prosim o kontrolu logu
Napsal: 11 pro 2014 09:48
Logfile of random's system information tool 1.10 (written by random/random)
Run by sef at 2014-12-11 09:39:31
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 15 GB (13%) free of 122 GB
Total RAM: 8139 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:39:48, on 11.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
E:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\aida64.exe
E:\Program Files (x86)\TPUCapture\TPUCapture.exe
C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe
C:\PROGRA~2\Raptr\raptr.exe
C:\PROGRA~2\Raptr\raptr_im.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\sef.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daum.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.*.*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: eee1ef70083a013208d37190b1a6e5ef0063429 - {11111111-1111-1111-1111-110611341129} - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll
O2 - BHO: 2142d562cda342799c74bac15bb026030068153 - {11111111-1111-1111-1111-110611811153} - C:\Program Files (x86)\Sense\Sense-bho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ControlCenterCount] C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe
O4 - HKLM\..\Run: [Fast Boot] C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Raptr] "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup
O4 - HKCU\..\Run: [CCleaner Monitoring] "E:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [CCEnhancer] C:\Users\sef\Desktop\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2.exe /AUTO
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-21-1463186153-2632091326-3034755131-500\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background (User 'Administrator')
O4 - HKUS\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - Startup: TPUCapture.lnk = E:\Program Files (x86)\TPUCapture\TPUCapture.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/Nirvana/ ... cmatic.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB022049-4C4B-4C3A-8A21-C6C0BE63B89D}: NameServer = 208.67.222.222,208.67.220.220
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - (no file)
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - (no file)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - e:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Moborobo Device Service (MoboroboDeviceService) - Unknown owner - C:\Program Files (x86)\Moborobo\MoboroboDeviceService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_FastBoot - MSI - C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
O23 - Service: MSI_LiveUpdate_Service - Micro-Star International - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PST Service - Unknown owner - C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 9131 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
winlogon.exe
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"e:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
C:\Windows\System32\svchost.exe -k LPDService
"C:\Program Files (x86)\Moborobo\MoboroboDeviceService.exe"
"C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
"C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"taskhost.exe"
taskeng.exe {FF0E207E-8386-492E-91A4-B02B0317E842}
taskeng.exe {57726FB3-EA96-4378-8D46-05A805D6DC22}
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\SavePass 1.1\f025b33d-4fe1-43d1-9072-60df121c2890.exe" 001504 971F64B27F234AC0B6AAF2A9542B8569IE 63429 1417149375 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 SavePass 1.1
"C:\Program Files (x86)\SavePass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe" /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='167904785' /bic=971F64B27F234AC0B6AAF2A9542B8569IE /verifier=6d03157a566d4768035584e8f611bb25 /installerversion=1_35_09_29 /installationtime=1417149375 /statsdomain=http://stats.newonlinedatastack.com /errorsdomain=http://errors.newonlinedatastack.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newonlinedatastack.com /runfrom='task' /externallog=''
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Logitech Gaming Software\LCore.exe" /minimized
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"E:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
"E:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\aida64.exe"
"E:\Program Files (x86)\TPUCapture\TPUCapture.exe"
"C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\PROGRA~2\Raptr\raptr.exe" --log_to_file --from_stub --newver
raptr_im.exe
"C:\Program Files (x86)\Raptr\raptr_ep64.exe"
C:\Windows\explorer.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2416.0.49538135\2078440858" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x1002 --gpu-device-id=0x6810 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.301.1013.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.1.529698009\639649112" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.3.1832840561\1526696552" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.4.2086127896\389876990" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.5.303117273\1189827045" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.6.179550522\1669668342" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.7.1881437686\2134994189" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.8.1243923220\1781124732" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.9.1349236475\2120228737" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.12.959790832\1733812321" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2416.14.439990625\957516847" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.16.1952414849\1426370979" /prefetch:673131151
"E:\Download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.23.632390786\1773540195" /prefetch:673131151
======Scheduled tasks folder======
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-1.job - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe /rawdata=W7Y/C2U2mi1QcsgJG/5KPy4hbRuwHzyu5LRys9TEiBSuH6WgLTbvkA+krwa11jNe4EllbxPidd5P3CWj+VQZjOZTosLkGQFcz6pg8+Jit7Tuqist3I7TnxlTRhbgSQ3GxIu0uqwhE2FobSmKB3dXmwVsOshR+R05TVhnAfA2rLuwMLsUKZ4HDWS+XcFpxzN5tdb0ZSYmoRs9SBHCx9iK89j/pUfKyXxfrj97b1Rj5gzqzRp4d1W/k1/b2VxdlzV0cP+GpUjNYqj1GxxnaR31WyDchbD119I+DIO5nII8Z2fhUY87xwVLGEnjH9wImNjWoclb1AO3tobkQ4Q0Jw6eNYqcWz0VC2nFhwcfA0sqQiLaKl1KlPlO+32mZ1gAGR00atDBjY/ytr6JOIY2/fV0p6j3jxs6/k3yEbVHEKb1DB+UdRPXQ4QaDKqq5uxzNwryA4LtNoafCn9qWFxlyVKbbg5wYfA4qXuMsClV0T7J3R0wQRhOYgr8WFgqxBLOuImVUWO6wxrkQ21ZX7Z7h/b5E+uBpJbAZ60qA4Qwwmj8lyDx8BQallMb46uF490HJjDIt/ePwils45GCKYhIP5SEcSAl4/KS7U5UqrEFEJcvnYxm7BhV2YGkZzhrVjjIN43FR4ZW83o2iYoiAenu0ODDrQHt1uZvUmCbtI9lEiz7tQtrqKcDhs/E1pQOlUEOgImOolndDfCSt7PQRmAjinUYz7xhE/xQdtyyf84l5cpXxp8dCZ4bQ14YZ+ojfRO8PctvSjeyGX8T0ikr9BpY1WeDM5GyzzfS8+ciGpRNDMvRQC1sO2auLw8fwV74vKbKZk0mS/XtNxfj1TtqW0Hj5KVBzzDdGn85f1MuoNZoBz9KtAEWTzwyp29++sRz88N9ONzyujWUF/KVjN/vqfP2CfRSSbkOIi/EplbUj7zZ6D9k3Y8SoRk6JheY6QYigBM+/sjU+bUplO2K8UV+YHGiyU+BefDgGsQf0/DffPCHJbGtvuKOlDKZbrJg4gpnNbepYhDMXdG6PIHiyopNJgnqA7IsActbPUnBxYsqkdSlAopm2sL+IeEzZc76FyJOnVfEBscIwTV82iX8CowS7Hzs30iIJiZSA9eUOKAnFIoIpLtJ5TS81KJu1Jz2hFeeD0038HSGCTDNQRFgmpzdl6SS6vKbhcl3Ck+SfXnuSzxSJ77Uh0GM2uSx72Upc6YPgc/yqXavWJB8+NHhTUB3NwlnTAulPBFuey9N6ncX30dT41xsyJICf1f2RLen1UttdXrxGN6GmmUneit0tdtyGnP3jSvvQHdF4BMOsZvkiv8i53dj0RpPYGeSl9vqTEJRZS/ppUem6vXK6Mg/r5gAerPL5tN2A20ay5sj5derY1TmObzMeXaXQLXkeAatjOzVqcR7nrzqdckfvN6JVri0Ykz/8OuGK3RvwjzuvFFVEkgxnM3e2OPzDNblNja9N35voJ29pivpE+EQBoHBJN+Bp3yMB5BVO+f6Ou0gMzNrVMpawNLrVL02pnr+FVFe0Nw7ecen0xy1
