Zpomalený počítač, pomalé zapínání
Napsal: 31 srp 2014 17:18
Dobrý den, poslední dobou se mi zdá počítač značně zpomalený, bohužel jsem nebyl nyní velice dlouhou dobu doma, takže nevím kdy to přesně nastalo abych dal například bod obnovy. Počítač se velice pomalu zpouští ( Někdy i třeba 5 - 10 min - vím pro někoho je to normální ale pamatuji si kdy jsem na zapnutí čekal 40 sec - 2 min ). Myslím že zde bude asi pár breberek.
Zde přikládám log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by R at 2014-08-31 18:06:38
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 187 GB (20%) free of 941 GB
Total RAM: 4076 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:07:06, on 31.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Creative\Shared Files\CTSched.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
C:\Program Files (x86)\Gaming Keyboard\OSD.exe
C:\Program Files (x86)\Opera\Opera.exe
C:\Program Files (x86)\GameforgeLive\gfl_client.exe
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE
C:\Program Files\trend micro\R.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: CrossriderApp0060548 - {11111111-1111-1111-1111-110611051148} - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: HulaToo - {ab65caf0-fc3b-40f8-8b88-6d096a48f659} - C:\Program Files (x86)\HulaToo\HulaToobho.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VICTORY Gaming Keyboard] "C:\Program Files (x86)\Gaming Keyboard\Monitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files (x86)\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\R\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [PCSpeedUp] C:\Program Files (x86)\Zrychleni Pocitace\PCSUNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\updateHulaToo.exe
O23 - Service: Util HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11873 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
taskeng.exe {7ED44CF8-49D3-4364-832A-82A2AAA0F262}
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-10.exe" /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /tJxyO='HD-V1.9' /gxHLJeS=1000 /Khmjsabq=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /QrmGrtMqY=http://logs.infodatacloud.com /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\SysWOW64\nethtsrv.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\netupdsrv.exe
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files (x86)\HulaToo\updateHulaToo.exe"
"C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1928
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\IDT\WDM\beats64.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\Creative\Shared Files\CTSched.exe" /logon
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Gaming Keyboard\OSD.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Opera\Opera.exe" "C:\Users\R\Desktop\pactirik.png"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\GameforgeLive\gfl_client.exe" "/noautopatch"
"C:\Windows\system32\wuauclt.exe"
"taskhost.exe"
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE -Embedding
C:\Windows\splwow64.exe 8192
C:\Windows\system32\prevhost.exe {914FEED8-267A-4BAA-B8AA-21E233792679} -Embedding
C:\Windows\servicing\TrustedInstaller.exe
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE -Embedding
C:\Windows\system32\msiexec.exe /V
"C:\Users\R\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-1.job - C:\Program Files (x86)\HD-V1.9\HD-V1.9-codedownloader.exe /wctdmcm /INRZpZ=task /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /cMGCQvA=1.34.7.1 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /KcfqCdY=http://js.infodatacloud.com /zqCwG=opera /agmcq='HD-V1.9' /CxkcGSgZ=http://js.clientdemocloud.com /narrgKQh /hjtAnGCZR='{"asw":[0, 64, 0]}' /WbSDW='http://update.infodatacloud.com/ie_code ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-10.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-10.exe /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /tJxyO='HD-V1.9' /gxHLJeS=1000 /Khmjsabq=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /QrmGrtMqY=http://logs.infodatacloud.com /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-11.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-11.exe /UyUVonODa=E9uP+Vw3RAPkis1kxxNVFAjLf58wDvDt875DpAEKBFLLTWGHsQWF+zFC10ITA6T4pqMJBP2ojHbPfihqsQobHHWWvzd7VDFhAknb2L87sy+PwVyZnUJQgrgRp5NCxa6pMkFjSLdcalhUUk9r1hzAwfHhAWX6XMQls5emFsHMNQoa2y4cSCcQ8BVKGpVkUbgjF4FR36d4Qv8hDIemNaSoHKEPZ/4uVuWoGu/T5Y4aYjpd3OYJj3KpNsi185CmEKRWkR8Y68BuqBJyGnIFUaO+8CiETUbl7ADM1uDK97Zw0ta6yGBPNKocnuRlO0Y7Ng38iumQD7PJDwfxjubtzK6ynZ3pBMJLkIUjDIr+Wi5QwAswPuq4pqTh0JyYzQGlxT9xfgpbRSd+xuFgbU0ZY8R3xpYQcjHsmZESL8bAEHzDsdH9nQEc7kmYNeQRZc4ee7sPmdxBhv9Sbki0AKPmLEWCDXaokW3lH/vcEJ7MyBjIT2e6jveo6dScWGnm5tgHfa3mivX10hvbhSOmAOjChGVUtlZc4mwfRosBk3frAyKoKP2vZHN+aheg9Q/ySM1Y1JKd1evAtGRwwDmxz0ts3Yi2apsugq6loiEuHej8mz9heaUt8+PfHRfSbWVs8MdAQWFo7mG6inWVe9Fr4+HkRYXMutk0N26FS1ytcrMXYCHo96wxhtpxT7/zXtnREx1zqdL+yP/TuSoVRB/43cchwPG9+cS8jwqLxVEgIkjuA5oyD29F9B7kqjAU6da7rWSIR3jCTstLtO2J+crclFsWBAFYw9sZ5ev0Zj/dqOK+C5r/7o4mDbNCjTgnBIHk+ATnN9Zscf9hJNAKTl4qOPrlSZXUIVNfeZ7YtUApoHrqPeJnhGPe6xfsGwAHZ0dr3OWj0KiEES+i6lZ0+FzxL5buSHtqDYLSJRysgV+lctzBIjJJLuyzY8r0bQ5GSheDwfq6z8fCxgbyyEVCmWAUwM9a/y6oKHqrSZNvYJHD9u+lRPG60zgl5rpiimg/UNlU8W0KS7FWWVLFBWCrvdrqB3FVKCSbgzD1sgaO2NhJ5PenImA9YEPfLlG/6CFhOWARhbGAUEZ8F7ds88oZvahGFDdqdKCmzMIpsKMCTGpNYt5/DfKzNuHC3z2XwoMJWlbLAsgpVbeAEEU4VzawqmYJkT/z2mdH10C5VEs8JTu8DIb7Bnn9iYJPQVRxRx7EwOH85GZZuWccK8LVv5Bl26+VIWdIZVpWWtIIQsXwenmYPWhRoq77N8v92yJl++mWComI1CFYSD0xkOrQ3t7lCOnvIqNVm5jsslzBwEN4DGQVyAR2WbZGfIH8+qh+LYCkAiomhPEaobS+dD1DaguBhHgUo/YB6MR3IKZjg1ocuPKvCs/5SnvdEbpJXnKqi4tabPiI8s7WFk2Ohote5TA/MPyqEkCmOjHmW2XjycSai6Bh1LaJtBprRqtddpoNEDDahLoVJUcx2GSRUyj7SvuqhCcINzo4gc6c9i3tZIqbcBxR8pLTtG5wFXbHuZ77MRpk2OSLUArD/mdsSkL7PBNWkCtrk0Ez+VC2gDzHVuz+6oq6TpzJ17pI3w0abssEPmR61330BsL0n/YaUtaoE5NGUN8sH7DwpAGicisZZrS6z++Zrdus75uswRrKx0zZ+z8EAJDBSyUX3BUJ2uFZ3m0xvJIJ+KzwYitUnIR3er4DeS5Qh9qihbyMySY=
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-2.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-2.exe /YwWvhAcB /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /zyRtRsaCB=11111111-1111-1111-1111-110611051148 /zqCwG=opera /Hfiqloix /narrgKQh /WbSDW='http://update.infodatacloud.com/ie_enab ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-3.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-3.exe /UyUVonODa=UXJrb5BiGgKcYViDipC7D9ktrixqrKQwkIBGsFmWQiji6627g2WqG1ZDDmSq/+CQBNlEfRxBORRF/GMYYj3X2vevLRra4jXmnrPfv3+FGP7rc6a6P09iGuFowAZeygwENFdiMybB+wfeJxgpHAugnePDqCODc7tiXf0IKTkpCDlTFNpswrmcp37L3338Rzv8O2W7RSTICRCYam67MdleXAR+3tIjCvubZlIKh3JPi27Z1KTiVoa6nWQEHBWV8eLIOKjQPAzY1bXnCZqX7NymPJB6yWf40RNhn9WQraNb2Nly+lOfqxv7tTqKqvKax5HdrKzIqwcJesIg+V0fISomp6utJVup8KGFUcGAS8U2UpMix2pn/1u7iHCZb9shdGTA89ffqkE+AuKHI/vTS7vVI87MsccGohpPDWoJA9ajYGlB79x5SKFRLcuuk7a2Ih1WqFXFq3Z5vvUlmAmah0vCRqvRKCSrofIrNsZPb9VRvEGLwYDQVG7gG3vJxRFW00rlntGHDGX6BczayOZpsgadA3LckNgEh+JqibstGyyshmOIQT0pQ56JLeSzCUE30+M1043LVydNX6REJY16HEyMMp9jIkC12ORDJ1WfVvF2KQbcZIwu1aiZflfOOHvKoDRXPcM6ptzbirb1kjOk7uCgt0XtXC9M2T+DAfAx5nA4oj5MHnzg5Gc00XyEf/Uhd/iQJtBpc4wlVp62X4mq7wghvdCstXxpjWq33sue3/cqUnCHPcX1cbivRCDhYo+HLLOtWvzh77ReVXkpquXhZMxfVD/XEOF1mvht7xX+bPTBhKDhb4p2lQ8XjPpUHFCRsh5f8JOruE4lMJV/DVxaRfhvYBoY22JaQI6nS/Cq7+PjUDtjptRXfBUZITnNrx7FYwuZeyhMWVERRIxq6nubDX6Uo15jwvW7ahHI8H88Qyjcu/GqqcRjt+6VrgaWQkaXAs5uP85ugj4Jg9n0c4/FZcafFvHoKizj1wLjxVZ8XHGnwEngo7pfvpO4ANpWlfGrfcvKE4eXH2zUrhm2nedarYV6i+E+tiXf8ean2LeWgiX9yovM/VNL57JgV3HlAuE7XsggVKoQUAyQkAlYXathZgyyJgUi6whsaJMyMQvfc0w2Hc6YQ9ka08eQKM5SXDQB72UQ8m6qjhTQp8kfY46nVPIKQIYJLfSIOSjjwIwLbrAgU2YBo4wTdWzi7sFe8faGF2i6zOuGesdTIIXcUdNv6cQisueOICd2DdMag8ydM3JKVSZXp1iKIh1Vlr24C4u/ZWse411AlIUHukLntJEe+jy0yDLiBzDDgGo0qokz6LEo6S/qHnW0OFj3Ou3gOHg7T/CPuYvUctay2WlN4hkPONCJ9A==
