wizzymantv keylogger,Steam mi vyskakuji porad nejaky stranky
Napsal: 31 srp 2014 14:42
PLS RSIT LOG:Logfile of random's system information tool 1.10 (written by random/random)
Run by User at 2014-08-31 15:33:57
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 598 GB (84%) free of 715 GB
Total RAM: 4091 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:34:11, on 31.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Users\User\AppData\Local\FirmwareOfficeRecycle\IconInterpreterOpen.exe
C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Gaming Keyboard\OSD.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\User.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:40685
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 216.239.32.20 google.com
O1 - Hosts: 216.239.32.20 google.com www.google.ad
O1 - Hosts: 216.239.32.20 google.com www.google.ae
O1 - Hosts: 216.239.32.20 google.com www.google.com.af
O1 - Hosts: 216.239.32.20 google.com www.google.com.ag
O1 - Hosts: 216.239.32.20 google.com www.google.com.ai
O1 - Hosts: 216.239.32.20 google.com www.google.al
O1 - Hosts: 216.239.32.20 google.com www.google.am
O1 - Hosts: 216.239.32.20 google.com www.google.co.ao
O1 - Hosts: 216.239.32.20 google.com www.google.com.ar
O1 - Hosts: 216.239.32.20 google.com www.google.as
O1 - Hosts: 216.239.32.20 google.com www.google.at
O1 - Hosts: 216.239.32.20 google.com www.google.com.au
O1 - Hosts: 216.239.32.20 google.com www.google.az
O1 - Hosts: 216.239.32.20 google.com www.google.ba
O1 - Hosts: 216.239.32.20 google.com www.google.com.bd
O1 - Hosts: 216.239.32.20 google.com www.google.be
O1 - Hosts: 216.239.32.20 google.com www.google.bf
O1 - Hosts: 216.239.32.20 google.com www.google.bg
O1 - Hosts: 216.239.32.20 google.com www.google.com.bh
O1 - Hosts: 216.239.32.20 google.com www.google.bi
O1 - Hosts: 216.239.32.20 google.com www.google.bj
O1 - Hosts: 216.239.32.20 google.com www.google.com.bn
O1 - Hosts: 216.239.32.20 google.com www.google.com.bo
O1 - Hosts: 216.239.32.20 google.com www.google.com.br
O1 - Hosts: 216.239.32.20 google.com www.google.bs
O1 - Hosts: 216.239.32.20 google.com www.google.bt
O1 - Hosts: 216.239.32.20 google.com www.google.co.bw
O1 - Hosts: 216.239.32.20 google.com www.google.by
O1 - Hosts: 216.239.32.20 google.com www.google.com.bz
O1 - Hosts: 216.239.32.20 google.com www.google.ca
O1 - Hosts: 216.239.32.20 google.com www.google.cd
O1 - Hosts: 216.239.32.20 google.com www.google.cf
O1 - Hosts: 216.239.32.20 google.com www.google.cg
O1 - Hosts: 216.239.32.20 google.com www.google.ch
O1 - Hosts: 216.239.32.20 google.com www.google.ci
O1 - Hosts: 216.239.32.20 google.com www.google.co.ck
O1 - Hosts: 216.239.32.20 google.com www.google.cl
O1 - Hosts: 216.239.32.20 google.com www.google.cm
O1 - Hosts: 216.239.32.20 google.com www.google.cn
O1 - Hosts: 216.239.32.20 google.com www.google.com.co
O1 - Hosts: 216.239.32.20 google.com www.google.co.cr
O1 - Hosts: 216.239.32.20 google.com www.google.com.cu
O1 - Hosts: 216.239.32.20 google.com www.google.cv
O1 - Hosts: 216.239.32.20 google.com www.google.com.cy
O1 - Hosts: 216.239.32.20 google.com www.google.cz
O1 - Hosts: 216.239.32.20 google.com www.google.de
O1 - Hosts: 216.239.32.20 google.com www.google.dj
O1 - Hosts: 216.239.32.20 google.com www.google.dk
O1 - Hosts: 216.239.32.20 google.com www.google.dm
O1 - Hosts: 216.239.32.20 google.com www.google.com.do
O1 - Hosts: 216.239.32.20 google.com www.google.dz
O1 - Hosts: 216.239.32.20 google.com www.google.com.ec
O1 - Hosts: 216.239.32.20 google.com www.google.ee
O1 - Hosts: 216.239.32.20 google.com www.google.com.eg
O1 - Hosts: 216.239.32.20 google.com www.google.es
O1 - Hosts: 216.239.32.20 google.com www.google.com.et
O1 - Hosts: 216.239.32.20 google.com www.google.fi
O1 - Hosts: 216.239.32.20 google.com www.google.com.fj
O1 - Hosts: 216.239.32.20 google.com www.google.fm
O1 - Hosts: 216.239.32.20 google.com www.google.fr
O1 - Hosts: 216.239.32.20 google.com www.google.ga
O1 - Hosts: 216.239.32.20 google.com www.google.ge
O1 - Hosts: 216.239.32.20 google.com www.google.gg
O1 - Hosts: 216.239.32.20 google.com www.google.com.gh
O1 - Hosts: 216.239.32.20 google.com www.google.com.gi
O1 - Hosts: 216.239.32.20 google.com www.google.gl
O1 - Hosts: 216.239.32.20 google.com www.google.gm
O1 - Hosts: 216.239.32.20 google.com www.google.gp
O1 - Hosts: 216.239.32.20 google.com www.google.gr
O1 - Hosts: 216.239.32.20 google.com www.google.com.gt
O1 - Hosts: 216.239.32.20 google.com www.google.gy
O1 - Hosts: 216.239.32.20 google.com www.google.com.hk
O1 - Hosts: 216.239.32.20 google.com www.google.hn
O1 - Hosts: 216.239.32.20 google.com www.google.hr
O1 - Hosts: 216.239.32.20 google.com www.google.ht
O1 - Hosts: 216.239.32.20 google.com www.google.hu
O1 - Hosts: 216.239.32.20 google.com www.google.co.id
O1 - Hosts: 216.239.32.20 google.com www.google.ie
O1 - Hosts: 216.239.32.20 google.com www.google.co.il
O1 - Hosts: 216.239.32.20 google.com www.google.im
O1 - Hosts: 216.239.32.20 google.com www.google.co.in
O1 - Hosts: 216.239.32.20 google.com www.google.iq
O1 - Hosts: 216.239.32.20 google.com www.google.is
O1 - Hosts: 216.239.32.20 google.com www.google.it
O1 - Hosts: 216.239.32.20 google.com www.google.je
O1 - Hosts: 216.239.32.20 google.com www.google.com.jm
O1 - Hosts: 216.239.32.20 google.com www.google.jo
O1 - Hosts: 216.239.32.20 google.com www.google.co.jp
O1 - Hosts: 216.239.32.20 google.com www.google.co.ke
O1 - Hosts: 216.239.32.20 google.com www.google.com.kh
O1 - Hosts: 216.239.32.20 google.com www.google.ki
O1 - Hosts: 216.239.32.20 google.com www.google.kg
O1 - Hosts: 216.239.32.20 google.com www.google.co.kr
O1 - Hosts: 216.239.32.20 google.com www.google.com.kw
O1 - Hosts: 216.239.32.20 google.com www.google.kz
O1 - Hosts: 216.239.32.20 google.com www.google.la
O1 - Hosts: 216.239.32.20 google.com www.google.com.lb
O1 - Hosts: 216.239.32.20 google.com www.google.li
O1 - Hosts: 216.239.32.20 google.com www.google.lk
O1 - Hosts: 216.239.32.20 google.com www.google.co.ls
O2 - BHO: CrossriderApp0048559 - {11111111-1111-1111-1111-110411851159} - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: ͬ˛˝Ň»Ľü°˛×°Ö§łÖ - {F72C8153-7140-4FEE-8F69-CA4579D71195} - C:\Program Files (x86)\Tongbu\Addin\tbIEAddin.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [VICTORY Gaming Keyboard] "C:\Program Files (x86)\Gaming Keyboard\Monitor.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD5B331D-8735-43FC-A8ED-F847E7761D95}: NameServer = 213.46.172.36,213.46.172.37
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: 0fe17f7f7055ca8.exe - Unknown owner - C:\Users\User\AppData\Local\0c8010b42ce9c0896292f9a00871cf6d\0fe17f7f7055ca8.exe (file missing)
O23 - Service: 8466e4bf6f86000.exe - Unknown owner - C:\Users\User\AppData\Local\e5a6946aeccac218acdd006c605848c5\8466e4bf6f86000.exe (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: CronDockWord.exe - Unknown owner - C:\Users\User\AppData\Local\CronDockWord\CronDockWord.exe (file missing)
O23 - Service: DebugPathRoot.exe - Unknown owner - C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\MotionOCRWin32.exe
O23 - Service: e177f95e8bcdff0.exe - Unknown owner - C:\Users\User\AppData\Local\5b37c15f318304c12ff7bd21aaf6bc6b\e177f95e8bcdff0.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FirmwareOfficeRecycle.exe - Unknown owner - C:\Users\User\AppData\Local\FirmwareOfficeRecycle\FirmwareOfficeRecycle.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PirritDesktop - Unknown owner - C:\Users\User\AppData\Local\PirritSuggestor\PirritService.exe (file missing)