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-11.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-11.exe /rawdata=IAyjVvt7e3YBICiB6iZ3mTRS0cHx8zfTkjcTKC0abFdubjBKtPTZGh0odGxvX6W3nHVd6Zy+vrYKRh3bo3LxMD4Rmc462L2QkBNkgC6Jnf2uj4SEq9OaS5GiIjSld1J1q5AhHibj9Lnj/UdQ/9XhzwSMBjbmZhLrOct6EvneH5q3Ay9XekxUjs9WUOMvS62gR+3sIgwnTr36EwI/E/OKzOKrWcevy/yM+LaL/LvfnX4D7VNYUXAn/4QcObA3vU8SaVygVl4cLkcw//XKR9WoLRPatBQJgHc31LLCeqBicXtjjDj936lgNNxkG+icCSiLAzKnKivecyrbCJfbwIzcxz6a86YCos6K48gKg+KAteOv0iRHaAT/i9NdFwRydmCufMYbLbERF5LC+wyZSTuXNhRpoofrU+iTI+jQLyT3pCogQHR9t/XIfNOpey73HB/N6w66v2FEcAinU725ylzgMXyGZZgvyi7ZxaPnMtBfojuQKWQvKeMw4gYu5Cy8Im1qmqIUTqgPuRRAsVNGKOQY1+mdSy0bsjT+mDcdkHUTxKwlf25+U3G9fJs98r/aNiojffdlg4bw9tp2zwOJsHsQQSiDoZgh791VDXALIbN92gz5zOiAangaqsJ2eTyOxBohXNH8jmyE9IrJ2vj9QOdKJrNZ4msUcmw2HwA1M2uEh5syl7ye98OxoXQjKdg8NY4N7WoHahTTUF5TC80SMQCygCp5jsR6JLmo2v5vcJD2ld0HmIWC8QeYXVQV55UU4U6GUZ/L977GTFybSwldIshIRUR479WIyu15a2XTbNi7lr7MjuXe2xgAITxD+IqEp//WZ15VmND2Wf8tq+u1bgJ/xBoUjJeu7vNJWYWvtRJn3rJd8qkBcWwQQ1gNkfgZF/hnll8Uu8/PXp8emq7HUnmnJ0nhdQ0K3BfE3QBXCxPEhdNpGQCo2L4HzNGDs3uOnisQCNpoeYylatz6h7BJVkaRJi4Q0zMHrT9iBmHQBiQD5/pzczRvE/k87U2ho2KnBEdugEIH0SfVAUNy10OsOhIRhFMm5TYw371IA3GoHFYvsB2PPTFbxvMgClTj9KH9hdZ8Fl/U6HJJBC6zgWy96G8h/DL+Y293HoUmSs/+dii2BUDbthWgXJNjpW7izWw3DPv611Iwsb8X6tIWXMbgvwxM2WtCI77tjpUYs0mp0zOMFVkpw7/7nRnGyUxVPp+OnS+8Nnnv1g+tzy1Hg0urymDVhrUATEp9gIEYA4thGZ6fvtrF8CsI1EICQjDGe7//T1VABET2XpxyrpJidetPomSdVUnlRRd9URXhqjCqN133souBt3pjrFjFhpPMCkinV6i4SkyZpYjWTuboCFdhM/UDOVyih3+lHQFDw06r9WWtakiiD53xir5Mu8OhiMsozlk/MxK1XPB9DhzSoWlHX69p6PSpyR8OJ7WnwcdFcm6YseVsCqb7chPosEuvxKIlS0MJziHfSz2lSlSkO/0PYwlj/9zGiCZRkFOuApmgrxLd60wjlaxebq7OHH/ZCNwkl6qUuV0EnuiSXX4shoISnXje4pgIxKkP0eEBnfoCScXN2sR0/foCSDp7LULrl3y8c7pYJ+mGYRhh9pYjNh0joTjrpjp2MnQKYBhuM/FKsas9vi+Td3forsw03c0PVN221GArr+ID06yxSx2bGFiHIHBDBuSYE9A6Pp05oRzhgwghxJ21lESczHHgPJRe82bkEG0TvSFC9A6W1iIeeViu5IIvZchwoNddAH6VrNqG/4SW8gqlhdWsZb2gLAWw8HUmtW9o7oSlSfvTQJVmg1GNWiT6/8rjCSEAn3spNkYncXitUlW6kg4uEF3Orsp7ZAWGXPTSggCGWcoy9lIqSJ2kaxToPAUfAj5JoHull51R6kqcua2BNAsek5gOtaCC0fuQQeQkt25DIK966ukv3wHLor7lHXhBMo0aI2HTGjfLu3ZH7DpsKEBcLtz3tbjsfYZx44/nnlQ6E2F3A08bYeeN19ccEBmhnjiVJIrr6FQTwNfc9s7AzhTo0zGdPrbupbjDiIRwoO7DpRKVBdMx0R/FQZJlZlN+PZJl5TzEeatyxcrFmT0FB+XhciHLU8+puJS0THzDVLoMUQpmFxFlsmTI4f6ukZeNsG5mQid7p1UVoNSfJqC6/ruyr5C8WMrkt7u7z8Fb0kjdXTRRwMUAmO95FeeeFSzRZvsyM7CbAAoLa8qFAxNPOxxg3RoMEdQ2MWzvv1rCQxU7dRQFZdMHMH8gpVGwQ0/RBdP4vx3T/JSsN2M9iCAWBjsNhJuScbwXFBezIAYOCwn/F1TR0MJzBHtGGOI2dh/qrbM/P1DQIb8DQd1qcHkWRc0desluznPr7cScFYBhngEZfWOAqpAD4oTir+Zxjw==
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-2.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-2.exe /rawdata=izA118TQ+apea9dHCUQbHW155alsfeFdToEmbh9gQkxh5osK5y1UAxRC9MLaoQ+ztqNul4Xcv0iqBjPg2nHXhQSQLjH1sW1kkroVoncyFxjxus9p9PX30UySNeiUZMB0LYr6QG06rx3sZNqZow0yrevPDdbsoJ7x1E3KaT/cfeTGXhKsQWHQGqEnx/R4yyfmz4LRXzrVMizoeqCg29yA2+Qri7KjM3Q5bXKUeICZ9dHx8JqyA6f9sEwrJ2mz2IoEk82yzUW+Yzi6BPGgygu5eMkiiHoaZubR0n9ZwrAhFwRLON7iq2PyKzqNUTKMKmxcwiA0l+THoG5lBm01F2W1s6GE4YiQ5HITLCBPo7f5OOilAwQcfZ3iPKrITfKG5/5iZqOFn/NeiBl2VJMYBtwyRR/fVTYjBjTh5vfaKyTND3XCFl52w7vZO6Hz7lXmPnbknfQlSURa4rhOOgSmN3p+j6+M4A3SP0pLHz8mxhTYC54JUmS0DQCkHcsnG/xhvvmDrT2hHt0mF5+JD8x1hLccE1M2a3BNqk1N9w0ypsINQQqGKa+bsXeweubLD4PtfFPp5EcUr2PNGNOvOdluVvTfejcTlsTrlobs+Jk8qhDDmMOr+6qAFS+N+WBPe+/87KOqCDuM5YLTpZ7YX1iOgBWMvowQzL9+e8VqU4yE2qKx03Ff+A2XyE6y6RJUAGXV4XLbxoj0AjzNFT1ZOk5f+pr7/ymYrOuGUkgVcuCMn9IvDZdqjhUcxic22MKT0q+GLECmYYSA2pl1+cMoHzclDbrVOxziNqGq6IjwkHtu4Frb/ImXFhNlKvxniYN8FMuUn6QN0JzFgJg742xtHzGwMN+O3Q==
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.exe /rawdata=aTEAQ5T2Uk6wAsXeadHw85VCIZL7Ye4KlgKhFzlaQzrYjv/AameQpszMWphOzuHq6S1bS4pGliXXkJwIeRqgWnYk9ajpyYmwYDjlRs+jnLNBC39Clgbr14L0pR2Dt+JU/AGrCuLLs9OXcAJzVFivZAS3kcsiqTcDO2N1WVPakrU1PdQtyyex4fi45eF7krVONrtaF3SgOGvURqhy82aGSQMQaCBHSePSiH3DMGFSWKzGIgG2vsemFYmvUKyAfe4HEy4wNNQ1ylDKKQvUYSetkQB6DCipmuf9QynL/LVPXQPj/rnZhru9INPlaYxO6xqEgn81RDHm8sioGSz2141raSryZQ8kAf5B2O6xayTloS9QC3A5x4TSXVYhtA8wocK4i8RNOIqo4477Vsz3XVzrU1IPPIGqOvu/8y9Xaf46lWTH/TtjdOJmKrjgkXkpwPlc5ipuQPFqJ5c5jJnoedoBnUTgNK9pSA1S/OKwfaRs8vnWaQVytQlB6H5jaFLaw2X2A6eKxXisyJy1hkDgA/E/0vde5fY/4vNWSph8TAqoLvIvBirGFRHkAYtq9Y7KQ5CrXABpXpLuVqNgv953y9r7VefuGY159KmSQXRoNoAjMe3ceYc27ZTyKR6Z7MpZkuCs5Pj9IvcLjOmBiHuwMRDhzhA3oVMbI9hEjIhWpoI/SLpj3HyUzWuZDgSMJ+nwVsz2EjMxwUR374HLmAdHVFuqK+5vFO6JfMAOS+i7Fmlgf2+5FVzuU8jBRUXvYbF8tIliY/Y9SbGGfkV3iRKuShTqnrczxjwgXvilPbamuOGTirNCW3z+GRuYqjTqgHMHwXKXTGB6L9dzDb4NH2P3tfS2ww1uiMuZlrjbxf3S+Snkm5pkssPjAxwhE4UMTNGow4SIFImZlSD2e7IfAShHDiZZZFsifw8Mes8K4JyzOQCt6U7KoRoY5edDtOcEioX4QAjBgJv4LwIBDD4a4vxtzcCKiYxMdpOju6oH125fIkbgI+ET1b/9LI8yCSXt4XBDTSyO
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-5_user.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.exe /rawdata=aTEAQ5T2Uk6wAsXeadHw85VCIZL7Ye4KlgKhFzlaQzrYjv/AameQpszMWphOzuHq6S1bS4pGliXXkJwIeRqgWnYk9ajpyYmwYDjlRs+jnLNBC39Clgbr14L0pR2Dt+JU/AGrCuLLs9OXcAJzVFivZAS3kcsiqTcDO2N1WVPakrU1PdQtyyex4fi45eF7krVONrtaF3SgOGvURqhy82aGSQMQaCBHSePSiH3DMGFSWKzGIgG2vsemFYmvUKyAfe4HEy4wNNQ1ylDKKQvUYSetkQB6DCipmuf9QynL/LVPXQPj/rnZhru9INPlaYxO6xqEgn81RDHm8sioGSz2141raSryZQ8kAf5B2O6xayTloS9QC3A5x4TSXVYhtA8wocK4i8RNOIqo4477Vsz3XVzrU1IPPIGqOvu/8y9Xaf46lWTH/TtjdOJmKrjgkXkpwPlc5ipuQPFqJ5c5jJnoedoBnUTgNK9pSA1S/OKwfaRs8vnWaQVytQlB6H5jaFLaw2X2A6eKxXisyJy1hkDgA/E/0vde5fY/4vNWSph8TAqoLvIvBirGFRHkAYtq9Y7KQ5CrXABpXpLuVqNgv953y9r7VefuGY159KmSQXRoNoAjMe3ceYc27ZTyKR6Z7MpZkuCs5Pj9IvcLjOmBiHuwMRDhzhA3oVMbI9hEjIhWpoI/SLpj3HyUzWuZDgSMJ+nwVsz2EjMxwUR374HLmAdHVFuqK+5vFO6JfMAOS+i7Fmlgf2+5FVzuU8jBRUXvYbF8tIliY/Y9SbGGfkV3iRKuShTqnrczxjwgXvilPbamuOGTirNCW3z+GRuYqjTqgHMHwXKXTGB6L9dzDb4NH2P3tfS2w6UD2DjezPcPjJLwTCap0UNOSRm4u5HvmieemkKesoyfevi5ITv7XR+fBs/zVqOmbG3+KuKk4XPBgH/3lrEcbG8uWBIX1QxTlnByEDlOeclhHQMeGbuKEGB1CkSFSCTpyKL3ZTpyhCgigxT+Dnhh3X61vHnYKLEg5C+Q/Ixrsfee