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-4.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-4.exe /DAnsD /vMUHVTT='HD-V1.9' /xcYFSh='C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9.xpi' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /cMGCQvA=1.34.7.1 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /YVWtt=300 /HhCkPpIQR=d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com /hrUOtTUay=0.95 /pcvGEASqh=ad55cd0d79f24466095b3188599e8e4f86b2faf04e86f4bcfa878632814acf518com60548 /CvZQfrLv=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /60548.rdf /tJxyO='HD-V1.9' /TWQaAl='Lights out for YouTube' /dPcamqIOa='InfoHD-V1.8' /zqCwG=opera /hjtAnGCZR='{"asw":[0, 64, 0]}' /narrgKQh /qAWas /ifFjF /WbSDW='http://update.infodatacloud.com/ff_agen ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5.exe /mRtSki /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /xBDhTPmfR=http://ipgeoapi.com/ /DfGnzcfk=http://update.infodatacloud.com /mUbPo=2 /QrmGrtMqY=http://logs.infodatacloud.com /WbSDW='http://update.infodatacloud.com/updater ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5_user.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5.exe /mRtSki /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /xBDhTPmfR=http://ipgeoapi.com/ /DfGnzcfk=http://update.infodatacloud.com /mUbPo=2 /QrmGrtMqY=http://logs.infodatacloud.com /WbSDW='http://update.infodatacloud.com/updater ... pdate.json' /sVEgHa /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\HPCeeScheduleForR.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForR (null)
C:\Windows\tasks\PC SpeedUp Service Deactivator.job - C:\Program Files (x86)\Zrychleni Pocitace\PCSUSD.exe /dev0 /idle
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611051148}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho64.dll [2014-07-22 723816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-08-05 545264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-08-05 193520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611051148}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll [2014-07-22 537448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-08-05 453104]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ab65caf0-fc3b-40f8-8b88-6d096a48f659}]
HulaToo - C:\Program Files (x86)\HulaToo\HulaToobho.dll [2014-07-22 249624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-08-05 157680]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BeatsOSDApp"=C:\Program Files\IDT\WDM\beats64.exe [2010-10-21 37888]
"hpsysdrv"=c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [2008-11-20 62768]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2012-04-24 1425408]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15 499608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"NCPluginUpdater"=C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [2014-08-19 21720]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"=C:\Program Files (x86)\Creative\Shared Files\CTSched.exe [2006-11-17 53341]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-07-24 21650016]
"Spotify Web Helper"=C:\Users\R\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-07-06 1178168]
"AdobeBridge"= []
"PCSpeedUp"=C:\Program Files (x86)\Zrychleni Pocitace\PCSUNotifier.exe [2014-07-16 300840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1a92553fc3706c469bd5c78793b2aa21]
C:\Users\R\AppData\Local\Temp\FlashPlayerPlugin_11_9_900_117.exe .. []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6ee4f606bfbd1a4c62361754fecafaa2]
C:\Users\R\AppData\Local\Temp\interrupts.exe .. []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15 499608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe /Auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easybits Recovery]
C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [2011-02-10 61112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ6\ICQ.exe [2008-09-01 173304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
L:\Icq\ICQLite\ICQLite.exe -minimize []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe /autostart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Online Backup]
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Overwolf]
C:\Program Files (x86)\Overwolf\Overwolf.exe -silent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp]
C:\Program Files (x86)\Zrychleni Pocitace\PCSpeedUp.lnk []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDP]
C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-07-24 21650016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
C:\Users\R\AppData\Roaming\Spotify\spotify.exe [2014-07-06 6162488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\R\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-07-06 1178168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2014-05-28 1775808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-05-30 5622512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
C:\Program Files\IDT\WDM\sttray64.exe [2012-04-24 1425408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe [2010-07-04 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 442880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LOLRecorder.lnk]
C:\PROGRA~2\LOLREP~1\LOLREC~1.EXE [2012-02-25 495104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^R^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk]
C:\PROGRA~2\MYPCBA~1\MYPCBA~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^R^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Xfire.lnk]
C:\PROGRA~2\Xfire\Xfire.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe []
"VICTORY Gaming Keyboard"=C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [2013-04-09 270336]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2014-01-17 421888]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2011-08-16 52920]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EnableShellExecuteHooks"=1
"NoDriveTypeAutoRun"=28
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Loki\Loki.exe"="C:\Program Files\Loki\Loki.exe:*:Enabled:Loki"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.XFR1"=xfcodec64.dll
