Prosím o kontrolu logu!!!
Napsal: 02 říj 2014 13:42
Logfile of random's system information tool 1.10 (written by random/random)
Run by masina at 2014-10-02 14:36:30
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 6 GB (4%) free of 134 GB
Total RAM: 4095 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:37:09, on 2.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe
C:\Users\masina\AppData\Roaming\miner\minerd.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\SupTab\HpUI.exe
C:\Program Files (x86)\SupTab\Loader32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Program Files\trend micro\masina.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp& ... 4_343E7F8D
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp& ... 4_343E7F8D
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: eee1ef70083a013208d37190b1a6e5ef0063429 - {11111111-1111-1111-1111-110611341129} - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O2 - BHO: YouaTubeAdoBlockke - {bd21c7f7-d467-4b95-8f46-6552160fff79} - C:\Program Files (x86)\YouaTubeAdoBlockke\G8UxyUpPJxJQ6S.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [mncgnfjSrv] C:\Windows\system32\mncgnfj.vbe
O4 - HKLM\..\Run: [MSStp] C:\Windows\system32\msstp.vbe
O4 - HKLM\..\Run: [mncgakmbeSrv] C:\Windows\inf\mncgakmbe.vbe
O4 - HKLM\..\Run: [msfpoxuSrv] "C:\Windows\system32\msfpoxu.vbe" msqbit msbfpiu
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [miner] "C:\Users\masina\AppData\Roaming\miner\nircmd.exe" exec hide "C:\Users\masina\AppData\Roaming\miner\start.bat"
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\masina\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [RGSC] D:\GAMES\GTA\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [EADM] "D:\GAMES\ORigin ORG\Origin\Origin.exe" -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update focusbase - Unknown owner - C:\Program Files (x86)\focusbase\updatefocusbase.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9024 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
C:\ProgramData\IePluginServices\PluginService.exe -service
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {A4A8B7C3-3C39-4AC4-BE9A-ECA3BAF7578D}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\SavePass 1.1\6df3fd71-f640-4846-8266-c7fa64cee956.exe" /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='0' /bic=CCCA49A8DF7E49A7AEDF798C03FD154BIE /verifier=fb02a82073014edf4aa3acf35db1e006 /installerversion=1_35_09_16 /installationtime=1411058915 /statsdomain=http://stats.newclientonlinestorage.com /errorsdomain=http://errors.newclientonlinestorage.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newclientonlinestorage.com /runfrom='task' /externallog=''
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe"
C:\Users\masina\AppData\Roaming/miner/minerd.exe --url stratum+tcp://eu.ltcrabbit.com:3333 --userpass tetroboylp.cpu1:cpu1
\??\C:\Windows\system32\conhost.exe "2854358472135954990-302555317635516246-1675070690-701124794-1154935056-970703377
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\CCleaner\CCleaner.exe" /uac
taskmgr.exe /3
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\SupTab\HpUI.exe"
"C:\Program Files (x86)\SupTab\Loader32.exe"
"C:\Program Files (x86)\SupTab\Loader64.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2904
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://isearch.omiga-plus.com/?type=hp& ... 4_343E7F8D
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=716.19003ce0.2112644093 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 716 "\\.\pipe\gecko-crash-server-pipe.716" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --proxy-stub-channel=Flash3924.6F173FA8.1155 --host-broker-channel=Flash3924.6F173FA8.18887 --host-pid=3924 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --channel=1268.0033F334.259201147 --proxy-stub-channel=Flash3924.6F173FA8.1155 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" --host-npapi-version=27 --type=renderer
wmiadap.exe /F /T /R
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe {F887E707-F589-41BD-BEF7-FBB67013F3FC}
taskeng.exe {DE97F150-A8CA-4B96-A58F-4583EE78788E}
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\masina\Downloads\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\097303b6-b048-49fd-90e1-a57e1215487e.job - C:\Program Files (x86)\SavePass 1.1\097303b6-b048-49fd-90e1-a57e1215487e.exe 001504 CCCA49A8DF7E49A7AEDF798C03FD154BIE 63429 1411058915 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 SavePass 1.1
C:\Windows\tasks\6df3fd71-f640-4846-8266-c7fa64cee956.job - C:\Program Files (x86)\SavePass 1.1\6df3fd71-f640-4846-8266-c7fa64cee956.exe /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='0' /bic=CCCA49A8DF7E49A7AEDF798C03FD154BIE /verifier=fb02a82073014edf4aa3acf35db1e006 /installerversion=1_35_09_16 /installationtime=1411058915 /statsdomain=http://stats.newclientonlinestorage.com /errorsdomain=http://errors.newclientonlinestorage.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newclientonlinestorage.com /runfrom='task' /externallog=''
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-1.job - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe /rawdata=G/eQa/eJ9AC+lQwThnkdlFjJErLt/FMkb7M1K7llYeus3s4TLkUyTiwF+yNClGyGoq3A3H0pJ0AxS1tgryfJJs6lwPDJOzQ0u/zGU1LO5pHBcBC38YX6ctzGJexpOpfNGETDdY7uTAvw3oT6H7aSO+v9LUsFkbKK826AiRV+LnyWR4ccfyg7ZpV26XTJ67sl9lSQux9iIVKoVNZ/jzH1GV8GIUpCPf9KLNvsmZFVs5sK2cCWS4Snd2Ks04uGr894D7Uwd0yclug+PYOECL+eZBK9vdVNK9GGRftpvha8pnbmZCfIAEEXKRs4KAMVMlSvONc4mR4sqluajPVmyuU8KBokMTyj1FQsblg61ofDKrA+vpzRHUjUKlFy839YiAnsJP/XtW48UTj1RilEtcXppe7TJLuvuZr4hffccmnKXtNiHInsM0GJBVia+AQxACYhFisfW8o7Aw2BI46tYdxOK0J21Nx59mtuGyTMTrP5+XhWRzEJ9u21MZfgTB8vuIowQN4Qi3d0IbSY9WxUcQiP74i2R3I95q9gxYM3GndefhQ6v4GXgNnDDM2HFs6SZC2n66yZaR4YNq21dfQWRKhN+A2zsdOP+xMFSoIx3DW4oNM0yPN/TrEJJPQa4Qrxbq6hPtKj5aAT+KbpUHXNpgnaj/B/EQ0Jqh6Nb5IL83GuFNVQAg40V0uuib1oNsJVUU5/6H7nGPTbHDeiYR3OlZ3dMUkvcWIPmaNTpeemabLkAzyKH+KsjxagG4EXGFLN+84U96nntmlFV1ka3eNdBsDTgL/I0RU/Zfy4peuV80+RwzWuIE+H7xy5D7CrRGFVm15PO8Wa8DJhNA3Mg7TjZY8frhpotiwypDJgfHQIMPJbE5n4evVnGhSAtXA3aEdzaRZbOhBzVFg14nx3aaTaO4Cf18K5JdC1P4s13yKFy88Q5EZSsGp+YaQCuHgrys1jfHat2Zg3UVoUnxWGGsPSdPTEAaIN5h8TQQWCKjkiPTlXiPCwwpWEEOn35KqLGc5pSXnXEvLG1AEe4KnXzgYhtZXAKqkMlZd06PN0nHOz7qNZBkqj9kMo2HxZkorwZ+NRihgiEouR7ujdnev1NXf/NJhx5374HqYdMeyMFkIHMqLfSfKkdBfxn5VYX/t+5OGTkJdoOzWA2W0eDqmGR28jvvGUYY0rtJyKHx7EddZvsgRcOcg=
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-11.exe /rawdata=p2k3YC8kX43yNQAlCOoLO/jB9IWDpMg7c6ieqwDVigM80kv8HQGBbKxwPdZinA1mnfq/WroKVvmc3YHggv9ghQ0X0CuNfeAVPGlHOF/IRxSpE+OlmYEEm0WHUzQPOZYCooNrB1jltepzmyyKy83ZQgWS9oYORrV5s1vpEYVJlf+uyLX3WnvydjGIqYsoQeEpVHaqCqDluyhJ4ojf6kHby32u1HENQ1decJ0SBeiG2I7sTcJ9oNbFlulU2jhMkR5eXZQ+7kJjtkRh0pqbgi6ig/UEB/KjMjsZiEuhvq/XheA3iqrFnhoSodYvyYpQHF/2Jlx6NrTwtzb5jjDu5qTb3oiFRg5Qsje+4OzPTlwvexej+dMeI1xjPGyrsqyEjuzaCTtKdnp9t7NCVm8OeQ7se1fUlBqHaw219RRqp38Sm7OpcFb36uSkHPHatDPwQ0lZ7Ncg7W0kYE92IMXkJ56xTamZqs3fn7R11LS3ux2dRjeRM9vSK9L2j9GPg7gzoRKyKgdxVUoEyBGI5e3w2TqoT5TpDIpZ/jCalwJFExK4mH83Gpvkgis2xT22hRF0DP7QsuRZwFhH2L61SJzKJMblZ4ezw7AwgKptf+tfy2OGNFiWyCPihDg/Q5rwol63FdBJLc4uizIhc2iTzXdy1PdUgRsmSD3kAU0nysaV8YSgnWNiKHSicYqgdxgf7/BPgzby8PLqSlenMk3Z1as5XbzUndPErwvxHxg0cFlp7iIZfS2OsZKzVlKslBYBGog6yZXzFRz/ZMq6ZQpA7IGSgy3wCLHdGBF0hPonFZMWAgYb1PqOJIiKD6X1VJG+0HIwaS1LquTnM+RKBpg5iESCXAVzogUrxIYkOssndUMxztc1oXw8T16tzX0BA7Nw+yHU5tmbmQCq++alFz8fcFchEmtJxsRu1MjlXjfp3j/xB3/2LQB07htKmXL5iMpjtWIbjYNrZrq/47Hjj0q4FwHHWj9sxFIYI42ArHkZoSHFtReZL1G4nTEuujCYsYQmud8f8GIcTvNsAgmiGMHCtcMd6EaSpD6ifonymrS8A9DBuD7WIArmSgpWSieMzZ1uJgpyDIXu6+bysL0AWbIQeFlcjKw2zTlZ7f1Huufl03hqUd0c9ApL5rV+yCrvpHH3Jlp1WYECjfK2luXHHHPrZBWsyCRI6q+zVPmMU4NmwPuMLZyW4rN1/V4fAcUIiz3ZeLm9gyyOI+s9UPA2KG0hHtNtafVLBe1oh7jFSJw6+/QGyjmlIdyp0YHBgxjxn53AxDVB2lQumtxru34xreioKgkvU4RHuQZx1mF7XhRsaTguoqSF7uNWmIkMzD0oBuWboL2EI7YkD6Dj+Zo+iR3iBK7SAipJMpkLn5eXqm8ALWdUilbs8SUztd37k+11xJDIltsEDTw11j0aANd+hVCEIPGbpJeDM1vjKW59I7A8018J2dx9uf/hK1v5Pi967hYVwQfIXwRdyTBdzNMMUahI3p454zlZwGyx83ii9xOKgOp9nVK+e1V61J0oghUC1DS760CqOMjtk/slgBYvknvwKFkJe47N7Dr7UWV+b9nLkbKksd9ZLwg73tFDxbatx2XhwvYw8HLzn+DO15RVHFYyXra+Y+s8Fz5l+FFCJNLhFWIMMrkHcCkgw5AHHU4FpLg0Hio+kCH20lBjUsxuKv0ZhbZnsJCSaVoyGSsD4VbMtpPP9DlHS7lDV/dpE092jqpUo4DjrRJ8bmZvDo5V6v9XVmbMkYQ/HiF9n3ZInAJYJ5haSf7crv6rijIJZN+WhCsv0Ley74JJE+xf3dsyKRk4boFzd5QOPNG07tc0gpEXb0aXCp8mK+COxV1vvHbKCWqjqCJ3BaK+3OYansCS5Iw/1maxzZ0/mw01frjEZKzKpwOX0iOndbfjedEJb3AfAeQqASnSzSxn6E6IHJOzLEjDKT2kJfJPUwJS0Pn80zLJrf9wXIyG1yZuAL9rjaBmXbmPj0kk8NYeyj6hesztGwN+exe6q/lEYNSqTNiGBmZa+1ixo9wDp6dpPjle+FutW2bZk8l2Y8fF
