9+oJUVLVvY2sGtSWXTHzUDRIgw1wbR4qJ69SSt5mpJMbJTTFPbq5dcDsJBptFaI+Kx/o9blzwZZFxo+uuEpYdGtxhWxOoHR4m0r5lk37cmDLzlL8j3Km5TlsLH+6hYJdONk5nn+BumyITJzW+M1S887JMrGSKJrAh0Nt915jturhcejst8XoluXwOquFehvmVxyjVOLi3aUQiPogGJt78ui3VfKl8Z9tKKJ8HmLgXH1EiAwGhw0D6/YZdXp1eUWfLj2oxCQZH1mAQenE2rHK2JyFwy1zTd1iaeBZLeSs0JZyc+T8VChuvSNAy9f15NN1cN5mvGrMMHkFYwhIDhBOXbFX2kap0UCnTKPISK716D9t8D+Kxsm9vM6KlO4a2iIGppjBUNVwgcRfiAYWfITBi1Wg0oQK53VDxWii8CV/P2ioVu35D/duJ5l5xXzXLmsuKHSedRHEIsbFFSkqe2RlbDORMwkJxRIcLvOJZRB2JjbOSt/Nzvn7ScRznUKtrBq++WV/DlUB7YFGebBrDoFVJlme6Ybffo7rTlMyPYe7XonSkz2hP5FhArRbbMoQdDcF5Z7akWHNCF5SwPsWA+roHpeElsTSZyzxPl72DuamZmY+1pTg3XZJUKN1n52w7+e8aK2St15T0ZJ9SuzGhA9u/aPQ8RzetRWQD3wFoCUuMBwTm/Nj0QgZZA+aPVuMVoZ73r79v6V415Rh/x/w4e+txzRyalfy02quEXqQubdrH1pXGAseMRRY1ccon7U1NcZ3UGkbVhdlf6o6Ds/ujGxKNmk8Cgd36tgnthIqoMCCHIHZI0s5IaJ+VkjyE/CKeqIKouuY1hyxGWwMZlVzRaQD5c2pnc9y3MvPMXRyf4zukUEqsA3mYXdKFy/uYkDjKTSFY+x80EdXNO2vJM7jyd6RUJpzcXQaTWDy4AxngnMr/H1P40TUUpooFetLW5ZwaFMy9vrQ7NcfvKRuJGKGjVLqMlzDVjCAoCWdL19XjBRmCEiDZuQSL0fnbIYXecAOtj+JcAQphKvjDVTAlXgbFMvkks+3JQkQGhqGjuZGtr7kC+CFcU6gZQYR/PNKAuREIUXnJGM0+405nqy5djJz9obtGNH7C9EMiXDOPVcrXRWsFgrRvB5y9WoSqy8TWhfBDEF1brW88fnHdVOiUzIiriasThUzdl/yLA0Tg13HN7+uBgixZvOMQLsUng8NGEvolJm9+gXhzY6ekVKG2FsBhGxQE=
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-3.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-3.exe /qzWkN=g+BL3EpxqZYb7DfId15Gh2FTk+ng52onGgaAeL7zISkXNT1xEKNd2s03YqnmzUBIIFHL53iUygvM031uzHI/VQDrRh3pHRG8WRc3Ou7X56XQf2Dcd5nY8Xs1ieUOjm+/a7/vwYmChKhsG+1688knGtnn8QAAgnEW2e3t2UtxWYFCtocv2cLYZkdyA1ZLKW1oy0/blFJBewI33APpojDF8bNMtkV7A0Ft1KcNrr4H3wXn31PfWFnDnahMiSe6YYln12dPQZCgMiYGkiKMDcppXZUFxPBxxhhVr9Oc44AHL+w94Wp7VwGe5FRLOoNY6j5fsDB1vcu6J66Z44v3nX+99bn1K3MrTjBiAUcMA+HrCcADtH8qqbqeP4juFa0luiCNsKnvjDAzOV2JYDJwEq4ClCU52E6p1H6PQtiWs9Kae04Dux5zX23GjqQ3jaAtNegv3Gmw5iyr7YvjsmUXPY+c70/Nu77jxYWuX6pU8Bd2VS9coL5CONeEDLdCOnAbPrCTfaR3WSg3BOAq6n7G7oIQuGMDrq/bCUVqvSLWb0+hdBxqE4TCoPQ0bhUG7FGf4MDx7HwHo4wEYjOYa16JSypgHIoMfGXJZDlomJS8G6iDJCRVw4nXo4zwmuDdsGN6/scyhI393AJX5LiHVLV3rLrCKowiij1pEXVTcv+caFWwAC8WmI95HfESP3RQZgsvQsrA68ihotCFQXniFtxdrqokcjJ1xOKXiS555I9O/AftQl7f0UyrnfMOdQ0hfgFoPBXkHLnC7sWcwS2LxnmnqJoIisu1zvtSWTXeuw7rRUidaJshUU8B/CIMo1lhHqGVdrB+zUXdL4FDVDrpM7w5xzSBUVLPXnlBC7PGISlkcypgZ1F88TII+zwbg1ZK3E5rHImL9YNiaxwZS3OS1qnjkihb3gxbFiaT973b9X3PrmLwj8VwZT44gFUQmP70p3dflWsMr4Ot/aUR6M8bNNua29Xz4JyUiwk5qlk3xUqvpVpktjZqSJ/xLZJqvOX3hzb2597PmCgxAcgL+4lzWPhZNRdLiUuADpW8YMGykh1T5in0xiDEUOfDDQb8VDWxzmMQoTdl+9ieJ2/r1nJ5SNZEYB2visukyoubwDFcT68pBaSsGpmEV4YcfzLTwjG9HIOPJuMzLEN1NdzHsCHbkkyQ0Z7xv+eQE/pmwvrL18Yu3CWCKsWfHfXAhCYANmOjPEffvBq+nJu3V1Oqn+pGbwpWymSlIqx2kEim0RYmYzzO7zI3jjVLg66sNtoO9ctdUHv15UUsCdr1CWUWhHqr9i+s+kcME7BTR7Np6LxylWv7IFjJtupVophhM26C93S/aSG6RRg7BZbJtzPz2veG6K0GqluwyQ==
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-4.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-4.exe /zUDYVOfKZ /czeXVoVH='HD-V1.9' /guLuXGk='C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168.xpi' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /MBxxWezKH=300 /rQqUqB=0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com /BPldBcs=0.95 /cMtnkAeX=a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762 /JPBSDf=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /61762.rdf /UfxezKjj='HD-V1.9' /BykEld='Turn YouTube videos to High Definition by default' /OlsHtY='InfoHD-V1.8' /aaDFWNW=ch /HaSZZW='{"asw":[32770, -1602223867, 0]}' /WOWkiqR /GjatKFEvu /ouFRYqTVd /tUhLI='http://update.infogenservice.com/ff_age ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5.exe /jkAyfrw /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /RugkKYbJC=http://ipgeoapi.com/ /WTHMYHf=http://update.infogenservice.com /lvDfMb=2 /XlOtcfFVl=http://logs.infogenservice.com /tUhLI='http://update.infogenservice.com/update ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5_user.