O23 - Service: PirritUpdater - Unknown owner - C:\Program Files (x86)\Pirrit\AutoUpdater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WinRST - Unknown owner - C:\Program Files (x86)\WinRST\WinRST.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 16191 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\MotionOCRWin32.exe
C:\Users\User\AppData\Local\FirmwareOfficeRecycle\FirmwareOfficeRecycle.exe
"C:\Program Files (x86)\Pirrit\AutoUpdater.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\WinRST\WinRST.exe"
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
atieclxx
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
IconInterpreterOpen.exe
"C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Gaming Keyboard\OSD.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-56a534bd-1114-4de2-9c08-de9c12ea3c21 -SystemEventPortName:HostProcess-d5b43a74-ed36-4d38-ad43-dd124022e3b0 -IoCancelEventPortName:HostProcess-006129e3-4d6c-46ba-93d7-5051270fc4e2 -NonStateChangingEventPortName:HostProcess-ced9680f-57ac-43a4-be90-76483565d6ec -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c33f394f-d8a0-49a2-88f0-6807264c0ed5 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Program Files (x86)\Steam\config\htmlcache" -cookiepath "C:\Program Files (x86)\Steam\config\cookies" -steampid 5692 --blacklist-accelerated-compositing --process-per-tab --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3960.0.2033263845\1430495657" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x68c1 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.2.1000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.2.1743190065\411163397" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.5.1688524800\1312424062" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3960.6.1479982264\217345010" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.7.464246185\1044245472" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.11.242232173\15007078" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\User\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll" --lang=cs --channel="3960.12.1396642052\1790176727" /prefetch:-390060480
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.16.1942553814\1533115564" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.18.2073480362\259407345" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe59_ Global\UsGthrCtrlFltPipeMssGthrPipe59 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\User\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-1.job - C:\Program Files (x86)\Apps Hat\Apps Hat-codedownloader.exe /KErnuMLG /IeOlK=task /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /hMcthrAC=http://js.demogensrv.com /KnYThIW=ch /IjULhBEC='Apps Hat' /fsnbs=http://js.clientdemocloud.com /AAbsiszl /TZAWX='{"asw":[8, 8388865, 8192]}' /WUDZEY='http://update.demogensrv.com/ie_code_ag ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-11.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-11.exe /fHvrm=RZMHaz6kC1yF82Qxs2oBE/RvrVY2Ybo5XhMJxRb4pUxY3ZBzfOBjACK/w18TSNsHJ6z6h/cQd0VrwPAIDKIU9qWNa0b7exsAfzJqOxZ6SkDvtroTAgkHSNWUidud+O7QKIBnzWMxIlzzl7wwiy9OkO305cR9N2jxYFA1ewro7mGMGGxs6uzN+WQr0TSd8QGelr8w6jAN8qRapufAJPxRvwEq0dTh/oe+J185dO7yule46jIAkQSW/4iP4r3mn6smsUhvH6V/luIMzCEQXwKnSUD2jJt+G6naQiYvpNcxQl+t4V9vtAGl0VmEqQLPJLh4LERJ92IktG96i0rv2098cTD8XtISekhOVe+zs6RVNvuGKYrAT7aYv3HlSVaDQyq1TubLnaTOcaVvvAKtHYwpFxn/3TMxCsyRKLSh5tx1qb3gH3bbMEoplKwRJl43HT87ovTdNKEB8Ro5k9ILdA9ifyjU1LN/3dM8hOwZlW/yAjOCsQkF1krtMD6iq7EFffRrJJG/hdCFbs459n7wIkI8NkONF8wi3/F0mmsn8l2rX9I0hskMEOPTn8IkkJLRygBRazfX3hXt1WcTFIbnTC8k6LnD73VWAkv1E+NnT4VI1X7IFwHB64f0T+CSNR+oxoRRkruWPN51wVKZIBU4AVsQZ0fR7D+Xkvbc4IDun6gdtSmdAP9oHDzqFpJgE8XGc6K7F9837iuGepUqjPPKMChpZ1GQ/jggej8AiTHNkxZYUyRLzJC7pErIiLQOdpNrVsU2lpndGwmDy5fktSdfUKvUeuc2//3/8S56Bt/PtitpAD93PU/Nz1a4wYNBBxROv5efHBaIa+m2C6qXNfwI9S6SlX5GyYit9HK0gkdrLS9wqAoviXYneGHlFc529jnuCTFoNxHxkYcS1fEWJVzjwjK9GtFFgR41Wt5eiu2OIg6yP7Uip0u7nKID6YEKAyYEJ/7c1L/clk0zKTwo0+gZ73JyC4JLOjxfC282gqEljuRhef8uyG0Rah7OfaZKnnKFIQVQjGhUiLi8lRy24vBR3i7W09t8k557urlS/C8kFycuhrlb/rwLTQ9vVqKW9PXJi0bLQDK5SKUiLTh2vjFAX1yN8K1dyH1pbAnVZOlfq0wgEDgfN7xpgr0EXQaNhlhcAH0TTH8I0paFQ8dh5JSw7A1T3HmWNsqUpCjdN0Rzd75DXKlOTb1h0lJuKZHw6sMH5cIu6hXyuPx7CvxLVGGlwIKLVdao5hDYm403xaBUnrnVP3fX/9QxbSClKgXknhcwWQ+QjGiMsYA1TeLqxmzKuzxI5gv/QbA29AGTJYVQdytrTEXNIeW3WtySfFjQQofMI10stC6T1iKPmgHI7Z0I/pd75Brl0pejx9nSfJH4nJzLiGoviyhRgTEIu6gUcadn9FhIbC6Auj9vCZbXp1iyFaJtEl+JgQEZBkkZ2C/lMZUjqrc6wqMk1LCcTTbon6XX6qQmshiDWRYd7I1+fL+g5NxRTbckEVsYUeKjnjbdjJiTq/rulXLJTw52tmr7QNvym4Z2WLj2ycqCsU/zFX5axHdaedgmA//WDpznDhPjVm5x6I+E37ENeilarl1K3eoAnQfxt6FdJ5BgZvY0ipXSJ7fncOs5C8hdCmjMEm9O/v9PLDvwlOzz+K6LY/6oQ87EgCyus9LtOeIcVqgdX3Brj0Y/6yoc1Z0diqg0Ete0yNc6Yjs=
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-2.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-2.exe /YMmAdk /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /tPTsxJ=11111111-1111-1111-1111-110411851159 /KnYThIW=ch /AAbsiszl /WUDZEY='http://update.demogensrv.com/ie_enable_ ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-4.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-4.exe /WcPdmF /tlXRNE='Apps Hat' /FAmTNpDoq='C:\Program Files (x86)\Apps Hat\48559.xpi' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /QyNPVnxx=300 /XYDvX=39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com /csSaPmn=0.94 /wZlfdPUdl=a39ed7c16185d4f88b976666d4928ba01fe4550c17a4f4a62ad1c45e0afdf81a4com48559 /ocdMLWR=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /48559.rdf /coaxQmy='Apps Hat' /BDyqM='Apps Hat is the cool new Android app store that helps you discover hot new apps, both free and discounted. Get personalised recommendations, price drop alerts, and share your favourite apps with your friends.' /LNvLrmGBG='Nero' /KnYThIW=ch /TZAWX='{"asw":[8, 8388865, 8192]}' /AAbsiszl /jngKTGD /XwGPiFIOB /WUDZEY='http://update.demogensrv.com/ff_agent_u ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5.exe /tYYjLolaj /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /nWcMkaj=http://ipgeoapi.com/ /LOxcpm=http://update.demogensrv.com /ypSmK=2 /SEfUEIJq=http://logs.demogensrv.com /WUDZEY='http://update.demogensrv.com/updater_ag ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5_user.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5.exe /tYYjLolaj /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /nWcMkaj=http://ipgeoapi.com/ /LOxcpm=http://update.demogensrv.com /ypSmK=2 /SEfUEIJq=http://logs.demogensrv.com /WUDZEY='http://update.demogensrv.com/updater_ag ... pdate.json' /ntRfp /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-6.job - C:\Program Files (x86)\Apps Hat\Apps Hat-novainstaller.exe /xNlXmmsw /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /hMcthrAC=http://js.demogensrv.com /KnYThIW=ch /fxVrX /IjULhBEC=Apps Hat /EYjsYgpml='nova' /fsnbs=http://js.clientdemocloud.com /TZAWX='{"asw":[8, 8388865, 8192]}' /IeOlK=task /WUDZEY='http://update.demogensrv.com/novacode/{ ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-7.job - C:\Program Files (x86)\Apps Hat\Apps Hat-nova.exe /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /hMcthrAC=http://js.demogensrv.com /KnYThIW=ch /fxVrX /IjULhBEC=Apps Hat /EYjsYgpml='nova' /fsnbs=http://js.clientdemocloud.com /TZAWX='{"asw":[8, 8388865, 8192]}' /WUDZEY='http://update.demogensrv.com/novarun/{C ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1570955093-1124358558-1990792310-1000Core.job - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1570955093-1124358558-1990792310-1000UA.job - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}]