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-2.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-2.exe /rawdata=CgmdSlVbS2hZm+5TPmMVbd++0Uq9ny/PXdnBMuqX1Tvlk4JoFAvyzfdzS5OS6ukYOk8v3wJtGup/omgav8AFLjPH2rrRM46h89U5RIgleGQgnfKypbAoqySZGt7FJnB2B9QIAghKD9J/28TK8BUSKwzPIUzQg4wfwBnVV0sjWSBYP6rR0Oe04AP8LDCmfRufbHvin4Wl3winOI7QVPtVDybB4NXg6+3jSNMpi2tuEoTIESp60s0kQRCqPKOcRSg5nAUPn4NfqP733ER4yIBiXuPuCveHtX/K3/2JK2Zv8lrNrAtBlbBH/LMSfO1AtR3Z7bMxwP2mCR6wHtSqWzyFvk9jIlwXEx4+XEV+AU484vBg0vg2OrzoFA9yElF1LY+3+06+ywhXl5AH3GsqFyIQpn21BVnh7JyJfhV3rPkVlGzeBNzaLcgYZI5t5qzlyH6ezK/zB2DMLcOQk/EtqT6VrLz3edpPACFOXEHt7woWG33xJBSMp+YSP5FrOnoBoPkEPPDlmLGlfZdIdxTGTKNkWvHqkYxG+GMemQ0rxIUKfhqxWhRNRZAqbpphimmLoxP6A1b4hteEP+8hC5rQrOb1K12LapqpTAiVHkajRoORYELcIiJXicNk4/ZIgb6BM4nPJQ/PFWSEyi4EEW+esMuEFOD58FlIrEVaG1oWxijIVkt0zv7Mze4e9Hm2lEHW8IfIuike1vp3rgnMmQxB5M9o23fz0MfKQE7drN1/0HSgiTwswJZ67Ho/8ACrcckg97A3pjNd2gMovuK75mvItO2w7MzUGGj2qeF/HWTWg4H0dGFjsti89HyKy5hCpaHrtZFreitqaoFCCliUzxFXPLqHUg==
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-4.exe /rawdata=n2pFoBdsixQMGTzF4GEN+l4kAL9zzanVuMcImj1+W99sFGHoeYHX+imkvKx/QlatUbZgqB7CaBQMEzMxTPTS/ne+lRi1gy3afF6NizoGRN4Qtpe75FHDKLhQy7brlIdJ0tWhgiNgdkroYqjJK6ci2ZIhROVBdlVaAyUxufmpeNObtHdHWSyeZelSg5SoPHdjccfccFf8qq1J19qvw3nCFBGSxyTWJAYIzdtZ9uxPBFDC32kWIOUiR2BM/9aegSIuf3oubuWUwYuZtdJ2xIqBP6Bsdcj4p3rAt9XymCaT3frny3r8FOsqhG3NLDadO8RWcw6T24ww19NFug0ZWvU/2pnp6Um01nfm63e6j0tq+IUjGe3iDPN8mX6UjfhqPUMv/HqPMxhq98WZa2bH5QFAVwo7qtQ5EKBCyfM0+/gFddXx8GUCL8L3+q8Yz0w5sQ14gKGpvCV94o32kvr2v8bgi4y0c5aE1bU5hCuXk3hE/Kq5XvNDLdg4hZaKsOoH6zw2FqdGzdaUTwGRgKc5YweRl0YjOck13CYT1+6r9dcpJY9z4MamDGA/qBHlTWLKIMSIXU30OyMV4DPa1rJmdIz/NBHLCy2avSywksxQJqyGNj9Pyzr+sJCbMrnLOzqiSexirwA1Ad7SceSbv+pIHQL/0eajmOLIIOPYRfUp/ztn/eUgxgVxV69SDX/7/ClNjH8StXzsJjpBR2kqGprgnJlSbivlrPUhQHa8cfX07PhC9kfBwH9twXRt9ZnRlhyy0kRPkUEJkyxt+wJBe7QNTPjq8+1x7Dz4XunsSNOfvbJ1c5/0ZIw9tv/MEV8ME7ijcuj57DbPZblCTXZBZHELKijuFiVh305UU85EHFDGEmhoU0y7hYNqR3EbJH+I06vMLucvqBy9L7jeJ3GeHHHvDDPehpqD2nLYypjr2fhZsCGxhS6gg+x8hH1lcr7scyVIRVFV2UUurE/ErJzwvMCqNiQLYFM4FGgVYkTrjbumon26iwoOH3Wy/VVVakY8LgbxaTKObIyfO0KfIcNwTtsVNMygdkOyi1SdSq0wiSIPiwwuwPQ0kbtEB5Gc4NgGQeP2M6HgKzplhk106Enugasnd61AqxZ+1aBQ+V0OlFQRRwx2/6I5c4xjI3z7cbuQWNb1idwJutgbW5mw0eTeaf9Rt8FERPwwrtvnT5Oon5Z2avjRVP2SjADJAkeesDoxi+LatXCIg7fsxEQG+Nhc9PS0J03Pdk9uOwkJzcw75E2mRLIkzoGm2D+r2eMSmq95Rek3LiOpgOWPdkO9vs7UK75g9yXFAP+GNWXo7wKU1RLb0tgtYAdyXS1lsvWrNkjKzn64eUVvPZ6PDyrcHT9ATHVNOFsh3iG6jbCrK6nEL1QtXLkEKuUVgevzg+vrMB0gLty8KKwhXHATRgmlM6THsFANk4eyQSptSWcenWv441hAQ+UmdYXREYnv/ulDoqQq9uIzohRivMvkCXMKG8F0v+gt+LsyNi7jcQ86ScDwZDnlQXLsK7VqqtEwLNXuw/PVHgHGkCPN
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-5.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-5.exe /rawdata=lQYJAUQLFOYS2qw2D1iN5hbdEx6CBez0w7jNjabdHwJeDYYpTwdtMdlfYXay6zx6JXbwnobZ6ja9O00CR7fnoyO2ps5NJHNS0SdWtPqASrZLeJnhQAXlMevZ/lzV/Try98TrH/XY0YQfpnuPfuFCIs8FOF92SnP/91r9ycoEjeWf1YiyiCPd/QNyh3VuQRf3qW63E4ys7CshwE2fSRf+4XevCAXVlb/bOBtyrxZM5/nyWFpqM62iJEgPOQAfzSITycZ4profgQNSwyjmB1cNHA+tUDIriLIuuDMhgXDAG/PrwsXDJZVvNs+sq+FnVa5j8tXiLSXXOG8JuodTg6H7agNXa+1pKz3bZwUyoEj1Tfo7+G9nqGxjqlRC7lLU6odA0EuzJl5uU8UZS5erX2WGAIyhoI6xLMTN2r5/5lg+87hodql5KiFA6TZHOLvENXe2NjD9qz7odZm3yRbqSHhgtQDp38VjJiqdi1B+9XoxnjomilAy4ggtN8eBmxLFRiD0U3uUl17UOUZKpKQvhDrTPbZ97AZCexbcN6zd3+/0rhBhgeMYGhIgGJ+ZbqHEjAIMWzjGZWaV+pyVV69Zo06lxl7T+sH5svqJ4K4J/uYVyFaXIkngnhQ/GH2izKHHPAjwT5OKaMf0sf4dbkvvZNQGrlU5IKvu8podIpE9LWeC+uszp33hAVBlI8C46jfzGWjWaQc9MBlH83wNenCEkV1m9VDj5KGNp+ORAHSLoqY+53CDS7aDDFJrQBBZDW350y9BvpbtC/4dnFnvyf9Ymh7Mv+j/aI/IPlGTrk88XukGUhnYFy/y+YNwofXRlsEnTQ3PY6osdnncTLz+ZtMEU1/9WmsRmrHcQuBEFuO1I+zwykbWvonXODmittb/PR7TgIV6hDlMNXrgb+kYiMkUtynvbpKP98JWQlNn0y/ZuiHZt0CNAxzRD/m3eWe80agi4xJpPYouTfM6KAuGbtuz3o1qepEU2ZZTrC6SZQ8OKfuE8q6r4FzAQsGDWUnrxD8EHrkT
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-5_user.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-5.exe /rawdata=lQYJAUQLFOYS2qw2D1iN5hbdEx6CBez0w7jNjabdHwJeDYYpTwdtMdlfYXay6zx6JXbwnobZ6ja9O00CR7fnoyO2ps5NJHNS0SdWtPqASrZLeJnhQAXlMevZ/lzV/Try98TrH/XY0YQfpnuPfuFCIs8FOF92SnP/91r9ycoEjeWf1YiyiCPd/QNyh3VuQRf3qW63E4ys7CshwE2fSRf+4XevCAXVlb/bOBtyrxZM5/nyWFpqM62iJEgPOQAfzSITycZ4profgQNSwyjmB1cNHA+tUDIriLIuuDMhgXDAG/PrwsXDJZVvNs+sq+FnVa5j8tXiLSXXOG8JuodTg6H7agNXa+1pKz3bZwUyoEj1Tfo7+G9nqGxjqlRC7lLU6odA0EuzJl5uU8UZS5erX2WGAIyhoI6xLMTN2r5/5lg+87hodql5KiFA6TZHOLvENXe2NjD9qz7odZm3yRbqSHhgtQDp38VjJiqdi1B+9XoxnjomilAy4ggtN8eBmxLFRiD0U3uUl17UOUZKpKQvhDrTPbZ97AZCexbcN6zd3+/0rhBhgeMYGhIgGJ+ZbqHEjAIMWzjGZWaV+pyVV69Zo06lxl7T+sH5svqJ4K4J/uYVyFaXIkngnhQ/GH2izKHHPAjwT5OKaMf0sf4dbkvvZNQGrlU5IKvu8podIpE9LWeC+uszp33hAVBlI8C46jfzGWjWaQc9MBlH83wNenCEkV1m9VDj5KGNp+ORAHSLoqY+53CDS7aDDFJrQBBZDW350y9BvpbtC/4dnFnvyf9Ymh7Mv+j/aI/IPlGTrk88XukGUhnYFy/y+YNwofXRlsEnTQ3PY6osdnncTLz+ZtMEU1/9WhpcF7mr5ZreYmeit+mVj1ChZ2bEKYcWRkyP5YPuNiKNYh4e9H4eq2N9GODqCKFuQCl2oHxpbtdZrPlKD4Fy8+WXwnZOvNsiai/cAn1c30yXFMgfnsgREf2dd97FmTQXRREipdNkYncFKSs1N4ws1Yss1HgJvnP7jRXYtcPGmU0Q
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-6.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-6.exe /rawdata=NMWz51km1gSZXatavL/7pP0HHxOieSmFSesXcgXceKrzI4jZNnhu8r1f43aD8UWMfYCkx8bkAuM2o4i9c++NmhSEbumKFrkFvXCfBfGWlHlMNtwmsopguC8HrFBvW+bS1wJnshh86VgJ97kiCr4JFW7o3BwyObg0irTcbXmrPqwyfGWodFkCEXYrCA+LiyaEAr7uW97u6R/16JLawWOQ9VVLCJSSJ8QEUF5RMcfFVH6/V7ApYSfnHG7PiDsx6523bdimGQk0mINyJ0AWhC7gur2gVjpTZsZi3Xvs59trdQduABFHBjx7H8eTVRlDlfo8NUO0m7c/iswotoa3Zj22eyZbsSifs6mWw+Xe0lgvpmBLFMmm/ov8M9e4Jj61LlYhh1QQxwMpxW4jd9nqSFSFJ5NmGcyRtRs8hKENt1poPuiLpJ1TBVVYnPTrw5W005kHBO5t4e+L9MuPz+msTnZNTbf0GhpW3IB9MYIfQjLPjdSc+hDpojJ7RFQPUD65Yg2DFX6p7L6IGHl/RYhLqx+bYdrWd9/X4yMMpF0IuBTscqf/OGIZ1edO7i05y2J7nDhFOUNE/qZU+b6qq5TcDCw8Sm2voxo0S2fR3Y5R1TUOxZMDEYafGIHsDaFZrt77YqPqJQ/ueUZihx/GRU0/+iZnXzAOSPOqYbsKRhmDNLTiZqNwaYSKS87Kdzz4foPnq4h41VoWrhUTQubgwnjR4fIUQRvB09q7ThyNLd4/MKMttOrpDQaXolsqU8sHfe1V09QF3pIEAowcQcMC/8zyFSk54b9Osq3EgwhAJYbkpq9bEzS0FFBGW3W5oKsriOAqMe1rO8NlWzlJ0tncGSLLMPPsWmrug5u12RFZ/yA5X0NQlHa8zQacGnYH9RDMQ9dKHlwqkXXhVfywDM+Jqq2JbRMS1iL4tR3Zl4Ot5HviD7/dlss4ZaQ35E/2o+6U7T2KVOhu3ig0g8heh+esZjJ1wr1gL0W9zJdOKAzORY2EqTg8v/niAU6n2tad+xJ4uHAGZmZdaEeuTiufuoRN/k7K+a+GNg2Zh3Dt0BOilX/ViQK69zptCvtdLvs97CJt3tre/ee3fr1Q68pKfMn227mvZ5KdpK0KrXn/jgJXTQ/ksdXfPPezUbwCTS+Ia2mZ+H3C7wumcIREgm/z9e9oZFpKn6yX/MrzO6qow8Cccw0+YCyiI6kuCeLHiTOPSpD8q5B0/nGyp1ZK1LQpHKhUy02J+p1OTdO3c9sYxWtmyNsg1NKcoSrdnGp4BLIgc3ek/xlxcHrouJX3DOMAU4gjDG8bR4DSIW0Zq8c1Sgnrf/bkAiMp2L3UkFj28FUMCOpsb4LWdN3v9zbxgF02Tj7bp1LLePxhs09SiwPfOvhBylOKe4CwngZj6WvlNvVIalaPuApCaDMQ+gsvy/QxrT2dDf189UdxLCnCSy4InZTicF1XeVKq0qPJBgtkhaUn3Ss8vguqLG21zntXeS7MnDzXL6uAJObMdVSxds5n3/1cWiHAevBnMrt6Whhj8/aC68HPT9QKB2NA
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-7.exe /rawdata=UsCh5Fed0FRwWn5yo5uFEpQiuAuumlwwRlSQtxkCqBodIDeVii4ffGTplDSnOHT/dj3cGaOYX2xf7aZDwJ48JAlKp3StuFKamErgTOLt6/hWTNqmS2/fwkeDslrbRQXh4wcZum881z8O/1wvXONILBqttrm8iwnwcW35wPBfttOOxtxaD1nIP5LDBPMi8AZOc1i2rhqnRt2zlHZLGQ1tsPCyVKeKEPM9f5g58WPlrFRu1qhwPkVKHVsgg8npkT88aOubg0yT6cyj1j/TmjchgH8zSdXYU1kVAJZ49mMSTcfWwm8AuBBY3UOiMiNSdrKe0rDXkfiW1QeMXlfKxhOi4pSoYqbrNpaIjnMnHHhqJxWE1hu6kyzLuEbi3HC066G5qpMFrUC04vxZaxmIil4QJKb0N/RqjpIh0twR7LHyzXnyjsYeNX1nBaakcB24imvB1+O+7Lngio9fDks+Fcvm7ERG6qx3pszYT2UsLU0sZs5GqB1887634w2K1AEKK5/cxt0yvyaXlJ0PDxr3Y4VLR/Nhv2riHEegcPLKeaDjYvlKRRWcDc38KmPFPAyae8Dw6PR5rouaAhpWdpXGq6Jo0rKm7aDVXT5E1A1SRgYJeLUEgqApLmAx/HKsCoLy7ehSquGEnpQWZ9rNMwwF1LBnrTZNWD7uxUq2jBV+RUKHpmY+h+gcYBx7AjPOGOEHfDkNowj3K/F08ATqqfQ685ZnM9lAWOEKoKbzWkBbkETFBkCrA6vTCuYJXlVI85OnmapiWiZKOa7tieejU6z4Rx8rAgYrZq3InrsN499H60UuVNOtgebDl3eTN5aJTTmhWkuQ3q3jWeBaSZq7CoOgcrR1KRJ3TfxK3+A46OZf9leyu03J52TsutCQVbVsMiK50nsPO0Ya9kUz0+GLVJrvQxCOVa2s/8yC3mGwgLpNL9CPHoCFdfT/RW9shWepoT18zDFAFfu2HSoMlEqbnqW6z1Maj7hsaAHcensiwH9S8AWVMSFz6LKoVAi+2tgMc9Uyppu4ag0KlyjtZzlSh0DJ/Sn67Sd45ofS6Zdl2SWxOlEjADLs+OhAEgBfpNdcqBCWYWmvUxYUL9OT/LfU4EMT6k/tLJh9bneeRN1/+74bsZX6o7Q8m44lmD9siU4hT1aZGwQEzn3TFS1xpgxF32NQIosdB3tkcJOp8QBaurHwH2+w044leeG4CeG60RpVTQpOh2YY15YJm/jPGZsP/kJ5ZU1NRN0Y5lyDjI5Y60aiHdTFc4Co/Tj8M0LDs9UG8mvPCSVB9KLMJQsFHk95et0pZwruu5NdkPYui3G4jmLg5/oza9usaHtg6/9I14Miux4hDM/pDHFwbcKhq88qVyJkBvDVcQ==
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\masina\AppData\Roaming\Mozilla\Firefox\Profiles\kq77xfhl.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\masina\AppData\Roaming\Mozilla\Firefox\Profiles\kq77xfhl.default\extensions\