C:\Windows\tasks\5432e15e-8b38-4917-9568-a8baef47582c.job - C:\Program Files (x86)\SavePass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='167904785' /bic=971F64B27F234AC0B6AAF2A9542B8569IE /verifier=6d03157a566d4768035584e8f611bb25 /installerversion=1_35_09_29 /installationtime=1417149375 /statsdomain=http://stats.newonlinedatastack.com /errorsdomain=http://errors.newonlinedatastack.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newonlinedatastack.com /runfrom='task' /externallog=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\f025b33d-4fe1-43d1-9072-60df121c2890.job - C:\Program Files (x86)\SavePass 1.1\f025b33d-4fe1-43d1-9072-60df121c2890.exe 001504 971F64B27F234AC0B6AAF2A9542B8569IE 63429 1417149375 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 SavePass 1.1
C:\Windows\tasks\fd74a172-49f3-4b56-9556-083971d5629d-1.job - C:\Program Files (x86)\Sense\Sense-codedownloader.exe /rawdata=EEOw26hJ4wiFMUn32OXBsedk1AXP0HNKbw5HeGmXeB4uvvNpTs12zd2YaFZI6cDBejIKo3nPy/4BQReDBJbrvJWEY5WsiqA+Bo6rDR8CHrWyDYLD7plW1522iKNeqG1cUNwH6LN1vYy+if8tiYZieieLGGiwfLzg1uY0TT+kXqAeWYnOwWzNcJ5P/7RQ4ewcphQS/4nvHIQcTNoE3D1T/uIwijLVi1p8JzCSsHm4uX4V7nJX5MyOd5/p/fqTAuBrx+7Lj+mwUomR4qVOBm1U7/2CoydLbn0rJ9nYw9BRUPHa3zLQe6gAJhB8inxPbyOenl3FSPgEoXoMRtttQ8EInSyj+fkBDq7xF15P7jkqwmzJwfo/JgbsOTYQcTOcH5k4Ge3NsQOa6nbrOTtfvuiuXJZ6mmngJLhck/Vezk8rn4XBgy0hv6f0FhO7PW3KeIm7LXgMeVUhLK6zakQnf81MyLI+Nw3O7kcK1QGk1qPgFdgnkBCChK3KMIv+A2RuPTGRklaLojIHbcZUJvbF2zfNs/3CodkAeyjWSYShwYWxqOaGFnPqWvoMxwVmb8/O7jyoOrW47Y64p1Bg0KTfV9Ck7B7Y77wzQ6HBSK1E0MNewSusRy5icPigEC4Ecoaj/hVgQm/DbpIR/4jiDXSYEF5HeSxgbBMvDfrIyIc/ydjlHgSD6cZghpFNssmXiIDxOTrpkSBIrEKZvoP2jRViygweJlYFYc70LsQJ2cOze6/vd3vRe2+ynsWI8oePC7Fy55BdlZkehww5AfNwIJykHl4UyGxsUB6lzTuLt/V8Z66xbfL9KaCcTb4z+M1jXHuHgaU5gbGU+4+DVw51SAx2FQqidg8UHOXBJDVAHlQSZpEjgymtxVxdJ6h14mjg0bImM2DWhVdjnJInF8ruatJL4cHoD1qUgsAF3z/N6RjslsAyTw7NKjZLbkuwNYC+Q2p7tAloX3kB4toc6QURS0i7BzhsFAVBreAmJy1S1dc5GS/dve4Nr4oamMjivqf/0vq9XBHOMM4twHjzgN9eSa4HnUIL29zbGANQBOvhKSpo+B7Y0OMuFAX3yN5TFxHgDK24gzBVIhUuOsJwfSaoDiXowV7Y4EItn/0f9bC9AjbcLjBNzNZiWcHL7QCEhfQCYGOLtF50bwJG8p6q5+kv2u0tw3c+UchowuJNcSPMkGanJJWOMg8l8hLAYl2elT3kqjKZOXIJWPMaM0OrJ3lKwTV1gNjumTeoHgZZdxUVZ6Z/l5Q+/v0pTZTRdxKwYe/pZhGFU1YI6bDzpgZcTbxKsToZl94oGEbYM/Smw6diHPJ/GLVLO5/AHbTqVUijsoXwAjV/CHpKnfYwDZajdZd8sEHCAMc1I7eMjvy1Bn5RNy5CLyu42ie5e+J4zBYoYOyMLBLhGo/ctzekRTfHfeou9tqFa7+gnvJY2quNI+vfbKemAMwcm3T/UzQMQ6IkG6GcapEIncMCYL+R0lEzmWy+B+V8kjCCK80lA1jzov7S/U78aGev7M95SHRCi2PUgxj8BheHLG6za5iRHwM3oYVwnf6BR2IWi9b4CzdJNcKnyuUF9E7lNFG4IDTlgphkOK9o8bz6GAIZTPaS5fW78PWJ4DH53l3W+qJOB777+I4OJ5FUVjP6vXJofcfMKZG+78qNupoZS5sN6vb4g+4GebjPBsQQ9x1s+WqLVsCAcAC8NBIP7F7SuKw=
C:\Windows\tasks\fd74a172-49f3-4b56-9556-083971d5629d-5.job - C:\Program Files (x86)\Sense\fd74a172-49f3-4b56-9556-083971d5629d-5.exe /rawdata=ljDKYv7SOfoyQZf8n5btBIEHlvKu9darPa3JSVHMk4bY5ZxI4DfrqMioWLzfgNqctpBwtcF/LZWEh0tWk4xCihRltrfILjF5hlZl2+i6l7bAvcwf/ozPz10GMCgMBI46LCcMxqns9m0llsiJawn8/7isg7sxCD8wmWU1gEqJj8AcTE7fRJBzHxaq4/l1rT1OyjC8ul6mYQPMQc/XC1vMH1jtRxUbaTM18fbly5rRigV23KBrVZJ/XPjURaxNLKMVhIKLjex0BiWpqvFKHPiij4LcDOARUIFSzhY3Ey3xEezNqZUcCzB2mOFYF//B2agBDgiA2YvpuZoElyaAG6PRoURMb2jbOOFuluPwVxDN7TQW5cMdWAzsGFHFLCnU3hSCcLfks8ECdS6Pf2nk7zbkvvJp2KVySUzaoyP1fnSboJjMkE69Q+NiJWbOrCNO1sY6kIphrsPD07oU9dR+G8jG7lN2YHvhHIb0AKzqaVp8eysPBBRuexBAAq1UDwZujN97CFwl0P2+hjyEIppVYYshuPbNONBJrfCYJvwrys85pq7GHZSZ7ahQJotwWlD1urUw/4Qy16IZyWfOm9ucqmIpdpkz80gPK7/eWNywBB0xQAFIwTF2QbdV3uGjV20xuIH81FvD8m4zzGUNj4EOlGGb4cSHtYY9yImQtk9NU/o+N8ILUcaJeS3zwl6js+LdddPRK/B4vgF1HxucCBQACtQT6Y0tpDX0yrwusA/RG8s+jctxj2GZ8WpH5CeGg2wP5h3Ta+asLInEPcdmrp2GrEDFu+Czy93kTEr9PZXVftgBSBKaSmRs0n4JWmYdLkZkaVvlMiN9P8VW40vv3wjOxeVGdrmUPUOaKwbEUtOC89pAbmyjsfbWxRNxehPQyg+pySy9z/DQZmFaXxhO16QayHanwXIf9hYyAVxb/7HdPvTdpMgDGMfvispzSjsWhI+9mWDMyo5n4rZP8USoEtgdj6KhpcG5CL8z+QRJbhd7IcX+RycJ49IVrglShNCpD4gpQgT5xOpp5NadXxL4ao6GACVc3Lrq1ZFU0WgouE+L2M1bImQI+JPswQkD49hg19TiUyb6nsXZqG5/IhoClmv0zHPvtDddAhOQ8DipLPszjHYfaJzoi1TBM8p3thhpDY5gl+vnveHtO5Ls+tWTgVAG9M8G96dhzkt4tdEPj+15lamb3o8=
C:\Windows\tasks\fd74a172-49f3-4b56-9556-083971d5629d-5_user.job - C:\Program Files (x86)\Sense\fd74a172-49f3-4b56-9556-083971d5629d-5.exe /rawdata=ljDKYv7SOfoyQZf8n5btBIEHlvKu9darPa3JSVHMk4bY5ZxI4DfrqMioWLzfgNqctpBwtcF/LZWEh0tWk4xCihRltrfILjF5hlZl2+i6l7bAvcwf/ozPz10GMCgMBI46LCcMxqns9m0llsiJawn8/7isg7sxCD8wmWU1gEqJj8AcTE7fRJBzHxaq4/l1rT1OyjC8ul6mYQPMQc/XC1vMH1jtRxUbaTM18fbly5rRigV23KBrVZJ/XPjURaxNLKMVhIKLjex0BiWpqvFKHPiij4LcDOARUIFSzhY3Ey3xEezNqZUcCzB2mOFYF//B2agBDgiA2YvpuZoElyaAG6PRoURMb2jbOOFuluPwVxDN7TQW5cMdWAzsGFHFLCnU3hSCcLfks8ECdS6Pf2nk7zbkvvJp2KVySUzaoyP1fnSboJjMkE69Q+NiJWbOrCNO1sY6kIphrsPD07oU9dR+G8jG7lN2YHvhHIb0AKzqaVp8eysPBBRuexBAAq1UDwZujN97CFwl0P2+hjyEIppVYYshuPbNONBJrfCYJvwrys85pq7GHZSZ7ahQJotwWlD1urUw/4Qy16IZyWfOm9ucqmIpdpkz80gPK7/eWNywBB0xQAFIwTF2QbdV3uGjV20xuIH81FvD8m4zzGUNj4EOlGGb4cSHtYY9yImQtk9NU/o+N8ILUcaJeS3zwl6js+LdddPRK/B4vgF1HxucCBQACtQT6Y0tpDX0yrwusA/RG8s+jctxj2GZ8WpH5CeGg2wP5h3Ta+asLInEPcdmrp2GrEDFu+Czy93kTEr9PZXVftgBSBKaSmRs0n4JWmYdLkZkaVvlMiN9P8VW40vv3wjOxeVGdrmUPUOaKwbEUtOC89pAbmyjsfbWxRNxehPQyg+pySy9z/DQZmFaXxhO16QayHanwXIf9hYyAVxb/7HdPvTdpMgDGMfvispzSjsWhI+9mWDMyo5n4rZP8USoEtgdj6KhpcG5CL8z+QRJbhd7IcX+RycJ49IVrglShNCpD4gpQgT5ZHkuY2e5c0l0q4OmpxVNccLplFmYGbKI/dRn7VUCR0k5peylz469YisyuoNlmQJ7LbptJegLa8gDdI4estyx1mmZpSp2OKWvj2QEYZPG2zDLDx5Qo8RED1JJw0F+GUgD5kPTJFzsNvgBgnaHcdqiUQVEXXvvSFq8R30NN0w0imm5DK6AO57Fs1USik8HKUXmHBvLstVXlLpkvYEDMkznO0XgMH1kVJoxASbXc20vU/yfYSqyZLvbvQDwW5zL1a+wQd9Yb6FiCUmfInLjVZuEbRDpxypP73R+kTiIWpGOLKbvMvlgIg688+nm0/vjytI6+MJXqOXBbB5JP+6Ck79hoA==
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1463186153-2632091326-3034755131-1001Core.job - C:\Users\sef\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1463186153-2632091326-3034755131-1001UA.job - C:\Users\sef\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129}]
SavePass 1.1 - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll [2014-11-28 624032]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611811153}]
Sense - C:\Program Files (x86)\Sense\Sense-bho.dll [2014-11-28 746456]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-25 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-25 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"=C:\Program Files\Logitech Gaming Software\LCore.exe [2013-11-14 8292120]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2013-04-03 3684488]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=E:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
"CCEnhancer"=C:\Users\sef\Desktop\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2.exe [2014-11-26 286208]
"DAEMON Tools Lite"=E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ControlCenterCount"=C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [2012-03-26 872448]
"Fast Boot"=C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [2012-09-19 764472]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-11-17 767176]
"Raptr"=C:\Program Files (x86)\Raptr\raptrstub.exe [2014-12-08 55568]
C:\Users\sef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