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-5.exe /jkAyfrw /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /RugkKYbJC=http://ipgeoapi.com/ /WTHMYHf=http://update.infogenservice.com /lvDfMb=2 /XlOtcfFVl=http://logs.infogenservice.com /tUhLI='http://update.infogenservice.com/update ... pdate.json' /RwcRQamFg /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-6.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-6.exe /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /coNJs /iUogpmnmb=HD-V1.9 /CgnmDlFbf84380d-77a2-4bc9-a2e7-5540de71071e.dll /rPhBrxCfX925a6da0-08c2-4cac-b63c-87e7d905d204.dll /hfgFCwMmqf7a4cc7e-9a86-4d86-a37b-ee13c88ab168-64.exe /lGCHTpn='nova' /QaZWS=http://js.clientdemocloud.com /HaSZZW='{"asw":[32770, -1602223867, 0]}' /tUhLI='http://update.infogenservice.com/novaru ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-7.job - C:\Program Files (x86)\HD-V1.9\f7a4cc7e-9a86-4d86-a37b-ee13c88ab168-7.exe /eYUadnJG /czeXVoVH='HD-V1.9' /NTKQsLzu=61762 /tyutJad='001859' /ZhPjJOLxa='0' /iqJRaLB='0' /QBsotRPK=6F26FD6331EF42CC8A0AC13B8B685718IE /PvJtTS=152a0c218bc945671311e216b106ec62 /zMIKjxRrN=1_34_07_29 /mqtMO=1.34.7.29 /ZTXOElFrk=1406913860 /xgiwSpi=http://stats.infogenservice.com /WrHwj=http://errors.infogenservice.com /EiqWCRllV=http://js.infogenservice.com /aaDFWNW=ch /coNJs /iUogpmnmb=HD-V1.9 /CgnmDlFbf84380d-77a2-4bc9-a2e7-5540de71071e.dll /rPhBrxCfX925a6da0-08c2-4cac-b63c-87e7d905d204.dll /hfgFCwMmqf7a4cc7e-9a86-4d86-a37b-ee13c88ab168-64.exe /lGCHTpn='nova' /QaZWS=http://js.clientdemocloud.com /HaSZZW='{"asw":[32770, -1602223867, 0]}' /IXonsqn=task /tUhLI='http://update.infogenservice.com/novaco ... pdate.json' /IXonsqn='task' /mcmUK=''
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3893988867-3537961221-3907201996-1000Core.job - C:\Users\Wareza\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3893988867-3537961221-3907201996-1000UA.job - C:\Users\Wareza\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Wareza\AppData\Roaming\Mozilla\Firefox\Profiles\7x9so9sh.default
prefs.js - "browser.search.useDBForOrder" - true
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.60.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@protectdisc.com/NPMPDRM]
"Description"=MPDRM License Acquisition Plugin
"Path"=C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198]
"Description"=15.0.0.198
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
nppl3260.dll
nppl3260.xpt
nprjplug.dll
nprpjplug.dll
nsjsrealplayerplugin.xpt
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Users\Wareza\AppData\Roaming\Mozilla\Firefox\Profiles\7x9so9sh.default\extensions\
0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com
39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com
587fea1b-1c76-43c0-8b29-3c3da78e2485@2309207e-4ba6-42d8-b8a2-3b0a22e052b5.com
ffxtlbr@buenosearch.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Wareza\AppData\Roaming\Mozilla\Firefox\Profiles\7x9so9sh.default\searchplugins\
Ask.xml
buenosearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}]
SavePass - C:\Program Files (x86)\SavePass\SavePass-bho64.dll [2014-07-20 796696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171162}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho64.dll [2014-08-01 774000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-16 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}]
