pomaly internet okna se mi sami oteviraji
Napsal: 24 zář 2014 13:10
prosim o pomoc uz nvm co s tim porad se to zasekava oteviraji se okna preskakuje me to kdyz chci kliknout na odkaz abych klikl na reklamu atd. Doufam ze poslu spravny lig z rsit.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jakub at 2014-09-24 13:32:11
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 4 GB (1%) free of 305 GB
Total RAM: 3001 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:32:18, on 24.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Program Files\trend micro\Jakub.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sqczlin.cz/o
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: CrossriderApp0059568 - {11111111-1111-1111-1111-110511951168} - C:\Program Files (x86)\HD-V1.8\HD-V1.8-bho.dll (file missing)
O3 - Toolbar: SiteFinder - {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files (x86)\SiteFinder\SiteFinder.dll (file missing)
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Site Finder - {CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files (x86)\SiteFinder\SiteFinder.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: c:\progra~2\movies~1\datamngr\mgrldr.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: EgisTec Service (IGBASVC) - Egis Technology Inc. - C:\Program Files (x86)\Acer Bio Protection\BASVC.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCDApp\StartHelp.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9337 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\Acer Bio Protection\CompPtcVUI.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
"taskhost.exe"
taskeng.exe {8343AB1D-6CDA-416B-BF9E-49162F5D5A21}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
C:\Windows\system32\HPSIsvc.exe
"C:\Program Files (x86)\Acer Bio Protection\BASVC.exe"
"C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"
C:\Windows\SysWOW64\netupdsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3220.112dd790.547052132 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 3220 "\\.\pipe\gecko-crash-server-pipe.3220" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --proxy-stub-channel=Flash1544.6EDB8BD8.4588 --host-broker-channel=Flash1544.6EDB8BD8.11170 --host-pid=1544 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --channel=2348.0046F714.223950553 --proxy-stub-channel=Flash1544.6EDB8BD8.4588 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" --host-npapi-version=27 --type=renderer
"C:\Users\Jakub\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-1.job - C:\Program Files (x86)\HD-V1.8\HD-V1.8-codedownloader.exe /UhDrlG /gjWvTITqL=task /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /wvFkWe=http://js.democlientnet.com /CjQVh=ff /kftdvfCHI='HD-V1.8' /jZIHa=http://js.clientdemocloud.com /AZptvQBh /tjDinAv='{"asw":[67108872, 5, 0]}' /bbHKcWc='http://update.democlientnet.com/ie_code ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-10.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-10.exe /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /dsHOwFaOL='HD-V1.8' /akkGk=1000 /xvrPint=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /VFGQskT=http://logs.democlientnet.com /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-11.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-11.exe 001715 23371C0280574D30A9607A6DFAF80BF1IE 59568 1404211088 93-0,102-0,104-0,178-288,179-288,180-288,223-288
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-2.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-2.exe /CqKHedRW /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /BYdOfmzOk=11111111-1111-1111-1111-110511951168 /CjQVh=ff /ZojoP /AZptvQBh /bbHKcWc='http://update.democlientnet.com/ie_enab ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-3.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-3.exe /oiPMR=Fdzeru8B6UTGbAfExr6RI8fEricdQ/T8RzA6U0k/p4u4u0+ZnFHN/jEwgefjGNmV9U2pirHZscq98VbVqb6/kMASUi4YV/E9A4ogoMMmURkv84J9mTGXR7mcI3t43gPF6kYEYJbVeqWM6XrzeePhscIwLK44m+rR5vl918ILGUdTf1ZgQUCSfC5jEjjBZQSnUG90dzdG08z2AO732aCpjWhKtzqeGurXLjDGl8ZQevhPD2UxqELg8O9MUGoex5PruGqMc01xnMPPwWT6ZplWp9vXN/0tWvFp0jEgurmgSYXpLszSKYuw/gfKZ/y3V7luNa9c6qyZ3FvS+qiBmi6VfGbHZkQEYTaQEzH2bfgLDUJMwojUkfBs+2Cswx2VxLCgTUNxMz+zbVT7CGy3h4hyaxQi+NgV1SyefujG50mhyE1PAIU/5aAj5sO8f8FfyVHZatOEHpSRQdvDD71gJN0UvbhHP3B3BzIk8RWj25GJgkCEprXbzv44T+hH8UJrtVfqGpZ3+tvzdOW5NUrNRhbikAKdW8F0wc9A0gg5toCZjNE7xgMUV92KpqDttrPafFJJ6OuMfSSkjRXwnnMI5i5iKJk1oe/xCjYCfc+yhdS8MwxxqQZ8bJS0N3xSYrIuYh2+OoVD/bLemRI8kcfWIyFb8YbtuMu34DvFKItF2XZ3a00QbbqakywkqPhfXcdH3lQdNB73I55GyIf1gut1EYMDzH7h4JrCuHuBYKrKMmRWl28RGis5u+q6IF9pwFGyUN3oQUWeybHw0wGUti85Kk8DPhOd5Bupxe3Swh/f2eaYLEIRXPjyU97ob2ICH0ImZnwVbfCOMacGTa35mqch1305sXUmor8Z9dmzVqkCKrbeNko/ToVu2yfdanBjQWPljBayvnivx1l6q7wsrHK1Ojf5vyhZyX5IPaQgyYCcmEazTdZxymAcZjnllbCrTun2ClzVeOxB8gqE0nKlb3gIl9GmWQ7wcLxNM9fxfno5vYq6TJpERq+VNsZxaYBOFkW+3dFfMzAiGYP1NjkWPK4fA0O9IOC//xpeQrzpiEfPDS8OmfWIRz7O89zZOCtqTKVy5gL2Bwx8XYpJKbrffPAb5703tAD5lseye+GZSnlvi5WSomdh61Asnh82wYOX3ismxvIfURbkgOLWxaWJg4mkv+5wkJ+KKMHdUiouPEYhVRUxj+Ch/3d3N5KWj+mHeCBAjD/w4Jmj32eQU7IqBF0i2u7VhJyxmYftO7ueO8zZAE6Gm6tX6fqR2Rzv9SyyaFDM7wJgscHXdoJXMBnKf5p/Ed+iROGBl3Dt2pB2fzCtpl7PLOD040Ef+Z/xqoJGuPR1ZkwQeQrnWy+4OURjdoyYsIp8jA==
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-4.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-4.exe /afqlWsxT /tmYzF='HD-V1.8' /bNoksL='C:\Program Files (x86)\HD-V1.8\59568.xpi' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /JcyMnkJE=300 /bedFK=f80af4ec-42b9-429d-99b0-4078ec7cf864@44882d20-8865-4b13-b79e-ae8470d9a955.com /JqUZR=0.94 /mozpiHe=af80af4ec42b9429d99b04078ec7cf86444882d2088654b13b79eae8470d9a955com59568 /xKbJX=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /59568.rdf /dsHOwFaOL='HD-V1.8' /bLKeQD='Turn YouTube videos to High Definition by default' /vXZtTvB='InfoHD-V1.8' /CjQVh=ff /tjDinAv='{"asw":[67108872, 5, 0]}' /AZptvQBh /PSuzmpV /kXxfiNB /bbHKcWc='http://update.democlientnet.com/ff_agen ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5.exe /ARaItDTUx /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /XxMXNLpLI=http://ipgeoapi.com/ /fuwhFY=http://update.democlientnet.com /VOaTqVU=2 /VFGQskT=http://logs.democlientnet.com /bbHKcWc='http://update.democlientnet.com/updater ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5_user.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5.exe /ARaItDTUx /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /XxMXNLpLI=http://ipgeoapi.com/ /fuwhFY=http://update.democlientnet.com /VOaTqVU=2 /VFGQskT=http://logs.democlientnet.com /bbHKcWc='http://update.democlientnet.com/updater ... pdate.json' /Bzbhgmoy /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-6.job - C:\Program Files (x86)\HD-V1.8\HD-V1.8-novainstaller.exe /yUfafiBNd /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /wvFkWe=http://js.democlientnet.com /CjQVh=ff /JKTpqGJSV /kftdvfCHI=HD-V1.8 /hwvSBu='nova' /jZIHa=http://js.clientdemocloud.com /tjDinAv='{"asw":[67108872, 5, 0]}' /gjWvTITqL=task /bbHKcWc='http://update.democlientnet.com/novacod ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-7.job - C:\Program Files (x86)\HD-V1.8\HD-V1.8-nova.exe /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /wvFkWe=http://js.democlientnet.com /CjQVh=ff /JKTpqGJSV /kftdvfCHI=HD-V1.8 /hwvSBu='nova' /jZIHa=http://js.clientdemocloud.com /tjDinAv='{"asw":[67108872, 5, 0]}' /bbHKcWc='http://update.democlientnet.com/novarun ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AmiUpdXp.job - C:\Users\Jakub\AppData\Local\8522\a28710.exe