0UG@3.org
http-nowhere@cwilper.github.com
n@P.co.uk
VJKPXI46039420@JMZUIOB85844870.com
{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129}]
SavePass 1.1 - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho64.dll [2014-09-18 825240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro64.dll [2014-07-22 500584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bd21c7f7-d467-4b95-8f46-6552160fff79}]
YouaTubeAdoBlockke
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129}]
SavePass 1.1 - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll [2014-09-18 611224]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\SupTab\SupTab.dll [2014-07-22 515464]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-23 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro.dll [2014-07-22 418664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bd21c7f7-d467-4b95-8f46-6552160fff79}]
YouaTubeAdoBlockke - C:\Program Files (x86)\YouaTubeAdoBlockke\G8UxyUpPJxJQ6S.dll [2013-09-14 621056]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-23 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"miner"=C:\Users\masina\AppData\Roaming\miner\nircmd.exe [2013-08-11 44032]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe [2014-07-22 3211776]
"uTorrent"=C:\Users\masina\AppData\Roaming\uTorrent\uTorrent.exe [2014-09-19 1416016]
"RGSC"=D:\GAMES\GTA\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe /silent []
"EADM"=D:\GAMES\ORigin ORG\Origin\Origin.exe -AutoStart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
c:\users\masina\appdata\local\akamai\netsession_win.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ETDWare]
c:\program files\elantech\etdctrl.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"mncgnfjSrv"=C:\Windows\system32\mncgnfj.vbe []
"MSStp"=C:\Windows\system32\msstp.vbe []
"mncgakmbeSrv"=C:\Windows\inf\mncgakmbe.vbe [2014-01-19 1342]
"msfpoxuSrv"=C:\Windows\system32\msfpoxu.vbe msqbit msbfpiu []
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe [2014-07-22 3211776]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-10-02 14:36:32 ----D---- C:\Program Files\trend micro
2014-10-02 14:36:30 ----D---- C:\rsit
2014-10-02 14:27:02 ----D---- C:\ProgramData\WebbbiNga
2014-10-02 14:26:57 ----D---- C:\Program Files (x86)\WebbbiNga
2014-10-02 14:26:44 ----A---- C:\Windows\SYSWOW64\setup.exe
2014-10-02 14:11:43 ----D---- C:\ProgramData\NextCoupe
2014-10-02 14:11:39 ----D---- C:\Program Files (x86)\NextCoupe
2014-10-02 13:52:59 ----D---- C:\Windows\system32\appmgmt
2014-10-02 13:48:28 ----D---- C:\Program Files (x86)\Seznam.cz
2014-10-02 13:47:35 ----D---- C:\Users\masina\AppData\Roaming\Seznam.cz
2014-10-02 13:46:42 ----A---- C:\Windows\system32\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}w64.sys
2014-10-01 19:49:15 ----A---- C:\Windows\system32\qdvd.dll
2014-10-01 19:49:14 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-09-25 18:10:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-25 17:19:09 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-09-25 17:19:09 ----A---- C:\Windows\system32\tzres.dll
2014-09-25 16:51:38 ----A---- C:\Windows\ntbtlog.txt
2014-09-25 11:38:53 ----D---- C:\Users\masina\AppData\Roaming\Guild Wars 2
2014-09-19 11:29:20 ----D---- C:\Users\masina\AppData\Roaming\Macromedia
2014-09-19 11:25:36 ----D---- C:\ProgramData\McAfee
2014-09-19 11:25:24 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-19 11:25:17 ----D---- C:\Windows\SYSWOW64\Macromed
2014-09-19 11:25:13 ----D---- C:\Windows\system32\Macromed
2014-09-18 18:52:01 ----D---- C:\Program Files (x86)\D3Crack
2014-09-18 18:48:43 ----D---- C:\Program Files (x86)\SavePass 1.1
2014-09-18 13:22:09 ----D---- C:\Users\masina\AppData\Roaming\Mozilla
2014-09-18 13:21:59 ----D---- C:\ProgramData\Mozilla
2014-09-18 13:21:58 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 14:20:57 ----D---- C:\UpdateChromeLinksLogs
2014-09-16 14:20:40 ----A---- C:\Windows\SYSWOW64\mfc71.dll
2014-09-16 14:20:40 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2014-09-14 10:02:10 ----D---- C:\Program Files (x86)\YouaTubeAdoBlockke
2014-09-14 10:01:47 ----D---- C:\ProgramData\GoSaVVe
2014-09-14 10:01:41 ----D---- C:\Program Files (x86)\GoSaVVe
2014-09-12 07:01:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-12 07:01:42 ----A---- C:\Windows\system32\ieui.dll
2014-09-12 07:01:39 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-12 07:01:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-12 07:01:39 ----A---- C:\Windows\system32\iernonce.dll
2014-09-12 07:01:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-12 07:01:38 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-12 07:01:38 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-12 07:01:38 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-12 07:01:38 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-12 07:01:37 ----A---- C:\Windows\system32\vbscript.dll
2014-09-12 07:01:37 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-12 07:01:37 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-12 07:01:36 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-12 07:01:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-12 07:01:36 ----A---- C:\Windows\system32\msrating.dll
2014-09-12 07:01:36 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-12 07:01:36 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\iesetup.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-12 07:01:33 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-12 07:01:33 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-12 07:01:32 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-12 07:01:32 ----A---- C:\Windows\system32\mshtml.dll
2014-09-12 07:01:31 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-12 07:01:31 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-12 07:01:31 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-12 07:01:31 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-12 07:01:31 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-12 07:01:31 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-12 07:01:30 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-12 07:01:28 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-12 07:01:27 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-12 07:01:27 ----A---- C:\Windows\system32\wininet.dll
2014-09-12 07:01:27 ----A---- C:\Windows\system32\iertutil.dll
2014-09-12 07:01:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-12 07:01:26 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-12 07:01:26 ----A---- C:\Windows\system32\urlmon.dll
2014-09-12 07:01:26 ----A---- C:\Windows\system32\jscript9.dll
2014-09-12 07:01:24 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-12 07:01:23 ----A---- C:\Windows\system32\ieframe.dll
2014-09-12 07:01:22 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-11 11:39:41 ----D---- C:\Users\masina\AppData\Roaming\Battle.net
2014-09-11 09:14:22 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-11 09:14:22 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 09:13:44 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 09:13:43 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-11 09:12:47 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-11 09:12:47 ----A---- C:\Windows\system32\schannel.dll
2014-09-11 09:12:47 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 09:12:47 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-09-11 09:12:46 ----A---- C:\Windows\system32\certcli.dll
2014-09-11 07:25:22 ----SHD---- C:\Config.Msi
2014-09-11 07:14:59 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-11 07:14:59 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-10 23:04:46 ----A---- C:\Windows\system32\aepdu.dll
2014-09-10 23:04:45 ----A---- C:\Windows\system32\aeinv.dll
2014-09-08 13:56:38 ----SHD---- C:\ProgramData\SecuROM
2014-09-06 09:24:51 ----D---- C:\Program Files (x86)\Splashtop
======List of files/folders modified in the last 1 month======
2014-10-02 14:36:32 ----RD---- C:\Program Files
2014-10-02 14:34:34 ----D---- C:\Windows\system32\Tasks
2014-10-02 14:33:48 ----D---- C:\Windows\Temp
2014-10-02 14:32:51 ----D---- C:\Windows\system32\config
2014-10-02 14:30:39 ----RD---- C:\Users
2014-10-02 14:29:55 ----D---- C:\ProgramData\9a0fddfed70e753