"vidc.XVID"=xvidvfw.dll
"wave6"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-08-31 18:06:39 ----D---- C:\Program Files\trend micro
2014-08-31 18:06:38 ----D---- C:\rsit
2014-08-31 17:06:05 ----A---- C:\Windows\system32\drivers\TrueSight.sys
2014-08-31 17:06:04 ----D---- C:\ProgramData\RogueKiller
2014-08-31 15:14:59 ----A---- C:\awh86DB.tmp
2014-08-30 17:29:50 ----A---- C:\awh1F7A.tmp
2014-08-28 21:53:48 ----A---- C:\awh61DC.tmp
2014-08-28 08:26:46 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-28 08:26:46 ----A---- C:\Windows\system32\win32k.sys
2014-08-28 08:26:46 ----A---- C:\Windows\system32\gdi32.dll
2014-08-25 06:26:10 ----A---- C:\awhD561.tmp
2014-08-23 12:45:34 ----A---- C:\awhD004.tmp
2014-08-19 01:31:01 ----A---- C:\awh88F8.tmp
2014-08-15 02:03:57 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-15 02:03:57 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-15 02:03:57 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-15 02:03:57 ----A---- C:\Windows\system32\icardagt.exe
2014-08-15 02:03:56 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-15 02:03:56 ----A---- C:\Windows\system32\icardres.dll
2014-08-15 02:03:31 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-15 02:03:31 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-14 02:12:56 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-14 02:12:56 ----A---- C:\Windows\system32\tzres.dll
2014-08-14 02:12:46 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-14 02:12:46 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-14 02:12:46 ----A---- C:\Windows\system32\msihnd.dll
2014-08-14 02:12:46 ----A---- C:\Windows\system32\msi.dll
2014-08-14 02:12:46 ----A---- C:\Windows\system32\consent.exe
2014-08-14 02:12:46 ----A---- C:\Windows\system32\authui.dll
2014-08-14 02:12:45 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-14 02:12:37 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-14 02:12:32 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-14 02:12:32 ----A---- C:\Windows\system32\shell32.dll
2014-08-14 02:12:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-14 02:12:27 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-14 02:12:27 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-14 02:12:26 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 02:12:26 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-14 02:12:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-08-14 02:12:25 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-14 02:12:25 ----A---- C:\Windows\system32\iernonce.dll
2014-08-14 02:12:25 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-14 02:12:24 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-14 02:12:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-08-14 02:12:24 ----A---- C:\Windows\system32\urlmon.dll
2014-08-14 02:12:24 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 02:12:24 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-14 02:12:23 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-08-14 02:12:23 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-08-14 02:12:23 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-14 02:12:23 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-14 02:12:23 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-14 02:12:22 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-08-14 02:12:22 ----A---- C:\Windows\system32\iesetup.dll
2014-08-14 02:12:22 ----A---- C:\Windows\system32\iertutil.dll
2014-08-14 02:12:22 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-14 02:12:21 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\ieui.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\ieframe.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\wininet.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\vbscript.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\jscript9.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-14 02:12:19 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-14 02:12:18 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 02:12:18 ----A---- C:\Windows\system32\msrating.dll
2014-08-14 02:12:18 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-14 02:12:18 ----A---- C:\Windows\system32\mshtml.dll
2014-08-14 02:11:52 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-14 02:11:51 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-14 02:11:50 ----A---- C:\Windows\system32\aepdu.dll
2014-08-14 02:11:48 ----A---- C:\Windows\system32\aeinv.dll
2014-08-14 01:33:30 ----A---- C:\awh5B29.tmp
2014-08-10 23:10:33 ----A---- C:\awh1479.tmp
2014-08-10 21:30:13 ----A---- C:\awh59E0.tmp
2014-08-08 18:33:23 ----A---- C:\awhF508.tmp
2014-08-07 19:54:14 ----A---- C:\awh7C.tmp
2014-08-07 14:24:56 ----A---- C:\awh34A.tmp
2014-08-06 18:10:42 ----A---- C:\awhF112.tmp
2014-08-06 13:58:56 ----A---- C:\awh4DB3.tmp
2014-08-03 08:33:59 ----A---- C:\awhB259.tmp
======List of files/folders modified in the last 1 month======
2014-08-31 18:06:54 ----D---- C:\Windows\Prefetch
2014-08-31 18:06:45 ----D---- C:\Windows\Temp
2014-08-31 18:06:39 ----RD---- C:\Program Files
2014-08-31 18:06:04 ----D---- C:\Users\R\AppData\Roaming\Skype
2014-08-31 17:56:43 ----D---- C:\Windows\system32\config
2014-08-31 17:15:19 ----D---- C:\Windows\Tasks
2014-08-31 17:15:19 ----D---- C:\Windows\system32\Tasks
2014-08-31 17:06:05 ----D---- C:\Windows\system32\drivers
2014-08-31 17:06:04 ----D---- C:\ProgramData
2014-08-31 15:12:17 ----A---- C:\Windows\SYSWOW64\log.txt
2014-08-31 15:11:52 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2014-08-31 15:09:10 ----D---- C:\Program Files (x86)\HulaToo
2014-08-29 06:25:03 ----D---- C:\Windows\winsxs
2014-08-29 06:22:58 ----D---- C:\Windows\System32
2014-08-29 06:22:58 ----AD---- C:\Windows\SysWOW64
2014-08-29 02:19:09 ----A---- C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-08-29 02:16:48 ----D---- C:\Users\R\AppData\Roaming\HpUpdate
2014-08-29 02:01:19 ----SHD---- C:\System Volume Information
2014-08-28 21:06:53 ----D---- C:\Users\R\AppData\Roaming\TS3Client
2014-08-28 08:25:03 ----D---- C:\Windows\system32\catroot
2014-08-22 02:50:40 ----D---- C:\Users\R\AppData\Roaming\HP Support Assistant
2014-08-21 20:27:06 ----SHD---- C:\Windows\Installer
2014-08-21 20:27:06 ----D---- C:\Config.Msi
2014-08-21 20:23:06 ----RD---- C:\Program Files (x86)
2014-08-21 20:22:40 ----D---- C:\Program Files (x86)\Google
2014-08-15 08:17:26 ----D---- C:\Windows\rescache
2014-08-15 06:15:37 ----D---- C:\Windows\Microsoft.NET
2014-08-15 06:15:11 ----RSD---- C:\Windows\assembly
2014-08-15 05:22:43 ----D---- C:\Windows\ehome
2014-08-15 05:22:42 ----RSD---- C:\Windows\Fonts
2014-08-15 05:22:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-15 05:22:27 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 05:22:25 ----D---- C:\Program Files\Internet Explorer
2014-08-15 05:22:24 ----D---- C:\Windows\SYSWOW64\en-US
2014-08-15 05:22:22 ----D---- C:\Windows\system32\en-US
