nainstalovany shopper pro a jina havet
Napsal: 01 říj 2014 21:23
Ahoj, snazil jsem se vsechno odinstalovat, vcetne zakazu pluginu, ale pro jistotu prikladam log pro kontrolu, diky moc:
Logfile of random's system information tool 1.10 (written by random/random)
Run by naši at 2014-10-01 22:16:17
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 190 GB (80%) free of 238 GB
Total RAM: 4094 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:16:20, on 1.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera_crashreporter.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Users\naši\Downloads\HijackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files\trend micro\naši.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: d0ac00b04d3e0131269239ed9417a9330048559 - {11111111-1111-1111-1111-110411851159} - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll (file missing)
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - (no file)
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7474 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\System32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\ProgramData\IePluginServices\PluginService.exe -service
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1856
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1816
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --ran-launcher /crash-reporter-parent-id=3464
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=gpu-process --channel="3464.0.969013644\1129042304" --crash-reporter-pid=3356 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17 --gpu-vendor-id=0x1002 --gpu-device-id=0x9442 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.1100 --crash-reporter-pid=3356 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.4.192807329\1367797085" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.5.1377823006\9346098" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.14.1151204481\1547823284" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.15.1011182084\731436586" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" --disable-direct-npapi-requests --lang=cs --channel="3464.16.659244092\1356394583" --crash-reporter-pid=3356 /prefetch:-390060480
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.17.152075727\1965750818" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.18.565504178\1122318254" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.20.1735778499\1162660694" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.21.1623778774\1045510778" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.22.250260514\310277218" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.23.1643393943\1510114338" /prefetch:673131151
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-781b60ee-ed6c-44ae-b6dd-8a6f3f1b6fb4 -SystemEventPortName:HostProcess-db7276b4-46dd-47f3-ba13-779695818a91 -IoCancelEventPortName:HostProcess-a4594277-f593-4d70-a1d2-8ad29362f4f6 -NonStateChangingEventPortName:HostProcess-bdea8ea8-53de-4950-af40-e64fd5b8e8b2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:87e86204-a6af-452e-99e4-f56730d8c5dd -DeviceGroupId:WpdFsGroup
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\naši\Downloads\HijackThis.exe"
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\naši\Downloads\hijackthis.log
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.25.199819135\294053515" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.26.1259814472\992360294" /prefetch:673131151
"C:\Users\naši\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-1.job - C:\Program Files (x86)\Apps Hat\Apps Hat-codedownloader.exe /rawdata=KfmK0yoeXsD1mzF4+RxuVgKScxomlCFjb1o90mYOW2lQX3lXLzwg3gicZIBheCAVLLdqVALAaG4q66SP5mBXKvX4vQaG4fN9L8NGRrRMVC3MqaIcGlpkdBKDM/axrgoY6j5ttlr2XsgncWiydLyvw3erzedesjg337rCZl/Rt1O5THPP/yoCXL4qRvbJFwv2zQz/jVc94efPkxIifpNkdXyvNTle4tUTLbE4TFaGDMOyeqE6hpAfVnoW9yjOIwOa6Xb7YwG2mDeyeLEcVi3zKB+4pPU6aA77vSsR2Q/z13lb7OywIl2Gwuce11kfPhw7TEOYQh/yY6CqIizOEx4eHRtktZQAI8DXQBBjsKapwZ+ab1q5DnEwSbALF5TTH0Rl5sBq/L/bMdmsJX71EeDHSCt76/1YDm3wwWQKE+fFZoBRXlWYrytnyiNFBql+5/QuMF4XoYhqJmthmGSuY0AtEfpwrFtCSFpbroqEuyG1I5H2XFBD2LfrujoUjkmGOxxLgjiv5aI8zLiaXqwLIxlURo0ysAC7Ad5jOgxdTxZ9pi/MUHjGufjZ5/aIWlj77lB9kAxduJT/1fFNPrbo5hpBwo66n7hzMToXNf+/Yn2MYr6Z6cd9I/w7k1Wbw37rK3iEynIPh67C4nzvrPJuIAldErcXw6qXfxmf5PX7H3D8pbOn3bTydhwEW1VCegqpFXplnNcxEUZKlnCjoxhpXjSJlY1SzvBTM8ZJwYFrXDTX+K6GLE9c+Ux+HMAIpjVZ1jHvreBDLWsFjalS4x1ZWuSDuELbU7sKom892v5wGHA2ttn/T0XtYVUGwkp9Uv7J7yzMvuWcIRV5xQ/Nh+x4rubAFRCZVk+gPEUixFAW5gtEuYsyZ7VmO3Pi2y2IyeIJszWQtRjVQ4PeuC7V6mniBswPznT2l2dtJ8yj1P4aODUCMWmrdQA8dOYRqSLozhyHVcUnEc2JNjj/j/VLlGy+ssJ7PrRzRdY6yIGtOgW44UH++qEEtVqC5osHpIEzNZcQjJU8GPhYzcHoe341gf8CapgBcjTVAvQM2nSrFoghuC9qCdjgNtCyMj0/VdhlngCswyEgqxsGkGoSarCA11iAEqO+Qt1OS/z9WYR0uzz4gSDXNZRFADSr7d51KVn35VUh2U5XbBxqxiS5KJEqGlKRFbE4F6scWzwEy+wHU4tnoelfk1Q142KUhgBWSNy3pFQxBm0jSktvkTas9Wrsl8/HVOnCkE/E5ruxd9B+xXAIJ17dly7iIXZIOIm81eA4ozgi3+M5qokIgvcbSPAEizdjGh9oMAgiGY5sdxjcCn+X/SepUaJFvC2On6TaxCcBr0us/d0uYokzwOh69a+DSpP9ZpQkS1C1Wdq0qc5crY+ZS7ynsKnJArpblqqYUI53Z0RWUzYkjpNOtMlqysK7z0p/EUukVK97rFMwCAsc2L8v8TAYMMwElbqetba4ogFPcB7SJdRV8K04IMClu3ytQ32Nci4V+QX/Ns4OFW1neXSupzrptb+0GiaGbsktZQUIvXWOyy7Y
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-2.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-2.exe /rawdata=R4zV3jAYVl0nsm/Dwmdk33nqOuuKKSAsVQFe2718iK1dqY5NbxXjQExYgQ+pqcQe/j1yiQ5WlABRRyxTOAWqyNk5zFB1zIcCOKuJ3YB2bW6exBGPTLQelYMzP0b8DAph0SaNAxGjg2RaNXw6CMi5TBxpC57VZQrCKpJykuHyliKQ5W08160SptRx/TihwP6YPriWvpFSwEbX2S99mKIZwg5lnHqtCKJZOyHbIlCZRw+cDih44R8dUHB7Gb0mHJthTH0i34kSfYEzTsKTb3Glsj0yzmyYwzsBYxCQucLOFAdnVUNzDjf/7TIwXXFCWR6LhzDkyYiH3ENG4WH7Z+YlMV7o4MLMfmbvy3piCP/eawThT09sFk+CN70py0R4hNmzKjCQq9wPEFSP+n7g52mxcC79Rc5zxTQKQ5hhMS8ORuvWLtRIHrBe6hm07vXX1NWFdjUAVkzcTDGis/yftx1bZWjD5I2PQlg5m+/cjXkUcD3lw8nfrkHOmAbH5e6p+AJVv1QgTQav14rH/OTvwdYcHcZl/wScBG49UkMJ6my0p7RyoKkZK7sUn7JNl2HfPqISAJQXQuA45MLcspCsKWVBLx18ZP9/TEOigWHrdtCR7iamIX0Ko7MiSFBLRXCOI3X0cuTG93fETxss93Q65hiNvuqHKUQLe6+8Ygmcuqj5jXeqn7SPN5BmbbZdNT8hoXPZ5dCavliRzezHSBYK33fOueYpsGiPyDcA4eI5C8DPwDCeOGAvLf/lrLSQjm9yuytHz14qBVdb7TS5JkgihYVGysCc785eSlB5x5eweBHU7T1u5uTYnmQRycn4DrRjTkJySdUNyC0CXfmOYqHa1XWfPg==