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1984125612-1973881249-3784162068-1000Core.job - C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1984125612-1973881249-3784162068-1000UA.job - C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\mreyfwhb.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://sqc.zlin.cz/o/"
prefs.js - "keyword.URL" - "http://websearch.exitingsearch.info/?pi ... =50&l=1&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0]
"Description"=DivX Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin]
"Description"=VideoDownloadConverter Plugin
"Path"=C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\mreyfwhb.default\extensions\
cg9.6xu@ahahnhknl.com
EOPN29927080@OCIFAPD100469180.com
oqthxvb@jbujbcfw.net
sitematcher@sitematcher.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951168}]
HD-V1.8 - C:\Program Files (x86)\HD-V1.8\HD-V1.8-bho64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B0CDA5A-B244-DD44-12A1-76CB865C7F3B}]
SAveLots
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63A74F4E-FB96-C709-047D-605445B6E8B2}]
SNT - C:\Program Files (x86)\SNT\BGpYOd.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98C291DE-287E-AE21-0C31-0CE533A393D2}]
RandOmPRRIce - C:\ProgramData\RandOmPRRIce\vo.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6A17344-1E02-489E-2468-93F7C287A76E}]
safoeeweb - C:\Program Files (x86)\safoeeweb\TykdtSp.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B50E5A3D-14C4-536E-6790-87E9977C4084}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\y_lVEC.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951168}]
HD-V1.8 - C:\Program Files (x86)\HD-V1.8\HD-V1.8-bho.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} - SiteFinder - C:\Program Files (x86)\SiteFinder\SiteFinder.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-16 138096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-18 946352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Users\Jakub\AppData\Roaming\BitTorrent\BitTorrent.exe [2013-06-21 882520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2014-01-20 811792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Jakub\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Jakub\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixMyRegistry]
C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [2013-07-22 1886840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2009-09-02 380928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2009-09-02 159232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2009-09-02 358912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-03-21 1061960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-03-29 1631144]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VitaKeyPdtWzd]
C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe [2010-07-24 3576176]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-08-14 1190920]
"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2014-05-28 455512]
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2014-01-10 1861968]
"SDTray"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\progra~2\movies~1\datamngr\x64\mgrldr.dll C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-02 259584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=C:\Program Files (x86)\Acer Bio Protection\PwdFilterV64
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2014-09-24 13:32:12 ----D---- C:\Program Files\trend micro
2014-09-24 13:32:11 ----D---- C:\rsit
2014-09-24 11:19:36 ----A---- C:\awhEF2E.tmp
2014-09-24 09:56:13 ----A---- C:\Windows\system32\sdnclean64.exe
2014-09-24 09:56:10 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-09-24 09:55:56 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-23 08:18:02 ----A---- C:\awhBE7E.tmp
2014-09-23 06:36:49 ----A---- C:\awhD2E8.tmp
2014-09-22 18:58:50 ----A---- C:\awhE3B9.tmp
2014-09-22 08:39:16 ----A---- C:\awh209.tmp
2014-09-20 21:54:53 ----A---- C:\awhA5EF.tmp
2014-09-20 16:48:32 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 16:14:05 ----A---- C:\awh4021.tmp
2014-09-13 11:37:20 ----A---- C:\Windows\system32\ieui.dll
2014-09-13 11:37:19 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-13 11:37:17 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-13 11:37:17 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-13 11:37:16 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-13 11:37:16 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-13 11:37:16 ----A---- C:\Windows\system32\iernonce.dll
2014-09-13 11:37:15 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-13 11:37:15 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-13 11:37:15 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-13 11:37:15 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-13 11:37:14 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-13 11:37:14 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-13 11:37:14 ----A---- C:\Windows\system32\vbscript.dll
2014-09-13 11:37:14 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-13 11:37:14 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-13 11:37:13 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-13 11:37:13 ----A---- C:\Windows\system32\msrating.dll
2014-09-13 11:37:13 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-13 11:37:12 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-13 11:37:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-13 11:37:12 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-13 11:37:12 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-13 11:37:12 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-13 11:37:11 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-13 11:37:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-13 11:37:11 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-13 11:37:11 ----A---- C:\Windows\system32\iesetup.dll
2014-09-13 11:37:11 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-13 11:37:11 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-13 11:37:10 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-13 11:37:10 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-13 11:37:08 ----A---- C:\Windows\system32\mshtml.dll