SavePass - C:\Program Files (x86)\SavePass\SavePass-bho.dll [2014-07-20 587288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171162}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll [2014-08-01 573296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-15 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-05-07 436600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-15 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-03-19 529784]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{828DC97A-2277-4E10-92A9-4907FA0922A9}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"SmartFaceVWatcher"=C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-02-05 709976]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2010-03-03 35672]
"TosNC"=C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2010-03-09 595816]
"Toshiba TEMPRO"=C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2010-02-11 1050072]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2009-11-05 505696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2009-03-09 52600]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2009-08-13 570680]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2010-03-03 913720]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2010-03-17 1489760]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2010-02-23 705368]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2010-04-19 136136]
"CanonSolutionMenu"=C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]
"PrintDisp"=C:\Windows\system32\PrintDisp.exe [2011-01-03 976896]
"tedcgtelwn"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\tedcgtelwn..vbs []
"qrnvvhxtfg"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\qrnvvhxtfg..vbs []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DriveCrypt Startup"=C:\Program Files (x86)\DriveCrypt\DriveCrypt.exe [2013-05-09 1249280]
"SmartSerialMail Sending"=C:\Program Files (x86)\JAM Software\SmartSerialMail\SmartSerialMailServiceApp.exe [2011-11-10 12234136]
"tedcgtelwn"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\tedcgtelwn..vbs []
"qrnvvhxtfg"=wscript.exe //B C:\Users\Wareza\AppData\Local\Temp\qrnvvhxtfg..vbs []
"Pokki"=C:\Users\Wareza\AppData\Local\Pokki\Engine\Launcher.dll [2013-12-05 1271064]
"SUPERAntiSpyware"=C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SUPERAntiSpywarePro.exe [2010-10-25 2408688]
"cz.seznam.software.autoupdate"=C:\Users\Wareza\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Wareza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"TWebCamera"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2009-10-06 1294136]
"FontExpertType1Loader"=C:\Program Files (x86)\FontExpert\Type1Loader.exe [2010-05-14 294208]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-01-20 43848]
"Nástroj WD Quick View"=C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [2012-09-19 5236664]
"VNT"=C:\Program Files (x86)\VNT\vntldr.exe [2014-03-19 196048]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-04 3890208]
"TkBellExe"=C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [2011-12-10 296056]
[HKEY_CURRENT_USER\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Acdiacra"=C:\Users\Wareza\AppData\Roaming\Ebefno\vopow.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Users\Wareza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
qrnvvhxtfg..vbs
tedcgtelwn..vbs
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"C:\Users\Wareza\AppData\Roaming\wind.exe"="C:\Users\Wareza\AppData\Roaming\wind.exe:*:Enabled:Windows Messanger"
"C:\Users\Wareza\AppData\Local\Temp\wind.exe"="C:\Users\Wareza\AppData\Local\Temp\wind.exe:*:Enabled:Windows Messanger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.txt - open -
======List of files/folders created in the last 1 month======
2014-08-01 20:53:13 ----D---- C:\rsit
2014-08-01 20:44:39 ----D---- C:\FRST