TPUCapture.lnk - E:\Program Files (x86)\TPUCapture\TPUCapture.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-10-10 441856]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"NoAutoRebootWithLoggedOnUsers"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe"="e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe:*:Enabled:PotPlayer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe"="e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe:*:Enabled:PotPlayer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-12-11 09:39:31 ----DC---- C:\rsit
2014-12-11 09:39:31 ----D---- C:\Program Files\trend micro
2014-12-11 09:30:39 ----SHDC---- C:\$RECYCLE.BIN
2014-12-11 09:30:37 ----D---- C:\Windows\temp
2014-12-11 09:30:35 ----AC---- C:\ComboFix.txt
2014-12-05 09:58:57 ----A---- C:\Windows\SYSWOW64\vp6vfw.dll
2014-12-03 09:58:58 ----D---- C:\Program Files (x86)\SereneScreen
2014-12-03 09:58:58 ----A---- C:\Windows\SYSWOW64\MarineAquarium3.scr
2014-12-01 05:11:24 ----D---- C:\Program Files\BreakPoint Software
2014-12-01 05:10:59 ----D---- C:\Users\sef\AppData\Roaming\BreakPoint Software
2014-12-01 04:48:54 ----D---- C:\ProgramData\Orbit
2014-11-30 04:34:52 ----D---- C:\Users\sef\AppData\Roaming\ATI
2014-11-30 04:34:52 ----D---- C:\ProgramData\ATI
2014-11-29 12:57:15 ----D---- C:\ProgramData\AMD
2014-11-29 12:57:15 ----D---- C:\Program Files (x86)\AMD AVT
2014-11-29 12:57:03 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-29 12:48:42 ----D---- C:\Program Files\ATI
2014-11-29 12:48:24 ----D---- C:\Program Files\ATI Technologies
2014-11-29 12:47:19 ----DC---- C:\AMD
2014-11-29 12:16:38 ----D---- C:\Users\sef\AppData\Roaming\KC Softwares
2014-11-29 12:15:05 ----D---- C:\ProgramData\Binarysense
2014-11-29 04:18:07 ----D---- C:\Program Files (x86)\System Ninja
2014-11-28 20:22:05 ----A---- C:\Windows\winhlp32.exe
2014-11-28 20:22:05 ----A---- C:\Windows\SYSWOW64\ftsrch.dll
2014-11-28 20:22:05 ----A---- C:\Windows\SYSWOW64\ftlx041e.dll
2014-11-28 20:22:05 ----A---- C:\Windows\SYSWOW64\ftlx0411.dll
2014-11-28 20:22:05 ----A---- C:\Windows\system32\ftsrch.dll
2014-11-28 20:22:05 ----A---- C:\Windows\system32\ftlx041e.dll
2014-11-28 20:22:05 ----A---- C:\Windows\system32\ftlx0411.dll
2014-11-28 11:50:39 ----D---- C:\Program Files\DVD Maker
2014-11-28 05:37:46 ----D---- C:\Program Files (x86)\Sense
2014-11-28 05:36:18 ----D---- C:\Program Files (x86)\SavePass 1.1
2014-11-28 05:24:01 ----D---- C:\Program Files (x86)\7-Zip
2014-11-25 22:57:42 ----D---- C:\Program Files (x86)\QuickTime
2014-11-25 17:57:10 ----D---- C:\Users\sef\AppData\Roaming\Oracle
2014-11-17 21:16:20 ----A---- C:\Windows\system32\amdhcp64.dll
2014-11-17 21:16:18 ----A---- C:\Windows\SYSWOW64\amdhcp32.dll
2014-11-17 21:16:16 ----A---- C:\Windows\system32\atimpc64.dll
2014-11-17 21:16:16 ----A---- C:\Windows\system32\amdpcom64.dll
2014-11-17 21:16:14 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2014-11-17 21:16:14 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2014-11-17 21:16:00 ----A---- C:\Windows\system32\atiuxp64.dll
2014-11-17 21:15:58 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2014-11-17 21:15:56 ----A---- C:\Windows\system32\atiu9p64.dll
2014-11-17 21:15:54 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2014-11-17 21:15:50 ----A---- C:\Windows\system32\aticfx64.dll
2014-11-17 21:15:46 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2014-11-17 21:15:40 ----A---- C:\Windows\system32\atidxx64.dll
2014-11-17 21:15:36 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2014-11-17 21:15:28 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2014-11-17 21:15:22 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2014-11-17 21:15:14 ----A---- C:\Windows\system32\atiumd6a.dll
2014-11-17 21:15:10 ----A---- C:\Windows\system32\atiumd64.dll
2014-11-17 21:13:08 ----A---- C:\Windows\system32\drivers\amdacpksd.sys
2014-11-17 21:11:26 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2014-11-17 20:57:26 ----A---- C:\Windows\system32\clinfo.exe
2014-11-17 20:57:14 ----A---- C:\Windows\SYSWOW64\amdocl_ld32.exe
2014-11-17 20:57:14 ----A---- C:\Windows\SYSWOW64\amdocl_as32.exe
2014-11-17 20:57:14 ----A---- C:\Windows\system32\amdocl_ld64.exe
2014-11-17 20:57:14 ----A---- C:\Windows\system32\amdocl_as64.exe
2014-11-17 20:57:10 ----A---- C:\Windows\system32\OpenVideo64.dll
2014-11-17 20:57:04 ----A---- C:\Windows\SYSWOW64\OpenVideo.dll
2014-11-17 20:56:58 ----A---- C:\Windows\system32\OVDecode64.dll
2014-11-17 20:56:54 ----A---- C:\Windows\SYSWOW64\OVDecode.dll
2014-11-17 20:56:48 ----A---- C:\Windows\system32\amdocl64.dll
2014-11-17 20:53:38 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2014-11-17 20:50:40 ----A---- C:\Windows\system32\OpenCL.dll
2014-11-17 20:50:36 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2014-11-17 20:12:02 ----A---- C:\Windows\system32\mantle64.dll
2014-11-17 20:11:42 ----A---- C:\Windows\SYSWOW64\mantle32.dll
2014-11-17 20:11:18 ----A---- C:\Windows\system32\amdmantle64.dll
2014-11-17 20:10:32 ----A---- C:\Windows\system32\atio6axx.dll
2014-11-17 19:54:42 ----A---- C:\Windows\SYSWOW64\amdmantle32.dll
2014-11-17 19:49:02 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2014-11-17 19:40:28 ----A---- C:\Windows\system32\mantleaxl64.dll
2014-11-17 19:40:16 ----A---- C:\Windows\SYSWOW64\mantleaxl32.dll
2014-11-17 19:40:00 ----A---- C:\Windows\system32\atiapfxx.exe
2014-11-17 19:39:52 ----A---- C:\Windows\system32\aticalrt64.dll
2014-11-17 19:39:50 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2014-11-17 19:39:42 ----A---- C:\Windows\system32\aticalcl64.dll
2014-11-17 19:39:40 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2014-11-17 19:39:26 ----A---- C:\Windows\system32\aticaldd64.dll
2014-11-17 19:36:06 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2014-11-17 19:22:08 ----A---- C:\Windows\system32\atidemgy.dll
2014-11-17 19:21:56 ----A---- C:\Windows\system32\atimuixx.dll
2014-11-17 19:21:48 ----A---- C:\Windows\system32\atieclxx.exe
2014-11-17 19:21:10 ----A---- C:\Windows\system32\atiesrxx.exe
2014-11-17 19:20:06 ----A---- C:\Windows\system32\atitmm64.dll
2014-11-17 19:17:06 ----A---- C:\Windows\system32\amdmmcl6.dll
2014-11-17 19:17:00 ----A---- C:\Windows\SYSWOW64\amdmmcl.dll
2014-11-17 19:10:00 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2014-11-17 19:10:00 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2014-11-17 19:10:00 ----A---- C:\Windows\system32\ativvsvl.dat
2014-11-17 19:10:00 ----A---- C:\Windows\system32\ativvsva.dat
2014-11-17 19:06:04 ----A---- C:\Windows\system32\coinst_14.30.dll
2014-11-17 18:55:12 ----A---- C:\Windows\system32\atiadlxx.dll
2014-11-17 18:55:00 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2014-11-17 18:54:46 ----A---- C:\Windows\system32\atig6pxx.dll
2014-11-17 18:54:44 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2014-11-17 18:54:44 ----A---- C:\Windows\system32\atiglpxx.dll
2014-11-17 18:54:40 ----A---- C:\Windows\system32\atig6txx.dll