2014-09-13 11:37:07 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-13 11:37:07 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-13 11:37:07 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-13 11:37:07 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-13 11:37:07 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-13 11:37:06 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-13 11:37:06 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-13 11:37:06 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-13 11:37:02 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-13 11:37:02 ----A---- C:\Windows\system32\iertutil.dll
2014-09-13 11:37:01 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-13 11:37:01 ----A---- C:\Windows\system32\wininet.dll
2014-09-13 11:37:00 ----A---- C:\Windows\system32\jscript9.dll
2014-09-13 11:36:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-13 11:36:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-13 11:36:59 ----A---- C:\Windows\system32\urlmon.dll
2014-09-13 11:36:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-13 11:36:55 ----A---- C:\Windows\system32\ieframe.dll
2014-09-13 11:36:54 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-13 03:01:37 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-13 03:01:37 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 13:15:36 ----A---- C:\awh11CB.tmp
2014-09-10 21:23:01 ----A---- C:\awhD2D8.tmp
2014-09-10 13:42:13 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-09-10 07:39:09 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-10 07:39:09 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-10 07:38:47 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-10 07:38:46 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-10 07:38:25 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-10 07:38:25 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-10 07:38:25 ----A---- C:\Windows\system32\kerberos.dll
2014-09-10 07:38:24 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-10 07:38:23 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-10 07:38:18 ----A---- C:\Windows\system32\aepdu.dll
2014-09-10 07:38:16 ----A---- C:\Windows\system32\aeinv.dll
2014-09-10 07:25:05 ----A---- C:\awh5BC5.tmp
2014-09-04 13:20:30 ----SHD---- C:\Windows\ftpcache
2014-09-04 13:18:42 ----A---- C:\Windows\system32\HPSIsvc.exe
2014-09-04 13:17:47 ----A---- C:\Windows\system32\mvhlewsi.DLL
2014-09-04 13:17:46 ----A---- C:\Windows\system32\HPM1210SM.exe
2014-09-04 13:17:45 ----A---- C:\Windows\system32\HPM1210LM.DLL
2014-09-04 13:05:10 ----D---- C:\Program Files\HP
2014-09-02 13:48:13 ----A---- C:\awh5C33.tmp
2014-09-01 09:25:18 ----A---- C:\awh118C.tmp
2014-08-31 22:32:45 ----A---- C:\awhD26B.tmp
2014-08-31 14:19:50 ----A---- C:\awh5E5F.tmp
2014-08-28 22:15:24 ----A---- C:\awhFF86.tmp
2014-08-28 10:47:46 ----A---- C:\Windows\system32\win32k.sys
2014-08-28 10:47:45 ----A---- C:\Windows\system32\gdi32.dll
2014-08-28 10:47:43 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-24 22:38:41 ----A---- C:\awhFD33.tmp
2014-08-17 09:37:27 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-17 09:37:27 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-17 09:37:27 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-17 09:37:27 ----A---- C:\Windows\system32\icardagt.exe
2014-08-17 09:37:24 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-17 09:37:24 ----A---- C:\Windows\system32\icardres.dll
2014-08-17 09:36:53 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-17 09:36:53 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-17 09:36:33 ----A---- C:\awh35A.tmp
2014-08-16 19:23:12 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-16 19:23:12 ----A---- C:\Windows\system32\tzres.dll
2014-08-16 19:23:03 ----A---- C:\Windows\system32\msi.dll
2014-08-16 19:23:02 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-16 19:23:01 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-16 19:23:01 ----A---- C:\Windows\system32\msihnd.dll
2014-08-16 19:23:01 ----A---- C:\Windows\system32\consent.exe
2014-08-16 19:23:01 ----A---- C:\Windows\system32\authui.dll
2014-08-16 19:23:00 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-16 19:22:55 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-16 19:22:51 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-16 19:22:51 ----A---- C:\Windows\system32\shell32.dll
2014-08-16 19:20:25 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-16 19:20:24 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-01 03:23:49 ----A---- C:\Windows\system32\wups2.dll
2014-08-01 03:23:49 ----A---- C:\Windows\system32\wucltux.dll
2014-08-01 03:23:49 ----A---- C:\Windows\system32\wuauclt.exe
2014-08-01 03:23:48 ----A---- C:\Windows\system32\wuaueng.dll
2014-08-01 03:23:29 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-08-01 03:23:29 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-08-01 03:23:29 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-08-01 03:23:29 ----A---- C:\Windows\system32\wups.dll
2014-08-01 03:23:29 ----A---- C:\Windows\system32\wudriver.dll
2014-08-01 03:23:29 ----A---- C:\Windows\system32\wuapi.dll
2014-08-01 03:23:01 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-08-01 03:23:00 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-08-01 03:23:00 ----A---- C:\Windows\system32\wuwebv.dll
2014-08-01 03:22:59 ----A---- C:\Windows\system32\wuapp.exe
2014-07-25 02:35:46 ----A---- C:\Windows\SYSWOW64\msvcr120_clr0400.dll
2014-07-24 23:47:06 ----A---- C:\Windows\system32\msvcr120_clr0400.dll
2014-07-23 14:47:55 ----A---- C:\awh63E9.tmp
2014-07-21 19:51:00 ----A---- C:\awh28F.tmp
2014-07-17 18:05:06 ----A---- C:\Windows\system32\drivers\MpFilter.sys
2014-07-11 12:58:11 ----A---- C:\awhF0D3.tmp
2014-07-11 12:34:35 ----D---- C:\7c2f80d69feeb8443af274d2a0
2014-07-11 12:19:18 ----D---- C:\074ad78ae838a954aaf94d700e26c7a3
2014-07-11 12:03:39 ----D---- C:\79b754d59677f7ce029e
2014-07-11 03:40:57 ----D---- C:\3419a10e1936d16f04dda72eeb
2014-07-11 03:34:15 ----A---- C:\awhB27C.tmp
2014-07-11 03:31:26 ----D---- C:\0f4fafd195af525e4ea33e2f505bdc4f
2014-07-11 03:16:56 ----A---- C:\awh9915.tmp
2014-07-11 03:14:42 ----D---- C:\321182a1c554e811c9884e
2014-07-11 03:06:19 ----D---- C:\ffcc849d520eea649f89215e6944a66a
2014-07-10 11:55:14 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-07-10 11:55:13 ----A---- C:\Windows\system32\osk.exe
2014-07-10 11:55:10 ----A---- C:\Windows\system32\qedit.dll
2014-07-10 11:55:09 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-10 11:55:08 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-10 11:55:01 ----A---- C:\Windows\system32\schannel.dll