2014-08-15 05:22:22 ----D---- C:\Windows\PolicyDefinitions
2014-08-15 05:22:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-08-15 02:19:36 ----D---- C:\ProgramData\Microsoft Help
2014-08-15 02:17:21 ----D---- C:\Windows\system32\catroot2
2014-08-15 02:13:08 ----D---- C:\Windows\system32\MRT
2014-08-15 02:09:51 ----D---- C:\Windows\debug
2014-08-15 02:09:44 ----A---- C:\Windows\system32\MRT.exe
2014-08-15 02:02:32 ----SD---- C:\Windows\system32\CompatTel
2014-08-07 18:06:14 ----RD---- C:\Program Files (x86)\Skype
2014-08-06 21:28:03 ----D---- C:\ProgramData\Skype
2014-08-06 21:28:02 ----D---- C:\Program Files (x86)\Common Files
2014-08-05 09:20:00 ----N---- C:\Windows\system32\MpSigStub.exe
2014-08-02 02:57:44 ----D---- C:\Program Files (x86)\GameforgeLive
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel RAID Controller; C:\Windows\system32\drivers\iaStor.sys [2010-11-05 438808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; SysWOW64\speedfan.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-07 279616]
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys [2014-07-21 46160]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-02-26 99800]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2014-02-26 197408]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-02-26 888536]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2012-04-24 536576]
R3 tihub3;TI USB3 Hub Service; C:\Windows\system32\DRIVERS\tihub3.sys [2014-02-26 136000]
R3 tixhci;TI XHCI Service; C:\Windows\system32\DRIVERS\tixhci.sys [2014-02-26 409408]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz136;cpuz136; \??\C:\Users\R\AppData\Local\Temp\cpuz136\cpuz136_x64.sys []
S3 dump_wmimmc;dump_wmimmc; C:\Windows\system32\drivers\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2004-12-31 4682]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-01-03 19456]
S3 ScreamBAudioSvc;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys [2010-07-01 38992]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-09-20 40664]
S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\taphss.sys [2012-08-01 38632]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-01-03 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-01-03 30208]
S3 XENfiltv;XENfiltv; C:\Windows\system32\drivers\XENfiltv.sys [2009-07-31 25600]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2011-10-19 423424]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-10 40999448]
R2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe [2014-07-21 179200]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-03-15 889664]
R2 PCSUService;PC Speed Up Service; C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe [2014-07-16 430888]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-26 76152]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2014-07-21 159744]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2012-04-24 318464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
R2 Update HulaToo;Update HulaToo; C:\Program Files (x86)\HulaToo\updateHulaToo.exe [2014-08-30 323352]
R2 Util HulaToo;Util HulaToo; C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe [2014-08-30 323352]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-22 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-21 116648]
S2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-09-27 86528]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-15 2458944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2013-01-07 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2013-01-07 79360]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-22 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-21 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-07-25 111616]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2011-07-17 4390376]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-05-28 564928]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-09-04 1255736]
S4 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
S4 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-06-24 8704]
S4 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
S4 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Zde je log z Roguekiller ( v procesech jsem měl asi 94 procesů a přitom jsem neměl nic zaplého, nejvíce mi zabírali SVhosty a nějaké další processy, které jsem ani neznal, tak jsem si na netu dohledal že by mi RK mohl tyto processy zabít.)
RogueKiller V9.2.8.0 (x64) [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : R [Práva správce]
Mód : Odebrat -- Datum : 08/31/2014 17:15:20
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 28 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE} | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE} | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE} | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NEVYBRÁNO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.trovi.com/?gd=&ctid=CT332219 ... 7D80&SSPV= -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.trovi.com/?gd=&ctid=CT332219 ... 7D80&SSPV= -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
¤¤¤ naplánované úlohy : 3 ¤¤¤
[Suspicious.Path] AmiUpdXp.job -- C:\Users\R\AppData\Local\21676\a24223.exe -> VYMAZÁNO
[Suspicious.Path] \\AmiUpdXp -- C:\Users\R\AppData\Local\21676\a24223.exe -> VYMAZÁNO
[Suspicious.Path] \Hewlett-Packard\HP Support Assistant\Update Check -- C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe (/s /p 1) -> VYMAZÁNO
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost
¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDS721010CLA332 +++++
--- User ---
[MBR] f0b7624901a6d69d5951aaab4625eb68
[BSP] 8ea6679b211905a05af3f7b0dd5e7fb6 : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 940605 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1926565888 | Size: 13162 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive2: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive4: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
============================================
RKreport_SCN_08312014_171352.log
Zde přikládám log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by R at 2014-08-31 18:06:38
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 187 GB (20%) free of 941 GB
Total RAM: 4076 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:07:06, on 31.8.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Creative\Shared Files\CTSched.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
C:\Program Files (x86)\Gaming Keyboard\OSD.exe
C:\Program Files (x86)\Opera\Opera.exe
C:\Program Files (x86)\GameforgeLive\gfl_client.exe
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE