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-4.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-4.exe /rawdata=F7UeaJ0Pqbd0mY3J0mIa7XBRySd+qDi7Uor4ER9YlPahUeBPCYg6NB0/hQ/HwgmBbKAmldqORoI8Zm7zxAVX34hykZKHASxRH8fqNzDJWVHp7lD7DNLOY3yLaIzZ0loJX6qMXB5E1GVflvDWHeEsrtLYW2eXIz4Bqw2ra1bvDj2Td87s/8scieC49ra+aoD6jObg+Xv0X+RdyqHeB5xocyuHtILlClu0YjcH4N6vOzrs6qR2sksqbIvfnV6/RljDK1NiSoISWBcIHWOiTvBTwOdYFeA46zm654ZCloMV4kmOMDZ0b+IIomGqCk0Rq7e+v1J2tl7Huy87838TTvkF5ZuNWc1PXplrCF8nmhvwDooBXSzJu4RbF5zA3APm+2bFAkHRi1TNikKJ1b/ZpMCQAUeIFBTFV3bRlCom2QW9tsRwzFddamqNbCut9WBmSWUh4yXKnS+4Po8nQJfwAGW1PG4MAR/krd8924rfV+rso80eO8zJivdabdiZip9VKtY5gbKdFVBZ4negrLzEGmExrQl6amF/iYb7GH9K8AOz9UtP1kAhBL3+FvHe32Z03Z8NA+aMVyLaig2ldicIEteZnbonabN2hQAAFUqkPBJzV1cLBZ0gr5gxklPjcrR5HEXBsue1GftKXxn6NAiR0UXF6b5A4ZBGZjuCf3Zf52z5wLpsbGmbcDNy1Kh/etwzxuNc3yqSH95VsyDyquYiSO2CmL8MzkIv3xJGjpH1FFRnwNyuVN3DtRQ2YQ4hysei0JxnqaBCFzMb/vU4K0HWBcp2LREN9U2S7on74Wi2F/ziipX5Ymu5ilHeF+jfuuoCk9xUAkU0Lyxifet0dniDK5JruCJURatsot2N91hBmSr+TGJcSGKaWgkFh9BqbdrXDssEpG/1nUYwZKnEDk6r9PG1D4/4yCzNaFxcV4DVXfD6qFcnjWMogL7X8bbfwyCbJpevd77XVaUgofuJyTdT0pLR/iSYzeMhpW7TiYcDtXdflV1Jgjj5HaWvUs0EzF/ngV/phHPeleiBrYAploV2yLNkJIIRwvjsCG0Bwnfu97qM0uad8iyMiHKG7kndCnL4mFJovSOWqQT1YFzqWySkoq6rG7LLe+0wkfkNlXnwbRgFGFVGRKpEA0b16kiFfkEBykBQ7QmJfnn0+8hybx8rUZT0bZNnhIAqRCS31m9kxCZr0DUqKCuqBIQuYZEl/YLZPtKzQ8YKmwQRHshdqc3AlcFc31CjSXaNMq2L7dLOjn/oM3D6fiTMQuwmAQjR5oiaRs9osV25Bm87My5XWhOWmB2gUpj4NrvHuGt7/h+Dy/F4mNEo/ihwb20RGxlmaxvTjaevsS8wYP+5AJZ5TRk2iiGfOQmJoXAJmtUmRxgWVnyHcyI5Vv2NUD8k4C7cgG3jAczyvrDgAnpYAnIHJRL5x0eCrLIDuRDXKTp1Q+EC6SX46Oz6Wtr2YV8k8ARmfP5bLPgc09UWQ5P4Ln28jD8lNaGFDxW9LOt+LzGXqtS+A/iU3sQM/GgLC30e9F6KNhT8lWhCDTiCmUFbI23ng+IzzTGxBcZLoGKHB/AuNPijmIybIDJBNIuybeOB+Mmm/0+SP42B6QgpwIXovYyJ7ljy856trSGmpodjOoptdmWDP07kvaII9o+WyeuvnslD49E1shZGal0U8HzRqaBoQuKR2nIUCeSE7HemviULeyZ/be7ga1OZo/sc9zAtdCBIbQupGZjdUN43yCjoQFQaA86L7FyEIP+XrDtN3n3TrtRHWeAWOABIDz8lFDDmAELFSiDGGMywpxx6i/yMAGXOA77RUjDHPFDuLqtt0Z1scoKeJ2vuAainYPx/98JfoNBiIMCnkVm8QIBalKKDxeCwQ+F4YjxI3I88qfMXJ7WpgzE6DehJYbg8N8edZjggnXM2BdWlaNoV+PfWI8iWTAFUEeUeJ6/o/cGWHDziLX7Z8IM/8PrSTXx8+o7xBE3LTNqqk25GcFirUA2Zga2n2GTI/BSH6FXMAmv+PcRf46zLo2gAv3w0npDLrKp1U5Nb3+Sl9c4uTRwdXi8AmZFSpUWzDIDvzFJD0FWWBoNqLyhuW/qpW/y8pJnE19c3yfJGb/2z84nqLwc+SjtAe/cTG9EAo2YoVFprkX1wR60lZPWsW26qdINOBMl8ODqBWn7eKOk1ZxLkiiSGHYat9fOIBAOkWHvKhLX28POu+3wd4UNndKb8AQndy+u5DK6AO57Fs1USik8HKUXmHBvLstVXlLpkvYEDMkznO0XgMH1kVJoxASbXc20vU/yfYSqyZLvbvQDwW5zL1a+wQd9Yb6FiCUmfInLjVZuEbRDpxypP73R+kTiIWpGOLKbvMvlgIg688+nm0/vjytI6+MJXqOXBbB5JP+6Ck79hoA==
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5.exe /rawdata=ci5FZ7cuFbJHivcNjFF2IQMZ8Y6LHRazGkXkzsS5w2fVwDUIkGFie6bduZTE+A2OeibvuKkRUitJg/feklgxcC9+vDKrnrSsds4l4KiQ5WVxqZppoqBXLjrW+x9JrJhPWd6didnghJ0ar5ySo9n4kDaXYae3eTQBbusBAq2zBJtiu0gF34+4E9wZpJzHvUfIfiQ1LxOzHUHzl1vXZHD+8lNNZtB1CGttRVudOEcwJJ6ksyjpgFGB8Xj0BPOAlEtLoOwzKUHC+rp6kB0qZpxSpsakwiaJLReYa/f8UYLLh7qyyTEuCNeoQmEVmUnY4RnKo4hrS7/36MRpfOkKYQjPw4SU3YIhuySIje86wYkYsrbE3Z6xdaAdmte3FEWR8q/sFj2Itxv785TSOwZJCLFZcTup/wg3PK43FUfsfV0zfvPt36IsXIVKtgUH8LYRtWGZIU69NlywCmhKkv9E8Bas1GhH4Sl5lm/JMlYrYPBJbou+u1uV+PGHgIHwR1WI0Xb9epQSOF2Ei3E83ZrqCVcLX0h/pUQbpK13+C5Q4Wl18eItGqRnYh7ookDxKhxoljmWf7i2Ue/pBMrzbv7IkFXks3vQPwdzI3z+katICNP1Kw1ZQz4d7ma5as9Cqh5FUjzklFdVJw4ABfMMTXISKFIhCuAglqjrkxWLwvOKf8SHOPcs7q164gFPlGEq5t86YZeFovgO0z9ZtLsIWAUIXZEVFmin97iyI1hXnXFIGWejk6vGhZZz9/Fqoh1sp4uJ1l/mFp9XSYKNBApwzYq61QQMypRkxLqnEUbFJKh12kxRV2jeI5+8Kh2vcOhJaFDdvdcSt9E0Xyas9kM+mAJrPgxoDZIz62o5DmM6jaCSDNyDAoaLWfdxPSqC9V0IFXypVO3FWfe1EI+BHN3dwtfw/Ky4NTju7gcca30Q/hoxojZr9svVCVqvilpRBN61YGxfGwzMti4kZ6i2LeDmWDXdUWcoMjNmGeLB8n2cK3dWCi+26wmiMckd5sdOdpo1lLjWEvJI
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5_user.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5.exe /rawdata=ci5FZ7cuFbJHivcNjFF2IQMZ8Y6LHRazGkXkzsS5w2fVwDUIkGFie6bduZTE+A2OeibvuKkRUitJg/feklgxcC9+vDKrnrSsds4l4KiQ5WVxqZppoqBXLjrW+x9JrJhPWd6didnghJ0ar5ySo9n4kDaXYae3eTQBbusBAq2zBJtiu0gF34+4E9wZpJzHvUfIfiQ1LxOzHUHzl1vXZHD+8lNNZtB1CGttRVudOEcwJJ6ksyjpgFGB8Xj0BPOAlEtLoOwzKUHC+rp6kB0qZpxSpsakwiaJLReYa/f8UYLLh7qyyTEuCNeoQmEVmUnY4RnKo4hrS7/36MRpfOkKYQjPw4SU3YIhuySIje86wYkYsrbE3Z6xdaAdmte3FEWR8q/sFj2Itxv785TSOwZJCLFZcTup/wg3PK43FUfsfV0zfvPt36IsXIVKtgUH8LYRtWGZIU69NlywCmhKkv9E8Bas1GhH4Sl5lm/JMlYrYPBJbou+u1uV+PGHgIHwR1WI0Xb9epQSOF2Ei3E83ZrqCVcLX0h/pUQbpK13+C5Q4Wl18eItGqRnYh7ookDxKhxoljmWf7i2Ue/pBMrzbv7IkFXks3vQPwdzI3z+katICNP1Kw1ZQz4d7ma5as9Cqh5FUjzklFdVJw4ABfMMTXISKFIhCuAglqjrkxWLwvOKf8SHOPcs7q164gFPlGEq5t86YZeFovgO0z9ZtLsIWAUIXZEVFmin97iyI1hXnXFIGWejk6vGhZZz9/Fqoh1sp4uJ1l/mFp9XSYKNBApwzYq61QQMypRkxLqnEUbFJKh12kxRV2jeI5+8Kh2vcOhJaFDdvdcSt9E0Xyas9kM+mAJrPgxoDYarwpGACy+zY093Wh3zNrP/i24+zEhf84yulDx1caFuJt06SlfR5Jov0ae3RNwZsr349Y75OIbFAAn2g5vHhK9mnSD5FKASwtpnPjSW4QAmr2HRRY4Yot8zr7FV2EpFWofpcaGpJQHm5XtbkhYIOnkWMPAy2FYVN/p4TgiqOmdt
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job - C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe -install
C:\Windows\tasks\d3e5ca24-558f-4581-a8e2-2e9c5b3052aa-11.job - C:\Program Files (x86)\iWebar\d3e5ca24-558f-4581-a8e2-2e9c5b3052aa-11.exe /rawdata=n5etkSywE+5e7DUULQZ5FompTTc9+sWVCEM0Y/XYXSoGcWOOOK5ozK/t3nyTNzFV4DwLoc3zJioHc/Y43hJF88ZWCNU6KMPOqHqdZjlb3+u4ThsPkKoeo7hGX++B8D0T6r7czePeHUwscCSZxwhBUah6k0urnECBqKmdcA4BwKW3vM8K+BgGsT3da3xZiucaWZKhlgJLDIax+IC+smqAvbZKaJLk7hevja+wiyLL5fmSfYZCecGDtG0Wzjfiaq+oRT0N0xUbh4OqRLxdxZo5zHSYa/m4EYMjfe7Ejtm+IYGfoZOjrtbKrYqLPK/HWfjvFgMc6iYTd/y54JniD4Z53o3UGU3fkebDXNw//Frzro07I0/6kmQpaG+AjR+p0aY5nF8wAL8FBf3tAA+eZJP8qnV1kGqve1TppeaGVfYsRHMzu2Q12zY2DgFx9foZpFJLSNZK8tCs0uGb4TIK1mWt6zUpS+fFgJYV0ZDY9zbUxrEPSakNBDeUS/bREseWZylmxl2o557FiKTOA9kVQ7LTjG1N0y+ab6SGwY6m/WHqtSFLrEBDUGZ+p8RyDtQcfzCwzxjJYqMfQrfhNN8a7A+Qfug13Bx5IFHBz52xlUv5ozNMQ5FaTm80H0Dmjcv+24q96t8lUWd0Bi0vw5Fy3g9FugDtwbSvHDj6056IvxM4P9OxSVwJnFXs2apdzeL6SIum4EtjketUiWkGZfqPKF53F8/s+0p+ykluNE0zv5ZGyGEAJEXMGtWdDe99RJuFklpmhIt3lKJu2EUx/wl/XKxFhsYdcWQ7rgo4HwabEx6mIkWeUETrRidl9Wz7CkBdiBcSSwipmol5XK3d5sWvc5IUTGFx7sUkUzCuwjVsdMDlcTEsCHHZS2ctEk9RjAuvhv0O4dFFoL4kc/XHbVdRFgFzm+ZOp6FXKMocA/s+OzKSynjYqcVXdG9DHgKhP2EQdaBH7wXrplD7HSp01eOJzOkTv5paymuaYQ0uFNVdkJR/zu0aR2Skl/9ltcSuzhcF8LF4mtc/X5Vx7sjWIVRH4/3RGGx1euGSdWJ7+yH2UBSam4azVUkVQpoQ3tCsdGd5eQrvO+kKLJpFUck5VP+HgGCu2Fa1Wd8tIhddMhu7Tn06aoD8QyuUUx0iVrSkLiZHJtXf9eDdGbKGvCoZPSjQxo1aBf4F6BhfjT3jOoiWscGkY2APOqaUYCq5EuMvwPi6TB9yRfqC89HwbasnTVsQGgRXA5710Spm4nJ0MeP26QUmIlGRsonNqqxv7mpTR7TKXdQYfZ5pSLJmWxAnJFRxN/yJriZy/SqfZgTpC7bFg+91A61Sd0saLw/Ou/1B49kly36XhOadMNWlVOs8ldTZyUd0O1k7pM2yOKLsdRYAwzhB2LAWWFyIT91eao