2014-07-10 11:55:00 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-07-10 11:54:59 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-10 11:54:59 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-10 11:54:58 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-10 11:54:58 ----A---- C:\Windows\system32\wdigest.dll
2014-07-10 11:54:58 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-10 11:54:58 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-10 11:54:57 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-07-10 11:54:57 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-10 11:54:54 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-07-10 11:54:54 ----A---- C:\Windows\system32\credssp.dll
2014-07-10 00:13:01 ----A---- C:\awhD410.tmp
2014-07-09 13:05:00 ----A---- C:\awh40F5.tmp
2014-07-09 09:29:28 ----A---- C:\awhBA65.tmp
2014-07-01 12:44:28 ----D---- C:\Users\Jakub\AppData\Roaming\DivX
2014-07-01 12:44:25 ----D---- C:\Program Files\DivX
2014-07-01 12:41:14 ----D---- C:\Program Files (x86)\DivX
2014-07-01 12:40:37 ----D---- C:\ProgramData\DivX
2014-07-01 12:38:25 ----D---- C:\Program Files (x86)\globalUpdate
2014-07-01 12:38:15 ----D---- C:\Program Files (x86)\HD-V1.8
2014-07-01 12:37:51 ----D---- C:\Program Files\PCDApp
======List of files/folders modified in the last 3 months======
2014-09-24 13:32:12 ----RD---- C:\Program Files
2014-09-24 13:30:15 ----D---- C:\Windows\Temp
2014-09-24 11:22:24 ----D---- C:\Windows\System32
2014-09-24 11:22:24 ----D---- C:\Windows\inf
2014-09-24 11:22:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-24 10:25:13 ----D---- C:\Windows\system32\config
2014-09-24 10:01:10 ----SHD---- C:\System Volume Information
2014-09-24 09:56:45 ----D---- C:\Windows\system32\Tasks
2014-09-24 09:56:31 ----SD---- C:\ProgramData\Microsoft
2014-09-24 09:56:10 ----HD---- C:\ProgramData
2014-09-24 09:55:56 ----RD---- C:\Program Files (x86)
2014-09-23 21:43:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-22 08:42:39 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-20 21:48:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-14 11:44:21 ----D---- C:\Windows\Microsoft.NET
2014-09-14 11:23:49 ----RSD---- C:\Windows\assembly
2014-09-13 12:11:21 ----D---- C:\Windows\winsxs
2014-09-13 12:00:34 ----D---- C:\Windows\system32\catroot
2014-09-13 12:00:07 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-13 12:00:07 ----D---- C:\Windows\SysWOW64
2014-09-13 12:00:07 ----D---- C:\Windows\system32\en-US
2014-09-13 12:00:07 ----D---- C:\Program Files\Internet Explorer
2014-09-13 12:00:06 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-13 11:44:32 ----SHD---- C:\Windows\Installer
2014-09-13 11:44:32 ----D---- C:\ProgramData\Microsoft Help
2014-09-13 11:37:45 ----D---- C:\Windows\system32\catroot2
2014-09-13 11:34:56 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-13 11:30:28 ----D---- C:\Windows
2014-09-13 11:30:27 ----D---- C:\Windows\system32\drivers
2014-09-13 11:30:22 ----D---- C:\Program Files\Microsoft Security Client
2014-09-13 11:30:21 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-09-13 11:29:07 ----D---- C:\Windows\system32\MRT
2014-09-13 03:03:11 ----A---- C:\Windows\system32\MRT.exe
2014-09-13 03:01:26 ----SD---- C:\Windows\system32\CompatTel
2014-09-10 12:42:28 ----D---- C:\Windows\Prefetch
2014-09-04 13:18:21 ----D---- C:\Windows\system32\DriverStore
2014-09-04 13:17:21 ----D---- C:\Windows\twain_32
2014-08-25 17:17:09 ----D---- C:\Windows\rescache
2014-08-17 14:20:32 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-17 14:20:32 ----D---- C:\Windows\system32\cs-CZ
2014-08-17 14:20:32 ----D---- C:\Windows\ehome
2014-08-17 14:20:24 ----D---- C:\Windows\PolicyDefinitions
2014-08-07 11:26:10 ----D---- C:\Program Files\Microsoft Silverlight
2014-08-07 11:26:10 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-07-27 20:17:25 ----D---- C:\Windows\system32\NDF
2014-07-11 13:21:02 ----D---- C:\Program Files\Windows Journal
2014-07-11 13:21:01 ----D---- C:\Windows\SYSWOW64\Dism
2014-07-11 13:21:01 ----D---- C:\Windows\system32\Dism
2014-07-11 12:18:04 ----D---- C:\Program Files (x86)\Steam
2014-07-10 18:31:13 ----D---- C:\Program Files (x86)\SiteFinder
2014-07-10 18:23:10 ----D---- C:\Program Files (x86)\Yontoo
2014-07-09 11:42:37 ----D---- C:\ProgramData\SAveLots
2014-07-09 09:53:49 ----D---- C:\Program Files (x86)\SW-Booster
2014-07-09 09:51:31 ----D---- C:\Users\Jakub\AppData\Roaming\Malwarebytes
2014-07-09 09:50:46 ----D---- C:\ProgramData\Malwarebytes
2014-07-01 12:43:37 ----D---- C:\Program Files (x86)\Common Files
2014-07-01 12:40:32 ----D---- C:\Windows\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-19 283200]
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys [2014-06-15 46160]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-12-31 360712]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2014-01-20 115472]
R2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys); C:\Windows\System32\Drivers\FPSensor.sys [2013-02-11 35888]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); C:\Windows\SysWOW64\Drivers\DKbFltr.sys [2009-03-26 25608]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-09-02 7369728]
R3 NETw5s64;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-02 187392]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S2 int15;int15; \??\C:\Windows\SysWOW64\drivers\int15_64.sys [2010-07-24 14192]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2012-12-24 20480]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 vpcuxd;Služba zástupné procedury virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcuxd.sys [2009-09-23 16384]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2014-01-20 385808]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-08-24 107016]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2010-04-29 127800]
R2 IGBASVC;EgisTec Service; C:\Program Files (x86)\Acer Bio Protection\BASVC.exe [2010-07-24 3457392]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2014-06-15 159744]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2014-01-20 402192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 d0e87c27;SW-Sustainer; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-08 116648]
S2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe []
S2 ProtectMonitor;Protect Monitor; C:\Program Files\PCDApp\StartHelp.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-23 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc []
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-08 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-03-29 543656]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-02-11 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jakub at 2014-09-24 13:32:11
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 4 GB (1%) free of 305 GB
Total RAM: 3001 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:32:18, on 24.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Program Files\trend micro\Jakub.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sqczlin.cz/o