2014-10-02 14:28:46 ----D---- C:\Users\masina\AppData\Roaming\uTorrent
2014-10-02 14:27:57 ----D---- C:\ProgramData\NVIDIA
2014-10-02 14:27:02 ----HD---- C:\ProgramData
2014-10-02 14:26:57 ----RD---- C:\Program Files (x86)
2014-10-02 14:26:44 ----D---- C:\Windows\SysWOW64
2014-10-02 14:26:07 ----D---- C:\Program Files (x86)\GTA3Mods
2014-10-02 14:25:34 ----D---- C:\Program Files (x86)\Google
2014-10-02 14:18:36 ----D---- C:\Windows\System32
2014-10-02 14:18:36 ----D---- C:\Windows\inf
2014-10-02 14:18:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-02 14:10:24 ----D---- C:\Windows\Tasks
2014-10-02 14:09:30 ----D---- C:\Windows
2014-10-02 14:09:25 ----D---- C:\Windows\system32\DriverStore
2014-10-02 14:09:25 ----D---- C:\Windows\system32\drivers
2014-10-02 14:09:25 ----D---- C:\Windows\system32\catroot
2014-10-02 14:03:25 ----D---- C:\Program Files (x86)\Common Files
2014-10-02 14:00:22 ----SHD---- C:\Windows\Installer
2014-10-02 13:57:34 ----SHD---- C:\System Volume Information
2014-10-02 13:56:07 ----D---- C:\ProgramData\WindowsMangerProtect
2014-10-02 13:52:30 ----A---- C:\Windows\win.ini
2014-10-02 13:45:14 ----D---- C:\Windows\Prefetch
2014-10-02 13:39:55 ----D---- C:\ProgramData\ProductData
2014-10-02 13:15:46 ----D---- C:\Windows\winsxs
2014-09-29 19:51:14 ----D---- C:\Windows\system32\wbem
2014-09-29 19:48:44 ----D---- C:\Windows\system32\wfp
2014-09-29 19:48:44 ----D---- C:\Windows\system32\catroot2
2014-09-29 19:48:41 ----D---- C:\Windows\registration
2014-09-27 17:53:00 ----D---- C:\Windows\rescache
2014-09-26 07:20:48 ----D---- C:\Windows\SYSWOW64\sk-SK
2014-09-26 07:20:48 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-26 07:20:48 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-09-26 07:20:48 ----D---- C:\Windows\system32\sk-SK
2014-09-26 07:20:48 ----D---- C:\Windows\system32\en-US
2014-09-26 07:20:48 ----D---- C:\Windows\system32\cs-CZ
2014-09-25 17:39:44 ----SD---- C:\ProgramData\Microsoft
2014-09-25 16:37:15 ----D---- C:\ProgramData\Origin
2014-09-25 16:29:12 ----D---- C:\Windows\servicing
2014-09-25 16:29:12 ----D---- C:\Users\masina\AppData\Roaming\Skype
2014-09-25 16:29:11 ----D---- C:\ProgramData\ShopperPro
2014-09-25 16:29:10 ----RD---- C:\Program Files (x86)\Skype
2014-09-22 08:42:39 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-20 07:56:32 ----D---- C:\Windows\Logs
2014-09-19 11:29:20 ----SD---- C:\Users\masina\AppData\Roaming\Microsoft
2014-09-17 18:23:19 ----D---- C:\Program Files (x86)\YouTube Accelerator
2014-09-17 07:15:43 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-09-16 14:34:41 ----D---- C:\Users\masina\AppData\Roaming\omiga-plus
2014-09-16 14:20:16 ----D---- C:\Program Files (x86)\Adobe
2014-09-16 14:20:12 ----D---- C:\Users\masina\AppData\Roaming\Adobe
2014-09-16 14:19:41 ----D---- C:\Program Files\Common Files
2014-09-16 14:18:36 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-16 14:18:32 ----DC---- C:\Windows\system32\DRVSTORE
2014-09-16 14:11:37 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-09-16 14:08:50 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-09-15 14:31:56 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2014-09-15 14:25:42 ----RSD---- C:\Windows\assembly
2014-09-14 11:14:29 ----D---- C:\Users\masina\AppData\Roaming\DAEMON Tools Lite
2014-09-14 10:43:11 ----AD---- C:\ProgramData\TEMP
2014-09-12 21:19:57 ----D---- C:\Windows\debug
2014-09-12 15:00:52 ----D---- C:\Windows\Microsoft.NET
2014-09-12 07:49:32 ----D---- C:\Program Files\Internet Explorer
2014-09-12 07:49:31 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-12 06:59:34 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-12 06:57:27 ----D---- C:\Program Files\Microsoft Security Client
2014-09-12 06:57:26 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-09-12 06:57:02 ----D---- C:\Windows\system32\MRT
2014-09-12 06:52:21 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 18:48:00 ----D---- C:\Windows\SYSWOW64\wbem
2014-09-11 18:48:00 ----D---- C:\Windows\PolicyDefinitions
2014-09-11 18:47:59 ----RSD---- C:\Windows\Media
2014-09-11 18:47:57 ----D---- C:\Windows\system32\CodeIntegrity
2014-09-11 18:47:38 ----D---- C:\Users\masina\AppData\Roaming\ProductData
2014-09-11 18:47:38 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-09-11 18:47:38 ----D---- C:\Program Files (x86)\SupTab
2014-09-11 18:41:08 ----D---- C:\Windows\system32\LogFiles
2014-09-11 07:14:03 ----SD---- C:\Windows\system32\CompatTel
2014-09-05 20:19:34 ----D---- C:\Windows\SoftwareDistribution
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-07-30 241696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2014-04-29 213848]
R1 {2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64;{2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64; C:\Windows\system32\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64.sys [2014-08-05 61632]
R1 {2b929fe1-284b-4766-afb9-19b0915b99b0}w64;{2b929fe1-284b-4766-afb9-19b0915b99b0}w64; C:\Windows\system32\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}w64.sys [2014-10-02 48832]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2014-04-29 516096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-05-12 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-29 60416]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R2 SPDRIVER_1.37.0.202;SPDRIVER_1.37.0.202; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.sys [2014-07-22 52584]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2007-08-09 13680]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-09-05 196384]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-29 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2014-03-26 14112]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-04-29 18432]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
S3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service; C:\Windows\system32\DRIVERS\InputFilter_FlexDef2b.sys [2010-06-19 17920]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2014-04-29 166400]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-04-29 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys []
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2014-04-29 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-04-29 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-04-29 29696]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-06-10 54784]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2014-04-29 33280]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-07-22 3427208]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-08-30 920864]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-09-15 75136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-08-29 414496]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2014-04-15 2185528]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-03-13 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-03-13 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-02 68608]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2014-05-04 2152736]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 Update focusbase;Update focusbase; C:\Program Files (x86)\focusbase\updatefocusbase.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-19 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2014-04-29 27136]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-02 68608]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-25 114288]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2014-04-29 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-11 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-03-13 50872]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2014-04-29 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-03-13 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-03-13 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-03-13 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2014-04-29 27136]
-----------------EOF-----------------
Run by masina at 2014-10-02 14:36:30
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 6 GB (4%) free of 134 GB
Total RAM: 4095 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:37:09, on 2.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe
C:\Users\masina\AppData\Roaming\miner\minerd.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\SupTab\HpUI.exe