4KZ2h2IElkE+O1/P9ENIYRRHv/2oeHKQrDmdf7rJPNJ5ioHiZebhWqCmb9Pi2cZ6cd3CgGIxHGGQzstdACmLM6f2fhh84FQMcb3EtWN810r0q54suV0JqNsI49VwPgq+IZKZjSFymwDMQ4h9nAI+Hfy2Y/qGLxSm1hASw/uCezv8Pt85kl6Dqkv8z61dlpAeYwRiXvRs3TYSiX/INWUqKseTwhWGJjiwHl3oUGoq55OcgzYtM2qXaZtioFfcdAU8ULsr8k6MmWpK4gfs/2SVH7FLNMD9QJClPJxsv+AmyaELetcNIDS5eiTPAb0JGVzMz8KRvuf8g7Y9rEjjr9JbwTk3O4rjV5/4Pnwnsj5Tm+TheI8/usYh/OYnd2wSHHtO8VzjohS67wY4+GkXZZoKy51WyJ7f2liN6M7ZwMq5CDm6+cJzRScJmeXzIp7lZZJNHPSruaYyb0OQkR48lQytKYIvk1cP8Ina1P0gP1VD9zPslM1S3Jf12NLPzjMB7ayCo5wzOlnvPmBoRJdTs0dSt+KzMpHePUE7oUdzbDfyq6MVyLtK+uWxK/1DxRVS0wmM2yZlZ8KrSCVIWC2S46Q44uuL4/rKeua2F7AAElLDqcA1bMY7W+doCt9gZjqXk7lvvnXiheVDiIG4lzV4M5TMOYB/q17VOGyXcE5vq5t+8yFLcFU/6plqx6p0kKg9OpsCnbzfBxV2c4HrWgECBU6uKgCDT609f5lbEQnxYlHDKkLOm90dhGL5aNo4ZGD53GHDNvUJd2bkbZGRiHOnse/XUzlRNpDeuLaXCsX+HMTnlUs3NJieYmoN8nydzk686LcT2vVAg8FAF/DFZnHBSt50pO53v+Akgz/+1TC9d8Rex5w3Y70nQzsEVevIK//+BKFJ03gFK4Dfp8NUcmoziyxBVJIerow4dpAIAsd7op06g4qjYDfCNZLqBp/ASAyrHTsGHkZ2J45y0gbw7gPgHsEc0NZeZWG3iZZ28gV55B5qofB8NMrOIBzraAm0ZUP4QoKszYHrHZQHjb6w80bGtGHGTtN0f3lrtEBaeTOi0uKCNRtFcKPTpsqM5qcHzhzuS+9/tvmMjCe0k5agbgsNDumhhahS18Ibg75RRYuUdBFK4r0GUwrlv3TQGA8NfXUf72OAx7qP+6KqNf
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\MFZWJ.job - C:\Users\na�i\AppData\Roaming\MFZWJ.exe /infocmdline=SXx4TGPymErWQBubtYA3iJBLaCY6pirT7KRBQ0QdwQg3yqvWWfelTUs7l1ip9ffaR2Qm1rJE8rcuacu2KueFBm2hjl1yeSTMlHj4GLYc3rCgUvGvr4xs6CeM72oVQSPv8v+xWrFZugWz1EcE+zlCQsSI9Y2og54HFxeMVn+znQFORNZaR/yNWtP57zx9m/zMFYYC2M39nKbEIckt2qt44ytNmt0WwdXiHdG1ZbEMrg3jsUf3nU+4ObWTwOQCxGG5sPW5PQ8iHQXe7kJSrCA0+tFODoC0v1tCm6jVZok8FRMPD8b/5ch+0pyFEmsV4J2Du5APXswjkdHP9E3vzRvpgSUgx9pTrmUt+9U2W0hMJWl0369niOgyOo7eaKNRUM6GgN1zOdz2uwUiFhMGzXUu6ctJryUtIDAu5kIT8vwUTQVkYo98LgYBmsAv6nkYLhKYVwFrQ/XQ1qT7ZDi+1Pm4RVMwT62ijaENMcwqyGpvfijV64cTq2hseeuBNvTrnb+M
C:\Windows\tasks\THAGUQRU.job - C:\Users\na�i\AppData\Roaming\THAGUQRU.exe /infocmdline=Qfw3Yosw65XpD88kKlWtn6dxVD86E3HF45ebJS/5Xa3n+bCT2NuMGqi5kc4IH9qDsUzZUUcrdLAeSz2coJkvJmOiyVbg00nln8mk3q508h8ICgmEtncXtxdbeGygffR18J1ush5KrFQ3ME/RHr8uVilwgMxIa+QyM2MsCF873kAvjx/zHZqwnCq0ZwoahYZ+J+c+4HXHcyw0NwITqb1Rx5NMFT44d03m7wYXCkH6aA73XeH+ppuFT1/8pRN0bAfrbFA+fcPH3v0Fjonq4rE6q1oHiY0IioC1jk2/P/gho3z/NU2I4eYID8ejgEK5P4CR5Z0OUG2Swwk/+bGTFJ7AFyL7lkAbFyHGy+bgIMGwDrzc7cSKQAjFjwa+ot2y3P0ibckKKtYB7FQc6Sgkv4mbV581HnzN2vIulYuuORfGC/mOMlv+8Hcwg9itNI0zSR8jEG/5NvSHuuhP2qkph644zCm8FbTvM6UBNTZranlQY9EhyZ2bQeJ1sKZzKHKI9WM+sZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-04-24 12480616]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-10-01 22:16:17 ----D---- C:\rsit
2014-10-01 22:16:17 ----D---- C:\Program Files\trend micro
2014-10-01 21:53:16 ----D---- C:\Program Files (x86)\globalUpdate
2014-10-01 21:53:03 ----D---- C:\Program Files (x86)\iWebar
2014-10-01 21:20:11 ----AD---- C:\ProgramData\TEMP
2014-10-01 21:17:43 ----D---- C:\ProgramData\IePluginServices
2014-10-01 21:17:38 ----D---- C:\ProgramData\WindowsMangerProtect
2014-10-01 20:56:11 ----D---- C:\Users\naši\AppData\Roaming\Ubisoft
2014-10-01 20:48:04 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-01 20:06:37 ----D---- C:\Users\naši\AppData\Roaming\GHISLER
2014-10-01 20:06:37 ----D---- C:\totalcmd
2014-10-01 20:01:42 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-10-01 20:01:42 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-10-01 20:01:42 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-10-01 20:01:42 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-10-01 20:01:41 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-10-01 20:01:41 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-10-01 19:48:15 ----D---- C:\posta
2014-10-01 19:38:13 ----D---- C:\Users\naši\AppData\Roaming\Windows Live Writer
2014-10-01 19:36:31 ----D---- C:\Users\naši\AppData\Roaming\TuneUp Software
2014-10-01 19:33:31 ----D---- C:\Windows\cs
2014-10-01 19:33:01 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-10-01 19:32:21 ----D---- C:\Program Files\Windows Live
2014-10-01 19:32:17 ----D---- C:\Windows\PCHEALTH
2014-10-01 19:31:58 ----D---- C:\Program Files (x86)\Windows Live
2014-10-01 19:28:17 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-10-01 19:25:00 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-10-01 19:15:43 ----D---- C:\Users\naši\AppData\Roaming\Macromedia
2014-10-01 19:11:09 ----D---- C:\Users\naši\AppData\Roaming\Opera Software
2014-10-01 19:10:20 ----D---- C:\Users\naši\AppData\Roaming\Adobe
2014-10-01 19:10:11 ----D---- C:\Users\naši\AppData\Roaming\Identities
2014-10-01 19:10:06 ----SD---- C:\Users\naši\AppData\Roaming\Microsoft
2014-10-01 19:10:06 ----D---- C:\Users\naši\AppData\Roaming\Media Center Programs
2014-09-30 15:13:29 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-09-30 15:13:27 ----D---- C:\Program Files\Microsoft Security Client
2014-09-30 13:48:30 ----D---- C:\Games
2014-09-23 13:41:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-23 13:41:39 ----A---- C:\Windows\system32\ieui.dll
2014-09-23 13:41:38 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-23 13:41:38 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-23 13:41:37 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-23 13:41:37 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-23 13:41:37 ----A---- C:\Windows\system32\iernonce.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\vbscript.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\msrating.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-23 13:41:35 ----A---- C:\Windows\system32\iesetup.dll
2014-09-23 13:41:35 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-23 13:41:35 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-23 13:41:34 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-23 13:41:34 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-23 13:41:34 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\mshtml.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-23 13:41:34 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-23 13:41:33 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-23 13:41:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-23 13:41:32 ----A---- C:\Windows\system32\wininet.dll
2014-09-23 13:41:32 ----A---- C:\Windows\system32\iertutil.dll