2014-08-01 20:18:47 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-08-01 19:41:43 ----D---- C:\Program Files (x86)\Seznam.cz
2014-08-01 19:24:33 ----D---- C:\Program Files (x86)\HD-V1.9
2014-07-20 16:01:47 ----N---- C:\bootsqm.dat
2014-07-20 10:56:04 ----D---- C:\Program Files (x86)\7-Zip
2014-07-20 10:52:50 ----D---- C:\Program Files (x86)\SavePass
2014-07-19 14:55:55 ----A---- C:\Windows\ETKINST.INI
2014-07-18 20:59:50 ----A---- C:\Windows\system32\drivers\aksdf.sys
2014-07-18 20:59:46 ----A---- C:\Windows\SYSWOW64\UNWISE.EXE
2014-07-18 20:04:10 ----D---- C:\ProgramData\ALI213
2014-07-18 17:25:03 ----A---- C:\Windows\system32\hasplms.exe
2014-07-18 17:25:03 ----A---- C:\Windows\system32\aksllmtp.exe
2014-07-18 17:25:02 ----A---- C:\Windows\system32\drivers\aksfridge.sys
2014-07-18 17:24:26 ----A---- C:\Windows\system32\drivers\akshhl.sys
2014-07-18 17:24:26 ----A---- C:\Windows\system32\aksusb4.dll
2014-07-18 17:24:26 ----A---- C:\Windows\system32\akshsp52.dll
2014-07-18 17:24:26 ----A---- C:\Windows\system32\akshhl30.dll
2014-07-18 16:10:19 ----A---- C:\Windows\system32\drivers\multikey.sys
2014-07-18 16:10:16 ----RA---- C:\Windows\SYSWOW64\drivers\nshe.sys
2014-07-17 16:15:20 ----D---- C:\Users\Wareza\AppData\Roaming\proxyeverysvr
2014-07-16 18:34:03 ----A---- C:\Windows\avastSS.scr
2014-07-16 18:32:20 ----A---- C:\Windows\system32\drivers\aswNdisFlt.sys
2014-07-15 20:20:44 ----A---- C:\Windows\system32\TURegOpt.exe
2014-07-15 20:20:40 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2014-07-15 20:20:40 ----A---- C:\Windows\system32\authuitu.dll
2014-07-15 20:20:31 ----D---- C:\ProgramData\AVG Secure Search
2014-07-15 20:18:26 ----D---- C:\Program Files (x86)\TuneUp Utilities 2013
2014-07-15 19:09:28 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-07-15 19:08:58 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-07-08 23:35:17 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-07-06 23:19:50 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2014-07-06 23:19:19 ----D---- C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX
======List of files/folders modified in the last 1 month======
2014-08-01 20:53:17 ----D---- C:\Program Files\trend micro
2014-08-01 20:51:24 ----AD---- C:\Windows
2014-08-01 20:21:24 ----RD---- C:\Program Files (x86)
2014-08-01 20:21:24 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-01 20:20:38 ----D---- C:\Windows\temp
2014-08-01 20:20:17 ----D---- C:\Program Files (x86)\Google
2014-08-01 19:51:32 ----D---- C:\Users\Wareza\AppData\Roaming\Seznam.cz
2014-08-01 19:41:52 ----D---- C:\Windows\Tasks
2014-08-01 19:41:52 ----D---- C:\Windows\system32\Tasks
2014-08-01 19:34:50 ----D---- C:\Users\Wareza\AppData\Roaming\QuickScan
2014-08-01 19:25:14 ----SHD---- C:\Windows\Installer
2014-08-01 19:25:14 ----D---- C:\Config.Msi
2014-08-01 12:55:33 ----D---- C:\Windows\system32\config
2014-08-01 12:37:15 ----D---- C:\Program Files\PCDApp
2014-07-30 22:49:22 ----D---- C:\Users\Wareza\AppData\Roaming\vlc
2014-07-30 20:44:04 ----D---- C:\Users\Wareza\AppData\Roaming\uTorrent
2014-07-29 12:53:30 ----SHD---- C:\System Volume Information
2014-07-26 09:10:09 ----D---- C:\Program Files\Microsoft Silverlight
2014-07-26 09:10:07 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-07-26 09:07:12 ----D---- C:\Windows\system32\MRT
2014-07-26 09:07:07 ----A---- C:\Windows\system32\MRT.exe
2014-07-26 09:06:38 ----D---- C:\ProgramData\Microsoft Help
2014-07-23 13:27:02 ----AD---- C:\Windows\System32
2014-07-23 13:27:01 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-23 13:26:56 ----D---- C:\Windows\inf
2014-07-21 12:57:04 ----D---- C:\Windows\system32\drivers
2014-07-21 12:57:03 ----D---- C:\Windows\system32\DriverStore
2014-07-21 12:57:03 ----D---- C:\Windows\system32\catroot