IEExtension.Extension - C:\Windows\system32\mscoree.dll [2010-11-05 444752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F72C8153-7140-4FEE-8F69-CA4579D71195}]
ͬ˛˝Ň»Ľü°˛×°Ö§łÖ - C:\Program Files (x86)\Tongbu\Addin\tbIEAddin.dll [2013-04-01 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 1271072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-22 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-31 43816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-22 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
C:\Users\User\AppData\Roaming\ICQM\icq.exe -CU []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ManyCam]
C:\Program Files (x86)\ManyCam\ManyCam.exe [2014-06-09 8795312]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RazerGameBooster]
C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
C:\Program Files (x86)\RocketDock\RocketDock.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartAudio]
C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartFaceVWatcher]
C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2014-08-28 1939136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwidget]
C:\Program Files (x86)\XWidget\xwidget.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~2\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-15 98304]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"VICTORY Gaming Keyboard"=C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [2013-04-09 270336]
"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2014-05-28 455512]
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2014-01-10 1861968]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-11 256896]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-08-31 15:33:57 ----D---- C:\rsit
2014-08-31 15:33:57 ----D---- C:\Program Files\trend micro
2014-08-30 21:47:05 ----D---- C:\ProgramData\Media Center Programs
2014-08-30 21:26:26 ----D---- C:\Program Files (x86)\Tomb Raider - Anniversary
2014-08-30 21:23:57 ----D---- C:\Windows\Downloaded Installations
2014-08-27 22:28:36 ----D---- C:\Program Files (x86)\Aspyr Media, Inc
2014-08-27 19:31:05 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-27 19:31:05 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 19:31:05 ----A---- C:\Windows\system32\gdi32.dll
2014-08-25 20:53:30 ----D---- C:\Users\User\AppData\Roaming\Mp3tag
2014-08-25 20:53:14 ----D---- C:\Program Files (x86)\Mp3tag
2014-08-25 02:16:22 ----D---- C:\Program Files (x86)\AMP WinOFF
2014-08-21 14:09:50 ----D---- C:\Program Files (x86)\The-Lost-Island
2014-08-20 16:06:31 ----D---- C:\Users\User\AppData\Roaming\Teiron
2014-08-20 15:06:25 ----D---- C:\Program Files (x86)\Tongbu
2014-08-19 19:02:51 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-19 19:02:51 ----D---- C:\Program Files\iTunes
2014-08-19 19:02:51 ----D---- C:\Program Files\iPod
2014-08-19 19:02:51 ----D---- C:\Program Files (x86)\iTunes
2014-08-16 21:00:35 ----A---- C:\Windows\SYSWOW64\Block.txt
2014-08-16 20:59:10 ----D---- C:\Windows\SYSWOW64\pack
2014-08-16 18:04:55 ----D---- C:\Program Files (x86)\Attomey ---
2014-08-15 21:16:03 ----D---- C:\Users\User\AppData\Roaming\Tomabo
2014-08-13 19:04:02 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-13 19:04:02 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-13 19:04:01 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-13 19:04:01 ----A---- C:\Windows\system32\icardagt.exe
2014-08-13 19:03:56 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-13 19:03:56 ----A---- C:\Windows\system32\icardres.dll
2014-08-13 19:03:05 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-13 19:03:04 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 18:29:30 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-13 18:29:30 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-13 18:29:15 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-13 18:29:15 ----A---- C:\Windows\system32\tzres.dll
2014-08-13 18:28:18 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-13 18:28:18 ----A---- C:\Windows\system32\msi.dll
2014-08-13 18:28:18 ----A---- C:\Windows\system32\authui.dll
2014-08-13 18:28:17 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-13 18:28:16 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-13 18:28:16 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 18:28:16 ----A---- C:\Windows\system32\consent.exe
2014-08-13 18:27:06 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 18:26:55 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-13 18:26:55 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-13 18:26:54 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-13 18:26:54 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-13 18:26:53 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 18:26:53 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 18:26:51 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-08-13 18:26:51 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-13 18:26:51 ----A---- C:\Windows\system32\iernonce.dll
2014-08-13 18:26:51 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-13 18:26:50 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-13 18:26:50 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-08-13 18:26:50 ----A---- C:\Windows\system32\urlmon.dll
2014-08-13 18:26:50 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 18:26:49 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-08-13 18:26:49 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-13 18:26:49 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-13 18:26:49 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-13 18:26:48 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-08-13 18:26:48 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-13 18:26:47 ----A---- C:\Windows\system32\iesetup.dll
2014-08-13 18:26:47 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-13 18:26:46 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-08-13 18:26:46 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-08-13 18:26:46 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-13 18:26:46 ----A---- C:\Windows\system32\iertutil.dll
2014-08-13 18:26:45 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-08-13 18:26:45 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-08-13 18:26:45 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-13 18:26:45 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-13 18:26:44 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-08-13 18:26:44 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-13 18:26:42 ----A---- C:\Windows\system32\ieui.dll
2014-08-13 18:26:42 ----A---- C:\Windows\system32\ieframe.dll
2014-08-13 18:26:42 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-13 18:26:41 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-08-13 18:26:41 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-13 18:26:40 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-13 18:26:40 ----A---- C:\Windows\system32\jscript9.dll