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: CrossriderApp0059568 - {11111111-1111-1111-1111-110511951168} - C:\Program Files (x86)\HD-V1.8\HD-V1.8-bho.dll (file missing)
O3 - Toolbar: SiteFinder - {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files (x86)\SiteFinder\SiteFinder.dll (file missing)
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launch Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files (x86)\Acer Bio Protection\PwdBank.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Site Finder - {CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files (x86)\SiteFinder\SiteFinder.dll (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: c:\progra~2\movies~1\datamngr\mgrldr.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - Unknown owner - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: EgisTec Service (IGBASVC) - Egis Technology Inc. - C:\Program Files (x86)\Acer Bio Protection\BASVC.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCDApp\StartHelp.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9337 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\Acer Bio Protection\CompPtcVUI.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
"taskhost.exe"
taskeng.exe {8343AB1D-6CDA-416B-BF9E-49162F5D5A21}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
C:\Windows\system32\HPSIsvc.exe
"C:\Program Files (x86)\Acer Bio Protection\BASVC.exe"
"C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"
C:\Windows\SysWOW64\netupdsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3220.112dd790.547052132 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 3220 "\\.\pipe\gecko-crash-server-pipe.3220" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --proxy-stub-channel=Flash1544.6EDB8BD8.4588 --host-broker-channel=Flash1544.6EDB8BD8.11170 --host-pid=1544 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --channel=2348.0046F714.223950553 --proxy-stub-channel=Flash1544.6EDB8BD8.4588 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" --host-npapi-version=27 --type=renderer
"C:\Users\Jakub\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-1.job - C:\Program Files (x86)\HD-V1.8\HD-V1.8-codedownloader.exe /UhDrlG /gjWvTITqL=task /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /wvFkWe=http://js.democlientnet.com /CjQVh=ff /kftdvfCHI='HD-V1.8' /jZIHa=http://js.clientdemocloud.com /AZptvQBh /tjDinAv='{"asw":[67108872, 5, 0]}' /bbHKcWc='http://update.democlientnet.com/ie_code ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-10.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-10.exe /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /dsHOwFaOL='HD-V1.8' /akkGk=1000 /xvrPint=93-0,102-0,104-0,178-288,179-288,180-288,223-288 /VFGQskT=http://logs.democlientnet.com /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-11.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-11.exe 001715 23371C0280574D30A9607A6DFAF80BF1IE 59568 1404211088 93-0,102-0,104-0,178-288,179-288,180-288,223-288
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-2.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-2.exe /CqKHedRW /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /BYdOfmzOk=11111111-1111-1111-1111-110511951168 /CjQVh=ff /ZojoP /AZptvQBh /bbHKcWc='http://update.democlientnet.com/ie_enab ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-3.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-3.exe /oiPMR=Fdzeru8B6UTGbAfExr6RI8fEricdQ/T8RzA6U0k/p4u4u0+ZnFHN/jEwgefjGNmV9U2pirHZscq98VbVqb6/kMASUi4YV/E9A4ogoMMmURkv84J9mTGXR7mcI3t43gPF6kYEYJbVeqWM6XrzeePhscIwLK44m+rR5vl918ILGUdTf1ZgQUCSfC5jEjjBZQSnUG90dzdG08z2AO732aCpjWhKtzqeGurXLjDGl8ZQevhPD2UxqELg8O9MUGoex5PruGqMc01xnMPPwWT6ZplWp9vXN/0tWvFp0jEgurmgSYXpLszSKYuw/gfKZ/y3V7luNa9c6qyZ3FvS+qiBmi6VfGbHZkQEYTaQEzH2bfgLDUJMwojUkfBs+2Cswx2VxLCgTUNxMz+zbVT7CGy3h4hyaxQi+NgV1SyefujG50mhyE1PAIU/5aAj5sO8f8FfyVHZatOEHpSRQdvDD71gJN0UvbhHP3B3BzIk8RWj25GJgkCEprXbzv44T+hH8UJrtVfqGpZ3+tvzdOW5NUrNRhbikAKdW8F0wc9A0gg5toCZjNE7xgMUV92KpqDttrPafFJJ6OuMfSSkjRXwnnMI5i5iKJk1oe/xCjYCfc+yhdS8MwxxqQZ8bJS0N3xSYrIuYh2+OoVD/bLemRI8kcfWIyFb8YbtuMu34DvFKItF2XZ3a00QbbqakywkqPhfXcdH3lQdNB73I55GyIf1gut1EYMDzH7h4JrCuHuBYKrKMmRWl28RGis5u+q6IF9pwFGyUN3oQUWeybHw0wGUti85Kk8DPhOd5Bupxe3Swh/f2eaYLEIRXPjyU97ob2ICH0ImZnwVbfCOMacGTa35mqch1305sXUmor8Z9dmzVqkCKrbeNko/ToVu2yfdanBjQWPljBayvnivx1l6q7wsrHK1Ojf5vyhZyX5IPaQgyYCcmEazTdZxymAcZjnllbCrTun2ClzVeOxB8gqE0nKlb3gIl9GmWQ7wcLxNM9fxfno5vYq6TJpERq+VNsZxaYBOFkW+3dFfMzAiGYP1NjkWPK4fA0O9IOC//xpeQrzpiEfPDS8OmfWIRz7O89zZOCtqTKVy5gL2Bwx8XYpJKbrffPAb5703tAD5lseye+GZSnlvi5WSomdh61Asnh82wYOX3ismxvIfURbkgOLWxaWJg4mkv+5wkJ+KKMHdUiouPEYhVRUxj+Ch/3d3N5KWj+mHeCBAjD/w4Jmj32eQU7IqBF0i2u7VhJyxmYftO7ueO8zZAE6Gm6tX6fqR2Rzv9SyyaFDM7wJgscHXdoJXMBnKf5p/Ed+iROGBl3Dt2pB2fzCtpl7PLOD040Ef+Z/xqoJGuPR1ZkwQeQrnWy+4OURjdoyYsIp8jA==
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-4.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-4.exe /afqlWsxT /tmYzF='HD-V1.8' /bNoksL='C:\Program Files (x86)\HD-V1.8\59568.xpi' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /JcyMnkJE=300 /bedFK=f80af4ec-42b9-429d-99b0-4078ec7cf864@44882d20-8865-4b13-b79e-ae8470d9a955.com /JqUZR=0.94 /mozpiHe=af80af4ec42b9429d99b04078ec7cf86444882d2088654b13b79eae8470d9a955com59568 /xKbJX=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /59568.rdf /dsHOwFaOL='HD-V1.8' /bLKeQD='Turn YouTube videos to High Definition by default' /vXZtTvB='InfoHD-V1.8' /CjQVh=ff /tjDinAv='{"asw":[67108872, 5, 0]}' /AZptvQBh /PSuzmpV /kXxfiNB /bbHKcWc='http://update.democlientnet.com/ff_agen ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5.exe /ARaItDTUx /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /XxMXNLpLI=http://ipgeoapi.com/ /fuwhFY=http://update.democlientnet.com /VOaTqVU=2 /VFGQskT=http://logs.democlientnet.com /bbHKcWc='http://update.democlientnet.com/updater ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5_user.job - C:\Program Files (x86)\HD-V1.8\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-5.exe /ARaItDTUx /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /XxMXNLpLI=http://ipgeoapi.com/ /fuwhFY=http://update.democlientnet.com /VOaTqVU=2 /VFGQskT=http://logs.democlientnet.com /bbHKcWc='http://update.democlientnet.com/updater ... pdate.json' /Bzbhgmoy /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-6.job - C:\Program Files (x86)\HD-V1.8\HD-V1.8-novainstaller.exe /yUfafiBNd /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /wvFkWe=http://js.democlientnet.com /CjQVh=ff /JKTpqGJSV /kftdvfCHI=HD-V1.8 /hwvSBu='nova' /jZIHa=http://js.clientdemocloud.com /tjDinAv='{"asw":[67108872, 5, 0]}' /gjWvTITqL=task /bbHKcWc='http://update.democlientnet.com/novacod ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\64d5b3d7-f9f6-433f-afe2-74bbfe31ec2d-7.job - C:\Program Files (x86)\HD-V1.8\HD-V1.8-nova.exe /tmYzF='HD-V1.8' /VcaOinD=59568 /iZKtjcC='001715' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=23371C0280574D30A9607A6DFAF80BF1IE /jANlEtyt=dcb2966b5f933c1eba23a72d30b08c61 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404211088 /bTnDNCp=http://stats.democlientnet.com /maTWCr=http://errors.democlientnet.com /wvFkWe=http://js.democlientnet.com /CjQVh=ff /JKTpqGJSV /kftdvfCHI=HD-V1.8 /hwvSBu='nova' /jZIHa=http://js.clientdemocloud.com /tjDinAv='{"asw":[67108872, 5, 0]}' /bbHKcWc='http://update.democlientnet.com/novarun ... pdate.json' /gjWvTITqL='task' /ZVXes=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AmiUpdXp.job - C:\Users\Jakub\AppData\Local\8522\a28710.exe