2014-07-19 20:07:26 ----D---- C:\Windows\SysWOW64
2014-07-19 16:16:38 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-07-19 16:16:35 ----D---- C:\Windows\system32\cs-CZ
2014-07-19 12:54:10 ----D---- C:\Windows\SYSWOW64\drivers
2014-07-19 12:54:10 ----D---- C:\Windows\system
2014-07-18 21:10:35 ----D---- C:\Hry
2014-07-18 20:59:49 ----D---- C:\Windows\system32\Setup
2014-07-18 20:44:50 ----D---- C:\Users\Wareza\AppData\Roaming\DAEMON Tools Lite
2014-07-18 20:44:49 ----D---- C:\ProgramData\DAEMON Tools Lite
2014-07-18 20:04:10 ----D---- C:\ProgramData
2014-07-18 20:00:25 ----D---- C:\Windows\Logs
2014-07-18 17:24:16 ----D---- C:\Program Files (x86)\Common Files
2014-07-16 18:34:12 ----A---- C:\Windows\system32\aswBoot.exe
2014-07-15 20:48:58 ----SHD---- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2014-07-15 20:48:58 ----HDC---- C:\ProgramData\{81083967-5051-4F49-910E-70164AD89C2D}
2014-07-15 20:18:37 ----D---- C:\ProgramData\TuneUp Software
2014-07-15 19:10:24 ----D---- C:\ProgramData\Oracle
2014-07-15 19:08:48 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-07-15 19:08:48 ----A---- C:\Windows\SYSWOW64\java.exe
2014-07-15 18:55:11 ----D---- C:\ProgramData\IObit
2014-07-15 18:55:11 ----D---- C:\Program Files (x86)\IObit
2014-07-09 09:05:23 ----D---- C:\Windows\system32\catroot2
2014-07-09 09:05:17 ----D---- C:\Windows\winsxs
2014-07-08 23:36:17 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-07-02 00:18:15 ----D---- C:\Windows\debug
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2014-07-16 448400]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-16 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-16 224896]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 PCTCore;PCTools KDS; C:\Windows\system32\drivers\PCTCore64.sys [2011-11-14 367912]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2014-07-16 28184]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-16 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-16 1041168]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-17 427360]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [2010-01-29 115600]
R1 NetworkX;NetworkX; C:\Windows\System32\ckldrv.sys [2010-03-19 30272]
R1 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [2012-07-15 55384]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-07-28 81768]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aksdf;aksdf; C:\Windows\system32\DRIVERS\aksdf.sys [2006-12-13 65024]
R2 aksfridge;aksfridge; \??\C:\Windows\system32\drivers\aksfridge.sys [2013-02-19 141064]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-16 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-16 79184]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-16 92008]
R2 hardlock;hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2006-12-04 314368]
R2 multikey;Virtual USB MultiKey; C:\Windows\system32\DRIVERS\multikey.sys [2014-07-18 67584]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 akshasp;SafeNet Inc. HASP Key; C:\Windows\system32\DRIVERS\akshasp.sys [2013-01-14 60488]
R3 aksusb;SafeNet Inc. USB Key; C:\Windows\system32\DRIVERS\aksusb.sys [2013-03-05 303368]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2010-08-07 3058168]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 FwLnk;FwLnk Driver; C:\Windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-04-20 169584]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 SynTP;Synaptics Pointing Device Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
R3 toshidpt;Bluetooth HID Port; C:\Windows\system32\drivers\Toshidpt.sys [2009-06-19 9608]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2009-09-24 212072]