2014-08-13 18:26:40 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-13 18:26:39 ----A---- C:\Windows\system32\wininet.dll
2014-08-13 18:26:39 ----A---- C:\Windows\system32\vbscript.dll
2014-08-13 18:26:39 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-13 18:26:38 ----A---- C:\Windows\system32\msrating.dll
2014-08-13 18:26:38 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-13 18:26:37 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 18:26:37 ----A---- C:\Windows\system32\mshtml.dll
2014-08-13 18:26:12 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-13 18:26:11 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-13 18:25:51 ----A---- C:\Windows\system32\aepdu.dll
2014-08-13 18:25:49 ----A---- C:\Windows\system32\aeinv.dll
2014-08-12 18:33:35 ----D---- C:\Users\User\AppData\Roaming\Dropbox
2014-08-10 17:39:41 ----D---- C:\downloads
2014-08-03 10:55:24 ----A---- C:\Windows\system32\wups2.dll
2014-08-03 10:55:24 ----A---- C:\Windows\system32\wuauclt.exe
2014-08-03 10:55:23 ----A---- C:\Windows\system32\wucltux.dll
2014-08-03 10:55:23 ----A---- C:\Windows\system32\wuaueng.dll
2014-08-03 10:55:04 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-08-03 10:55:04 ----A---- C:\Windows\system32\wups.dll
2014-08-03 10:55:04 ----A---- C:\Windows\system32\wudriver.dll
2014-08-03 10:55:03 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-08-03 10:55:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-08-03 10:55:03 ----A---- C:\Windows\system32\wuapi.dll
2014-08-03 10:54:48 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-08-03 10:54:48 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-08-03 10:54:48 ----A---- C:\Windows\system32\wuwebv.dll
2014-08-03 10:54:47 ----A---- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2014-08-31 15:33:57 ----RD---- C:\Program Files
2014-08-31 15:33:10 ----D---- C:\Windows\Temp
2014-08-31 15:20:49 ----D---- C:\Program Files (x86)\Steam
2014-08-31 12:55:12 ----D---- C:\Windows\system32\config
2014-08-31 12:41:08 ----SHD---- C:\System Volume Information
2014-08-30 22:03:14 ----D---- C:\Windows\system32\Tasks
2014-08-30 21:47:05 ----HD---- C:\ProgramData
2014-08-30 21:46:55 ----RSD---- C:\Windows\assembly
2014-08-30 21:26:26 ----RD---- C:\Program Files (x86)
2014-08-30 21:25:29 ----SHD---- C:\Windows\Installer
2014-08-30 21:25:18 ----D---- C:\Windows\SysWOW64
2014-08-30 21:23:57 ----D---- C:\Windows
2014-08-30 18:49:46 ----D---- C:\Users\User\AppData\Roaming\vlc
2014-08-29 16:29:51 ----D---- C:\Windows\System32
2014-08-29 16:29:51 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-08-29 16:29:48 ----D---- C:\Windows\inf
2014-08-27 22:26:12 ----RD---- C:\Wizzy
2014-08-27 22:18:18 ----D---- C:\Windows\winsxs
2014-08-27 19:27:06 ----D---- C:\Windows\system32\catroot
2014-08-27 19:13:33 ----D---- C:\Windows\system32\wdi
2014-08-26 16:52:46 ----D---- C:\Program Files (x86)\Last-World
2014-08-24 19:47:17 ----D---- C:\Program Files (x86)\QuadCoreM2
2014-08-23 18:07:18 ----D---- C:\Users\User\AppData\Roaming\OBS
2014-08-23 18:05:50 ----D---- C:\Program Files\OBS
2014-08-23 18:05:38 ----D---- C:\Program Files (x86)\OBS
2014-08-21 21:35:44 ----D---- C:\Users\User\AppData\Roaming\DivX
2014-08-21 21:35:07 ----D---- C:\Windows\system32\catroot2
2014-08-21 13:47:29 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-08-20 16:00:07 ----D---- C:\Users\User\AppData\Roaming\ihelper2014
2014-08-19 19:12:43 ----D---- C:\Program Files (x86)\Opera
2014-08-17 01:47:26 ----D---- C:\Program Files (x86)\Google
2014-08-17 01:47:01 ----D---- C:\Windows\Tasks
2014-08-16 15:50:40 ----D---- C:\Windows\Microsoft.NET
2014-08-15 20:27:10 ----D---- C:\Users\User\AppData\Roaming\Skype
2014-08-15 11:46:09 ----D---- C:\Program Files (x86)\Internet Explorer
2014-08-14 15:16:06 ----D---- C:\Windows\system32\drivers
2014-08-13 21:17:05 ----D---- C:\Windows\ehome
2014-08-13 21:17:04 ----RSD---- C:\Windows\Fonts
2014-08-13 21:16:57 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-13 21:16:57 ----D---- C:\Windows\system32\cs-CZ
2014-08-13 21:16:56 ----D---- C:\Windows\SYSWOW64\en-US
2014-08-13 21:16:56 ----D---- C:\Windows\system32\en-US
2014-08-13 21:16:56 ----D---- C:\Windows\PolicyDefinitions
2014-08-13 21:16:56 ----D---- C:\Program Files\Internet Explorer
2014-08-13 19:31:00 ----D---- C:\ProgramData\Microsoft Help
2014-08-13 19:15:58 ----D---- C:\Windows\system32\MRT
2014-08-13 19:12:34 ----A---- C:\Windows\system32\MRT.exe
2014-08-13 19:01:23 ----SD---- C:\Windows\system32\CompatTel
2014-08-12 18:35:13 ----D---- C:\Windows\Prefetch
2014-08-01 22:54:59 ----D---- C:\Users\User\AppData\Roaming\.minecraft
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2007-11-09 26968]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-04-20 169584]
R3 ManyCam;ManyCam Virtual Webcam; C:\Windows\system32\DRIVERS\mcvidrv.sys [2014-05-13 42224]
R3 mcaudrv_simple;ManyCam Virtual Microphone; C:\Windows\system32\drivers\mcaudrv_x64.sys [2014-05-13 35440]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2013-03-28 1226344]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2013-08-06 23040]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RegFltrX64;RegFltrX64; \??\C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\RegFltrX64.sys []
S3 RgFltX64;RgFltX64; \??\C:\Users\User\AppData\Local\FirmwareOfficeRecycle\RgFltX64.sys []
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 xhunter1;xhunter1; \??\C:\Windows\xhunter1.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-06-12 43336]
R2 DebugPathRoot.exe;DebugPathRoot.exe; C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\MotionOCRWin32.exe [2014-06-03 110592]
R2 FirmwareOfficeRecycle.exe;FirmwareOfficeRecycle.exe; C:\Users\User\AppData\Local\FirmwareOfficeRecycle\FirmwareOfficeRecycle.exe [2014-07-28 98341]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 PirritUpdater;PirritUpdater; C:\Program Files (x86)\Pirrit\AutoUpdater.exe [2014-02-20 59904]
R2 WinRST;WinRST; C:\Program Files (x86)\WinRST\WinRST.exe [2014-02-26 59904]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-08-01 641352]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S2 0fe17f7f7055ca8.exe;0fe17f7f7055ca8.exe; C:\Users\User\AppData\Local\0c8010b42ce9c0896292f9a00871cf6d\0fe17f7f7055ca8.exe []
S2 8466e4bf6f86000.exe;8466e4bf6f86000.exe; C:\Users\User\AppData\Local\e5a6946aeccac218acdd006c605848c5\8466e4bf6f86000.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 CronDockWord.exe;CronDockWord.exe; C:\Users\User\AppData\Local\CronDockWord\CronDockWord.exe []
S2 e177f95e8bcdff0.exe;e177f95e8bcdff0.exe; C:\Users\User\AppData\Local\5b37c15f318304c12ff7bd21aaf6bc6b\e177f95e8bcdff0.exe []
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-06 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-17 116648]
S2 PirritDesktop;PirritDesktop; C:\Users\User\AppData\Local\PirritSuggestor\PirritService.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-21 262320]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-06 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-17 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-07-25 111616]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-03-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
mam v PC keylogger nebo nejaky malware?