2014-11-17 18:54:26 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2014-11-17 18:54:12 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2014-11-17 18:52:18 ----A---- C:\Windows\system32\amdave64.dll
2014-11-17 18:52:12 ----A---- C:\Windows\SYSWOW64\amdave32.dll
2014-11-17 18:52:00 ----A---- C:\Windows\system32\atisamu64.dll
2014-11-17 18:51:56 ----A---- C:\Windows\SYSWOW64\atisamu32.dll
2014-11-17 18:49:40 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2014-11-17 15:08:00 ----A---- C:\Windows\system32\kdbsdk64.dll
2014-11-17 15:03:08 ----A---- C:\Windows\SYSWOW64\kdbsdk32.dll
======List of files/folders modified in the last 1 month======
2014-12-11 09:39:42 ----D---- C:\Windows\Prefetch
2014-12-11 09:39:31 ----RD---- C:\Program Files
2014-12-11 09:30:38 ----DC---- C:\Qoobox
2014-12-11 09:30:37 ----D---- C:\Windows
2014-12-11 09:29:31 ----C---- C:\Windows\system.ini
2014-12-11 07:47:59 ----D---- C:\Windows\system32\config
2014-12-11 06:59:01 ----D---- C:\Windows\SYSWOW64\drivers
2014-12-11 06:59:01 ----D---- C:\Windows\SysWOW64
2014-12-11 06:59:01 ----D---- C:\Windows\AppPatch
2014-12-11 06:59:01 ----D---- C:\Program Files (x86)\Common Files
2014-12-11 06:44:17 ----D---- C:\Windows\System32
2014-12-11 06:44:17 ----D---- C:\Windows\inf
2014-12-11 06:44:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-11 06:41:43 ----D---- C:\Windows\system32\catroot2
2014-12-11 06:41:42 ----SHD---- C:\System Volume Information
2014-12-11 06:41:20 ----D---- C:\Windows\system32\drivers
2014-12-11 06:41:11 ----D---- C:\Windows\SoftwareDistribution
2014-12-11 06:39:46 ----D---- C:\Program Files (x86)\Raptr
2014-12-11 06:39:36 ----D---- C:\Users\sef\AppData\Roaming\Raptr
2014-12-11 06:38:52 ----D---- C:\Windows\system32\Tasks
2014-12-11 03:24:26 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-12-11 02:06:22 ----SHD---- C:\Windows\Installer
2014-12-08 18:08:48 ----D---- C:\ProgramData\Spyware Terminator
2014-12-06 22:10:41 ----D---- C:\Users\sef\AppData\Roaming\DAEMON Tools Lite
2014-12-06 22:10:40 ----D---- C:\Windows\Logs
2014-12-05 15:29:25 ----D---- C:\ProgramData\Moborobo
2014-12-05 09:58:56 ----D---- C:\ProgramData\Package Cache
2014-12-05 02:30:10 ----D---- C:\Windows\SYSWOW64\directx
2014-12-03 09:59:02 ----D---- C:\Users\sef\AppData\Roaming\Marine Aquarium 3
2014-12-03 09:58:58 ----RD---- C:\Program Files (x86)
2014-12-01 04:48:54 ----D---- C:\ProgramData
2014-11-30 04:33:55 ----D---- C:\Windows\system32\catroot
2014-11-29 13:31:39 ----D---- C:\Windows\rescache
2014-11-29 12:56:58 ----D---- C:\Windows\system32\DriverStore
2014-11-29 12:56:42 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-11-29 12:50:44 ----D---- C:\Windows\Tasks
2014-11-29 12:50:13 ----D---- C:\Windows\system32\drivers\etc
2014-11-29 12:49:19 ----D---- C:\Windows\erdnt
2014-11-29 09:46:24 ----D---- C:\Windows\Panther
2014-11-29 09:28:06 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-11-29 09:21:51 ----D---- C:\Program Files (x86)\Canon
2014-11-28 20:22:07 ----D---- C:\Windows\winsxs
2014-11-28 20:22:07 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-11-28 20:22:07 ----D---- C:\Windows\system32\cs-CZ
2014-11-28 20:22:07 ----D---- C:\Windows\cs-CZ
2014-11-28 14:15:30 ----D---- C:\ProgramData\Adobe
2014-11-28 05:36:57 ----D---- C:\Program Files\Common Files\System
2014-11-25 17:12:08 ----D---- C:\Program Files\Java
2014-11-25 17:11:12 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-11-25 17:11:10 ----D---- C:\ProgramData\Oracle
2014-11-25 17:11:09 ----D---- C:\Program Files (x86)\Java
2014-11-20 22:18:07 ----D---- C:\Program Files (x86)\Creative
2014-11-20 22:16:02 ----D---- C:\Program Files (x86)\MSI
2014-11-20 22:15:08 ----D---- C:\Windows\Minidump
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2012-10-18 16440]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-02-22 20464]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2012-10-18 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2012-10-18 13368]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-06-18 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO64A.SYS [2014-01-26 31648]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2013-10-02 51496]
R3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\E:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\kerneld.x64 [2012-08-21 30624]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-17 16756736]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-17 581120]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 bcgame;Nostromo HID Device Minidriver; C:\Windows\system32\drivers\bcgame.sys [2007-08-14 35328]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\Windows\system32\DRIVERS\ikbevent.sys [2012-10-22 20968]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\Windows\system32\DRIVERS\imsevent.sys [2012-10-22 19944]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver; C:\Windows\system32\DRIVERS\ISCTD64.sys [2012-10-22 46016]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
R3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [2013-05-30 64280]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2009-11-24 16008]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [2012-10-25 13368]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [2010-10-22 14136]
R3 NTIOLib_FastBoot;NTIOLib_FastBoot; \??\C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [2012-10-26 13368]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-04-10 849992]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2012-10-15 24680]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2012-10-15 52200]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2014-08-07 34032]
R3 vhidmini;Virtual Hid Device; C:\Windows\system32\DRIVERS\vhidmini.sys [2007-09-29 13952]
S2 AODDriver4.1;AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys []
S2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys []
S3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2012-01-15 36256]
S3 atillk64;atillk64; \??\C:\Program Files (x86)\GIGABYTE\atBIOS\AtiTool\atillk64.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTCFilterService;USB Networking Driver Filter Service; C:\Windows\system32\DRIVERS\motfilt.sys [2013-03-20 6144]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz136;cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys []
S3 dc3d;MS Hardware Device Detection Driver (USB); C:\Windows\system32\DRIVERS\dc3d.sys [2011-08-01 52584]
S3 DIRECTIO;DIRECTIO; \??\E:\Program Files\PerformanceTest\DirectIo64.sys [2012-08-13 25704]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 getbus;getbus; \??\C:\Users\sef\AppData\Local\Temp\getbus.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2012-11-02 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2012-11-02 27760]