2014-09-23 13:41:31 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-23 13:41:31 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-23 13:41:31 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-23 13:41:31 ----A---- C:\Windows\system32\urlmon.dll
2014-09-23 13:41:31 ----A---- C:\Windows\system32\jscript9.dll
2014-09-23 13:41:30 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-23 13:41:29 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-23 13:41:29 ----A---- C:\Windows\system32\ieframe.dll
2014-09-23 12:50:53 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-23 12:50:53 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-23 12:50:53 ----A---- C:\Windows\system32\kerberos.dll
2014-09-23 12:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-23 12:50:52 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-02 19:49:55 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-09-02 19:49:55 ----A---- C:\Windows\system32\win32k.sys
2014-09-02 19:49:55 ----A---- C:\Windows\system32\gdi32.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wups2.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wucltux.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wuaueng.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wuauclt.exe
2014-09-02 19:43:54 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-09-02 19:43:54 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-09-02 19:43:54 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-09-02 19:43:54 ----A---- C:\Windows\system32\wups.dll
2014-09-02 19:43:54 ----A---- C:\Windows\system32\wudriver.dll
2014-09-02 19:43:54 ----A---- C:\Windows\system32\wuapi.dll
2014-09-02 19:43:48 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-09-02 19:43:48 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-09-02 19:43:48 ----A---- C:\Windows\system32\wuwebv.dll
2014-09-02 19:43:48 ----A---- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2014-10-01 22:16:17 ----RD---- C:\Program Files
2014-10-01 22:15:42 ----D---- C:\Windows\Temp
2014-10-01 22:09:12 ----D---- C:\Windows\System32
2014-10-01 22:09:12 ----D---- C:\Windows\inf
2014-10-01 22:09:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-01 21:56:36 ----D---- C:\Windows\system32\config
2014-10-01 21:53:40 ----SHD---- C:\Windows\Installer
2014-10-01 21:53:39 ----RD---- C:\Program Files (x86)
2014-10-01 21:53:17 ----D---- C:\Windows\Tasks
2014-10-01 21:53:17 ----D---- C:\Windows\system32\Tasks
2014-10-01 21:41:51 ----D---- C:\Windows\SysWOW64
2014-10-01 21:40:45 ----HD---- C:\ProgramData
2014-10-01 21:37:14 ----HD---- C:\Windows\system32\GroupPolicy
2014-10-01 21:37:14 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-10-01 21:37:13 ----D---- C:\Program Files\Common Files
2014-10-01 20:55:00 ----D---- C:\Windows\Microsoft.NET
2014-10-01 20:54:12 ----RSD---- C:\Windows\assembly
2014-10-01 20:52:09 ----SHD---- C:\System Volume Information
2014-10-01 20:02:02 ----D---- C:\Windows\winsxs
2014-10-01 19:33:31 ----D---- C:\Windows
2014-10-01 19:32:23 ----SD---- C:\ProgramData\Microsoft
2014-10-01 19:32:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-10-01 19:28:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-01 19:28:50 ----D---- C:\Windows\system32\cs-CZ
2014-10-01 19:25:02 ----D---- C:\Windows\SYSWOW64\en-US
2014-10-01 19:25:02 ----D---- C:\Windows\system32\en-US
2014-10-01 19:21:03 ----D---- C:\Windows\Prefetch
2014-10-01 19:10:09 ----SHD---- C:\$Recycle.Bin
2014-10-01 19:10:06 ----RD---- C:\Users
2014-09-30 18:44:59 ----D---- C:\Windows\system32\catroot
2014-09-30 18:07:44 ----D---- C:\Windows\rescache
2014-09-30 15:13:31 ----D---- C:\Windows\system32\drivers
2014-09-30 13:48:50 ----D---- C:\Program Files (x86)\Opera
2014-09-23 13:55:27 ----D---- C:\Program Files\Internet Explorer
2014-09-23 13:55:26 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-23 13:43:19 ----D---- C:\Windows\SYSWOW64\directx
2014-09-23 13:42:05 ----D---- C:\Windows\system32\catroot2
2014-09-23 13:10:59 ----D---- C:\Windows\system32\MRT
2014-09-23 13:10:57 ----A---- C:\Windows\system32\MRT.exe
2014-09-23 12:57:00 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-22 08:42:39 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-02 20:00:40 ----D---- C:\Windows\system32\DriverStore
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-09-19 123704]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 MxEFUF;Matrox Extio Upper Function Filter; C:\Windows\system32\DRIVERS\MxEFUF64.sys [2011-10-20 157696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-04-29 359936]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-04-08 94720]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-04-24 4028520]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2014-04-09 2472136]
R3 pimou;Pluralinput Mouse 0.8.6; C:\Windows\system32\DRIVERS\pimou.sys [2014-01-13 23608]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-04-14 931544]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
R3 ZCLDRV;ZCL Service; C:\Windows\system32\DRIVERS\ZclDrv64.sys [2013-06-27 71680]
S0 amdkmafd;AMD Audio Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmafd.sys [2013-03-14 21600]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 11922944]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys []
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys []
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys []
S3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys []
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys []
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-04-29 238080]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-09-24 705416]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-12-08 2028864]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2014-10-01 528896]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-01 68608]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-23 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-01 68608]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-04-18 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by naši at 2014-10-01 22:16:17
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 190 GB (80%) free of 238 GB
Total RAM: 4094 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:16:20, on 1.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera_crashreporter.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Users\naši\Downloads\HijackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe
C:\Program Files\trend micro\naši.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: d0ac00b04d3e0131269239ed9417a9330048559 - {11111111-1111-1111-1111-110411851159} - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll (file missing)
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - (no file)
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7474 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\System32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\ProgramData\IePluginServices\PluginService.exe -service
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1856
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1816
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --ran-launcher /crash-reporter-parent-id=3464
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=gpu-process --channel="3464.0.969013644\1129042304" --crash-reporter-pid=3356 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17 --gpu-vendor-id=0x1002 --gpu-device-id=0x9442 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.970.100.1100 --crash-reporter-pid=3356 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.4.192807329\1367797085" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.5.1377823006\9346098" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.14.1151204481\1547823284" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.15.1011182084\731436586" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" --disable-direct-npapi-requests --lang=cs --channel="3464.16.659244092\1356394583" --crash-reporter-pid=3356 /prefetch:-390060480
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.17.152075727\1965750818" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.18.565504178\1122318254" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.20.1735778499\1162660694" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.21.1623778774\1045510778" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.22.250260514\310277218" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.23.1643393943\1510114338" /prefetch:673131151
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-781b60ee-ed6c-44ae-b6dd-8a6f3f1b6fb4 -SystemEventPortName:HostProcess-db7276b4-46dd-47f3-ba13-779695818a91 -IoCancelEventPortName:HostProcess-a4594277-f593-4d70-a1d2-8ad29362f4f6 -NonStateChangingEventPortName:HostProcess-bdea8ea8-53de-4950-af40-e64fd5b8e8b2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:87e86204-a6af-452e-99e4-f56730d8c5dd -DeviceGroupId:WpdFsGroup
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\naši\Downloads\HijackThis.exe"
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\naši\Downloads\hijackthis.log
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.25.199819135\294053515" /prefetch:673131151
"C:\Program Files (x86)\Opera\24.0.1558.64\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=cs --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3356 --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3464.26.1259814472\992360294" /prefetch:673131151
"C:\Users\naši\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-1.job - C:\Program Files (x86)\Apps Hat\Apps Hat-codedownloader.exe /rawdata=KfmK0yoeXsD1mzF4+RxuVgKScxomlCFjb1o90mYOW2lQX3lXLzwg3gicZIBheCAVLLdqVALAaG4q66SP5mBXKvX4vQaG4fN9L8NGRrRMVC3MqaIcGlpkdBKDM/axrgoY6j5ttlr2XsgncWiydLyvw3erzedesjg337rCZl/Rt1O5THPP/yoCXL4qRvbJFwv2zQz/jVc94efPkxIifpNkdXyvNTle4tUTLbE4TFaGDMOyeqE6hpAfVnoW9yjOIwOa6Xb7YwG2mDeyeLEcVi3zKB+4pPU6aA77vSsR2Q/z13lb7OywIl2Gwuce11kfPhw7TEOYQh/yY6CqIizOEx4eHRtktZQAI8DXQBBjsKapwZ+ab1q5DnEwSbALF5TTH0Rl5sBq/L/bMdmsJX71EeDHSCt76/1YDm3wwWQKE+fFZoBRXlWYrytnyiNFBql+5/QuMF4XoYhqJmthmGSuY0AtEfpwrFtCSFpbroqEuyG1I5H2XFBD2LfrujoUjkmGOxxLgjiv5aI8zLiaXqwLIxlURo0ysAC7Ad5jOgxdTxZ9pi/MUHjGufjZ5/aIWlj77lB9kAxduJT/1fFNPrbo5hpBwo66n7hzMToXNf+/Yn2MYr6Z6cd9I/w7k1Wbw37rK3iEynIPh67C4nzvrPJuIAldErcXw6qXfxmf5PX7H3D8pbOn3bTydhwEW1VCegqpFXplnNcxEUZKlnCjoxhpXjSJlY1SzvBTM8ZJwYFrXDTX+K6GLE9c+Ux+HMAIpjVZ1jHvreBDLWsFjalS4x1ZWuSDuELbU7sKom892v5wGHA2ttn/T0XtYVUGwkp9Uv7J7yzMvuWcIRV5xQ/Nh+x4rubAFRCZVk+gPEUixFAW5gtEuYsyZ7VmO3Pi2y2IyeIJszWQtRjVQ4PeuC7V6mniBswPznT2l2dtJ8yj1P4aODUCMWmrdQA8dOYRqSLozhyHVcUnEc2JNjj/j/VLlGy+ssJ7PrRzRdY6yIGtOgW44UH++qEEtVqC5osHpIEzNZcQjJU8GPhYzcHoe341gf8CapgBcjTVAvQM2nSrFoghuC9qCdjgNtCyMj0/VdhlngCswyEgqxsGkGoSarCA11iAEqO+Qt1OS/z9WYR0uzz4gSDXNZRFADSr7d51KVn35VUh2U5XbBxqxiS5KJEqGlKRFbE4F6scWzwEy+wHU4tnoelfk1Q142KUhgBWSNy3pFQxBm0jSktvkTas9Wrsl8/HVOnCkE/E5ruxd9B+xXAIJ17dly7iIXZIOIm81eA4ozgi3+M5qokIgvcbSPAEizdjGh9oMAgiGY5sdxjcCn+X/SepUaJFvC2On6TaxCcBr0us/d0uYokzwOh69a+DSpP9ZpQkS1C1Wdq0qc5crY+ZS7ynsKnJArpblqqYUI53Z0RWUzYkjpNOtMlqysK7z0p/EUukVK97rFMwCAsc2L8v8TAYMMwElbqetba4ogFPcB7SJdRV8K04IMClu3ytQ32Nci4V+QX/Ns4OFW1neXSupzrptb+0GiaGbsktZQUIvXWOyy7Y
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-2.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-2.exe /rawdata=R4zV3jAYVl0nsm/Dwmdk33nqOuuKKSAsVQFe2718iK1dqY5NbxXjQExYgQ+pqcQe/j1yiQ5WlABRRyxTOAWqyNk5zFB1zIcCOKuJ3YB2bW6exBGPTLQelYMzP0b8DAph0SaNAxGjg2RaNXw6CMi5TBxpC57VZQrCKpJykuHyliKQ5W08160SptRx/TihwP6YPriWvpFSwEbX2S99mKIZwg5lnHqtCKJZOyHbIlCZRw+cDih44R8dUHB7Gb0mHJthTH0i34kSfYEzTsKTb3Glsj0yzmyYwzsBYxCQucLOFAdnVUNzDjf/7TIwXXFCWR6LhzDkyYiH3ENG4WH7Z+YlMV7o4MLMfmbvy3piCP/eawThT09sFk+CN70py0R4hNmzKjCQq9wPEFSP+n7g52mxcC79Rc5zxTQKQ5hhMS8ORuvWLtRIHrBe6hm07vXX1NWFdjUAVkzcTDGis/yftx1bZWjD5I2PQlg5m+/cjXkUcD3lw8nfrkHOmAbH5e6p+AJVv1QgTQav14rH/OTvwdYcHcZl/wScBG49UkMJ6my0p7RyoKkZK7sUn7JNl2HfPqISAJQXQuA45MLcspCsKWVBLx18ZP9/TEOigWHrdtCR7iamIX0Ko7MiSFBLRXCOI3X0cuTG93fETxss93Q65hiNvuqHKUQLe6+8Ygmcuqj5jXeqn7SPN5BmbbZdNT8hoXPZ5dCavliRzezHSBYK33fOueYpsGiPyDcA4eI5C8DPwDCeOGAvLf/lrLSQjm9yuytHz14qBVdb7TS5JkgihYVGysCc785eSlB5x5eweBHU7T1u5uTYnmQRycn4DrRjTkJySdUNyC0CXfmOYqHa1XWfPg==