Run by User at 2014-08-31 15:33:57
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 598 GB (84%) free of 715 GB
Total RAM: 4091 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:34:11, on 31.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Users\User\AppData\Local\FirmwareOfficeRecycle\IconInterpreterOpen.exe
C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Gaming Keyboard\OSD.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\User.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:40685
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 216.239.32.20 google.com
O1 - Hosts: 216.239.32.20 google.com www.google.ad
O1 - Hosts: 216.239.32.20 google.com www.google.ae
O1 - Hosts: 216.239.32.20 google.com www.google.com.af
O1 - Hosts: 216.239.32.20 google.com www.google.com.ag
O1 - Hosts: 216.239.32.20 google.com www.google.com.ai
O1 - Hosts: 216.239.32.20 google.com www.google.al
O1 - Hosts: 216.239.32.20 google.com www.google.am
O1 - Hosts: 216.239.32.20 google.com www.google.co.ao
O1 - Hosts: 216.239.32.20 google.com www.google.com.ar
O1 - Hosts: 216.239.32.20 google.com www.google.as
O1 - Hosts: 216.239.32.20 google.com www.google.at
O1 - Hosts: 216.239.32.20 google.com www.google.com.au
O1 - Hosts: 216.239.32.20 google.com www.google.az
O1 - Hosts: 216.239.32.20 google.com www.google.ba
O1 - Hosts: 216.239.32.20 google.com www.google.com.bd
O1 - Hosts: 216.239.32.20 google.com www.google.be
O1 - Hosts: 216.239.32.20 google.com www.google.bf
O1 - Hosts: 216.239.32.20 google.com www.google.bg
O1 - Hosts: 216.239.32.20 google.com www.google.com.bh
O1 - Hosts: 216.239.32.20 google.com www.google.bi
O1 - Hosts: 216.239.32.20 google.com www.google.bj
O1 - Hosts: 216.239.32.20 google.com www.google.com.bn
O1 - Hosts: 216.239.32.20 google.com www.google.com.bo
O1 - Hosts: 216.239.32.20 google.com www.google.com.br
O1 - Hosts: 216.239.32.20 google.com www.google.bs
O1 - Hosts: 216.239.32.20 google.com www.google.bt
O1 - Hosts: 216.239.32.20 google.com www.google.co.bw
O1 - Hosts: 216.239.32.20 google.com www.google.by
O1 - Hosts: 216.239.32.20 google.com www.google.com.bz
O1 - Hosts: 216.239.32.20 google.com www.google.ca
O1 - Hosts: 216.239.32.20 google.com www.google.cd
O1 - Hosts: 216.239.32.20 google.com www.google.cf
O1 - Hosts: 216.239.32.20 google.com www.google.cg
O1 - Hosts: 216.239.32.20 google.com www.google.ch
O1 - Hosts: 216.239.32.20 google.com www.google.ci
O1 - Hosts: 216.239.32.20 google.com www.google.co.ck
O1 - Hosts: 216.239.32.20 google.com www.google.cl
O1 - Hosts: 216.239.32.20 google.com www.google.cm
O1 - Hosts: 216.239.32.20 google.com www.google.cn
O1 - Hosts: 216.239.32.20 google.com www.google.com.co
O1 - Hosts: 216.239.32.20 google.com www.google.co.cr
O1 - Hosts: 216.239.32.20 google.com www.google.com.cu
O1 - Hosts: 216.239.32.20 google.com www.google.cv
O1 - Hosts: 216.239.32.20 google.com www.google.com.cy
O1 - Hosts: 216.239.32.20 google.com www.google.cz
O1 - Hosts: 216.239.32.20 google.com www.google.de
O1 - Hosts: 216.239.32.20 google.com www.google.dj
O1 - Hosts: 216.239.32.20 google.com www.google.dk
O1 - Hosts: 216.239.32.20 google.com www.google.dm
O1 - Hosts: 216.239.32.20 google.com www.google.com.do
O1 - Hosts: 216.239.32.20 google.com www.google.dz
O1 - Hosts: 216.239.32.20 google.com www.google.com.ec
O1 - Hosts: 216.239.32.20 google.com www.google.ee
O1 - Hosts: 216.239.32.20 google.com www.google.com.eg
O1 - Hosts: 216.239.32.20 google.com www.google.es
O1 - Hosts: 216.239.32.20 google.com www.google.com.et
O1 - Hosts: 216.239.32.20 google.com www.google.fi
O1 - Hosts: 216.239.32.20 google.com www.google.com.fj
O1 - Hosts: 216.239.32.20 google.com www.google.fm
O1 - Hosts: 216.239.32.20 google.com www.google.fr
O1 - Hosts: 216.239.32.20 google.com www.google.ga
O1 - Hosts: 216.239.32.20 google.com www.google.ge
O1 - Hosts: 216.239.32.20 google.com www.google.gg
O1 - Hosts: 216.239.32.20 google.com www.google.com.gh
O1 - Hosts: 216.239.32.20 google.com www.google.com.gi
O1 - Hosts: 216.239.32.20 google.com www.google.gl
O1 - Hosts: 216.239.32.20 google.com www.google.gm
O1 - Hosts: 216.239.32.20 google.com www.google.gp
O1 - Hosts: 216.239.32.20 google.com www.google.gr
O1 - Hosts: 216.239.32.20 google.com www.google.com.gt
O1 - Hosts: 216.239.32.20 google.com www.google.gy
O1 - Hosts: 216.239.32.20 google.com www.google.com.hk
O1 - Hosts: 216.239.32.20 google.com www.google.hn
O1 - Hosts: 216.239.32.20 google.com www.google.hr
O1 - Hosts: 216.239.32.20 google.com www.google.ht
O1 - Hosts: 216.239.32.20 google.com www.google.hu
O1 - Hosts: 216.239.32.20 google.com www.google.co.id
O1 - Hosts: 216.239.32.20 google.com www.google.ie
O1 - Hosts: 216.239.32.20 google.com www.google.co.il
O1 - Hosts: 216.239.32.20 google.com www.google.im
O1 - Hosts: 216.239.32.20 google.com www.google.co.in
O1 - Hosts: 216.239.32.20 google.com www.google.iq
O1 - Hosts: 216.239.32.20 google.com www.google.is
O1 - Hosts: 216.239.32.20 google.com www.google.it
O1 - Hosts: 216.239.32.20 google.com www.google.je
O1 - Hosts: 216.239.32.20 google.com www.google.com.jm
O1 - Hosts: 216.239.32.20 google.com www.google.jo
O1 - Hosts: 216.239.32.20 google.com www.google.co.jp
O1 - Hosts: 216.239.32.20 google.com www.google.co.ke
O1 - Hosts: 216.239.32.20 google.com www.google.com.kh
O1 - Hosts: 216.239.32.20 google.com www.google.ki
O1 - Hosts: 216.239.32.20 google.com www.google.kg
O1 - Hosts: 216.239.32.20 google.com www.google.co.kr
O1 - Hosts: 216.239.32.20 google.com www.google.com.kw
O1 - Hosts: 216.239.32.20 google.com www.google.kz
O1 - Hosts: 216.239.32.20 google.com www.google.la
O1 - Hosts: 216.239.32.20 google.com www.google.com.lb
O1 - Hosts: 216.239.32.20 google.com www.google.li
O1 - Hosts: 216.239.32.20 google.com www.google.lk
O1 - Hosts: 216.239.32.20 google.com www.google.co.ls
O2 - BHO: CrossriderApp0048559 - {11111111-1111-1111-1111-110411851159} - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IEExtension.Extension - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: ͬ˛˝Ň»Ľü°˛×°Ö§łÖ - {F72C8153-7140-4FEE-8F69-CA4579D71195} - C:\Program Files (x86)\Tongbu\Addin\tbIEAddin.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [VICTORY Gaming Keyboard] "C:\Program Files (x86)\Gaming Keyboard\Monitor.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{AD5B331D-8735-43FC-A8ED-F847E7761D95}: NameServer = 213.46.172.36,213.46.172.37
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: 0fe17f7f7055ca8.exe - Unknown owner - C:\Users\User\AppData\Local\0c8010b42ce9c0896292f9a00871cf6d\0fe17f7f7055ca8.exe (file missing)
O23 - Service: 8466e4bf6f86000.exe - Unknown owner - C:\Users\User\AppData\Local\e5a6946aeccac218acdd006c605848c5\8466e4bf6f86000.exe (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: CronDockWord.exe - Unknown owner - C:\Users\User\AppData\Local\CronDockWord\CronDockWord.exe (file missing)
O23 - Service: DebugPathRoot.exe - Unknown owner - C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\MotionOCRWin32.exe
O23 - Service: e177f95e8bcdff0.exe - Unknown owner - C:\Users\User\AppData\Local\5b37c15f318304c12ff7bd21aaf6bc6b\e177f95e8bcdff0.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FirmwareOfficeRecycle.exe - Unknown owner - C:\Users\User\AppData\Local\FirmwareOfficeRecycle\FirmwareOfficeRecycle.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PirritDesktop - Unknown owner - C:\Users\User\AppData\Local\PirritSuggestor\PirritService.exe (file missing)
O23 - Service: PirritUpdater - Unknown owner - C:\Program Files (x86)\Pirrit\AutoUpdater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WinRST - Unknown owner - C:\Program Files (x86)\WinRST\WinRST.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 16191 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\MotionOCRWin32.exe