S3 GPU-Z;GPU-Z; \??\C:\Users\sef\AppData\Local\Temp\GPU-Z.sys []
S3 GPUZ;GPUZ; \??\C:\Windows\TEMP\GPUZ.sys []
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2012-01-15 36256]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-10-10 5343584]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 ipadtst;ipadtst; \??\C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys []
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2013-02-22 358896]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2013-02-22 792560]
S3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys []
S3 motandroidusb;Mot ADB Interface Driver; C:\Windows\System32\Drivers\motoandroid.sys [2013-03-26 32768]
S3 motccgp;Motorola USB Composite Device Driver; C:\Windows\system32\DRIVERS\motccgp.sys [2013-03-19 23552]
S3 motccgpfl;MotCcgpFlService; C:\Windows\system32\DRIVERS\motccgpfl.sys []
S3 MotoSwitchService;MotoSwitch Service; C:\Windows\system32\DRIVERS\motswch.sys [2012-06-08 8832]
S3 Motousbnet;Motorola USB Networking Driver Service; C:\Windows\system32\DRIVERS\Motousbnet.sys [2013-03-19 27648]
S3 motusbdevice;Motorola USB Dev Driver; C:\Windows\system32\DRIVERS\motusbdevice.sys [2013-03-20 12288]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\E:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys []
S3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2005-03-29 8192]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2011-08-17 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 NTIOLib_1_0_1;NTIOLib_1_0_1; \??\C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [2009-10-05 14136]
S3 NTIOLib_1_0_2;NTIOLib_1_0_2; \??\C:\Program Files (x86)\MSI\ControlCenter\NTIOLib_X64.sys [2012-02-14 13328]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\C:\MSI\MSI SUITE\NTIOLib_X64.sys []
S3 NTIOLib_1_1_S;NTIOLib_1_1_S; \??\C:\MSI\MSI SUITE\Super-Charger\NTIOLib_X64.sys []
S3 NTIOLib_MSISMB_CC;NTIOLib_MSISMB_CC; \??\C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [2012-11-09 13368]
S3 NTIOLib_SuiteFB;NTIOLib_SuiteFB; \??\C:\MSI\MSI SUITE\FastBoot\NTIOLib_X64.sys []
S3 Point64;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 rzendpt;rzendpt; C:\Windows\system32\DRIVERS\rzendpt.sys [2013-11-15 39080]
S3 rzudd;Razer Mouse Driver; C:\Windows\system32\DRIVERS\rzudd.sys [2013-11-15 149160]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-15 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-15 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-15 158320]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 SaiK1709;SaiK1709; C:\Windows\system32\DRIVERS\SaiK1709.sys [2012-09-20 180544]
S3 SaiU1709;SaiU1709; C:\Windows\system32\DRIVERS\SaiU1709.sys [2012-09-20 47168]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2012-08-23 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 TVICHW32;TVICHW32; \??\C:\Program Files (x86)\GIGABYTE\EasyBoost\TVicHW64.sys []
S3 uisp;Logitech USB ICP driver; C:\Windows\System32\Drivers\mtdfu.sys [2014-01-04 17936]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2013-03-18 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-17 239616]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; e:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-08-22 9216]
R2 LPDSVC;@%systemroot%\system32\lpdsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MoboroboDeviceService;Moborobo Device Service; C:\Program Files (x86)\Moborobo\MoboroboDeviceService.exe [2014-03-28 70952]
R2 MSI_FastBoot;MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [2012-10-26 103992]
R2 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2014-10-24 1730000]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [2014-03-17 162800]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-10-13 76152]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2014-05-07 108032]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-20 116648]
S2 PST Service;PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-20 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-06 111616]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-23 257712]
S4 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-07-27 636952]
S4 ISCTAgent;ISCT Always Updated Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2012-10-22 149032]
S4 OnlineStorageService;OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [2012-07-12 7908664]
S4 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2013-04-03 1149104]
-----------------EOF-----------------
Run by sef at 2014-12-11 09:39:31
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 15 GB (13%) free of 122 GB
Total RAM: 8139 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:39:48, on 11.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
E:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\aida64.exe
E:\Program Files (x86)\TPUCapture\TPUCapture.exe
C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe
C:\PROGRA~2\Raptr\raptr.exe
C:\PROGRA~2\Raptr\raptr_im.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\sef.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daum.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.*.*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: eee1ef70083a013208d37190b1a6e5ef0063429 - {11111111-1111-1111-1111-110611341129} - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll
O2 - BHO: 2142d562cda342799c74bac15bb026030068153 - {11111111-1111-1111-1111-110611811153} - C:\Program Files (x86)\Sense\Sense-bho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ControlCenterCount] C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe
O4 - HKLM\..\Run: [Fast Boot] C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Raptr] "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup
O4 - HKCU\..\Run: [CCleaner Monitoring] "E:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [CCEnhancer] C:\Users\sef\Desktop\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2.exe /AUTO
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-21-1463186153-2632091326-3034755131-500\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background (User 'Administrator')
O4 - HKUS\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?')
O4 - Startup: TPUCapture.lnk = E:\Program Files (x86)\TPUCapture\TPUCapture.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/Nirvana/ ... cmatic.cab
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB022049-4C4B-4C3A-8A21-C6C0BE63B89D}: NameServer = 208.67.222.222,208.67.220.220
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - (no file)
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - (no file)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - e:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Moborobo Device Service (MoboroboDeviceService) - Unknown owner - C:\Program Files (x86)\Moborobo\MoboroboDeviceService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_FastBoot - MSI - C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