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-4.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-4.exe /rawdata=F7UeaJ0Pqbd0mY3J0mIa7XBRySd+qDi7Uor4ER9YlPahUeBPCYg6NB0/hQ/HwgmBbKAmldqORoI8Zm7zxAVX34hykZKHASxRH8fqNzDJWVHp7lD7DNLOY3yLaIzZ0loJX6qMXB5E1GVflvDWHeEsrtLYW2eXIz4Bqw2ra1bvDj2Td87s/8scieC49ra+aoD6jObg+Xv0X+RdyqHeB5xocyuHtILlClu0YjcH4N6vOzrs6qR2sksqbIvfnV6/RljDK1NiSoISWBcIHWOiTvBTwOdYFeA46zm654ZCloMV4kmOMDZ0b+IIomGqCk0Rq7e+v1J2tl7Huy87838TTvkF5ZuNWc1PXplrCF8nmhvwDooBXSzJu4RbF5zA3APm+2bFAkHRi1TNikKJ1b/ZpMCQAUeIFBTFV3bRlCom2QW9tsRwzFddamqNbCut9WBmSWUh4yXKnS+4Po8nQJfwAGW1PG4MAR/krd8924rfV+rso80eO8zJivdabdiZip9VKtY5gbKdFVBZ4negrLzEGmExrQl6amF/iYb7GH9K8AOz9UtP1kAhBL3+FvHe32Z03Z8NA+aMVyLaig2ldicIEteZnbonabN2hQAAFUqkPBJzV1cLBZ0gr5gxklPjcrR5HEXBsue1GftKXxn6NAiR0UXF6b5A4ZBGZjuCf3Zf52z5wLpsbGmbcDNy1Kh/etwzxuNc3yqSH95VsyDyquYiSO2CmL8MzkIv3xJGjpH1FFRnwNyuVN3DtRQ2YQ4hysei0JxnqaBCFzMb/vU4K0HWBcp2LREN9U2S7on74Wi2F/ziipX5Ymu5ilHeF+jfuuoCk9xUAkU0Lyxifet0dniDK5JruCJURatsot2N91hBmSr+TGJcSGKaWgkFh9BqbdrXDssEpG/1nUYwZKnEDk6r9PG1D4/4yCzNaFxcV4DVXfD6qFcnjWMogL7X8bbfwyCbJpevd77XVaUgofuJyTdT0pLR/iSYzeMhpW7TiYcDtXdflV1Jgjj5HaWvUs0EzF/ngV/phHPeleiBrYAploV2yLNkJIIRwvjsCG0Bwnfu97qM0uad8iyMiHKG7kndCnL4mFJovSOWqQT1YFzqWySkoq6rG7LLe+0wkfkNlXnwbRgFGFVGRKpEA0b16kiFfkEBykBQ7QmJfnn0+8hybx8rUZT0bZNnhIAqRCS31m9kxCZr0DUqKCuqBIQuYZEl/YLZPtKzQ8YKmwQRHshdqc3AlcFc31CjSXaNMq2L7dLOjn/oM3D6fiTMQuwmAQjR5oiaRs9osV25Bm87My5XWhOWmB2gUpj4NrvHuGt7/h+Dy/F4mNEo/ihwb20RGxlmaxvTjaevsS8wYP+5AJZ5TRk2iiGfOQmJoXAJmtUmRxgWVnyHcyI5Vv2NUD8k4C7cgG3jAczyvrDgAnpYAnIHJRL5x0eCrLIDuRDXKTp1Q+EC6SX46Oz6Wtr2YV8k8ARmfP5bLPgc09UWQ5P4Ln28jD8lNaGFDxW9LOt+LzGXqtS+A/iU3sQM/GgLC30e9F6KNhT8lWhCDTiCmUFbI23ng+IzzTGxBcZLoGKHB/AuNPijmIybIDJBNIuybeOB+Mmm/0+SP42B6QgpwIXovYyJ7ljy856trSGmpodjOoptdmWDP07kvaII9o+WyeuvnslD49E1shZGal0U8HzRqaBoQuKR2nIUCeSE7HemviULeyZ/be7ga1OZo/sc9zAtdCBIbQupGZjdUN43yCjoQFQaA86L7FyEIP+XrDtN3n3TrtRHWeAWOABIDz8lFDDmAELFSiDGGMywpxx6i/yMAGXOA77RUjDHPFDuLqtt0Z1scoKeJ2vuAainYPx/98JfoNBiIMCnkVm8QIBalKKDxeCwQ+F4YjxI3I88qfMXJ7WpgzE6DehJYbg8N8edZjggnXM2BdWlaNoV+PfWI8iWTAFUEeUeJ6/o/cGWHDziLX7Z8IM/8PrSTXx8+o7xBE3LTNqqk25GcFirUA2Zga2n2GTI/BSH6FXMAmv+PcRf46zLo2gAv3w0npDLrKp1U5Nb3+Sl9c4uTRwdXi8AmZFSpUWzDIDvzFJD0FWWBoNqLyhuW/qpW/y8pJnE19c3yfJGb/2z84nqLwc+SjtAe/cTG9EAo2YoVFprkX1wR60lZPWsW26qdINOBMl8ODqBWn7eKOk1ZxLkiiSGHYat9fOIBAOkWHvKhLX28POu+3wd4UNndKb8AQndy+u5DK6AO57Fs1USik8HKUXmHBvLstVXlLpkvYEDMkznO0XgMH1kVJoxASbXc20vU/yfYSqyZLvbvQDwW5zL1a+wQd9Yb6FiCUmfInLjVZuEbRDpxypP73R+kTiIWpGOLKbvMvlgIg688+nm0/vjytI6+MJXqOXBbB5JP+6Ck79hoA==
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5.exe /rawdata=ci5FZ7cuFbJHivcNjFF2IQMZ8Y6LHRazGkXkzsS5w2fVwDUIkGFie6bduZTE+A2OeibvuKkRUitJg/feklgxcC9+vDKrnrSsds4l4KiQ5WVxqZppoqBXLjrW+x9JrJhPWd6didnghJ0ar5ySo9n4kDaXYae3eTQBbusBAq2zBJtiu0gF34+4E9wZpJzHvUfIfiQ1LxOzHUHzl1vXZHD+8lNNZtB1CGttRVudOEcwJJ6ksyjpgFGB8Xj0BPOAlEtLoOwzKUHC+rp6kB0qZpxSpsakwiaJLReYa/f8UYLLh7qyyTEuCNeoQmEVmUnY4RnKo4hrS7/36MRpfOkKYQjPw4SU3YIhuySIje86wYkYsrbE3Z6xdaAdmte3FEWR8q/sFj2Itxv785TSOwZJCLFZcTup/wg3PK43FUfsfV0zfvPt36IsXIVKtgUH8LYRtWGZIU69NlywCmhKkv9E8Bas1GhH4Sl5lm/JMlYrYPBJbou+u1uV+PGHgIHwR1WI0Xb9epQSOF2Ei3E83ZrqCVcLX0h/pUQbpK13+C5Q4Wl18eItGqRnYh7ookDxKhxoljmWf7i2Ue/pBMrzbv7IkFXks3vQPwdzI3z+katICNP1Kw1ZQz4d7ma5as9Cqh5FUjzklFdVJw4ABfMMTXISKFIhCuAglqjrkxWLwvOKf8SHOPcs7q164gFPlGEq5t86YZeFovgO0z9ZtLsIWAUIXZEVFmin97iyI1hXnXFIGWejk6vGhZZz9/Fqoh1sp4uJ1l/mFp9XSYKNBApwzYq61QQMypRkxLqnEUbFJKh12kxRV2jeI5+8Kh2vcOhJaFDdvdcSt9E0Xyas9kM+mAJrPgxoDZIz62o5DmM6jaCSDNyDAoaLWfdxPSqC9V0IFXypVO3FWfe1EI+BHN3dwtfw/Ky4NTju7gcca30Q/hoxojZr9svVCVqvilpRBN61YGxfGwzMti4kZ6i2LeDmWDXdUWcoMjNmGeLB8n2cK3dWCi+26wmiMckd5sdOdpo1lLjWEvJI
C:\Windows\tasks\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5_user.job - C:\Program Files (x86)\Apps Hat\a4aaf92a-33e2-41f5-82e9-aab6fb67c8a5-5.exe /rawdata=ci5FZ7cuFbJHivcNjFF2IQMZ8Y6LHRazGkXkzsS5w2fVwDUIkGFie6bduZTE+A2OeibvuKkRUitJg/feklgxcC9+vDKrnrSsds4l4KiQ5WVxqZppoqBXLjrW+x9JrJhPWd6didnghJ0ar5ySo9n4kDaXYae3eTQBbusBAq2zBJtiu0gF34+4E9wZpJzHvUfIfiQ1LxOzHUHzl1vXZHD+8lNNZtB1CGttRVudOEcwJJ6ksyjpgFGB8Xj0BPOAlEtLoOwzKUHC+rp6kB0qZpxSpsakwiaJLReYa/f8UYLLh7qyyTEuCNeoQmEVmUnY4RnKo4hrS7/36MRpfOkKYQjPw4SU3YIhuySIje86wYkYsrbE3Z6xdaAdmte3FEWR8q/sFj2Itxv785TSOwZJCLFZcTup/wg3PK43FUfsfV0zfvPt36IsXIVKtgUH8LYRtWGZIU69NlywCmhKkv9E8Bas1GhH4Sl5lm/JMlYrYPBJbou+u1uV+PGHgIHwR1WI0Xb9epQSOF2Ei3E83ZrqCVcLX0h/pUQbpK13+C5Q4Wl18eItGqRnYh7ookDxKhxoljmWf7i2Ue/pBMrzbv7IkFXks3vQPwdzI3z+katICNP1Kw1ZQz4d7ma5as9Cqh5FUjzklFdVJw4ABfMMTXISKFIhCuAglqjrkxWLwvOKf8SHOPcs7q164gFPlGEq5t86YZeFovgO0z9ZtLsIWAUIXZEVFmin97iyI1hXnXFIGWejk6vGhZZz9/Fqoh1sp4uJ1l/mFp9XSYKNBApwzYq61QQMypRkxLqnEUbFJKh12kxRV2jeI5+8Kh2vcOhJaFDdvdcSt9E0Xyas9kM+mAJrPgxoDYarwpGACy+zY093Wh3zNrP/i24+zEhf84yulDx1caFuJt06SlfR5Jov0ae3RNwZsr349Y75OIbFAAn2g5vHhK9mnSD5FKASwtpnPjSW4QAmr2HRRY4Yot8zr7FV2EpFWofpcaGpJQHm5XtbkhYIOnkWMPAy2FYVN/p4TgiqOmdt
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Application Starter - f1375f225883e83d52e8db9690775c3c.job - C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe -install
C:\Windows\tasks\d3e5ca24-558f-4581-a8e2-2e9c5b3052aa-11.job - C:\Program Files (x86)\iWebar\d3e5ca24-558f-4581-a8e2-2e9c5b3052aa-11.exe /rawdata=n5etkSywE+5e7DUULQZ5FompTTc9+sWVCEM0Y/XYXSoGcWOOOK5ozK/t3nyTNzFV4DwLoc3zJioHc/Y43hJF88ZWCNU6KMPOqHqdZjlb3+u4ThsPkKoeo7hGX++B8D0T6r7czePeHUwscCSZxwhBUah6k0urnECBqKmdcA4BwKW3vM8K+BgGsT3da3xZiucaWZKhlgJLDIax+IC+smqAvbZKaJLk7hevja+wiyLL5fmSfYZCecGDtG0Wzjfiaq+oRT0N0xUbh4OqRLxdxZo5zHSYa/m4EYMjfe7Ejtm+IYGfoZOjrtbKrYqLPK/HWfjvFgMc6iYTd/y54JniD4Z53o3UGU3fkebDXNw//Frzro07I0/6kmQpaG+AjR+p0aY5nF8wAL8FBf3tAA+eZJP8qnV1kGqve1TppeaGVfYsRHMzu2Q12zY2DgFx9foZpFJLSNZK8tCs0uGb4TIK1mWt6zUpS+fFgJYV0ZDY9zbUxrEPSakNBDeUS/bREseWZylmxl2o557FiKTOA9kVQ7LTjG1N0y+ab6SGwY6m/WHqtSFLrEBDUGZ+p8RyDtQcfzCwzxjJYqMfQrfhNN8a7A+Qfug13Bx5IFHBz52xlUv5ozNMQ5FaTm80H0Dmjcv+24q96t8lUWd0Bi0vw5Fy3g9FugDtwbSvHDj6056IvxM4P9OxSVwJnFXs2apdzeL6SIum4EtjketUiWkGZfqPKF53F8/s+0p+ykluNE0zv5ZGyGEAJEXMGtWdDe99RJuFklpmhIt3lKJu2EUx/wl/XKxFhsYdcWQ7rgo4HwabEx6mIkWeUETrRidl9Wz7CkBdiBcSSwipmol5XK3d5sWvc5IUTGFx7sUkUzCuwjVsdMDlcTEsCHHZS2ctEk9RjAuvhv0O4dFFoL4kc/XHbVdRFgFzm+ZOp6FXKMocA/s+OzKSynjYqcVXdG9DHgKhP2EQdaBH7wXrplD7HSp01eOJzOkTv5paymuaYQ0uFNVdkJR/zu0aR2Skl/9ltcSuzhcF8LF4mtc/X5Vx7sjWIVRH4/3RGGx1euGSdWJ7+yH2UBSam4azVUkVQpoQ3tCsdGd5eQrvO+kKLJpFUck5VP+HgGCu2Fa1Wd8tIhddMhu7Tn06aoD8QyuUUx0iVrSkLiZHJtXf9eDdGbKGvCoZPSjQxo1aBf4F6BhfjT3jOoiWscGkY2APOqaUYCq5EuMvwPi6TB9yRfqC89HwbasnTVsQGgRXA5710Spm4nJ0MeP26QUmIlGRsonNqqxv7mpTR7TKXdQYfZ5pSLJmWxAnJFRxN/yJriZy/SqfZgTpC7bFg+91A61Sd0saLw/Ou/1B49kly36XhOadMNWlVOs8ldTZyUd0O1k7pM2yOKLsdRYAwzhB2LAWWFyIT91eao4KZ2h2IElkE+O1/P9ENIYRRHv/2oeHKQrDmdf7rJPNJ5ioHiZebhWqCmb9Pi2cZ6cd3CgGIxHGGQzstdACmLM6f2fhh84FQMcb3EtWN810r0q54suV0JqNsI49VwPgq+IZKZjSFymwDMQ4h9nAI+Hfy2Y/qGLxSm1hASw/uCezv8Pt85kl6Dqkv8z61dlpAeYwRiXvRs3TYSiX/INWUqKseTwhWGJjiwHl3oUGoq55OcgzYtM2qXaZtioFfcdAU8ULsr8k6MmWpK4gfs/2SVH7FLNMD9QJClPJxsv+AmyaELetcNIDS5eiTPAb0JGVzMz8KRvuf8g7Y9rEjjr9JbwTk3O4rjV5/4Pnwnsj5Tm+TheI8/usYh/OYnd2wSHHtO8VzjohS67wY4+GkXZZoKy51WyJ7f2liN6M7ZwMq5CDm6+cJzRScJmeXzIp7lZZJNHPSruaYyb0OQkR48lQytKYIvk1cP8Ina1P0gP1VD9zPslM1S3Jf12NLPzjMB7ayCo5wzOlnvPmBoRJdTs0dSt+KzMpHePUE7oUdzbDfyq6MVyLtK+uWxK/1DxRVS0wmM2yZlZ8KrSCVIWC2S46Q44uuL4/rKeua2F7AAElLDqcA1bMY7W+doCt9gZjqXk7lvvnXiheVDiIG4lzV4M5TMOYB/q17VOGyXcE5vq5t+8yFLcFU/6plqx6p0kKg9OpsCnbzfBxV2c4HrWgECBU6uKgCDT609f5lbEQnxYlHDKkLOm90dhGL5aNo4ZGD53GHDNvUJd2bkbZGRiHOnse/XUzlRNpDeuLaXCsX+HMTnlUs3NJieYmoN8nydzk686LcT2vVAg8FAF/DFZnHBSt50pO53v+Akgz/+1TC9d8Rex5w3Y70nQzsEVevIK//+BKFJ03gFK4Dfp8NUcmoziyxBVJIerow4dpAIAsd7op06g4qjYDfCNZLqBp/ASAyrHTsGHkZ2J45y0gbw7gPgHsEc0NZeZWG3iZZ28gV55B5qofB8NMrOIBzraAm0ZUP4QoKszYHrHZQHjb6w80bGtGHGTtN0f3lrtEBaeTOi0uKCNRtFcKPTpsqM5qcHzhzuS+9/tvmMjCe0k5agbgsNDumhhahS18Ibg75RRYuUdBFK4r0GUwrlv3TQGA8NfXUf72OAx7qP+6KqNf