C:\Program Files (x86)\SupTab\Loader32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Program Files\trend micro\masina.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp& ... 4_343E7F8D
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp& ... 4_343E7F8D
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: eee1ef70083a013208d37190b1a6e5ef0063429 - {11111111-1111-1111-1111-110611341129} - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\ProgramData\ShopperPro\ShopperPro.dll
O2 - BHO: YouaTubeAdoBlockke - {bd21c7f7-d467-4b95-8f46-6552160fff79} - C:\Program Files (x86)\YouaTubeAdoBlockke\G8UxyUpPJxJQ6S.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [mncgnfjSrv] C:\Windows\system32\mncgnfj.vbe
O4 - HKLM\..\Run: [MSStp] C:\Windows\system32\msstp.vbe
O4 - HKLM\..\Run: [mncgakmbeSrv] C:\Windows\inf\mncgakmbe.vbe
O4 - HKLM\..\Run: [msfpoxuSrv] "C:\Windows\system32\msfpoxu.vbe" msqbit msbfpiu
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [miner] "C:\Users\masina\AppData\Roaming\miner\nircmd.exe" exec hide "C:\Users\masina\AppData\Roaming\miner\start.bat"
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\masina\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [RGSC] D:\GAMES\GTA\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [EADM] "D:\GAMES\ORigin ORG\Origin\Origin.exe" -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update focusbase - Unknown owner - C:\Program Files (x86)\focusbase\updatefocusbase.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9024 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
C:\ProgramData\IePluginServices\PluginService.exe -service
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {A4A8B7C3-3C39-4AC4-BE9A-ECA3BAF7578D}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\SavePass 1.1\6df3fd71-f640-4846-8266-c7fa64cee956.exe" /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='0' /bic=CCCA49A8DF7E49A7AEDF798C03FD154BIE /verifier=fb02a82073014edf4aa3acf35db1e006 /installerversion=1_35_09_16 /installationtime=1411058915 /statsdomain=http://stats.newclientonlinestorage.com /errorsdomain=http://errors.newclientonlinestorage.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newclientonlinestorage.com /runfrom='task' /externallog=''
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe"
C:\Users\masina\AppData\Roaming/miner/minerd.exe --url stratum+tcp://eu.ltcrabbit.com:3333 --userpass tetroboylp.cpu1:cpu1
\??\C:\Windows\system32\conhost.exe "2854358472135954990-302555317635516246-1675070690-701124794-1154935056-970703377
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\CCleaner\CCleaner.exe" /uac
taskmgr.exe /3
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\Windows\system32\sppsvc.exe
"C:\Program Files (x86)\SupTab\HpUI.exe"
"C:\Program Files (x86)\SupTab\Loader32.exe"
"C:\Program Files (x86)\SupTab\Loader64.exe"
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2904
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://isearch.omiga-plus.com/?type=hp& ... 4_343E7F8D
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=716.19003ce0.2112644093 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 716 "\\.\pipe\gecko-crash-server-pipe.716" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --proxy-stub-channel=Flash3924.6F173FA8.1155 --host-broker-channel=Flash3924.6F173FA8.18887 --host-pid=3924 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe" --channel=1268.0033F334.259201147 --proxy-stub-channel=Flash3924.6F173FA8.1155 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll" --host-npapi-version=27 --type=renderer
wmiadap.exe /F /T /R
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
taskeng.exe {F887E707-F589-41BD-BEF7-FBB67013F3FC}
taskeng.exe {DE97F150-A8CA-4B96-A58F-4583EE78788E}
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\masina\Downloads\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\097303b6-b048-49fd-90e1-a57e1215487e.job - C:\Program Files (x86)\SavePass 1.1\097303b6-b048-49fd-90e1-a57e1215487e.exe 001504 CCCA49A8DF7E49A7AEDF798C03FD154BIE 63429 1411058915 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 SavePass 1.1
C:\Windows\tasks\6df3fd71-f640-4846-8266-c7fa64cee956.job - C:\Program Files (x86)\SavePass 1.1\6df3fd71-f640-4846-8266-c7fa64cee956.exe /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='0' /bic=CCCA49A8DF7E49A7AEDF798C03FD154BIE /verifier=fb02a82073014edf4aa3acf35db1e006 /installerversion=1_35_09_16 /installationtime=1411058915 /statsdomain=http://stats.newclientonlinestorage.com /errorsdomain=http://errors.newclientonlinestorage.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newclientonlinestorage.com /runfrom='task' /externallog=''
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-1.job - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe /rawdata=G/eQa/eJ9AC+lQwThnkdlFjJErLt/FMkb7M1K7llYeus3s4TLkUyTiwF+yNClGyGoq3A3H0pJ0AxS1tgryfJJs6lwPDJOzQ0u/zGU1LO5pHBcBC38YX6ctzGJexpOpfNGETDdY7uTAvw3oT6H7aSO+v9LUsFkbKK826AiRV+LnyWR4ccfyg7ZpV26XTJ67sl9lSQux9iIVKoVNZ/jzH1GV8GIUpCPf9KLNvsmZFVs5sK2cCWS4Snd2Ks04uGr894D7Uwd0yclug+PYOECL+eZBK9vdVNK9GGRftpvha8pnbmZCfIAEEXKRs4KAMVMlSvONc4mR4sqluajPVmyuU8KBokMTyj1FQsblg61ofDKrA+vpzRHUjUKlFy839YiAnsJP/XtW48UTj1RilEtcXppe7TJLuvuZr4hffccmnKXtNiHInsM0GJBVia+AQxACYhFisfW8o7Aw2BI46tYdxOK0J21Nx59mtuGyTMTrP5+XhWRzEJ9u21MZfgTB8vuIowQN4Qi3d0IbSY9WxUcQiP74i2R3I95q9gxYM3GndefhQ6v4GXgNnDDM2HFs6SZC2n66yZaR4YNq21dfQWRKhN+A2zsdOP+xMFSoIx3DW4oNM0yPN/TrEJJPQa4Qrxbq6hPtKj5aAT+KbpUHXNpgnaj/B/EQ0Jqh6Nb5IL83GuFNVQAg40V0uuib1oNsJVUU5/6H7nGPTbHDeiYR3OlZ3dMUkvcWIPmaNTpeemabLkAzyKH+KsjxagG4EXGFLN+84U96nntmlFV1ka3eNdBsDTgL/I0RU/Zfy4peuV80+RwzWuIE+H7xy5D7CrRGFVm15PO8Wa8DJhNA3Mg7TjZY8frhpotiwypDJgfHQIMPJbE5n4evVnGhSAtXA3aEdzaRZbOhBzVFg14nx3aaTaO4Cf18K5JdC1P4s13yKFy88Q5EZSsGp+YaQCuHgrys1jfHat2Zg3UVoUnxWGGsPSdPTEAaIN5h8TQQWCKjkiPTlXiPCwwpWEEOn35KqLGc5pSXnXEvLG1AEe4KnXzgYhtZXAKqkMlZd06PN0nHOz7qNZBkqj9kMo2HxZkorwZ+NRihgiEouR7ujdnev1NXf/NJhx5374HqYdMeyMFkIHMqLfSfKkdBfxn5VYX/t+5OGTkJdoOzWA2W0eDqmGR28jvvGUYY0rtJyKHx7EddZvsgRcOcg=
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-11.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-11.exe /rawdata=p2k3YC8kX43yNQAlCOoLO/jB9IWDpMg7c6ieqwDVigM80kv8HQGBbKxwPdZinA1mnfq/WroKVvmc3YHggv9ghQ0X0CuNfeAVPGlHOF/IRxSpE+OlmYEEm0WHUzQPOZYCooNrB1jltepzmyyKy83ZQgWS9oYORrV5s1vpEYVJlf+uyLX3WnvydjGIqYsoQeEpVHaqCqDluyhJ4ojf6kHby32u1HENQ1decJ0SBeiG2I7sTcJ9oNbFlulU2jhMkR5eXZQ+7kJjtkRh0pqbgi6ig/UEB/KjMjsZiEuhvq/XheA3iqrFnhoSodYvyYpQHF/2Jlx6NrTwtzb5jjDu5qTb3oiFRg5Qsje+4OzPTlwvexej+dMeI1xjPGyrsqyEjuzaCTtKdnp9t7NCVm8OeQ7se1fUlBqHaw219RRqp38Sm7OpcFb36uSkHPHatDPwQ0lZ7Ncg7W0kYE92IMXkJ56xTamZqs3fn7R11LS3ux2dRjeRM9vSK9L2j9GPg7gzoRKyKgdxVUoEyBGI5e3w2TqoT5TpDIpZ/jCalwJFExK4mH83Gpvkgis2xT22hRF0DP7QsuRZwFhH2L61SJzKJMblZ4ezw7AwgKptf+tfy2OGNFiWyCPihDg/Q5rwol63FdBJLc4uizIhc2iTzXdy1PdUgRsmSD3kAU0nysaV8YSgnWNiKHSicYqgdxgf7/BPgzby8PLqSlenMk3Z1as5XbzUndPErwvxHxg0cFlp7iIZfS2OsZKzVlKslBYBGog6yZXzFRz/ZMq6ZQpA7IGSgy3wCLHdGBF0hPonFZMWAgYb1PqOJIiKD6X1VJG+0HIwaS1LquTnM+RKBpg5iESCXAVzogUrxIYkOssndUMxztc1oXw8T16tzX0BA7Nw+yHU5tmbmQCq++alFz8fcFchEmtJxsRu1MjlXjfp3j/xB3/2LQB07htKmXL5iMpjtWIbjYNrZrq/47Hjj0q4FwHHWj9sxFIYI42ArHkZoSHFtReZL1G4nTEuujCYsYQmud8f8GIcTvNsAgmiGMHCtcMd6EaSpD6ifonymrS8A9DBuD7WIArmSgpWSieMzZ1uJgpyDIXu6+bysL0AWbIQeFlcjKw2zTlZ7f1Huufl03hqUd0c9ApL5rV+yCrvpHH3Jlp1WYECjfK2luXHHHPrZBWsyCRI6q+zVPmMU4NmwPuMLZyW4rN1/V4fAcUIiz3ZeLm9gyyOI+s9UPA2KG0hHtNtafVLBe1oh7jFSJw6+/QGyjmlIdyp0YHBgxjxn53AxDVB2lQumtxru34xreioKgkvU4RHuQZx1mF7XhRsaTguoqSF7uNWmIkMzD0oBuWboL2EI7YkD6Dj+Zo+iR3iBK7SAipJMpkLn5eXqm8ALWdUilbs8SUztd37k+11xJDIltsEDTw11j0aANd+hVCEIPGbpJeDM1vjKW59I7A8018J2dx9uf/hK1v5Pi967hYVwQfIXwRdyTBdzNMMUahI3p454zlZwGyx83ii9xOKgOp9nVK+e1V61J0oghUC1DS760CqOMjtk/slgBYvknvwKFkJe47N7Dr7UWV+b9nLkbKksd9ZLwg73tFDxbatx2XhwvYw8HLzn+DO15RVHFYyXra+Y+s8Fz5l+FFCJNLhFWIMMrkHcCkgw5AHHU4FpLg0Hio+kCH20lBjUsxuKv0ZhbZnsJCSaVoyGSsD4VbMtpPP9DlHS7lDV/dpE092jqpUo4DjrRJ8bmZvDo5V6v9XVmbMkYQ/HiF9n3ZInAJYJ5haSf7crv6rijIJZN+WhCsv0Ley74JJE+xf3dsyKRk4boFzd5QOPNG07tc0gpEXb0aXCp8mK+COxV1vvHbKCWqjqCJ3BaK+3OYansCS5Iw/1maxzZ0/mw01frjEZKzKpwOX0iOndbfjedEJb3AfAeQqASnSzSxn6E6IHJOzLEjDKT2kJfJPUwJS0Pn80zLJrf9wXIyG1yZuAL9rjaBmXbmPj0kk8NYeyj6hesztGwN+exe6q/lEYNSqTNiGBmZa+1ixo9wDp6dpPjle+FutW2bZk8l2Y8fF