C:\Program Files\trend micro\R.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: CrossriderApp0060548 - {11111111-1111-1111-1111-110611051148} - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: HulaToo - {ab65caf0-fc3b-40f8-8b88-6d096a48f659} - C:\Program Files (x86)\HulaToo\HulaToobho.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VICTORY Gaming Keyboard] "C:\Program Files (x86)\Gaming Keyboard\Monitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files (x86)\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\R\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [PCSpeedUp] C:\Program Files (x86)\Zrychleni Pocitace\PCSUNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files (x86)\ICQ6\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\updateHulaToo.exe
O23 - Service: Util HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11873 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
taskeng.exe {7ED44CF8-49D3-4364-832A-82A2AAA0F262}
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-10.exe" /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /tJxyO='HD-V1.9' /gxHLJeS=1000 /Khmjsabq=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /QrmGrtMqY=http://logs.infodatacloud.com /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\SysWOW64\nethtsrv.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\netupdsrv.exe
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files (x86)\HulaToo\updateHulaToo.exe"
"C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1928
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\IDT\WDM\beats64.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files (x86)\Creative\Shared Files\CTSched.exe" /logon
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Gaming Keyboard\OSD.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Opera\Opera.exe" "C:\Users\R\Desktop\pactirik.png"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\GameforgeLive\gfl_client.exe" "/noautopatch"
"C:\Windows\system32\wuauclt.exe"
"taskhost.exe"
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE -Embedding
C:\Windows\splwow64.exe 8192
C:\Windows\system32\prevhost.exe {914FEED8-267A-4BAA-B8AA-21E233792679} -Embedding
C:\Windows\servicing\TrustedInstaller.exe
C:\PROGRA~2\MICROS~1\Office12\WINWORD.EXE -Embedding
C:\Windows\system32\msiexec.exe /V
"C:\Users\R\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-1.job - C:\Program Files (x86)\HD-V1.9\HD-V1.9-codedownloader.exe /wctdmcm /INRZpZ=task /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /cMGCQvA=1.34.7.1 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /KcfqCdY=http://js.infodatacloud.com /zqCwG=opera /agmcq='HD-V1.9' /CxkcGSgZ=http://js.clientdemocloud.com /narrgKQh /hjtAnGCZR='{"asw":[0, 64, 0]}' /WbSDW='http://update.infodatacloud.com/ie_code ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-10.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-10.exe /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /tJxyO='HD-V1.9' /gxHLJeS=1000 /Khmjsabq=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /QrmGrtMqY=http://logs.infodatacloud.com /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-11.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-11.exe /UyUVonODa=E9uP+Vw3RAPkis1kxxNVFAjLf58wDvDt875DpAEKBFLLTWGHsQWF+zFC10ITA6T4pqMJBP2ojHbPfihqsQobHHWWvzd7VDFhAknb2L87sy+PwVyZnUJQgrgRp5NCxa6pMkFjSLdcalhUUk9r1hzAwfHhAWX6XMQls5emFsHMNQoa2y4cSCcQ8BVKGpVkUbgjF4FR36d4Qv8hDIemNaSoHKEPZ/4uVuWoGu/T5Y4aYjpd3OYJj3KpNsi185CmEKRWkR8Y68BuqBJyGnIFUaO+8CiETUbl7ADM1uDK97Zw0ta6yGBPNKocnuRlO0Y7Ng38iumQD7PJDwfxjubtzK6ynZ3pBMJLkIUjDIr+Wi5QwAswPuq4pqTh0JyYzQGlxT9xfgpbRSd+xuFgbU0ZY8R3xpYQcjHsmZESL8bAEHzDsdH9nQEc7kmYNeQRZc4ee7sPmdxBhv9Sbki0AKPmLEWCDXaokW3lH/vcEJ7MyBjIT2e6jveo6dScWGnm5tgHfa3mivX10hvbhSOmAOjChGVUtlZc4mwfRosBk3frAyKoKP2vZHN+aheg9Q/ySM1Y1JKd1evAtGRwwDmxz0ts3Yi2apsugq6loiEuHej8mz9heaUt8+PfHRfSbWVs8MdAQWFo7mG6inWVe9Fr4+HkRYXMutk0N26FS1ytcrMXYCHo96wxhtpxT7/zXtnREx1zqdL+yP/TuSoVRB/43cchwPG9+cS8jwqLxVEgIkjuA5oyD29F9B7kqjAU6da7rWSIR3jCTstLtO2J+crclFsWBAFYw9sZ5ev0Zj/dqOK+C5r/7o4mDbNCjTgnBIHk+ATnN9Zscf9hJNAKTl4qOPrlSZXUIVNfeZ7YtUApoHrqPeJnhGPe6xfsGwAHZ0dr3OWj0KiEES+i6lZ0+FzxL5buSHtqDYLSJRysgV+lctzBIjJJLuyzY8r0bQ5GSheDwfq6z8fCxgbyyEVCmWAUwM9a/y6oKHqrSZNvYJHD9u+lRPG60zgl5rpiimg/UNlU8W0KS7FWWVLFBWCrvdrqB3FVKCSbgzD1sgaO2NhJ5PenImA9YEPfLlG/6CFhOWARhbGAUEZ8F7ds88oZvahGFDdqdKCmzMIpsKMCTGpNYt5/DfKzNuHC3z2XwoMJWlbLAsgpVbeAEEU4VzawqmYJkT/z2mdH10C5VEs8JTu8DIb7Bnn9iYJPQVRxRx7EwOH85GZZuWccK8LVv5Bl26+VIWdIZVpWWtIIQsXwenmYPWhRoq77N8v92yJl++mWComI1CFYSD0xkOrQ3t7lCOnvIqNVm5jsslzBwEN4DGQVyAR2WbZGfIH8+qh+LYCkAiomhPEaobS+dD1DaguBhHgUo/YB6MR3IKZjg1ocuPKvCs/5SnvdEbpJXnKqi4tabPiI8s7WFk2Ohote5TA/MPyqEkCmOjHmW2XjycSai6Bh1LaJtBprRqtddpoNEDDahLoVJUcx2GSRUyj7SvuqhCcINzo4gc6c9i3tZIqbcBxR8pLTtG5wFXbHuZ77MRpk2OSLUArD/mdsSkL7PBNWkCtrk0Ez+VC2gDzHVuz+6oq6TpzJ17pI3w0abssEPmR61330BsL0n/YaUtaoE5NGUN8sH7DwpAGicisZZrS6z++Zrdus75uswRrKx0zZ+z8EAJDBSyUX3BUJ2uFZ3m0xvJIJ+KzwYitUnIR3er4DeS5Qh9qihbyMySY=
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-2.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-2.exe /YwWvhAcB /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /zyRtRsaCB=11111111-1111-1111-1111-110611051148 /zqCwG=opera /Hfiqloix /narrgKQh /WbSDW='http://update.infodatacloud.com/ie_enab ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-3.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-3.exe /UyUVonODa=UXJrb5BiGgKcYViDipC7D9ktrixqrKQwkIBGsFmWQiji6627g2WqG1ZDDmSq/+CQBNlEfRxBORRF/GMYYj3X2vevLRra4jXmnrPfv3+FGP7rc6a6P09iGuFowAZeygwENFdiMybB+wfeJxgpHAugnePDqCODc7tiXf0IKTkpCDlTFNpswrmcp37L3338Rzv8O2W7RSTICRCYam67MdleXAR+3tIjCvubZlIKh3JPi27Z1KTiVoa6nWQEHBWV8eLIOKjQPAzY1bXnCZqX7NymPJB6yWf40RNhn9WQraNb2Nly+lOfqxv7tTqKqvKax5HdrKzIqwcJesIg+V0fISomp6utJVup8KGFUcGAS8U2UpMix2pn/1u7iHCZb9shdGTA89ffqkE+AuKHI/vTS7vVI87MsccGohpPDWoJA9ajYGlB79x5SKFRLcuuk7a2Ih1WqFXFq3Z5vvUlmAmah0vCRqvRKCSrofIrNsZPb9VRvEGLwYDQVG7gG3vJxRFW00rlntGHDGX6BczayOZpsgadA3LckNgEh+JqibstGyyshmOIQT0pQ56JLeSzCUE30+M1043LVydNX6REJY16HEyMMp9jIkC12ORDJ1WfVvF2KQbcZIwu1aiZflfOOHvKoDRXPcM6ptzbirb1kjOk7uCgt0XtXC9M2T+DAfAx5nA4oj5MHnzg5Gc00XyEf/Uhd/iQJtBpc4wlVp62X4mq7wghvdCstXxpjWq33sue3/cqUnCHPcX1cbivRCDhYo+HLLOtWvzh77ReVXkpquXhZMxfVD/XEOF1mvht7xX+bPTBhKDhb4p2lQ8XjPpUHFCRsh5f8JOruE4lMJV/DVxaRfhvYBoY22JaQI6nS/Cq7+PjUDtjptRXfBUZITnNrx7FYwuZeyhMWVERRIxq6nubDX6Uo15jwvW7ahHI8H88Qyjcu/GqqcRjt+6VrgaWQkaXAs5uP85ugj4Jg9n0c4/FZcafFvHoKizj1wLjxVZ8XHGnwEngo7pfvpO4ANpWlfGrfcvKE4eXH2zUrhm2nedarYV6i+E+tiXf8ean2LeWgiX9yovM/VNL57JgV3HlAuE7XsggVKoQUAyQkAlYXathZgyyJgUi6whsaJMyMQvfc0w2Hc6YQ9ka08eQKM5SXDQB72UQ8m6qjhTQp8kfY46nVPIKQIYJLfSIOSjjwIwLbrAgU2YBo4wTdWzi7sFe8faGF2i6zOuGesdTIIXcUdNv6cQisueOICd2DdMag8ydM3JKVSZXp1iKIh1Vlr24C4u/ZWse411AlIUHukLntJEe+jy0yDLiBzDDgGo0qokz6LEo6S/qHnW0OFj3Ou3gOHg7T/CPuYvUctay2WlN4hkPONCJ9A==