O23 - Service: MSI_LiveUpdate_Service - Micro-Star International - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PST Service - Unknown owner - C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 9131 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
winlogon.exe
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"e:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
C:\Windows\System32\svchost.exe -k LPDService
"C:\Program Files (x86)\Moborobo\MoboroboDeviceService.exe"
"C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
"C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"taskhost.exe"
taskeng.exe {FF0E207E-8386-492E-91A4-B02B0317E842}
taskeng.exe {57726FB3-EA96-4378-8D46-05A805D6DC22}
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\SavePass 1.1\f025b33d-4fe1-43d1-9072-60df121c2890.exe" 001504 971F64B27F234AC0B6AAF2A9542B8569IE 63429 1417149375 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 SavePass 1.1
"C:\Program Files (x86)\SavePass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe" /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='167904785' /bic=971F64B27F234AC0B6AAF2A9542B8569IE /verifier=6d03157a566d4768035584e8f611bb25 /installerversion=1_35_09_29 /installationtime=1417149375 /statsdomain=http://stats.newonlinedatastack.com /errorsdomain=http://errors.newonlinedatastack.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newonlinedatastack.com /runfrom='task' /externallog=''
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Logitech Gaming Software\LCore.exe" /minimized
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"E:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
"E:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\aida64.exe"
"E:\Program Files (x86)\TPUCapture\TPUCapture.exe"
"C:\Program Files (x86)\MSI\Fast Boot\FastBoot.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\PROGRA~2\Raptr\raptr.exe" --log_to_file --from_stub --newver
raptr_im.exe
"C:\Program Files (x86)\Raptr\raptr_ep64.exe"
C:\Windows\explorer.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2416.0.49538135\2078440858" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x1002 --gpu-device-id=0x6810 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.301.1013.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.1.529698009\639649112" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.3.1832840561\1526696552" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.4.2086127896\389876990" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.5.303117273\1189827045" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.6.179550522\1669668342" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.7.1881437686\2134994189" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.8.1243923220\1781124732" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.9.1349236475\2120228737" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.12.959790832\1733812321" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2416.14.439990625\957516847" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.16.1952414849\1426370979" /prefetch:673131151
"E:\Download\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/Prerender15minTTL/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_08/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2416.23.632390786\1773540195" /prefetch:673131151
======Scheduled tasks folder======
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-1.job - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-codedownloader.exe /rawdata=W7Y/C2U2mi1QcsgJG/5KPy4hbRuwHzyu5LRys9TEiBSuH6WgLTbvkA+krwa11jNe4EllbxPidd5P3CWj+VQZjOZTosLkGQFcz6pg8+Jit7Tuqist3I7TnxlTRhbgSQ3GxIu0uqwhE2FobSmKB3dXmwVsOshR+R05TVhnAfA2rLuwMLsUKZ4HDWS+XcFpxzN5tdb0ZSYmoRs9SBHCx9iK89j/pUfKyXxfrj97b1Rj5gzqzRp4d1W/k1/b2VxdlzV0cP+GpUjNYqj1GxxnaR31WyDchbD119I+DIO5nII8Z2fhUY87xwVLGEnjH9wImNjWoclb1AO3tobkQ4Q0Jw6eNYqcWz0VC2nFhwcfA0sqQiLaKl1KlPlO+32mZ1gAGR00atDBjY/ytr6JOIY2/fV0p6j3jxs6/k3yEbVHEKb1DB+UdRPXQ4QaDKqq5uxzNwryA4LtNoafCn9qWFxlyVKbbg5wYfA4qXuMsClV0T7J3R0wQRhOYgr8WFgqxBLOuImVUWO6wxrkQ21ZX7Z7h/b5E+uBpJbAZ60qA4Qwwmj8lyDx8BQallMb46uF490HJjDIt/ePwils45GCKYhIP5SEcSAl4/KS7U5UqrEFEJcvnYxm7BhV2YGkZzhrVjjIN43FR4ZW83o2iYoiAenu0ODDrQHt1uZvUmCbtI9lEiz7tQtrqKcDhs/E1pQOlUEOgImOolndDfCSt7PQRmAjinUYz7xhE/xQdtyyf84l5cpXxp8dCZ4bQ14YZ+ojfRO8PctvSjeyGX8T0ikr9BpY1WeDM5GyzzfS8+ciGpRNDMvRQC1sO2auLw8fwV74vKbKZk0mS/XtNxfj1TtqW0Hj5KVBzzDdGn85f1MuoNZoBz9KtAEWTzwyp29++sRz88N9ONzyujWUF/KVjN/vqfP2CfRSSbkOIi/EplbUj7zZ6D9k3Y8SoRk6JheY6QYigBM+/sjU+bUplO2K8UV+YHGiyU+BefDgGsQf0/DffPCHJbGtvuKOlDKZbrJg4gpnNbepYhDMXdG6PIHiyopNJgnqA7IsActbPUnBxYsqkdSlAopm2sL+IeEzZc76FyJOnVfEBscIwTV82iX8CowS7Hzs30iIJiZSA9eUOKAnFIoIpLtJ5TS81KJu1Jz2hFeeD0038HSGCTDNQRFgmpzdl6SS6vKbhcl3Ck+SfXnuSzxSJ77Uh0GM2uSx72Upc6YPgc/yqXavWJB8+NHhTUB3NwlnTAulPBFuey9N6ncX30dT41xsyJICf1f2RLen1UttdXrxGN6GmmUneit0tdtyGnP3jSvvQHdF4BMOsZvkiv8i53dj0RpPYGeSl9vqTEJRZS/ppUem6vXK6Mg/r5gAerPL5tN2A20ay5sj5derY1TmObzMeXaXQLXkeAatjOzVqcR7nrzqdckfvN6JVri0Ykz/8OuGK3RvwjzuvFFVEkgxnM3e2OPzDNblNja9N35voJ29pivpE+EQBoHBJN+Bp3yMB5BVO+f6Ou0gMzNrVMpawNLrVL02pnr+FVFe0Nw7ecen0xy1
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-11.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-11.exe /rawdata=IAyjVvt7e3YBICiB6iZ3mTRS0cHx8zfTkjcTKC0abFdubjBKtPTZGh0odGxvX6W3nHVd6Zy+vrYKRh3bo3LxMD4Rmc462L2QkBNkgC6Jnf2uj4SEq9OaS5GiIjSld1J1q5AhHibj9Lnj/UdQ/9XhzwSMBjbmZhLrOct6EvneH5q3Ay9XekxUjs9WUOMvS62gR+3sIgwnTr36EwI/E/OKzOKrWcevy/yM+LaL/LvfnX4D7VNYUXAn/4QcObA3vU8SaVygVl4cLkcw//XKR9WoLRPatBQJgHc31LLCeqBicXtjjDj936lgNNxkG+icCSiLAzKnKivecyrbCJfbwIzcxz6a86YCos6K48gKg+KAteOv0iRHaAT/i9NdFwRydmCufMYbLbERF5LC+wyZSTuXNhRpoofrU+iTI+jQLyT3pCogQHR9t/XIfNOpey73HB/N6w66v2FEcAinU725ylzgMXyGZZgvyi7ZxaPnMtBfojuQKWQvKeMw4gYu5Cy8Im1qmqIUTqgPuRRAsVNGKOQY1+mdSy0bsjT+mDcdkHUTxKwlf25+U3G9fJs98r/aNiojffdlg4bw9tp2zwOJsHsQQSiDoZgh791VDXALIbN92gz5zOiAangaqsJ2eTyOxBohXNH8jmyE9IrJ2vj9QOdKJrNZ4msUcmw2HwA1M2uEh5syl7ye98OxoXQjKdg8NY4N7WoHahTTUF5TC80SMQCygCp5jsR6JLmo2v5vcJD2ld0HmIWC8QeYXVQV55UU4U6GUZ/L977GTFybSwldIshIRUR479WIyu15a2XTbNi7lr7MjuXe2xgAITxD+IqEp//WZ15VmND2Wf8tq+u1bgJ/xBoUjJeu7vNJWYWvtRJn3rJd8qkBcWwQQ1gNkfgZF/hnll8Uu8/PXp8emq7HUnmnJ0nhdQ0K3BfE3QBXCxPEhdNpGQCo2L4HzNGDs3uOnisQCNpoeYylatz6h7BJVkaRJi4Q0zMHrT9iBmHQBiQD5/pzczRvE/k87U2ho2KnBEdugEIH0SfVAUNy10OsOhIRhFMm5TYw371IA3GoHFYvsB2PPTFbxvMgClTj9KH9hdZ8Fl/U6HJJBC6zgWy96G8h/DL+Y293HoUmSs/+dii2BUDbthWgXJNjpW7izWw3DPv611Iwsb8X6tIWXMbgvwxM2WtCI77tjpUYs0mp0zOMFVkpw7/7nRnGyUxVPp+OnS+8Nnnv1g+tzy1Hg0urymDVhrUATEp9gIEYA4thGZ6fvtrF8CsI1EICQjDGe7//T1VABET2XpxyrpJidetPomSdVUnlRRd9URXhqjCqN133souBt3pjrFjFhpPMCkinV6i4SkyZpYjWTuboCFdhM/UDOVyih3+lHQFDw06r9WWtakiiD53xir5Mu8OhiMsozlk/MxK1XPB9DhzSoWlHX69p6PSpyR8OJ7WnwcdFcm6YseVsCqb7chPosEuvxKIlS0MJziHfSz2lSlSkO/0PYwlj/9zGiCZRkFOuApmgrxLd60wjlaxebq7OHH/ZCNwkl6qUuV0EnuiSXX4shoISnXje4pgIxKkP0eEBnfoCScXN2sR0/foCSDp7LULrl3y8c7pYJ+mGYRhh9pYjNh0joTjrpjp2MnQKYBhuM/FKsas9vi+Td3forsw03c0PVN221GArr+ID06yxSx2bGFiHIHBDBuSYE9A6Pp05oRzhgwghxJ21lESczHHgPJRe82bkEG0TvSFC9A6W1iIeeViu5IIvZchwoNddAH6VrNqG/4SW8gqlhdWsZb2gLAWw8HUmtW9o7oSlSfvTQJVmg1GNWiT6/8rjCSEAn3spNkYncXitUlW6kg4uEF3Orsp7ZAWGXPTSggCGWcoy9lIqSJ2kaxToPAUfAj5JoHull51R6kqcua2BNAsek5gOtaCC0fuQQeQkt25DIK966ukv3wHLor7lHXhBMo0aI2HTGjfLu3ZH7DpsKEBcLtz3tbjsfYZx44/nnlQ6E2F3A08bYeeN19ccEBmhnjiVJIrr6FQTwNfc9s7AzhTo0zGdPrbupbjDiIRwoO7DpRKVBdMx0R/FQZJlZlN+PZJl5TzEeatyxcrFmT0FB+XhciHLU8+puJS0THzDVLoMUQpmFxFlsmTI4f6ukZeNsG5mQid7p1UVoNSfJqC6/ruyr5C8WMrkt7u7z8Fb0kjdXTRRwMUAmO95FeeeFSzRZvsyM7CbAAoLa8qFAxNPOxxg3RoMEdQ2MWzvv1rCQxU7dRQFZdMHMH8gpVGwQ0/RBdP4vx3T/JSsN2M9iCAWBjsNhJuScbwXFBezIAYOCwn/F1TR0MJzBHtGGOI2dh/qrbM/P1DQIb8DQd1qcHkWRc0desluznPr7cScFYBhngEZfWOAqpAD4oTir+Zxjw==