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-2.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-2.exe /rawdata=CgmdSlVbS2hZm+5TPmMVbd++0Uq9ny/PXdnBMuqX1Tvlk4JoFAvyzfdzS5OS6ukYOk8v3wJtGup/omgav8AFLjPH2rrRM46h89U5RIgleGQgnfKypbAoqySZGt7FJnB2B9QIAghKD9J/28TK8BUSKwzPIUzQg4wfwBnVV0sjWSBYP6rR0Oe04AP8LDCmfRufbHvin4Wl3winOI7QVPtVDybB4NXg6+3jSNMpi2tuEoTIESp60s0kQRCqPKOcRSg5nAUPn4NfqP733ER4yIBiXuPuCveHtX/K3/2JK2Zv8lrNrAtBlbBH/LMSfO1AtR3Z7bMxwP2mCR6wHtSqWzyFvk9jIlwXEx4+XEV+AU484vBg0vg2OrzoFA9yElF1LY+3+06+ywhXl5AH3GsqFyIQpn21BVnh7JyJfhV3rPkVlGzeBNzaLcgYZI5t5qzlyH6ezK/zB2DMLcOQk/EtqT6VrLz3edpPACFOXEHt7woWG33xJBSMp+YSP5FrOnoBoPkEPPDlmLGlfZdIdxTGTKNkWvHqkYxG+GMemQ0rxIUKfhqxWhRNRZAqbpphimmLoxP6A1b4hteEP+8hC5rQrOb1K12LapqpTAiVHkajRoORYELcIiJXicNk4/ZIgb6BM4nPJQ/PFWSEyi4EEW+esMuEFOD58FlIrEVaG1oWxijIVkt0zv7Mze4e9Hm2lEHW8IfIuike1vp3rgnMmQxB5M9o23fz0MfKQE7drN1/0HSgiTwswJZ67Ho/8ACrcckg97A3pjNd2gMovuK75mvItO2w7MzUGGj2qeF/HWTWg4H0dGFjsti89HyKy5hCpaHrtZFreitqaoFCCliUzxFXPLqHUg==
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-4.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-4.exe /rawdata=n2pFoBdsixQMGTzF4GEN+l4kAL9zzanVuMcImj1+W99sFGHoeYHX+imkvKx/QlatUbZgqB7CaBQMEzMxTPTS/ne+lRi1gy3afF6NizoGRN4Qtpe75FHDKLhQy7brlIdJ0tWhgiNgdkroYqjJK6ci2ZIhROVBdlVaAyUxufmpeNObtHdHWSyeZelSg5SoPHdjccfccFf8qq1J19qvw3nCFBGSxyTWJAYIzdtZ9uxPBFDC32kWIOUiR2BM/9aegSIuf3oubuWUwYuZtdJ2xIqBP6Bsdcj4p3rAt9XymCaT3frny3r8FOsqhG3NLDadO8RWcw6T24ww19NFug0ZWvU/2pnp6Um01nfm63e6j0tq+IUjGe3iDPN8mX6UjfhqPUMv/HqPMxhq98WZa2bH5QFAVwo7qtQ5EKBCyfM0+/gFddXx8GUCL8L3+q8Yz0w5sQ14gKGpvCV94o32kvr2v8bgi4y0c5aE1bU5hCuXk3hE/Kq5XvNDLdg4hZaKsOoH6zw2FqdGzdaUTwGRgKc5YweRl0YjOck13CYT1+6r9dcpJY9z4MamDGA/qBHlTWLKIMSIXU30OyMV4DPa1rJmdIz/NBHLCy2avSywksxQJqyGNj9Pyzr+sJCbMrnLOzqiSexirwA1Ad7SceSbv+pIHQL/0eajmOLIIOPYRfUp/ztn/eUgxgVxV69SDX/7/ClNjH8StXzsJjpBR2kqGprgnJlSbivlrPUhQHa8cfX07PhC9kfBwH9twXRt9ZnRlhyy0kRPkUEJkyxt+wJBe7QNTPjq8+1x7Dz4XunsSNOfvbJ1c5/0ZIw9tv/MEV8ME7ijcuj57DbPZblCTXZBZHELKijuFiVh305UU85EHFDGEmhoU0y7hYNqR3EbJH+I06vMLucvqBy9L7jeJ3GeHHHvDDPehpqD2nLYypjr2fhZsCGxhS6gg+x8hH1lcr7scyVIRVFV2UUurE/ErJzwvMCqNiQLYFM4FGgVYkTrjbumon26iwoOH3Wy/VVVakY8LgbxaTKObIyfO0KfIcNwTtsVNMygdkOyi1SdSq0wiSIPiwwuwPQ0kbtEB5Gc4NgGQeP2M6HgKzplhk106Enugasnd61AqxZ+1aBQ+V0OlFQRRwx2/6I5c4xjI3z7cbuQWNb1idwJutgbW5mw0eTeaf9Rt8FERPwwrtvnT5Oon5Z2avjRVP2SjADJAkeesDoxi+LatXCIg7fsxEQG+Nhc9PS0J03Pdk9uOwkJzcw75E2mRLIkzoGm2D+r2eMSmq95Rek3LiOpgOWPdkO9vs7UK75g9yXFAP+GNWXo7wKU1RLb0tgtYAdyXS1lsvWrNkjKzn64eUVvPZ6PDyrcHT9ATHVNOFsh3iG6jbCrK6nEL1QtXLkEKuUVgevzg+vrMB0gLty8KKwhXHATRgmlM6THsFANk4eyQSptSWcenWv441hAQ+UmdYXREYnv/ulDoqQq9uIzohRivMvkCXMKG8F0v+gt+LsyNi7jcQ86ScDwZDnlQXLsK7VqqtEwLNXuw/PVHgHGkCPN
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-5.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-5.exe /rawdata=lQYJAUQLFOYS2qw2D1iN5hbdEx6CBez0w7jNjabdHwJeDYYpTwdtMdlfYXay6zx6JXbwnobZ6ja9O00CR7fnoyO2ps5NJHNS0SdWtPqASrZLeJnhQAXlMevZ/lzV/Try98TrH/XY0YQfpnuPfuFCIs8FOF92SnP/91r9ycoEjeWf1YiyiCPd/QNyh3VuQRf3qW63E4ys7CshwE2fSRf+4XevCAXVlb/bOBtyrxZM5/nyWFpqM62iJEgPOQAfzSITycZ4profgQNSwyjmB1cNHA+tUDIriLIuuDMhgXDAG/PrwsXDJZVvNs+sq+FnVa5j8tXiLSXXOG8JuodTg6H7agNXa+1pKz3bZwUyoEj1Tfo7+G9nqGxjqlRC7lLU6odA0EuzJl5uU8UZS5erX2WGAIyhoI6xLMTN2r5/5lg+87hodql5KiFA6TZHOLvENXe2NjD9qz7odZm3yRbqSHhgtQDp38VjJiqdi1B+9XoxnjomilAy4ggtN8eBmxLFRiD0U3uUl17UOUZKpKQvhDrTPbZ97AZCexbcN6zd3+/0rhBhgeMYGhIgGJ+ZbqHEjAIMWzjGZWaV+pyVV69Zo06lxl7T+sH5svqJ4K4J/uYVyFaXIkngnhQ/GH2izKHHPAjwT5OKaMf0sf4dbkvvZNQGrlU5IKvu8podIpE9LWeC+uszp33hAVBlI8C46jfzGWjWaQc9MBlH83wNenCEkV1m9VDj5KGNp+ORAHSLoqY+53CDS7aDDFJrQBBZDW350y9BvpbtC/4dnFnvyf9Ymh7Mv+j/aI/IPlGTrk88XukGUhnYFy/y+YNwofXRlsEnTQ3PY6osdnncTLz+ZtMEU1/9WmsRmrHcQuBEFuO1I+zwykbWvonXODmittb/PR7TgIV6hDlMNXrgb+kYiMkUtynvbpKP98JWQlNn0y/ZuiHZt0CNAxzRD/m3eWe80agi4xJpPYouTfM6KAuGbtuz3o1qepEU2ZZTrC6SZQ8OKfuE8q6r4FzAQsGDWUnrxD8EHrkT
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-5_user.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-5.exe /rawdata=lQYJAUQLFOYS2qw2D1iN5hbdEx6CBez0w7jNjabdHwJeDYYpTwdtMdlfYXay6zx6JXbwnobZ6ja9O00CR7fnoyO2ps5NJHNS0SdWtPqASrZLeJnhQAXlMevZ/lzV/Try98TrH/XY0YQfpnuPfuFCIs8FOF92SnP/91r9ycoEjeWf1YiyiCPd/QNyh3VuQRf3qW63E4ys7CshwE2fSRf+4XevCAXVlb/bOBtyrxZM5/nyWFpqM62iJEgPOQAfzSITycZ4profgQNSwyjmB1cNHA+tUDIriLIuuDMhgXDAG/PrwsXDJZVvNs+sq+FnVa5j8tXiLSXXOG8JuodTg6H7agNXa+1pKz3bZwUyoEj1Tfo7+G9nqGxjqlRC7lLU6odA0EuzJl5uU8UZS5erX2WGAIyhoI6xLMTN2r5/5lg+87hodql5KiFA6TZHOLvENXe2NjD9qz7odZm3yRbqSHhgtQDp38VjJiqdi1B+9XoxnjomilAy4ggtN8eBmxLFRiD0U3uUl17UOUZKpKQvhDrTPbZ97AZCexbcN6zd3+/0rhBhgeMYGhIgGJ+ZbqHEjAIMWzjGZWaV+pyVV69Zo06lxl7T+sH5svqJ4K4J/uYVyFaXIkngnhQ/GH2izKHHPAjwT5OKaMf0sf4dbkvvZNQGrlU5IKvu8podIpE9LWeC+uszp33hAVBlI8C46jfzGWjWaQc9MBlH83wNenCEkV1m9VDj5KGNp+ORAHSLoqY+53CDS7aDDFJrQBBZDW350y9BvpbtC/4dnFnvyf9Ymh7Mv+j/aI/IPlGTrk88XukGUhnYFy/y+YNwofXRlsEnTQ3PY6osdnncTLz+ZtMEU1/9WhpcF7mr5ZreYmeit+mVj1ChZ2bEKYcWRkyP5YPuNiKNYh4e9H4eq2N9GODqCKFuQCl2oHxpbtdZrPlKD4Fy8+WXwnZOvNsiai/cAn1c30yXFMgfnsgREf2dd97FmTQXRREipdNkYncFKSs1N4ws1Yss1HgJvnP7jRXYtcPGmU0Q
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-6.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-6.exe /rawdata=NMWz51km1gSZXatavL/7pP0HHxOieSmFSesXcgXceKrzI4jZNnhu8r1f43aD8UWMfYCkx8bkAuM2o4i9c++NmhSEbumKFrkFvXCfBfGWlHlMNtwmsopguC8HrFBvW+bS1wJnshh86VgJ97kiCr4JFW7o3BwyObg0irTcbXmrPqwyfGWodFkCEXYrCA+LiyaEAr7uW97u6R/16JLawWOQ9VVLCJSSJ8QEUF5RMcfFVH6/V7ApYSfnHG7PiDsx6523bdimGQk0mINyJ0AWhC7gur2gVjpTZsZi3Xvs59trdQduABFHBjx7H8eTVRlDlfo8NUO0m7c/iswotoa3Zj22eyZbsSifs6mWw+Xe0lgvpmBLFMmm/ov8M9e4Jj61LlYhh1QQxwMpxW4jd9nqSFSFJ5NmGcyRtRs8hKENt1poPuiLpJ1TBVVYnPTrw5W005kHBO5t4e+L9MuPz+msTnZNTbf0GhpW3IB9MYIfQjLPjdSc+hDpojJ7RFQPUD65Yg2DFX6p7L6IGHl/RYhLqx+bYdrWd9/X4yMMpF0IuBTscqf/OGIZ1edO7i05y2J7nDhFOUNE/qZU+b6qq5TcDCw8Sm2voxo0S2fR3Y5R1TUOxZMDEYafGIHsDaFZrt77YqPqJQ/ueUZihx/GRU0/+iZnXzAOSPOqYbsKRhmDNLTiZqNwaYSKS87Kdzz4foPnq4h41VoWrhUTQubgwnjR4fIUQRvB09q7ThyNLd4/MKMttOrpDQaXolsqU8sHfe1V09QF3pIEAowcQcMC/8zyFSk54b9Osq3EgwhAJYbkpq9bEzS0FFBGW3W5oKsriOAqMe1rO8NlWzlJ0tncGSLLMPPsWmrug5u12RFZ/yA5X0NQlHa8zQacGnYH9RDMQ9dKHlwqkXXhVfywDM+Jqq2JbRMS1iL4tR3Zl4Ot5HviD7/dlss4ZaQ35E/2o+6U7T2KVOhu3ig0g8heh+esZjJ1wr1gL0W9zJdOKAzORY2EqTg8v/niAU6n2tad+xJ4uHAGZmZdaEeuTiufuoRN/k7K+a+GNg2Zh3Dt0BOilX/ViQK69zptCvtdLvs97CJt3tre/ee3fr1Q68pKfMn227mvZ5KdpK0KrXn/jgJXTQ/ksdXfPPezUbwCTS+Ia2mZ+H3C7wumcIREgm/z9e9oZFpKn6yX/MrzO6qow8Cccw0+YCyiI6kuCeLHiTOPSpD8q5B0/nGyp1ZK1LQpHKhUy02J+p1OTdO3c9sYxWtmyNsg1NKcoSrdnGp4BLIgc3ek/xlxcHrouJX3DOMAU4gjDG8bR4DSIW0Zq8c1Sgnrf/bkAiMp2L3UkFj28FUMCOpsb4LWdN3v9zbxgF02Tj7bp1LLePxhs09SiwPfOvhBylOKe4CwngZj6WvlNvVIalaPuApCaDMQ+gsvy/QxrT2dDf189UdxLCnCSy4InZTicF1XeVKq0qPJBgtkhaUn3Ss8vguqLG21zntXeS7MnDzXL6uAJObMdVSxds5n3/1cWiHAevBnMrt6Whhj8/aC68HPT9QKB2NA
C:\Windows\tasks\7abad424-0b2a-452a-a110-32d11125f0b4-7.job - C:\Program Files (x86)\SavePass 1.1\7abad424-0b2a-452a-a110-32d11125f0b4-7.exe /rawdata=UsCh5Fed0FRwWn5yo5uFEpQiuAuumlwwRlSQtxkCqBodIDeVii4ffGTplDSnOHT/dj3cGaOYX2xf7aZDwJ48JAlKp3StuFKamErgTOLt6/hWTNqmS2/fwkeDslrbRQXh4wcZum881z8O/1wvXONILBqttrm8iwnwcW35wPBfttOOxtxaD1nIP5LDBPMi8AZOc1i2rhqnRt2zlHZLGQ1tsPCyVKeKEPM9f5g58WPlrFRu1qhwPkVKHVsgg8npkT88aOubg0yT6cyj1j/TmjchgH8zSdXYU1kVAJZ49mMSTcfWwm8AuBBY3UOiMiNSdrKe0rDXkfiW1QeMXlfKxhOi4pSoYqbrNpaIjnMnHHhqJxWE1hu6kyzLuEbi3HC066G5qpMFrUC04vxZaxmIil4QJKb0N/RqjpIh0twR7LHyzXnyjsYeNX1nBaakcB24imvB1+O+7Lngio9fDks+Fcvm7ERG6qx3pszYT2UsLU0sZs5GqB1887634w2K1AEKK5/cxt0yvyaXlJ0PDxr3Y4VLR/Nhv2riHEegcPLKeaDjYvlKRRWcDc38KmPFPAyae8Dw6PR5rouaAhpWdpXGq6Jo0rKm7aDVXT5E1A1SRgYJeLUEgqApLmAx/HKsCoLy7ehSquGEnpQWZ9rNMwwF1LBnrTZNWD7uxUq2jBV+RUKHpmY+h+gcYBx7AjPOGOEHfDkNowj3K/F08ATqqfQ685ZnM9lAWOEKoKbzWkBbkETFBkCrA6vTCuYJXlVI85OnmapiWiZKOa7tieejU6z4Rx8rAgYrZq3InrsN499H60UuVNOtgebDl3eTN5aJTTmhWkuQ3q3jWeBaSZq7CoOgcrR1KRJ3TfxK3+A46OZf9leyu03J52TsutCQVbVsMiK50nsPO0Ya9kUz0+GLVJrvQxCOVa2s/8yC3mGwgLpNL9CPHoCFdfT/RW9shWepoT18zDFAFfu2HSoMlEqbnqW6z1Maj7hsaAHcensiwH9S8AWVMSFz6LKoVAi+2tgMc9Uyppu4ag0KlyjtZzlSh0DJ/Sn67Sd45ofS6Zdl2SWxOlEjADLs+OhAEgBfpNdcqBCWYWmvUxYUL9OT/LfU4EMT6k/tLJh9bneeRN1/+74bsZX6o7Q8m44lmD9siU4hT1aZGwQEzn3TFS1xpgxF32NQIosdB3tkcJOp8QBaurHwH2+w044leeG4CeG60RpVTQpOh2YY15YJm/jPGZsP/kJ5ZU1NRN0Y5lyDjI5Y60aiHdTFc4Co/Tj8M0LDs9UG8mvPCSVB9KLMJQsFHk95et0pZwruu5NdkPYui3G4jmLg5/oza9usaHtg6/9I14Miux4hDM/pDHFwbcKhq88qVyJkBvDVcQ==
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\masina\AppData\Roaming\Mozilla\Firefox\Profiles\kq77xfhl.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.4.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Users\masina\AppData\Roaming\Mozilla\Firefox\Profiles\kq77xfhl.default\extensions\
0UG@3.org
http-nowhere@cwilper.github.com