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-4.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-4.exe /DAnsD /vMUHVTT='HD-V1.9' /xcYFSh='C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9.xpi' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /cMGCQvA=1.34.7.1 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /YVWtt=300 /HhCkPpIQR=d55cd0d7-9f24-4660-95b3-188599e8e4f8@6b2faf04-e86f-4bcf-a878-632814acf518.com /hrUOtTUay=0.95 /pcvGEASqh=ad55cd0d79f24466095b3188599e8e4f86b2faf04e86f4bcfa878632814acf518com60548 /CvZQfrLv=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /60548.rdf /tJxyO='HD-V1.9' /TWQaAl='Lights out for YouTube' /dPcamqIOa='InfoHD-V1.8' /zqCwG=opera /hjtAnGCZR='{"asw":[0, 64, 0]}' /narrgKQh /qAWas /ifFjF /WbSDW='http://update.infodatacloud.com/ff_agen ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5.exe /mRtSki /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /xBDhTPmfR=http://ipgeoapi.com/ /DfGnzcfk=http://update.infodatacloud.com /mUbPo=2 /QrmGrtMqY=http://logs.infodatacloud.com /WbSDW='http://update.infodatacloud.com/updater ... pdate.json' /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5_user.job - C:\Program Files (x86)\HD-V1.9\ca9f61e7-52b6-468d-8e67-8d2712eae4a9-5.exe /mRtSki /vMUHVTT='HD-V1.9' /PPaxQAJ=60548 /lbDgIs='001859' /mkeksm='0' /LkvzpvV='0' /TJhKabv=16130A7A5E114B97AB173613210AA2E7IE /KJLVpgRQK=4da8dca0403961426764cbb4272a95ec /kqhYNBGA=1_34_07_01 /HuPzCNl=1406051156 /JNqvk=http://stats.infodatacloud.com /cJTjo=http://errors.infodatacloud.com /xBDhTPmfR=http://ipgeoapi.com/ /DfGnzcfk=http://update.infodatacloud.com /mUbPo=2 /QrmGrtMqY=http://logs.infodatacloud.com /WbSDW='http://update.infodatacloud.com/updater ... pdate.json' /sVEgHa /INRZpZ='task' /PhQBUVeQ=''
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\HPCeeScheduleForR.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForR (null)
C:\Windows\tasks\PC SpeedUp Service Deactivator.job - C:\Program Files (x86)\Zrychleni Pocitace\PCSUSD.exe /dev0 /idle
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611051148}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho64.dll [2014-07-22 723816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-08-05 545264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-08-05 193520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611051148}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll [2014-07-22 537448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-08-05 453104]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ab65caf0-fc3b-40f8-8b88-6d096a48f659}]
HulaToo - C:\Program Files (x86)\HulaToo\HulaToobho.dll [2014-07-22 249624]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-08-05 157680]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BeatsOSDApp"=C:\Program Files\IDT\WDM\beats64.exe [2010-10-21 37888]
"hpsysdrv"=c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [2008-11-20 62768]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2012-04-24 1425408]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15 499608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"NCPluginUpdater"=C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [2014-08-19 21720]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CreativeTaskScheduler"=C:\Program Files (x86)\Creative\Shared Files\CTSched.exe [2006-11-17 53341]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-07-24 21650016]
"Spotify Web Helper"=C:\Users\R\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-07-06 1178168]
"AdobeBridge"= []
"PCSpeedUp"=C:\Program Files (x86)\Zrychleni Pocitace\PCSUNotifier.exe [2014-07-16 300840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1a92553fc3706c469bd5c78793b2aa21]
C:\Users\R\AppData\Local\Temp\FlashPlayerPlugin_11_9_900_117.exe .. []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6ee4f606bfbd1a4c62361754fecafaa2]
C:\Users\R\AppData\Local\Temp\interrupts.exe .. []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15 499608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [2011-01-12 1523360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 7]
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe /Auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-11-10 3514176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easybits Recovery]
C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [2011-02-10 61112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ6\ICQ.exe [2008-09-01 173304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
L:\Icq\ICQLite\ICQLite.exe -minimize []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObit Malware Fighter]
C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe /autostart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Online Backup]
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Overwolf]
C:\Program Files (x86)\Overwolf\Overwolf.exe -silent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp]
C:\Program Files (x86)\Zrychleni Pocitace\PCSpeedUp.lnk []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDP]
C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-07-24 21650016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify]
C:\Users\R\AppData\Roaming\Spotify\spotify.exe [2014-07-06 6162488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\R\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-07-06 1178168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\steam.exe [2014-05-28 1775808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-01-17 252296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-05-30 5622512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
C:\Program Files\IDT\WDM\sttray64.exe [2012-04-24 1425408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe [2010-07-04 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid]
C:\Program Files (x86)\Xvid\CheckUpdate.exe [2011-01-17 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamePark klient 2.lnk]
C:\PROGRA~1\GAMEPA~1\gpcl.exe [2011-07-29 442880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LOLRecorder.lnk]
C:\PROGRA~2\LOLREP~1\LOLREC~1.EXE [2012-02-25 495104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^R^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk]
C:\PROGRA~2\MYPCBA~1\MYPCBA~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^R^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Xfire.lnk]
C:\PROGRA~2\Xfire\Xfire.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe []
"VICTORY Gaming Keyboard"=C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [2013-04-09 270336]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2014-01-17 421888]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2011-08-16 52920]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EnableShellExecuteHooks"=1
"NoDriveTypeAutoRun"=28
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Loki\Loki.exe"="C:\Program Files\Loki\Loki.exe:*:Enabled:Loki"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.XFR1"=xfcodec64.dll
"vidc.XVID"=xvidvfw.dll
"wave6"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-08-31 18:06:39 ----D---- C:\Program Files\trend micro
2014-08-31 18:06:38 ----D---- C:\rsit
2014-08-31 17:06:05 ----A---- C:\Windows\system32\drivers\TrueSight.sys
2014-08-31 17:06:04 ----D---- C:\ProgramData\RogueKiller