C:\Users\User\AppData\Local\FirmwareOfficeRecycle\FirmwareOfficeRecycle.exe
"C:\Program Files (x86)\Pirrit\AutoUpdater.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\WinRST\WinRST.exe"
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
atieclxx
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
IconInterpreterOpen.exe
"C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Gaming Keyboard\OSD.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-56a534bd-1114-4de2-9c08-de9c12ea3c21 -SystemEventPortName:HostProcess-d5b43a74-ed36-4d38-ad43-dd124022e3b0 -IoCancelEventPortName:HostProcess-006129e3-4d6c-46ba-93d7-5051270fc4e2 -NonStateChangingEventPortName:HostProcess-ced9680f-57ac-43a4-be90-76483565d6ec -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c33f394f-d8a0-49a2-88f0-6807264c0ed5 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Program Files (x86)\Steam\config\htmlcache" -cookiepath "C:\Program Files (x86)\Steam\config\cookies" -steampid 5692 --blacklist-accelerated-compositing --process-per-tab --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3960.0.2033263845\1430495657" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x68c1 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.2.1000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.2.1743190065\411163397" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.5.1688524800\1312424062" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3960.6.1479982264\217345010" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.7.464246185\1044245472" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.11.242232173\15007078" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\User\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll" --lang=cs --channel="3960.12.1396642052\1790176727" /prefetch:-390060480
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.16.1942553814\1533115564" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_45/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="3960.18.2073480362\259407345" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe59_ Global\UsGthrCtrlFltPipeMssGthrPipe59 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Users\User\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-1.job - C:\Program Files (x86)\Apps Hat\Apps Hat-codedownloader.exe /KErnuMLG /IeOlK=task /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /hMcthrAC=http://js.demogensrv.com /KnYThIW=ch /IjULhBEC='Apps Hat' /fsnbs=http://js.clientdemocloud.com /AAbsiszl /TZAWX='{"asw":[8, 8388865, 8192]}' /WUDZEY='http://update.demogensrv.com/ie_code_ag ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-11.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-11.exe /fHvrm=RZMHaz6kC1yF82Qxs2oBE/RvrVY2Ybo5XhMJxRb4pUxY3ZBzfOBjACK/w18TSNsHJ6z6h/cQd0VrwPAIDKIU9qWNa0b7exsAfzJqOxZ6SkDvtroTAgkHSNWUidud+O7QKIBnzWMxIlzzl7wwiy9OkO305cR9N2jxYFA1ewro7mGMGGxs6uzN+WQr0TSd8QGelr8w6jAN8qRapufAJPxRvwEq0dTh/oe+J185dO7yule46jIAkQSW/4iP4r3mn6smsUhvH6V/luIMzCEQXwKnSUD2jJt+G6naQiYvpNcxQl+t4V9vtAGl0VmEqQLPJLh4LERJ92IktG96i0rv2098cTD8XtISekhOVe+zs6RVNvuGKYrAT7aYv3HlSVaDQyq1TubLnaTOcaVvvAKtHYwpFxn/3TMxCsyRKLSh5tx1qb3gH3bbMEoplKwRJl43HT87ovTdNKEB8Ro5k9ILdA9ifyjU1LN/3dM8hOwZlW/yAjOCsQkF1krtMD6iq7EFffRrJJG/hdCFbs459n7wIkI8NkONF8wi3/F0mmsn8l2rX9I0hskMEOPTn8IkkJLRygBRazfX3hXt1WcTFIbnTC8k6LnD73VWAkv1E+NnT4VI1X7IFwHB64f0T+CSNR+oxoRRkruWPN51wVKZIBU4AVsQZ0fR7D+Xkvbc4IDun6gdtSmdAP9oHDzqFpJgE8XGc6K7F9837iuGepUqjPPKMChpZ1GQ/jggej8AiTHNkxZYUyRLzJC7pErIiLQOdpNrVsU2lpndGwmDy5fktSdfUKvUeuc2//3/8S56Bt/PtitpAD93PU/Nz1a4wYNBBxROv5efHBaIa+m2C6qXNfwI9S6SlX5GyYit9HK0gkdrLS9wqAoviXYneGHlFc529jnuCTFoNxHxkYcS1fEWJVzjwjK9GtFFgR41Wt5eiu2OIg6yP7Uip0u7nKID6YEKAyYEJ/7c1L/clk0zKTwo0+gZ73JyC4JLOjxfC282gqEljuRhef8uyG0Rah7OfaZKnnKFIQVQjGhUiLi8lRy24vBR3i7W09t8k557urlS/C8kFycuhrlb/rwLTQ9vVqKW9PXJi0bLQDK5SKUiLTh2vjFAX1yN8K1dyH1pbAnVZOlfq0wgEDgfN7xpgr0EXQaNhlhcAH0TTH8I0paFQ8dh5JSw7A1T3HmWNsqUpCjdN0Rzd75DXKlOTb1h0lJuKZHw6sMH5cIu6hXyuPx7CvxLVGGlwIKLVdao5hDYm403xaBUnrnVP3fX/9QxbSClKgXknhcwWQ+QjGiMsYA1TeLqxmzKuzxI5gv/QbA29AGTJYVQdytrTEXNIeW3WtySfFjQQofMI10stC6T1iKPmgHI7Z0I/pd75Brl0pejx9nSfJH4nJzLiGoviyhRgTEIu6gUcadn9FhIbC6Auj9vCZbXp1iyFaJtEl+JgQEZBkkZ2C/lMZUjqrc6wqMk1LCcTTbon6XX6qQmshiDWRYd7I1+fL+g5NxRTbckEVsYUeKjnjbdjJiTq/rulXLJTw52tmr7QNvym4Z2WLj2ycqCsU/zFX5axHdaedgmA//WDpznDhPjVm5x6I+E37ENeilarl1K3eoAnQfxt6FdJ5BgZvY0ipXSJ7fncOs5C8hdCmjMEm9O/v9PLDvwlOzz+K6LY/6oQ87EgCyus9LtOeIcVqgdX3Brj0Y/6yoc1Z0diqg0Ete0yNc6Yjs=
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-2.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-2.exe /YMmAdk /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /tPTsxJ=11111111-1111-1111-1111-110411851159 /KnYThIW=ch /AAbsiszl /WUDZEY='http://update.demogensrv.com/ie_enable_ ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-4.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-4.exe /WcPdmF /tlXRNE='Apps Hat' /FAmTNpDoq='C:\Program Files (x86)\Apps Hat\48559.xpi' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /QyNPVnxx=300 /XYDvX=39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com /csSaPmn=0.94 /wZlfdPUdl=a39ed7c16185d4f88b976666d4928ba01fe4550c17a4f4a62ad1c45e0afdf81a4com48559 /ocdMLWR=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /48559.rdf /coaxQmy='Apps Hat' /BDyqM='Apps Hat is the cool new Android app store that helps you discover hot new apps, both free and discounted. Get personalised recommendations, price drop alerts, and share your favourite apps with your friends.' /LNvLrmGBG='Nero' /KnYThIW=ch /TZAWX='{"asw":[8, 8388865, 8192]}' /AAbsiszl /jngKTGD /XwGPiFIOB /WUDZEY='http://update.demogensrv.com/ff_agent_u ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5.exe /tYYjLolaj /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /nWcMkaj=http://ipgeoapi.com/ /LOxcpm=http://update.demogensrv.com /ypSmK=2 /SEfUEIJq=http://logs.demogensrv.com /WUDZEY='http://update.demogensrv.com/updater_ag ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5_user.job - C:\Program Files (x86)\Apps Hat\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-5.exe /tYYjLolaj /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /nWcMkaj=http://ipgeoapi.com/ /LOxcpm=http://update.demogensrv.com /ypSmK=2 /SEfUEIJq=http://logs.demogensrv.com /WUDZEY='http://update.demogensrv.com/updater_ag ... pdate.json' /ntRfp /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-6.job - C:\Program Files (x86)\Apps Hat\Apps Hat-novainstaller.exe /xNlXmmsw /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /hMcthrAC=http://js.demogensrv.com /KnYThIW=ch /fxVrX /IjULhBEC=Apps Hat /EYjsYgpml='nova' /fsnbs=http://js.clientdemocloud.com /TZAWX='{"asw":[8, 8388865, 8192]}' /IeOlK=task /WUDZEY='http://update.demogensrv.com/novacode/{ ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\1c4fb8c3-4482-4747-aa6c-6a5ce886c1ec-7.job - C:\Program Files (x86)\Apps Hat\Apps Hat-nova.exe /tlXRNE='Apps Hat' /WpYGyzbuA=48559 /CMToh='000820' /JKHyOHsPa='0' /jmQSexwWU='appshatmadness' /SNWPdw=A03CCF1D97E44490B6686D758867A071IE /stsoS=b0e46312ef3e3f0d9349c7f1bdf317ee /khHSlIt=1_34_07_01 /lHUAqI=1.34.7.1 /jEnATGADV=1404659937 /gJUkMzTp=http://stats.demogensrv.com /ftUune=http://errors.demogensrv.com /hMcthrAC=http://js.demogensrv.com /KnYThIW=ch /fxVrX /IjULhBEC=Apps Hat /EYjsYgpml='nova' /fsnbs=http://js.clientdemocloud.com /TZAWX='{"asw":[8, 8388865, 8192]}' /WUDZEY='http://update.demogensrv.com/novarun/{C ... pdate.json' /IeOlK='task' /ZwhOem=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1570955093-1124358558-1990792310-1000Core.job - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1570955093-1124358558-1990792310-1000UA.job - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-11 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d40c654d-7c51-4eb3-95b2-1e23905c2a2d}]