n@P.co.uk
VJKPXI46039420@JMZUIOB85844870.com
{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129}]
SavePass 1.1 - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho64.dll [2014-09-18 825240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro64.dll [2014-07-22 500584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bd21c7f7-d467-4b95-8f46-6552160fff79}]
YouaTubeAdoBlockke
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129}]
SavePass 1.1 - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll [2014-09-18 611224]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\SupTab\SupTab.dll [2014-07-22 515464]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-23 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
Shopper Pro - C:\ProgramData\ShopperPro\ShopperPro.dll [2014-07-22 418664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bd21c7f7-d467-4b95-8f46-6552160fff79}]
YouaTubeAdoBlockke - C:\Program Files (x86)\YouaTubeAdoBlockke\G8UxyUpPJxJQ6S.dll [2013-09-14 621056]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-23 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"miner"=C:\Users\masina\AppData\Roaming\miner\nircmd.exe [2013-08-11 44032]
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe [2014-07-22 3211776]
"uTorrent"=C:\Users\masina\AppData\Roaming\uTorrent\uTorrent.exe [2014-09-19 1416016]
"RGSC"=D:\GAMES\GTA\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe /silent []
"EADM"=D:\GAMES\ORigin ORG\Origin\Origin.exe -AutoStart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
c:\users\masina\appdata\local\akamai\netsession_win.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ETDWare]
c:\program files\elantech\etdctrl.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"mncgnfjSrv"=C:\Windows\system32\mncgnfj.vbe []
"MSStp"=C:\Windows\system32\msstp.vbe []
"mncgakmbeSrv"=C:\Windows\inf\mncgakmbe.vbe [2014-01-19 1342]
"msfpoxuSrv"=C:\Windows\system32\msfpoxu.vbe msqbit msbfpiu []
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.exe [2014-07-22 3211776]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-10-02 14:36:32 ----D---- C:\Program Files\trend micro
2014-10-02 14:36:30 ----D---- C:\rsit
2014-10-02 14:27:02 ----D---- C:\ProgramData\WebbbiNga
2014-10-02 14:26:57 ----D---- C:\Program Files (x86)\WebbbiNga
2014-10-02 14:26:44 ----A---- C:\Windows\SYSWOW64\setup.exe
2014-10-02 14:11:43 ----D---- C:\ProgramData\NextCoupe
2014-10-02 14:11:39 ----D---- C:\Program Files (x86)\NextCoupe
2014-10-02 13:52:59 ----D---- C:\Windows\system32\appmgmt
2014-10-02 13:48:28 ----D---- C:\Program Files (x86)\Seznam.cz
2014-10-02 13:47:35 ----D---- C:\Users\masina\AppData\Roaming\Seznam.cz
2014-10-02 13:46:42 ----A---- C:\Windows\system32\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}w64.sys
2014-10-01 19:49:15 ----A---- C:\Windows\system32\qdvd.dll
2014-10-01 19:49:14 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-09-25 18:10:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-25 17:19:09 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-09-25 17:19:09 ----A---- C:\Windows\system32\tzres.dll
2014-09-25 16:51:38 ----A---- C:\Windows\ntbtlog.txt
2014-09-25 11:38:53 ----D---- C:\Users\masina\AppData\Roaming\Guild Wars 2
2014-09-19 11:29:20 ----D---- C:\Users\masina\AppData\Roaming\Macromedia
2014-09-19 11:25:36 ----D---- C:\ProgramData\McAfee
2014-09-19 11:25:24 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-19 11:25:17 ----D---- C:\Windows\SYSWOW64\Macromed
2014-09-19 11:25:13 ----D---- C:\Windows\system32\Macromed
2014-09-18 18:52:01 ----D---- C:\Program Files (x86)\D3Crack
2014-09-18 18:48:43 ----D---- C:\Program Files (x86)\SavePass 1.1
2014-09-18 13:22:09 ----D---- C:\Users\masina\AppData\Roaming\Mozilla
2014-09-18 13:21:59 ----D---- C:\ProgramData\Mozilla
2014-09-18 13:21:58 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-16 14:20:57 ----D---- C:\UpdateChromeLinksLogs
2014-09-16 14:20:40 ----A---- C:\Windows\SYSWOW64\mfc71.dll
2014-09-16 14:20:40 ----A---- C:\Windows\SYSWOW64\gdiplus.dll
2014-09-14 10:02:10 ----D---- C:\Program Files (x86)\YouaTubeAdoBlockke
2014-09-14 10:01:47 ----D---- C:\ProgramData\GoSaVVe
2014-09-14 10:01:41 ----D---- C:\Program Files (x86)\GoSaVVe
2014-09-12 07:01:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-12 07:01:42 ----A---- C:\Windows\system32\ieui.dll
2014-09-12 07:01:39 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-12 07:01:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-12 07:01:39 ----A---- C:\Windows\system32\iernonce.dll
2014-09-12 07:01:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-12 07:01:38 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-12 07:01:38 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-12 07:01:38 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-12 07:01:38 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-12 07:01:37 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-12 07:01:37 ----A---- C:\Windows\system32\vbscript.dll
2014-09-12 07:01:37 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-12 07:01:37 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-12 07:01:36 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-12 07:01:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-12 07:01:36 ----A---- C:\Windows\system32\msrating.dll
2014-09-12 07:01:36 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-12 07:01:36 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-12 07:01:35 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\iesetup.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-12 07:01:35 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-12 07:01:33 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-12 07:01:33 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-12 07:01:32 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-12 07:01:32 ----A---- C:\Windows\system32\mshtml.dll
2014-09-12 07:01:31 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-12 07:01:31 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-12 07:01:31 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-12 07:01:31 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-12 07:01:31 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-12 07:01:31 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-12 07:01:30 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-12 07:01:28 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-12 07:01:27 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-12 07:01:27 ----A---- C:\Windows\system32\wininet.dll
2014-09-12 07:01:27 ----A---- C:\Windows\system32\iertutil.dll
2014-09-12 07:01:26 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-12 07:01:26 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-12 07:01:26 ----A---- C:\Windows\system32\urlmon.dll
2014-09-12 07:01:26 ----A---- C:\Windows\system32\jscript9.dll
2014-09-12 07:01:24 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-12 07:01:23 ----A---- C:\Windows\system32\ieframe.dll
2014-09-12 07:01:22 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-11 11:39:41 ----D---- C:\Users\masina\AppData\Roaming\Battle.net
2014-09-11 09:14:22 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-11 09:14:22 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 09:13:44 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 09:13:43 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-11 09:12:47 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-11 09:12:47 ----A---- C:\Windows\system32\schannel.dll
2014-09-11 09:12:47 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 09:12:47 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-11 09:12:46 ----A---- C:\Windows\SYSWOW64\certcli.dll
2014-09-11 09:12:46 ----A---- C:\Windows\system32\certcli.dll
2014-09-11 07:25:22 ----SHD---- C:\Config.Msi
2014-09-11 07:14:59 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-11 07:14:59 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-10 23:04:46 ----A---- C:\Windows\system32\aepdu.dll
2014-09-10 23:04:45 ----A---- C:\Windows\system32\aeinv.dll
2014-09-08 13:56:38 ----SHD---- C:\ProgramData\SecuROM
2014-09-06 09:24:51 ----D---- C:\Program Files (x86)\Splashtop
======List of files/folders modified in the last 1 month======
2014-10-02 14:36:32 ----RD---- C:\Program Files