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\MFZWJ.job - C:\Users\na�i\AppData\Roaming\MFZWJ.exe /infocmdline=SXx4TGPymErWQBubtYA3iJBLaCY6pirT7KRBQ0QdwQg3yqvWWfelTUs7l1ip9ffaR2Qm1rJE8rcuacu2KueFBm2hjl1yeSTMlHj4GLYc3rCgUvGvr4xs6CeM72oVQSPv8v+xWrFZugWz1EcE+zlCQsSI9Y2og54HFxeMVn+znQFORNZaR/yNWtP57zx9m/zMFYYC2M39nKbEIckt2qt44ytNmt0WwdXiHdG1ZbEMrg3jsUf3nU+4ObWTwOQCxGG5sPW5PQ8iHQXe7kJSrCA0+tFODoC0v1tCm6jVZok8FRMPD8b/5ch+0pyFEmsV4J2Du5APXswjkdHP9E3vzRvpgSUgx9pTrmUt+9U2W0hMJWl0369niOgyOo7eaKNRUM6GgN1zOdz2uwUiFhMGzXUu6ctJryUtIDAu5kIT8vwUTQVkYo98LgYBmsAv6nkYLhKYVwFrQ/XQ1qT7ZDi+1Pm4RVMwT62ijaENMcwqyGpvfijV64cTq2hseeuBNvTrnb+M
C:\Windows\tasks\THAGUQRU.job - C:\Users\na�i\AppData\Roaming\THAGUQRU.exe /infocmdline=Qfw3Yosw65XpD88kKlWtn6dxVD86E3HF45ebJS/5Xa3n+bCT2NuMGqi5kc4IH9qDsUzZUUcrdLAeSz2coJkvJmOiyVbg00nln8mk3q508h8ICgmEtncXtxdbeGygffR18J1ush5KrFQ3ME/RHr8uVilwgMxIa+QyM2MsCF873kAvjx/zHZqwnCq0ZwoahYZ+J+c+4HXHcyw0NwITqb1Rx5NMFT44d03m7wYXCkH6aA73XeH+ppuFT1/8pRN0bAfrbFA+fcPH3v0Fjonq4rE6q1oHiY0IioC1jk2/P/gho3z/NU2I4eYID8ejgEK5P4CR5Z0OUG2Swwk/+bGTFJ7AFyL7lkAbFyHGy+bgIMGwDrzc7cSKQAjFjwa+ot2y3P0ibckKKtYB7FQc6Sgkv4mbV581HnzN2vIulYuuORfGC/mOMlv+8Hcwg9itNI0zSR8jEG/5NvSHuuhP2qkph644zCm8FbTvM6UBNTZranlQY9EhyZ2bQeJ1sKZzKHKI9WM+sZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411851159}]
Apps Hat - C:\Program Files (x86)\Apps Hat\Apps Hat-bho.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-04-24 12480616]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-10-01 22:16:17 ----D---- C:\rsit
2014-10-01 22:16:17 ----D---- C:\Program Files\trend micro
2014-10-01 21:53:16 ----D---- C:\Program Files (x86)\globalUpdate
2014-10-01 21:53:03 ----D---- C:\Program Files (x86)\iWebar
2014-10-01 21:20:11 ----AD---- C:\ProgramData\TEMP
2014-10-01 21:17:43 ----D---- C:\ProgramData\IePluginServices
2014-10-01 21:17:38 ----D---- C:\ProgramData\WindowsMangerProtect
2014-10-01 20:56:11 ----D---- C:\Users\naši\AppData\Roaming\Ubisoft
2014-10-01 20:48:04 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-01 20:06:37 ----D---- C:\Users\naši\AppData\Roaming\GHISLER
2014-10-01 20:06:37 ----D---- C:\totalcmd
2014-10-01 20:01:42 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-10-01 20:01:42 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-10-01 20:01:42 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-10-01 20:01:42 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-10-01 20:01:41 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-10-01 20:01:41 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-10-01 19:48:15 ----D---- C:\posta
2014-10-01 19:38:13 ----D---- C:\Users\naši\AppData\Roaming\Windows Live Writer
2014-10-01 19:36:31 ----D---- C:\Users\naši\AppData\Roaming\TuneUp Software
2014-10-01 19:33:31 ----D---- C:\Windows\cs
2014-10-01 19:33:01 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-10-01 19:32:21 ----D---- C:\Program Files\Windows Live
2014-10-01 19:32:17 ----D---- C:\Windows\PCHEALTH
2014-10-01 19:31:58 ----D---- C:\Program Files (x86)\Windows Live
2014-10-01 19:28:17 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-10-01 19:25:00 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-10-01 19:15:43 ----D---- C:\Users\naši\AppData\Roaming\Macromedia
2014-10-01 19:11:09 ----D---- C:\Users\naši\AppData\Roaming\Opera Software
2014-10-01 19:10:20 ----D---- C:\Users\naši\AppData\Roaming\Adobe
2014-10-01 19:10:11 ----D---- C:\Users\naši\AppData\Roaming\Identities
2014-10-01 19:10:06 ----SD---- C:\Users\naši\AppData\Roaming\Microsoft
2014-10-01 19:10:06 ----D---- C:\Users\naši\AppData\Roaming\Media Center Programs
2014-09-30 15:13:29 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-09-30 15:13:27 ----D---- C:\Program Files\Microsoft Security Client
2014-09-30 13:48:30 ----D---- C:\Games
2014-09-23 13:41:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-23 13:41:39 ----A---- C:\Windows\system32\ieui.dll
2014-09-23 13:41:38 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-23 13:41:38 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-23 13:41:37 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-23 13:41:37 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-23 13:41:37 ----A---- C:\Windows\system32\iernonce.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-23 13:41:37 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-23 13:41:36 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\vbscript.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\msrating.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-23 13:41:36 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-23 13:41:35 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-23 13:41:35 ----A---- C:\Windows\system32\iesetup.dll
2014-09-23 13:41:35 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-23 13:41:35 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-23 13:41:34 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-23 13:41:34 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-23 13:41:34 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\mshtml.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-23 13:41:34 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-23 13:41:34 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-23 13:41:33 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-23 13:41:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-23 13:41:32 ----A---- C:\Windows\system32\wininet.dll