IEExtension.Extension - C:\Windows\system32\mscoree.dll [2010-11-05 444752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-11 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F72C8153-7140-4FEE-8F69-CA4579D71195}]
ͬ˛˝Ň»Ľü°˛×°Ö§łÖ - C:\Program Files (x86)\Tongbu\Addin\tbIEAddin.dll [2013-04-01 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2010-03-10 520760]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-03-10 2052392]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 1271072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-22 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-31 43816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\User\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-22 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
C:\Users\User\AppData\Roaming\ICQM\icq.exe -CU []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ManyCam]
C:\Program Files (x86)\ManyCam\ManyCam.exe [2014-06-09 8795312]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RazerGameBooster]
C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
C:\Program Files (x86)\RocketDock\RocketDock.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartAudio]
C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartFaceVWatcher]
C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [2009-10-19 238080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2014-08-28 1939136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TWebCamera]
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwidget]
C:\Program Files (x86)\XWidget\xwidget.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~2\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-15 98304]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"VICTORY Gaming Keyboard"=C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [2013-04-09 270336]
"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2014-05-28 455512]
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2014-01-10 1861968]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-11 256896]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-08-31 15:33:57 ----D---- C:\rsit
2014-08-31 15:33:57 ----D---- C:\Program Files\trend micro
2014-08-30 21:47:05 ----D---- C:\ProgramData\Media Center Programs
2014-08-30 21:26:26 ----D---- C:\Program Files (x86)\Tomb Raider - Anniversary
2014-08-30 21:23:57 ----D---- C:\Windows\Downloaded Installations
2014-08-27 22:28:36 ----D---- C:\Program Files (x86)\Aspyr Media, Inc
2014-08-27 19:31:05 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-27 19:31:05 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 19:31:05 ----A---- C:\Windows\system32\gdi32.dll
2014-08-25 20:53:30 ----D---- C:\Users\User\AppData\Roaming\Mp3tag
2014-08-25 20:53:14 ----D---- C:\Program Files (x86)\Mp3tag
2014-08-25 02:16:22 ----D---- C:\Program Files (x86)\AMP WinOFF
2014-08-21 14:09:50 ----D---- C:\Program Files (x86)\The-Lost-Island
2014-08-20 16:06:31 ----D---- C:\Users\User\AppData\Roaming\Teiron
2014-08-20 15:06:25 ----D---- C:\Program Files (x86)\Tongbu
2014-08-19 19:02:51 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-19 19:02:51 ----D---- C:\Program Files\iTunes
2014-08-19 19:02:51 ----D---- C:\Program Files\iPod
2014-08-19 19:02:51 ----D---- C:\Program Files (x86)\iTunes
2014-08-16 21:00:35 ----A---- C:\Windows\SYSWOW64\Block.txt
2014-08-16 20:59:10 ----D---- C:\Windows\SYSWOW64\pack
2014-08-16 18:04:55 ----D---- C:\Program Files (x86)\Attomey ---
2014-08-15 21:16:03 ----D---- C:\Users\User\AppData\Roaming\Tomabo
2014-08-13 19:04:02 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-13 19:04:02 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-13 19:04:01 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-13 19:04:01 ----A---- C:\Windows\system32\icardagt.exe
2014-08-13 19:03:56 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-13 19:03:56 ----A---- C:\Windows\system32\icardres.dll
2014-08-13 19:03:05 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-13 19:03:04 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 18:29:30 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-13 18:29:30 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-13 18:29:22 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 18:29:21 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-13 18:29:15 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-13 18:29:15 ----A---- C:\Windows\system32\tzres.dll
2014-08-13 18:28:18 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-13 18:28:18 ----A---- C:\Windows\system32\msi.dll
2014-08-13 18:28:18 ----A---- C:\Windows\system32\authui.dll
2014-08-13 18:28:17 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-13 18:28:16 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-13 18:28:16 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 18:28:16 ----A---- C:\Windows\system32\consent.exe
2014-08-13 18:27:06 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 18:26:55 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-13 18:26:55 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-13 18:26:54 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-13 18:26:54 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-13 18:26:53 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-13 18:26:53 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 18:26:53 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-13 18:26:51 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-08-13 18:26:51 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-13 18:26:51 ----A---- C:\Windows\system32\iernonce.dll
2014-08-13 18:26:51 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-13 18:26:50 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-13 18:26:50 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-08-13 18:26:50 ----A---- C:\Windows\system32\urlmon.dll
2014-08-13 18:26:50 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 18:26:49 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-08-13 18:26:49 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-13 18:26:49 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-13 18:26:49 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-13 18:26:48 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-08-13 18:26:48 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-13 18:26:47 ----A---- C:\Windows\system32\iesetup.dll
2014-08-13 18:26:47 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-13 18:26:46 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-08-13 18:26:46 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-08-13 18:26:46 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-13 18:26:46 ----A---- C:\Windows\system32\iertutil.dll
2014-08-13 18:26:45 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-08-13 18:26:45 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-08-13 18:26:45 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-13 18:26:45 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-13 18:26:44 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-08-13 18:26:44 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-13 18:26:42 ----A---- C:\Windows\system32\ieui.dll
2014-08-13 18:26:42 ----A---- C:\Windows\system32\ieframe.dll
2014-08-13 18:26:42 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-13 18:26:41 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-08-13 18:26:41 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-13 18:26:40 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-13 18:26:40 ----A---- C:\Windows\system32\jscript9.dll