2014-10-02 14:34:34 ----D---- C:\Windows\system32\Tasks
2014-10-02 14:33:48 ----D---- C:\Windows\Temp
2014-10-02 14:32:51 ----D---- C:\Windows\system32\config
2014-10-02 14:30:39 ----RD---- C:\Users
2014-10-02 14:29:55 ----D---- C:\ProgramData\9a0fddfed70e753
2014-10-02 14:28:46 ----D---- C:\Users\masina\AppData\Roaming\uTorrent
2014-10-02 14:27:57 ----D---- C:\ProgramData\NVIDIA
2014-10-02 14:27:02 ----HD---- C:\ProgramData
2014-10-02 14:26:57 ----RD---- C:\Program Files (x86)
2014-10-02 14:26:44 ----D---- C:\Windows\SysWOW64
2014-10-02 14:26:07 ----D---- C:\Program Files (x86)\GTA3Mods
2014-10-02 14:25:34 ----D---- C:\Program Files (x86)\Google
2014-10-02 14:18:36 ----D---- C:\Windows\System32
2014-10-02 14:18:36 ----D---- C:\Windows\inf
2014-10-02 14:18:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-10-02 14:10:24 ----D---- C:\Windows\Tasks
2014-10-02 14:09:30 ----D---- C:\Windows
2014-10-02 14:09:25 ----D---- C:\Windows\system32\DriverStore
2014-10-02 14:09:25 ----D---- C:\Windows\system32\drivers
2014-10-02 14:09:25 ----D---- C:\Windows\system32\catroot
2014-10-02 14:03:25 ----D---- C:\Program Files (x86)\Common Files
2014-10-02 14:00:22 ----SHD---- C:\Windows\Installer
2014-10-02 13:57:34 ----SHD---- C:\System Volume Information
2014-10-02 13:56:07 ----D---- C:\ProgramData\WindowsMangerProtect
2014-10-02 13:52:30 ----A---- C:\Windows\win.ini
2014-10-02 13:45:14 ----D---- C:\Windows\Prefetch
2014-10-02 13:39:55 ----D---- C:\ProgramData\ProductData
2014-10-02 13:15:46 ----D---- C:\Windows\winsxs
2014-09-29 19:51:14 ----D---- C:\Windows\system32\wbem
2014-09-29 19:48:44 ----D---- C:\Windows\system32\wfp
2014-09-29 19:48:44 ----D---- C:\Windows\system32\catroot2
2014-09-29 19:48:41 ----D---- C:\Windows\registration
2014-09-27 17:53:00 ----D---- C:\Windows\rescache
2014-09-26 07:20:48 ----D---- C:\Windows\SYSWOW64\sk-SK
2014-09-26 07:20:48 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-26 07:20:48 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-09-26 07:20:48 ----D---- C:\Windows\system32\sk-SK
2014-09-26 07:20:48 ----D---- C:\Windows\system32\en-US
2014-09-26 07:20:48 ----D---- C:\Windows\system32\cs-CZ
2014-09-25 17:39:44 ----SD---- C:\ProgramData\Microsoft
2014-09-25 16:37:15 ----D---- C:\ProgramData\Origin
2014-09-25 16:29:12 ----D---- C:\Windows\servicing
2014-09-25 16:29:12 ----D---- C:\Users\masina\AppData\Roaming\Skype
2014-09-25 16:29:11 ----D---- C:\ProgramData\ShopperPro
2014-09-25 16:29:10 ----RD---- C:\Program Files (x86)\Skype
2014-09-22 08:42:39 ----N---- C:\Windows\system32\MpSigStub.exe
2014-09-20 07:56:32 ----D---- C:\Windows\Logs
2014-09-19 11:29:20 ----SD---- C:\Users\masina\AppData\Roaming\Microsoft
2014-09-17 18:23:19 ----D---- C:\Program Files (x86)\YouTube Accelerator
2014-09-17 07:15:43 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-09-16 14:34:41 ----D---- C:\Users\masina\AppData\Roaming\omiga-plus
2014-09-16 14:20:16 ----D---- C:\Program Files (x86)\Adobe
2014-09-16 14:20:12 ----D---- C:\Users\masina\AppData\Roaming\Adobe
2014-09-16 14:19:41 ----D---- C:\Program Files\Common Files
2014-09-16 14:18:36 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-16 14:18:32 ----DC---- C:\Windows\system32\DRVSTORE
2014-09-16 14:11:37 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-09-16 14:08:50 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-09-15 14:31:56 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2014-09-15 14:25:42 ----RSD---- C:\Windows\assembly
2014-09-14 11:14:29 ----D---- C:\Users\masina\AppData\Roaming\DAEMON Tools Lite
2014-09-14 10:43:11 ----AD---- C:\ProgramData\TEMP
2014-09-12 21:19:57 ----D---- C:\Windows\debug
2014-09-12 15:00:52 ----D---- C:\Windows\Microsoft.NET
2014-09-12 07:49:32 ----D---- C:\Program Files\Internet Explorer
2014-09-12 07:49:31 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-12 06:59:34 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-12 06:57:27 ----D---- C:\Program Files\Microsoft Security Client
2014-09-12 06:57:26 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-09-12 06:57:02 ----D---- C:\Windows\system32\MRT
2014-09-12 06:52:21 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 18:48:00 ----D---- C:\Windows\SYSWOW64\wbem
2014-09-11 18:48:00 ----D---- C:\Windows\PolicyDefinitions
2014-09-11 18:47:59 ----RSD---- C:\Windows\Media
2014-09-11 18:47:57 ----D---- C:\Windows\system32\CodeIntegrity
2014-09-11 18:47:38 ----D---- C:\Users\masina\AppData\Roaming\ProductData
2014-09-11 18:47:38 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-09-11 18:47:38 ----D---- C:\Program Files (x86)\SupTab
2014-09-11 18:41:08 ----D---- C:\Windows\system32\LogFiles
2014-09-11 07:14:03 ----SD---- C:\Windows\system32\CompatTel
2014-09-05 20:19:34 ----D---- C:\Windows\SoftwareDistribution
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-07-30 241696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2014-04-29 213848]
R1 {2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64;{2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64; C:\Windows\system32\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64.sys [2014-08-05 61632]
R1 {2b929fe1-284b-4766-afb9-19b0915b99b0}w64;{2b929fe1-284b-4766-afb9-19b0915b99b0}w64; C:\Windows\system32\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}w64.sys [2014-10-02 48832]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2014-04-29 516096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-05-12 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-29 60416]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R2 SPDRIVER_1.37.0.202;SPDRIVER_1.37.0.202; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.202\jsdrv.sys [2014-07-22 52584]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-06-27 2753536]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2007-08-09 13680]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-09-05 196384]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-29 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2014-03-26 14112]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2014-04-29 18432]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-10-15 117760]
S3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service; C:\Windows\system32\DRIVERS\InputFilter_FlexDef2b.sys [2010-06-19 17920]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2014-04-29 166400]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-04-29 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys []
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2014-04-29 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2014-04-29 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2014-04-29 29696]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-06-10 54784]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2014-04-29 33280]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-07-22 3427208]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-08-30 920864]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-09-15 75136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-08-29 414496]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2014-04-15 2185528]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-03-13 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-03-13 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-02 68608]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2014-05-04 2152736]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 Update focusbase;Update focusbase; C:\Program Files (x86)\focusbase\updatefocusbase.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-19 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2014-04-29 27136]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-02 68608]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-25 114288]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2014-04-29 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-11 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-03-13 50872]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2014-04-29 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-03-13 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-03-13 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-03-13 139944]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2014-04-29 27136]
-----------------EOF-----------------