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1984125612-1973881249-3784162068-1000Core.job - C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1984125612-1973881249-3784162068-1000UA.job - C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\mreyfwhb.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://sqc.zlin.cz/o/"
prefs.js - "keyword.URL" - "http://websearch.exitingsearch.info/?pi ... =50&l=1&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0]
"Description"=DivX Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin]
"Description"=VideoDownloadConverter Plugin
"Path"=C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\mreyfwhb.default\extensions\
cg9.6xu@ahahnhknl.com
EOPN29927080@OCIFAPD100469180.com
oqthxvb@jbujbcfw.net
sitematcher@sitematcher.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951168}]
HD-V1.8 - C:\Program Files (x86)\HD-V1.8\HD-V1.8-bho64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B0CDA5A-B244-DD44-12A1-76CB865C7F3B}]
SAveLots
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63A74F4E-FB96-C709-047D-605445B6E8B2}]
SNT - C:\Program Files (x86)\SNT\BGpYOd.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98C291DE-287E-AE21-0C31-0CE533A393D2}]
RandOmPRRIce - C:\ProgramData\RandOmPRRIce\vo.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6A17344-1E02-489E-2468-93F7C287A76E}]
safoeeweb - C:\Program Files (x86)\safoeeweb\TykdtSp.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B50E5A3D-14C4-536E-6790-87E9977C4084}]
YoutubeAdblocker - C:\Program Files (x86)\YoutubeAdblocker\y_lVEC.x64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951168}]
HD-V1.8 - C:\Program Files (x86)\HD-V1.8\HD-V1.8-bho.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} - SiteFinder - C:\Program Files (x86)\SiteFinder\SiteFinder.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=C:\Users\Jakub\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-16 138096]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-18 946352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Users\Jakub\AppData\Roaming\BitTorrent\BitTorrent.exe [2013-06-21 882520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2014-01-20 811792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\Jakub\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\Jakub\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixMyRegistry]
C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [2013-07-22 1886840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe [2009-09-02 380928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe [2009-09-02 159232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe [2009-09-02 358912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-03-21 1061960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-03-29 1631144]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VitaKeyPdtWzd]
C:\Program Files (x86)\Acer Bio Protection\PdtWzd.exe [2010-07-24 3576176]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-08-14 1190920]
"DivXMediaServer"=C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [2014-05-28 455512]
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2014-01-10 1861968]
"SDTray"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\progra~2\movies~1\datamngr\x64\mgrldr.dll C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-02 259584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=C:\Program Files (x86)\Acer Bio Protection\PwdFilterV64
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2014-09-24 13:32:12 ----D---- C:\Program Files\trend micro
2014-09-24 13:32:11 ----D---- C:\rsit
2014-09-24 11:19:36 ----A---- C:\awhEF2E.tmp
2014-09-24 09:56:13 ----A---- C:\Windows\system32\sdnclean64.exe
2014-09-24 09:56:10 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-09-24 09:55:56 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-09-23 08:18:02 ----A---- C:\awhBE7E.tmp
2014-09-23 06:36:49 ----A---- C:\awhD2E8.tmp
2014-09-22 18:58:50 ----A---- C:\awhE3B9.tmp
2014-09-22 08:39:16 ----A---- C:\awh209.tmp
2014-09-20 21:54:53 ----A---- C:\awhA5EF.tmp
2014-09-20 16:48:32 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-20 16:14:05 ----A---- C:\awh4021.tmp
2014-09-13 11:37:20 ----A---- C:\Windows\system32\ieui.dll
2014-09-13 11:37:19 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-13 11:37:17 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-13 11:37:17 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-13 11:37:16 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-13 11:37:16 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-13 11:37:16 ----A---- C:\Windows\system32\iernonce.dll
2014-09-13 11:37:15 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-13 11:37:15 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-13 11:37:15 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-13 11:37:15 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-13 11:37:14 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-13 11:37:14 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-13 11:37:14 ----A---- C:\Windows\system32\vbscript.dll
2014-09-13 11:37:14 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-13 11:37:14 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-13 11:37:13 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-13 11:37:13 ----A---- C:\Windows\system32\msrating.dll
2014-09-13 11:37:13 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-13 11:37:12 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-13 11:37:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-13 11:37:12 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-13 11:37:12 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-13 11:37:12 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-13 11:37:11 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-13 11:37:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-13 11:37:11 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-13 11:37:11 ----A---- C:\Windows\system32\iesetup.dll
2014-09-13 11:37:11 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-13 11:37:11 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-13 11:37:10 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-13 11:37:10 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-13 11:37:08 ----A---- C:\Windows\system32\mshtml.dll