2014-08-13 18:26:40 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-13 18:26:39 ----A---- C:\Windows\system32\wininet.dll
2014-08-13 18:26:39 ----A---- C:\Windows\system32\vbscript.dll
2014-08-13 18:26:39 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-13 18:26:38 ----A---- C:\Windows\system32\msrating.dll
2014-08-13 18:26:38 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-13 18:26:37 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 18:26:37 ----A---- C:\Windows\system32\mshtml.dll
2014-08-13 18:26:12 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-13 18:26:11 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-13 18:25:51 ----A---- C:\Windows\system32\aepdu.dll
2014-08-13 18:25:49 ----A---- C:\Windows\system32\aeinv.dll
2014-08-12 18:33:35 ----D---- C:\Users\User\AppData\Roaming\Dropbox
2014-08-10 17:39:41 ----D---- C:\downloads
2014-08-03 10:55:24 ----A---- C:\Windows\system32\wups2.dll
2014-08-03 10:55:24 ----A---- C:\Windows\system32\wuauclt.exe
2014-08-03 10:55:23 ----A---- C:\Windows\system32\wucltux.dll
2014-08-03 10:55:23 ----A---- C:\Windows\system32\wuaueng.dll
2014-08-03 10:55:04 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-08-03 10:55:04 ----A---- C:\Windows\system32\wups.dll
2014-08-03 10:55:04 ----A---- C:\Windows\system32\wudriver.dll
2014-08-03 10:55:03 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-08-03 10:55:03 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-08-03 10:55:03 ----A---- C:\Windows\system32\wuapi.dll
2014-08-03 10:54:48 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-08-03 10:54:48 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-08-03 10:54:48 ----A---- C:\Windows\system32\wuwebv.dll
2014-08-03 10:54:47 ----A---- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2014-08-31 15:33:57 ----RD---- C:\Program Files
2014-08-31 15:33:10 ----D---- C:\Windows\Temp
2014-08-31 15:20:49 ----D---- C:\Program Files (x86)\Steam
2014-08-31 12:55:12 ----D---- C:\Windows\system32\config
2014-08-31 12:41:08 ----SHD---- C:\System Volume Information
2014-08-30 22:03:14 ----D---- C:\Windows\system32\Tasks
2014-08-30 21:47:05 ----HD---- C:\ProgramData
2014-08-30 21:46:55 ----RSD---- C:\Windows\assembly
2014-08-30 21:26:26 ----RD---- C:\Program Files (x86)
2014-08-30 21:25:29 ----SHD---- C:\Windows\Installer
2014-08-30 21:25:18 ----D---- C:\Windows\SysWOW64
2014-08-30 21:23:57 ----D---- C:\Windows
2014-08-30 18:49:46 ----D---- C:\Users\User\AppData\Roaming\vlc
2014-08-29 16:29:51 ----D---- C:\Windows\System32
2014-08-29 16:29:51 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-08-29 16:29:48 ----D---- C:\Windows\inf
2014-08-27 22:26:12 ----RD---- C:\Wizzy
2014-08-27 22:18:18 ----D---- C:\Windows\winsxs
2014-08-27 19:27:06 ----D---- C:\Windows\system32\catroot
2014-08-27 19:13:33 ----D---- C:\Windows\system32\wdi
2014-08-26 16:52:46 ----D---- C:\Program Files (x86)\Last-World
2014-08-24 19:47:17 ----D---- C:\Program Files (x86)\QuadCoreM2
2014-08-23 18:07:18 ----D---- C:\Users\User\AppData\Roaming\OBS
2014-08-23 18:05:50 ----D---- C:\Program Files\OBS
2014-08-23 18:05:38 ----D---- C:\Program Files (x86)\OBS
2014-08-21 21:35:44 ----D---- C:\Users\User\AppData\Roaming\DivX
2014-08-21 21:35:07 ----D---- C:\Windows\system32\catroot2
2014-08-21 13:47:29 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-08-20 16:00:07 ----D---- C:\Users\User\AppData\Roaming\ihelper2014
2014-08-19 19:12:43 ----D---- C:\Program Files (x86)\Opera
2014-08-17 01:47:26 ----D---- C:\Program Files (x86)\Google
2014-08-17 01:47:01 ----D---- C:\Windows\Tasks
2014-08-16 15:50:40 ----D---- C:\Windows\Microsoft.NET
2014-08-15 20:27:10 ----D---- C:\Users\User\AppData\Roaming\Skype
2014-08-15 11:46:09 ----D---- C:\Program Files (x86)\Internet Explorer
2014-08-14 15:16:06 ----D---- C:\Windows\system32\drivers
2014-08-13 21:17:05 ----D---- C:\Windows\ehome
2014-08-13 21:17:04 ----RSD---- C:\Windows\Fonts
2014-08-13 21:16:57 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-13 21:16:57 ----D---- C:\Windows\system32\cs-CZ
2014-08-13 21:16:56 ----D---- C:\Windows\SYSWOW64\en-US
2014-08-13 21:16:56 ----D---- C:\Windows\system32\en-US
2014-08-13 21:16:56 ----D---- C:\Windows\PolicyDefinitions
2014-08-13 21:16:56 ----D---- C:\Program Files\Internet Explorer
2014-08-13 19:31:00 ----D---- C:\ProgramData\Microsoft Help
2014-08-13 19:15:58 ----D---- C:\Windows\system32\MRT
2014-08-13 19:12:34 ----A---- C:\Windows\system32\MRT.exe
2014-08-13 19:01:23 ----SD---- C:\Windows\system32\CompatTel
2014-08-12 18:35:13 ----D---- C:\Windows\Prefetch
2014-08-01 22:54:59 ----D---- C:\Users\User\AppData\Roaming\.minecraft
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2007-11-09 26968]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-01-18 717368]
R3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDMI64.sys [2010-03-05 720952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-04-20 169584]
R3 ManyCam;ManyCam Virtual Webcam; C:\Windows\system32\DRIVERS\mcvidrv.sys [2014-05-13 42224]
R3 mcaudrv_simple;ManyCam Virtual Microphone; C:\Windows\system32\drivers\mcaudrv_x64.sys [2014-05-13 35440]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2013-03-28 1226344]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-03-10 316464]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2013-08-06 23040]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RegFltrX64;RegFltrX64; \??\C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\RegFltrX64.sys []
S3 RgFltX64;RgFltX64; \??\C:\Users\User\AppData\Local\FirmwareOfficeRecycle\RgFltX64.sys []
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-02-01 232992]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 xhunter1;xhunter1; \??\C:\Windows\xhunter1.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-03-15 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-06-12 43336]
R2 DebugPathRoot.exe;DebugPathRoot.exe; C:\Users\User\AppData\Local\95e7150cfbe0077d019a301ebb47332f\MotionOCRWin32.exe [2014-06-03 110592]
R2 FirmwareOfficeRecycle.exe;FirmwareOfficeRecycle.exe; C:\Users\User\AppData\Local\FirmwareOfficeRecycle\FirmwareOfficeRecycle.exe [2014-07-28 98341]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 PirritUpdater;PirritUpdater; C:\Program Files (x86)\Pirrit\AutoUpdater.exe [2014-02-20 59904]
R2 WinRST;WinRST; C:\Program Files (x86)\WinRST\WinRST.exe [2014-02-26 59904]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-08-01 641352]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S2 0fe17f7f7055ca8.exe;0fe17f7f7055ca8.exe; C:\Users\User\AppData\Local\0c8010b42ce9c0896292f9a00871cf6d\0fe17f7f7055ca8.exe []
S2 8466e4bf6f86000.exe;8466e4bf6f86000.exe; C:\Users\User\AppData\Local\e5a6946aeccac218acdd006c605848c5\8466e4bf6f86000.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 CronDockWord.exe;CronDockWord.exe; C:\Users\User\AppData\Local\CronDockWord\CronDockWord.exe []
S2 e177f95e8bcdff0.exe;e177f95e8bcdff0.exe; C:\Users\User\AppData\Local\5b37c15f318304c12ff7bd21aaf6bc6b\e177f95e8bcdff0.exe []
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-06 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-17 116648]
S2 PirritDesktop;PirritDesktop; C:\Users\User\AppData\Local\PirritSuggestor\PirritService.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-21 262320]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-06 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-17 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-07-25 111616]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-03-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
mam v PC keylogger nebo nejaky malware?