2014-08-31 15:14:59 ----A---- C:\awh86DB.tmp
2014-08-30 17:29:50 ----A---- C:\awh1F7A.tmp
2014-08-28 21:53:48 ----A---- C:\awh61DC.tmp
2014-08-28 08:26:46 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-28 08:26:46 ----A---- C:\Windows\system32\win32k.sys
2014-08-28 08:26:46 ----A---- C:\Windows\system32\gdi32.dll
2014-08-25 06:26:10 ----A---- C:\awhD561.tmp
2014-08-23 12:45:34 ----A---- C:\awhD004.tmp
2014-08-19 01:31:01 ----A---- C:\awh88F8.tmp
2014-08-15 02:03:57 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-15 02:03:57 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-15 02:03:57 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-15 02:03:57 ----A---- C:\Windows\system32\icardagt.exe
2014-08-15 02:03:56 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-15 02:03:56 ----A---- C:\Windows\system32\icardres.dll
2014-08-15 02:03:31 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-15 02:03:31 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-14 02:13:01 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-14 02:13:00 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-14 02:12:56 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-14 02:12:56 ----A---- C:\Windows\system32\tzres.dll
2014-08-14 02:12:46 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-14 02:12:46 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-14 02:12:46 ----A---- C:\Windows\system32\msihnd.dll
2014-08-14 02:12:46 ----A---- C:\Windows\system32\msi.dll
2014-08-14 02:12:46 ----A---- C:\Windows\system32\consent.exe
2014-08-14 02:12:46 ----A---- C:\Windows\system32\authui.dll
2014-08-14 02:12:45 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-14 02:12:37 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-14 02:12:32 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-14 02:12:32 ----A---- C:\Windows\system32\shell32.dll
2014-08-14 02:12:27 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-08-14 02:12:27 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-08-14 02:12:27 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-08-14 02:12:26 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-08-14 02:12:26 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 02:12:26 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-08-14 02:12:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-08-14 02:12:25 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-08-14 02:12:25 ----A---- C:\Windows\system32\iernonce.dll
2014-08-14 02:12:25 ----A---- C:\Windows\system32\ie4uinit.exe
2014-08-14 02:12:24 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-08-14 02:12:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-08-14 02:12:24 ----A---- C:\Windows\system32\urlmon.dll
2014-08-14 02:12:24 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 02:12:24 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-08-14 02:12:23 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-08-14 02:12:23 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-08-14 02:12:23 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-08-14 02:12:23 ----A---- C:\Windows\system32\msfeeds.dll
2014-08-14 02:12:23 ----A---- C:\Windows\system32\dxtmsft.dll
2014-08-14 02:12:22 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-08-14 02:12:22 ----A---- C:\Windows\system32\iesetup.dll
2014-08-14 02:12:22 ----A---- C:\Windows\system32\iertutil.dll
2014-08-14 02:12:22 ----A---- C:\Windows\system32\iedkcs32.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-08-14 02:12:21 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-08-14 02:12:21 ----A---- C:\Windows\system32\jsproxy.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\mshtmled.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\ieui.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\ieframe.dll
2014-08-14 02:12:20 ----A---- C:\Windows\system32\dxtrans.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\wininet.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\vbscript.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\jscript9diag.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\jscript9.dll
2014-08-14 02:12:19 ----A---- C:\Windows\system32\ieUnatt.exe
2014-08-14 02:12:19 ----A---- C:\Windows\system32\ieapfltr.dll
2014-08-14 02:12:18 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 02:12:18 ----A---- C:\Windows\system32\msrating.dll
2014-08-14 02:12:18 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-08-14 02:12:18 ----A---- C:\Windows\system32\mshtml.dll
2014-08-14 02:11:52 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-14 02:11:51 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-14 02:11:50 ----A---- C:\Windows\system32\aepdu.dll
2014-08-14 02:11:48 ----A---- C:\Windows\system32\aeinv.dll
2014-08-14 01:33:30 ----A---- C:\awh5B29.tmp
2014-08-10 23:10:33 ----A---- C:\awh1479.tmp
2014-08-10 21:30:13 ----A---- C:\awh59E0.tmp
2014-08-08 18:33:23 ----A---- C:\awhF508.tmp
2014-08-07 19:54:14 ----A---- C:\awh7C.tmp
2014-08-07 14:24:56 ----A---- C:\awh34A.tmp
2014-08-06 18:10:42 ----A---- C:\awhF112.tmp
2014-08-06 13:58:56 ----A---- C:\awh4DB3.tmp
2014-08-03 08:33:59 ----A---- C:\awhB259.tmp
======List of files/folders modified in the last 1 month======
2014-08-31 18:06:54 ----D---- C:\Windows\Prefetch
2014-08-31 18:06:45 ----D---- C:\Windows\Temp
2014-08-31 18:06:39 ----RD---- C:\Program Files
2014-08-31 18:06:04 ----D---- C:\Users\R\AppData\Roaming\Skype
2014-08-31 17:56:43 ----D---- C:\Windows\system32\config
2014-08-31 17:15:19 ----D---- C:\Windows\Tasks
2014-08-31 17:15:19 ----D---- C:\Windows\system32\Tasks
2014-08-31 17:06:05 ----D---- C:\Windows\system32\drivers
2014-08-31 17:06:04 ----D---- C:\ProgramData
2014-08-31 15:12:17 ----A---- C:\Windows\SYSWOW64\log.txt
2014-08-31 15:11:52 ----D---- C:\Program Files (x86)\Zrychleni Pocitace
2014-08-31 15:09:10 ----D---- C:\Program Files (x86)\HulaToo
2014-08-29 06:25:03 ----D---- C:\Windows\winsxs
2014-08-29 06:22:58 ----D---- C:\Windows\System32
2014-08-29 06:22:58 ----AD---- C:\Windows\SysWOW64
2014-08-29 02:19:09 ----A---- C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-08-29 02:16:48 ----D---- C:\Users\R\AppData\Roaming\HpUpdate
2014-08-29 02:01:19 ----SHD---- C:\System Volume Information
2014-08-28 21:06:53 ----D---- C:\Users\R\AppData\Roaming\TS3Client
2014-08-28 08:25:03 ----D---- C:\Windows\system32\catroot
2014-08-22 02:50:40 ----D---- C:\Users\R\AppData\Roaming\HP Support Assistant
2014-08-21 20:27:06 ----SHD---- C:\Windows\Installer
2014-08-21 20:27:06 ----D---- C:\Config.Msi
2014-08-21 20:23:06 ----RD---- C:\Program Files (x86)
2014-08-21 20:22:40 ----D---- C:\Program Files (x86)\Google
2014-08-15 08:17:26 ----D---- C:\Windows\rescache
2014-08-15 06:15:37 ----D---- C:\Windows\Microsoft.NET
2014-08-15 06:15:11 ----RSD---- C:\Windows\assembly
2014-08-15 05:22:43 ----D---- C:\Windows\ehome
2014-08-15 05:22:42 ----RSD---- C:\Windows\Fonts