2014-09-13 11:37:07 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-13 11:37:07 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-13 11:37:07 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-13 11:37:07 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-13 11:37:07 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-13 11:37:06 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-13 11:37:06 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-13 11:37:06 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-13 11:37:02 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-13 11:37:02 ----A---- C:\Windows\system32\iertutil.dll
2014-09-13 11:37:01 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-13 11:37:01 ----A---- C:\Windows\system32\wininet.dll
2014-09-13 11:37:00 ----A---- C:\Windows\system32\jscript9.dll
2014-09-13 11:36:59 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-13 11:36:59 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-13 11:36:59 ----A---- C:\Windows\system32\urlmon.dll
2014-09-13 11:36:56 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-13 11:36:55 ----A---- C:\Windows\system32\ieframe.dll
2014-09-13 11:36:54 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-13 03:01:37 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-13 03:01:37 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 13:15:36 ----A---- C:\awh11CB.tmp
2014-09-10 21:23:01 ----A---- C:\awhD2D8.tmp
2014-09-10 13:42:13 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-09-10 07:39:09 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-10 07:39:09 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-10 07:38:47 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-10 07:38:46 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-10 07:38:25 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-10 07:38:25 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-10 07:38:25 ----A---- C:\Windows\system32\kerberos.dll
2014-09-10 07:38:24 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-10 07:38:23 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-10 07:38:18 ----A---- C:\Windows\system32\aepdu.dll
2014-09-10 07:38:16 ----A---- C:\Windows\system32\aeinv.dll
2014-09-10 07:25:05 ----A---- C:\awh5BC5.tmp
2014-09-04 13:20:30 ----SHD---- C:\Windows\ftpcache
2014-09-04 13:18:42 ----A---- C:\Windows\system32\HPSIsvc.exe
2014-09-04 13:17:47 ----A---- C:\Windows\system32\mvhlewsi.DLL
2014-09-04 13:17:46 ----A---- C:\Windows\system32\HPM1210SM.exe
2014-09-04 13:17:45 ----A---- C:\Windows\system32\HPM1210LM.DLL
2014-09-04 13:05:10 ----D---- C:\Program Files\HP
2014-09-02 13:48:13 ----A---- C:\awh5C33.tmp
2014-09-01 09:25:18 ----A---- C:\awh118C.tmp
2014-08-31 22:32:45 ----A---- C:\awhD26B.tmp
2014-08-31 14:19:50 ----A---- C:\awh5E5F.tmp
2014-08-28 22:15:24 ----A---- C:\awhFF86.tmp
2014-08-28 10:47:46 ----A---- C:\Windows\system32\win32k.sys
2014-08-28 10:47:45 ----A---- C:\Windows\system32\gdi32.dll
2014-08-28 10:47:43 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-24 22:38:41 ----A---- C:\awhFD33.tmp
2014-08-17 09:37:27 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-17 09:37:27 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-17 09:37:27 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-17 09:37:27 ----A---- C:\Windows\system32\icardagt.exe
2014-08-17 09:37:24 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-17 09:37:24 ----A---- C:\Windows\system32\icardres.dll
2014-08-17 09:36:53 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-17 09:36:53 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-17 09:36:33 ----A---- C:\awh35A.tmp
2014-08-16 19:23:12 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-16 19:23:12 ----A---- C:\Windows\system32\tzres.dll
2014-08-16 19:23:03 ----A---- C:\Windows\system32\msi.dll
2014-08-16 19:23:02 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-16 19:23:01 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-16 19:23:01 ----A---- C:\Windows\system32\msihnd.dll
2014-08-16 19:23:01 ----A---- C:\Windows\system32\consent.exe
2014-08-16 19:23:01 ----A---- C:\Windows\system32\authui.dll
2014-08-16 19:23:00 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-16 19:22:55 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-16 19:22:51 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-16 19:22:51 ----A---- C:\Windows\system32\shell32.dll
2014-08-16 19:20:25 ----A---- C:\Windows\system32\rpcrt4.dll
2014-08-16 19:20:24 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-01 03:23:49 ----A---- C:\Windows\system32\wups2.dll
2014-08-01 03:23:49 ----A---- C:\Windows\system32\wucltux.dll
2014-08-01 03:23:49 ----A---- C:\Windows\system32\wuauclt.exe
2014-08-01 03:23:48 ----A---- C:\Windows\system32\wuaueng.dll
2014-08-01 03:23:29 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-08-01 03:23:29 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-08-01 03:23:29 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-08-01 03:23:29 ----A---- C:\Windows\system32\wups.dll
2014-08-01 03:23:29 ----A---- C:\Windows\system32\wudriver.dll
2014-08-01 03:23:29 ----A---- C:\Windows\system32\wuapi.dll
2014-08-01 03:23:01 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-08-01 03:23:00 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-08-01 03:23:00 ----A---- C:\Windows\system32\wuwebv.dll
2014-08-01 03:22:59 ----A---- C:\Windows\system32\wuapp.exe
2014-07-25 02:35:46 ----A---- C:\Windows\SYSWOW64\msvcr120_clr0400.dll
2014-07-24 23:47:06 ----A---- C:\Windows\system32\msvcr120_clr0400.dll
2014-07-23 14:47:55 ----A---- C:\awh63E9.tmp
2014-07-21 19:51:00 ----A---- C:\awh28F.tmp
2014-07-17 18:05:06 ----A---- C:\Windows\system32\drivers\MpFilter.sys
2014-07-11 12:58:11 ----A---- C:\awhF0D3.tmp
2014-07-11 12:34:35 ----D---- C:\7c2f80d69feeb8443af274d2a0
2014-07-11 12:19:18 ----D---- C:\074ad78ae838a954aaf94d700e26c7a3
2014-07-11 12:03:39 ----D---- C:\79b754d59677f7ce029e
2014-07-11 03:40:57 ----D---- C:\3419a10e1936d16f04dda72eeb
2014-07-11 03:34:15 ----A---- C:\awhB27C.tmp
2014-07-11 03:31:26 ----D---- C:\0f4fafd195af525e4ea33e2f505bdc4f
2014-07-11 03:16:56 ----A---- C:\awh9915.tmp
2014-07-11 03:14:42 ----D---- C:\321182a1c554e811c9884e
2014-07-11 03:06:19 ----D---- C:\ffcc849d520eea649f89215e6944a66a
2014-07-10 11:55:14 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-07-10 11:55:13 ----A---- C:\Windows\system32\osk.exe
2014-07-10 11:55:10 ----A---- C:\Windows\system32\qedit.dll
2014-07-10 11:55:09 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-10 11:55:08 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-10 11:55:01 ----A---- C:\Windows\system32\schannel.dll