2014-09-23 13:41:32 ----A---- C:\Windows\system32\iertutil.dll
2014-09-23 13:41:31 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-23 13:41:31 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-23 13:41:31 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-23 13:41:31 ----A---- C:\Windows\system32\urlmon.dll
2014-09-23 13:41:31 ----A---- C:\Windows\system32\jscript9.dll
2014-09-23 13:41:30 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-23 13:41:29 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-23 13:41:29 ----A---- C:\Windows\system32\ieframe.dll
2014-09-23 12:50:53 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-23 12:50:53 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-23 12:50:53 ----A---- C:\Windows\system32\kerberos.dll
2014-09-23 12:50:52 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-23 12:50:52 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-02 19:49:55 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-09-02 19:49:55 ----A---- C:\Windows\system32\win32k.sys
2014-09-02 19:49:55 ----A---- C:\Windows\system32\gdi32.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wups2.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wucltux.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wuaueng.dll
2014-09-02 19:44:02 ----A---- C:\Windows\system32\wuauclt.exe
2014-09-02 19:43:54 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-09-02 19:43:54 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-09-02 19:43:54 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-09-02 19:43:54 ----A---- C:\Windows\system32\wups.dll
2014-09-02 19:43:54 ----A---- C:\Windows\system32\wudriver.dll
2014-09-02 19:43:54 ----A---- C:\Windows\system32\wuapi.dll
2014-09-02 19:43:48 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-09-02 19:43:48 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-09-02 19:43:48 ----A---- C:\Windows\system32\wuwebv.dll
2014-09-02 19:43:48 ----A---- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2014-10-01 22:16:17 ----RD---- C:\Program Files
2014-10-01 22:15:42 ----D---- C:\Windows\Temp
2014-10-01 22:09:12 ----D---- C:\Windows\System32
2014-10-01 22:09:12 ----D---- C:\Windows\inf
2014-10-01 22:09:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-01 21:56:36 ----D---- C:\Windows\system32\config
2014-10-01 21:53:40 ----SHD---- C:\Windows\Installer
2014-10-01 21:53:39 ----RD---- C:\Program Files (x86)
2014-10-01 21:53:17 ----D---- C:\Windows\Tasks
2014-10-01 21:53:17 ----D---- C:\Windows\system32\Tasks
2014-10-01 21:41:51 ----D---- C:\Windows\SysWOW64
2014-10-01 21:40:45 ----HD---- C:\ProgramData
2014-10-01 21:37:14 ----HD---- C:\Windows\system32\GroupPolicy
2014-10-01 21:37:14 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-10-01 21:37:13 ----D---- C:\Program Files\Common Files
2014-10-01 20:55:00 ----D---- C:\Windows\Microsoft.NET
2014-10-01 20:54:12 ----RSD---- C:\Windows\assembly
2014-10-01 20:52:09 ----SHD---- C:\System Volume Information
2014-10-01 20:02:02 ----D---- C:\Windows\winsxs
2014-10-01 19:33:31 ----D---- C:\Windows
2014-10-01 19:32:23 ----SD---- C:\ProgramData\Microsoft
2014-10-01 19:32:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-10-01 19:28:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-01 19:28:50 ----D---- C:\Windows\system32\cs-CZ
2014-10-01 19:25:02 ----D---- C:\Windows\SYSWOW64\en-US
2014-10-01 19:25:02 ----D---- C:\Windows\system32\en-US
2014-10-01 19:21:03 ----D---- C:\Windows\Prefetch
2014-10-01 19:10:09 ----SHD---- C:\$Recycle.Bin
2014-10-01 19:10:06 ----RD---- C:\Users
2014-09-30 18:44:59 ----D---- C:\Windows\system32\catroot
2014-09-30 18:07:44 ----D---- C:\Windows\rescache
2014-09-30 15:13:31 ----D---- C:\Windows\system32\drivers
2014-09-30 13:48:50 ----D---- C:\Program Files (x86)\Opera
2014-09-23 13:55:27 ----D---- C:\Program Files\Internet Explorer
2014-09-23 13:55:26 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-23 13:43:19 ----D---- C:\Windows\SYSWOW64\directx
2014-09-23 13:42:05 ----D---- C:\Windows\system32\catroot2
2014-09-23 13:10:59 ----D---- C:\Windows\system32\MRT
2014-09-23 13:10:57 ----A---- C:\Windows\system32\MRT.exe
2014-09-23 12:57:00 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-22 08:42:39 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-02 20:00:40 ----D---- C:\Windows\system32\DriverStore
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-09-19 123704]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 MxEFUF;Matrox Extio Upper Function Filter; C:\Windows\system32\DRIVERS\MxEFUF64.sys [2011-10-20 157696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 11922944]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-04-29 359936]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-04-08 94720]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-04-24 4028520]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2014-04-09 2472136]
R3 pimou;Pluralinput Mouse 0.8.6; C:\Windows\system32\DRIVERS\pimou.sys [2014-01-13 23608]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-04-14 931544]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
R3 ZCLDRV;ZCL Service; C:\Windows\system32\DRIVERS\ZclDrv64.sys [2013-06-27 71680]
S0 amdkmafd;AMD Audio Bus Lower Filter; C:\Windows\system32\DRIVERS\amdkmafd.sys [2013-03-14 21600]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 11922944]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys []
S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys []
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys []
S3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys []
S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys []
S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-04-29 238080]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-09-24 705416]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-12-08 2028864]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2014-10-01 528896]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-01 68608]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-23 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-01 68608]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-04-18 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------