2014-08-15 05:22:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-15 05:22:27 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 05:22:25 ----D---- C:\Program Files\Internet Explorer
2014-08-15 05:22:24 ----D---- C:\Windows\SYSWOW64\en-US
2014-08-15 05:22:22 ----D---- C:\Windows\system32\en-US
2014-08-15 05:22:22 ----D---- C:\Windows\PolicyDefinitions
2014-08-15 05:22:20 ----D---- C:\Program Files (x86)\Internet Explorer
2014-08-15 02:19:36 ----D---- C:\ProgramData\Microsoft Help
2014-08-15 02:17:21 ----D---- C:\Windows\system32\catroot2
2014-08-15 02:13:08 ----D---- C:\Windows\system32\MRT
2014-08-15 02:09:51 ----D---- C:\Windows\debug
2014-08-15 02:09:44 ----A---- C:\Windows\system32\MRT.exe
2014-08-15 02:02:32 ----SD---- C:\Windows\system32\CompatTel
2014-08-07 18:06:14 ----RD---- C:\Program Files (x86)\Skype
2014-08-06 21:28:03 ----D---- C:\ProgramData\Skype
2014-08-06 21:28:02 ----D---- C:\Program Files (x86)\Common Files
2014-08-05 09:20:00 ----N---- C:\Windows\system32\MpSigStub.exe
2014-08-02 02:57:44 ----D---- C:\Program Files (x86)\GameforgeLive
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel RAID Controller; C:\Windows\system32\drivers\iaStor.sys [2010-11-05 438808]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; SysWOW64\speedfan.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-07 279616]
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys [2014-07-21 46160]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-02-26 99800]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2014-02-26 197408]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-02-26 888536]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\Windows\system32\DRIVERS\stwrt64.sys [2012-04-24 536576]
R3 tihub3;TI USB3 Hub Service; C:\Windows\system32\DRIVERS\tihub3.sys [2014-02-26 136000]
R3 tixhci;TI XHCI Service; C:\Windows\system32\DRIVERS\tixhci.sys [2014-02-26 409408]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz136;cpuz136; \??\C:\Users\R\AppData\Local\Temp\cpuz136\cpuz136_x64.sys []
S3 dump_wmimmc;dump_wmimmc; C:\Windows\system32\drivers\dump_wmimmc.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2004-12-31 4682]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-01-03 19456]
S3 ScreamBAudioSvc;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys [2010-07-01 38992]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-09-20 40664]
S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\taphss.sys [2012-08-01 38632]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-01-03 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-01-03 30208]
S3 XENfiltv;XENfiltv; C:\Windows\system32\drivers\XENfiltv.sys [2009-07-31 25600]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-02 89600]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2011-10-19 423424]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-10 40999448]
R2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe [2014-07-21 179200]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-03-15 889664]
R2 PCSUService;PC Speed Up Service; C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe [2014-07-16 430888]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-26 76152]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2014-07-21 159744]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2012-04-24 318464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
R2 Update HulaToo;Update HulaToo; C:\Program Files (x86)\HulaToo\updateHulaToo.exe [2014-08-30 323352]
R2 Util HulaToo;Util HulaToo; C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe [2014-08-30 323352]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-22 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-21 116648]
S2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-09-27 86528]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-03-15 2458944]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2013-01-07 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2013-01-07 79360]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-07-22 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-21 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-07-25 111616]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2011-07-17 4390376]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-05-28 564928]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-09-04 1255736]
S4 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
S4 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-06-24 8704]
S4 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
S4 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Zde je log z Roguekiller ( v procesech jsem měl asi 94 procesů a přitom jsem neměl nic zaplého, nejvíce mi zabírali SVhosty a nějaké další processy, které jsem ani neznal, tak jsem si na netu dohledal že by mi RK mohl tyto processy zabít.)
RogueKiller V9.2.8.0 (x64) [Jul 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : R [Práva správce]
Mód : Odebrat -- Datum : 08/31/2014 17:15:20
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 28 ¤¤¤
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE} | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE} | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE} | DhcpNameServer : 10.0.0.138 -> NEVYBRÁNO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NEVYBRÁNO
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.trovi.com/?gd=&ctid=CT332219 ... 7D80&SSPV= -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.trovi.com/?gd=&ctid=CT332219 ... 7D80&SSPV= -> NEVYBRÁNO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dl ... ar=msnhome -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-93735815-1299707322-140628041-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dl ... r=iesearch -> NEVYBRÁNO
¤¤¤ naplánované úlohy : 3 ¤¤¤
[Suspicious.Path] AmiUpdXp.job -- C:\Users\R\AppData\Local\21676\a24223.exe -> VYMAZÁNO
[Suspicious.Path] \\AmiUpdXp -- C:\Users\R\AppData\Local\21676\a24223.exe -> VYMAZÁNO
[Suspicious.Path] \Hewlett-Packard\HP Support Assistant\Update Check -- C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe (/s /p 1) -> VYMAZÁNO
¤¤¤ Soubory : 0 ¤¤¤
¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost
¤¤¤ Antirootkit : 0 (Driver: NAHRÁNO) ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDS721010CLA332 +++++
--- User ---
[MBR] f0b7624901a6d69d5951aaab4625eb68
[BSP] 8ea6679b211905a05af3f7b0dd5e7fb6 : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 940605 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1926565888 | Size: 13162 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive2: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive3: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
+++++ PhysicalDrive4: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )
============================================
RKreport_SCN_08312014_171352.log