2014-07-10 11:55:00 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-07-10 11:54:59 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-10 11:54:59 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-10 11:54:58 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-10 11:54:58 ----A---- C:\Windows\system32\wdigest.dll
2014-07-10 11:54:58 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-10 11:54:58 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-10 11:54:57 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-07-10 11:54:57 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-10 11:54:54 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-07-10 11:54:54 ----A---- C:\Windows\system32\credssp.dll
2014-07-10 00:13:01 ----A---- C:\awhD410.tmp
2014-07-09 13:05:00 ----A---- C:\awh40F5.tmp
2014-07-09 09:29:28 ----A---- C:\awhBA65.tmp
2014-07-01 12:44:28 ----D---- C:\Users\Jakub\AppData\Roaming\DivX
2014-07-01 12:44:25 ----D---- C:\Program Files\DivX
2014-07-01 12:41:14 ----D---- C:\Program Files (x86)\DivX
2014-07-01 12:40:37 ----D---- C:\ProgramData\DivX
2014-07-01 12:38:25 ----D---- C:\Program Files (x86)\globalUpdate
2014-07-01 12:38:15 ----D---- C:\Program Files (x86)\HD-V1.8
2014-07-01 12:37:51 ----D---- C:\Program Files\PCDApp
======List of files/folders modified in the last 3 months======
2014-09-24 13:32:12 ----RD---- C:\Program Files
2014-09-24 13:30:15 ----D---- C:\Windows\Temp
2014-09-24 11:22:24 ----D---- C:\Windows\System32
2014-09-24 11:22:24 ----D---- C:\Windows\inf
2014-09-24 11:22:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-24 10:25:13 ----D---- C:\Windows\system32\config
2014-09-24 10:01:10 ----SHD---- C:\System Volume Information
2014-09-24 09:56:45 ----D---- C:\Windows\system32\Tasks
2014-09-24 09:56:31 ----SD---- C:\ProgramData\Microsoft
2014-09-24 09:56:10 ----HD---- C:\ProgramData
2014-09-24 09:55:56 ----RD---- C:\Program Files (x86)
2014-09-23 21:43:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-22 08:42:39 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-20 21:48:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-14 11:44:21 ----D---- C:\Windows\Microsoft.NET
2014-09-14 11:23:49 ----RSD---- C:\Windows\assembly
2014-09-13 12:11:21 ----D---- C:\Windows\winsxs
2014-09-13 12:00:34 ----D---- C:\Windows\system32\catroot
2014-09-13 12:00:07 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-13 12:00:07 ----D---- C:\Windows\SysWOW64
2014-09-13 12:00:07 ----D---- C:\Windows\system32\en-US
2014-09-13 12:00:07 ----D---- C:\Program Files\Internet Explorer
2014-09-13 12:00:06 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-13 11:44:32 ----SHD---- C:\Windows\Installer
2014-09-13 11:44:32 ----D---- C:\ProgramData\Microsoft Help
2014-09-13 11:37:45 ----D---- C:\Windows\system32\catroot2
2014-09-13 11:34:56 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-13 11:30:28 ----D---- C:\Windows
2014-09-13 11:30:27 ----D---- C:\Windows\system32\drivers
2014-09-13 11:30:22 ----D---- C:\Program Files\Microsoft Security Client
2014-09-13 11:30:21 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-09-13 11:29:07 ----D---- C:\Windows\system32\MRT
2014-09-13 03:03:11 ----A---- C:\Windows\system32\MRT.exe
2014-09-13 03:01:26 ----SD---- C:\Windows\system32\CompatTel
2014-09-10 12:42:28 ----D---- C:\Windows\Prefetch
2014-09-04 13:18:21 ----D---- C:\Windows\system32\DriverStore
2014-09-04 13:17:21 ----D---- C:\Windows\twain_32
2014-08-25 17:17:09 ----D---- C:\Windows\rescache
2014-08-17 14:20:32 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-17 14:20:32 ----D---- C:\Windows\system32\cs-CZ
2014-08-17 14:20:32 ----D---- C:\Windows\ehome
2014-08-17 14:20:24 ----D---- C:\Windows\PolicyDefinitions
2014-08-07 11:26:10 ----D---- C:\Program Files\Microsoft Silverlight
2014-08-07 11:26:10 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-07-27 20:17:25 ----D---- C:\Windows\system32\NDF
2014-07-11 13:21:02 ----D---- C:\Program Files\Windows Journal
2014-07-11 13:21:01 ----D---- C:\Windows\SYSWOW64\Dism
2014-07-11 13:21:01 ----D---- C:\Windows\system32\Dism
2014-07-11 12:18:04 ----D---- C:\Program Files (x86)\Steam
2014-07-10 18:31:13 ----D---- C:\Program Files (x86)\SiteFinder
2014-07-10 18:23:10 ----D---- C:\Program Files (x86)\Yontoo
2014-07-09 11:42:37 ----D---- C:\ProgramData\SAveLots
2014-07-09 09:53:49 ----D---- C:\Program Files (x86)\SW-Booster
2014-07-09 09:51:31 ----D---- C:\Users\Jakub\AppData\Roaming\Malwarebytes
2014-07-09 09:50:46 ----D---- C:\ProgramData\Malwarebytes
2014-07-01 12:43:37 ----D---- C:\Program Files (x86)\Common Files
2014-07-01 12:40:32 ----D---- C:\Windows\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-19 283200]
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys [2014-06-15 46160]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-12-31 360712]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2014-01-20 115472]
R2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys); C:\Windows\System32\Drivers\FPSensor.sys [2013-02-11 35888]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); C:\Windows\SysWOW64\Drivers\DKbFltr.sys [2009-03-26 25608]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-09-02 7369728]
R3 NETw5s64;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows 7 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-02 187392]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S2 int15;int15; \??\C:\Windows\SysWOW64\drivers\int15_64.sys [2010-07-24 14192]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2012-12-24 20480]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows Vista; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 vpcuxd;Služba zástupné procedury virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcuxd.sys [2009-09-23 16384]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2014-01-20 385808]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-08-24 107016]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2010-04-29 127800]
R2 IGBASVC;EgisTec Service; C:\Program Files (x86)\Acer Bio Protection\BASVC.exe [2010-07-24 3457392]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2014-06-15 159744]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2014-01-20 402192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 d0e87c27;SW-Sustainer; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-08 116648]
S2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe []
S2 ProtectMonitor;Protect Monitor; C:\Program Files\PCDApp\StartHelp.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-23 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc []
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-08 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-20 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-03-29 543656]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-02-11 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------