R3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-06-19 50664]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2009-07-13 19824]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-06-19 94336]
R3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2010-02-03 60408]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [2012-08-28 11880]
S0 TfFsMon;TfFsMon; C:\Windows\system32\drivers\TfFsMon.sys []
S0 TFSysMon;TfSysMon; C:\Windows\system32\drivers\TfSysMon.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files (x86)\SuperAntiSpyware - Professional - XxXFreakyXxX\SASKUTIL.SYS [2010-05-10 67656]
S2 NSHE;Guardant Emulator Driver; \??\C:\Windows\system32\Drivers\NSHE.SYS []
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-03-15 6403072]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files (x86)\MediaCoder\SysInfoX64.sys []
S3 DCR;DCR; \??\C:\Program Files (x86)\DriveCrypt\DCR.Sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2012-03-08 48488]
S3 hmhrwoiz;hmhrwoiz; C:\Windows\system32\drivers\hmhrwoiz.sys []
S3 PCTBD;PC Tools Browser Defender Driver; C:\Windows\System32\Drivers\PCTBD64.sys [2011-09-28 70760]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 tap0901;avast! SecureLine TAP Adapter; C:\Windows\system32\DRIVERS\tap0901.sys [2013-04-30 40616]
S3 TfNetMon;TfNetMon; \??\C:\Windows\system32\drivers\TfNetMon.sys []
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2009-08-05 63856]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-01-07 43336]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-05-07 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-05-07 109048]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 CrypKey License;CrypKey License; C:\Windows\system32\crypserv.exe [2010-03-18 126976]
R2 DriveCryptService;DriveCrypt Service; C:\Program Files (x86)\DriveCrypt\DcrServ.exe [2013-05-09 202112]
R2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-04 136176]
R2 hasplms;Sentinel Local License Manager; C:\Windows\system32\hasplms.exe [2013-01-11 4466120]
R2 HDRExpose3Service;HDRExpose3Service; C:\Program Files\UCT\HDR Expose 3\HDRExpose3Service.exe [2013-10-13 65656]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\SysWOW64\nlssrv32.exe [2012-12-21 66560]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-04-24 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2011-04-24 107832]
R2 Printer Control;Printer Control; C:\Windows\system32\PrintCtrl.exe [2009-10-28 65536]
R2 ProtexisLicensing;ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [2007-06-05 177704]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 PSI_SVC_2_x64;Protexis Licensing V2 x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-11-30 336824]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2009-07-28 140632]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-05 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2012-09-17 2365792]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
R3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2010-02-25 196464]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-01 68608]
S2 ProtectMonitor;Protect Monitor; C:\Program Files\PCDApp\StartHelp.exe [2014-06-09 77705]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08 262320]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-03-08 1492840]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-08-01 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-04 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-01-20 641352]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-08-01 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-02-11 124368]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-07 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------