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-2.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-2.exe /rawdata=izA118TQ+apea9dHCUQbHW155alsfeFdToEmbh9gQkxh5osK5y1UAxRC9MLaoQ+ztqNul4Xcv0iqBjPg2nHXhQSQLjH1sW1kkroVoncyFxjxus9p9PX30UySNeiUZMB0LYr6QG06rx3sZNqZow0yrevPDdbsoJ7x1E3KaT/cfeTGXhKsQWHQGqEnx/R4yyfmz4LRXzrVMizoeqCg29yA2+Qri7KjM3Q5bXKUeICZ9dHx8JqyA6f9sEwrJ2mz2IoEk82yzUW+Yzi6BPGgygu5eMkiiHoaZubR0n9ZwrAhFwRLON7iq2PyKzqNUTKMKmxcwiA0l+THoG5lBm01F2W1s6GE4YiQ5HITLCBPo7f5OOilAwQcfZ3iPKrITfKG5/5iZqOFn/NeiBl2VJMYBtwyRR/fVTYjBjTh5vfaKyTND3XCFl52w7vZO6Hz7lXmPnbknfQlSURa4rhOOgSmN3p+j6+M4A3SP0pLHz8mxhTYC54JUmS0DQCkHcsnG/xhvvmDrT2hHt0mF5+JD8x1hLccE1M2a3BNqk1N9w0ypsINQQqGKa+bsXeweubLD4PtfFPp5EcUr2PNGNOvOdluVvTfejcTlsTrlobs+Jk8qhDDmMOr+6qAFS+N+WBPe+/87KOqCDuM5YLTpZ7YX1iOgBWMvowQzL9+e8VqU4yE2qKx03Ff+A2XyE6y6RJUAGXV4XLbxoj0AjzNFT1ZOk5f+pr7/ymYrOuGUkgVcuCMn9IvDZdqjhUcxic22MKT0q+GLECmYYSA2pl1+cMoHzclDbrVOxziNqGq6IjwkHtu4Frb/ImXFhNlKvxniYN8FMuUn6QN0JzFgJg742xtHzGwMN+O3Q==
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.exe /rawdata=aTEAQ5T2Uk6wAsXeadHw85VCIZL7Ye4KlgKhFzlaQzrYjv/AameQpszMWphOzuHq6S1bS4pGliXXkJwIeRqgWnYk9ajpyYmwYDjlRs+jnLNBC39Clgbr14L0pR2Dt+JU/AGrCuLLs9OXcAJzVFivZAS3kcsiqTcDO2N1WVPakrU1PdQtyyex4fi45eF7krVONrtaF3SgOGvURqhy82aGSQMQaCBHSePSiH3DMGFSWKzGIgG2vsemFYmvUKyAfe4HEy4wNNQ1ylDKKQvUYSetkQB6DCipmuf9QynL/LVPXQPj/rnZhru9INPlaYxO6xqEgn81RDHm8sioGSz2141raSryZQ8kAf5B2O6xayTloS9QC3A5x4TSXVYhtA8wocK4i8RNOIqo4477Vsz3XVzrU1IPPIGqOvu/8y9Xaf46lWTH/TtjdOJmKrjgkXkpwPlc5ipuQPFqJ5c5jJnoedoBnUTgNK9pSA1S/OKwfaRs8vnWaQVytQlB6H5jaFLaw2X2A6eKxXisyJy1hkDgA/E/0vde5fY/4vNWSph8TAqoLvIvBirGFRHkAYtq9Y7KQ5CrXABpXpLuVqNgv953y9r7VefuGY159KmSQXRoNoAjMe3ceYc27ZTyKR6Z7MpZkuCs5Pj9IvcLjOmBiHuwMRDhzhA3oVMbI9hEjIhWpoI/SLpj3HyUzWuZDgSMJ+nwVsz2EjMxwUR374HLmAdHVFuqK+5vFO6JfMAOS+i7Fmlgf2+5FVzuU8jBRUXvYbF8tIliY/Y9SbGGfkV3iRKuShTqnrczxjwgXvilPbamuOGTirNCW3z+GRuYqjTqgHMHwXKXTGB6L9dzDb4NH2P3tfS2ww1uiMuZlrjbxf3S+Snkm5pkssPjAxwhE4UMTNGow4SIFImZlSD2e7IfAShHDiZZZFsifw8Mes8K4JyzOQCt6U7KoRoY5edDtOcEioX4QAjBgJv4LwIBDD4a4vxtzcCKiYxMdpOju6oH125fIkbgI+ET1b/9LI8yCSXt4XBDTSyO
C:\Windows\tasks\50d4aed4-2aaa-454f-abde-2027603ed4ce-5_user.job - C:\Program Files (x86)\SavePass 1.1\50d4aed4-2aaa-454f-abde-2027603ed4ce-5.exe /rawdata=aTEAQ5T2Uk6wAsXeadHw85VCIZL7Ye4KlgKhFzlaQzrYjv/AameQpszMWphOzuHq6S1bS4pGliXXkJwIeRqgWnYk9ajpyYmwYDjlRs+jnLNBC39Clgbr14L0pR2Dt+JU/AGrCuLLs9OXcAJzVFivZAS3kcsiqTcDO2N1WVPakrU1PdQtyyex4fi45eF7krVONrtaF3SgOGvURqhy82aGSQMQaCBHSePSiH3DMGFSWKzGIgG2vsemFYmvUKyAfe4HEy4wNNQ1ylDKKQvUYSetkQB6DCipmuf9QynL/LVPXQPj/rnZhru9INPlaYxO6xqEgn81RDHm8sioGSz2141raSryZQ8kAf5B2O6xayTloS9QC3A5x4TSXVYhtA8wocK4i8RNOIqo4477Vsz3XVzrU1IPPIGqOvu/8y9Xaf46lWTH/TtjdOJmKrjgkXkpwPlc5ipuQPFqJ5c5jJnoedoBnUTgNK9pSA1S/OKwfaRs8vnWaQVytQlB6H5jaFLaw2X2A6eKxXisyJy1hkDgA/E/0vde5fY/4vNWSph8TAqoLvIvBirGFRHkAYtq9Y7KQ5CrXABpXpLuVqNgv953y9r7VefuGY159KmSQXRoNoAjMe3ceYc27ZTyKR6Z7MpZkuCs5Pj9IvcLjOmBiHuwMRDhzhA3oVMbI9hEjIhWpoI/SLpj3HyUzWuZDgSMJ+nwVsz2EjMxwUR374HLmAdHVFuqK+5vFO6JfMAOS+i7Fmlgf2+5FVzuU8jBRUXvYbF8tIliY/Y9SbGGfkV3iRKuShTqnrczxjwgXvilPbamuOGTirNCW3z+GRuYqjTqgHMHwXKXTGB6L9dzDb4NH2P3tfS2w6UD2DjezPcPjJLwTCap0UNOSRm4u5HvmieemkKesoyfevi5ITv7XR+fBs/zVqOmbG3+KuKk4XPBgH/3lrEcbG8uWBIX1QxTlnByEDlOeclhHQMeGbuKEGB1CkSFSCTpyKL3ZTpyhCgigxT+Dnhh3X61vHnYKLEg5C+Q/Ixrsfee
C:\Windows\tasks\5432e15e-8b38-4917-9568-a8baef47582c.job - C:\Program Files (x86)\SavePass 1.1\5432e15e-8b38-4917-9568-a8baef47582c.exe /agentregpath='SavePass 1.1' /appid=63429 /srcid='001504' /subid='0' /zdata='167904785' /bic=971F64B27F234AC0B6AAF2A9542B8569IE /verifier=6d03157a566d4768035584e8f611bb25 /installerversion=1_35_09_29 /installationtime=1417149375 /statsdomain=http://stats.newonlinedatastack.com /errorsdomain=http://errors.newonlinedatastack.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newonlinedatastack.com /runfrom='task' /externallog=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\f025b33d-4fe1-43d1-9072-60df121c2890.job - C:\Program Files (x86)\SavePass 1.1\f025b33d-4fe1-43d1-9072-60df121c2890.exe 001504 971F64B27F234AC0B6AAF2A9542B8569IE 63429 1417149375 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 SavePass 1.1
C:\Windows\tasks\fd74a172-49f3-4b56-9556-083971d5629d-1.job - C:\Program Files (x86)\Sense\Sense-codedownloader.exe /rawdata=EEOw26hJ4wiFMUn32OXBsedk1AXP0HNKbw5HeGmXeB4uvvNpTs12zd2YaFZI6cDBejIKo3nPy/4BQReDBJbrvJWEY5WsiqA+Bo6rDR8CHrWyDYLD7plW1522iKNeqG1cUNwH6LN1vYy+if8tiYZieieLGGiwfLzg1uY0TT+kXqAeWYnOwWzNcJ5P/7RQ4ewcphQS/4nvHIQcTNoE3D1T/uIwijLVi1p8JzCSsHm4uX4V7nJX5MyOd5/p/fqTAuBrx+7Lj+mwUomR4qVOBm1U7/2CoydLbn0rJ9nYw9BRUPHa3zLQe6gAJhB8inxPbyOenl3FSPgEoXoMRtttQ8EInSyj+fkBDq7xF15P7jkqwmzJwfo/JgbsOTYQcTOcH5k4Ge3NsQOa6nbrOTtfvuiuXJZ6mmngJLhck/Vezk8rn4XBgy0hv6f0FhO7PW3KeIm7LXgMeVUhLK6zakQnf81MyLI+Nw3O7kcK1QGk1qPgFdgnkBCChK3KMIv+A2RuPTGRklaLojIHbcZUJvbF2zfNs/3CodkAeyjWSYShwYWxqOaGFnPqWvoMxwVmb8/O7jyoOrW47Y64p1Bg0KTfV9Ck7B7Y77wzQ6HBSK1E0MNewSusRy5icPigEC4Ecoaj/hVgQm/DbpIR/4jiDXSYEF5HeSxgbBMvDfrIyIc/ydjlHgSD6cZghpFNssmXiIDxOTrpkSBIrEKZvoP2jRViygweJlYFYc70LsQJ2cOze6/vd3vRe2+ynsWI8oePC7Fy55BdlZkehww5AfNwIJykHl4UyGxsUB6lzTuLt/V8Z66xbfL9KaCcTb4z+M1jXHuHgaU5gbGU+4+DVw51SAx2FQqidg8UHOXBJDVAHlQSZpEjgymtxVxdJ6h14mjg0bImM2DWhVdjnJInF8ruatJL4cHoD1qUgsAF3z/N6RjslsAyTw7NKjZLbkuwNYC+Q2p7tAloX3kB4toc6QURS0i7BzhsFAVBreAmJy1S1dc5GS/dve4Nr4oamMjivqf/0vq9XBHOMM4twHjzgN9eSa4HnUIL29zbGANQBOvhKSpo+B7Y0OMuFAX3yN5TFxHgDK24gzBVIhUuOsJwfSaoDiXowV7Y4EItn/0f9bC9AjbcLjBNzNZiWcHL7QCEhfQCYGOLtF50bwJG8p6q5+kv2u0tw3c+UchowuJNcSPMkGanJJWOMg8l8hLAYl2elT3kqjKZOXIJWPMaM0OrJ3lKwTV1gNjumTeoHgZZdxUVZ6Z/l5Q+/v0pTZTRdxKwYe/pZhGFU1YI6bDzpgZcTbxKsToZl94oGEbYM/Smw6diHPJ/GLVLO5/AHbTqVUijsoXwAjV/CHpKnfYwDZajdZd8sEHCAMc1I7eMjvy1Bn5RNy5CLyu42ie5e+J4zBYoYOyMLBLhGo/ctzekRTfHfeou9tqFa7+gnvJY2quNI+vfbKemAMwcm3T/UzQMQ6IkG6GcapEIncMCYL+R0lEzmWy+B+V8kjCCK80lA1jzov7S/U78aGev7M95SHRCi2PUgxj8BheHLG6za5iRHwM3oYVwnf6BR2IWi9b4CzdJNcKnyuUF9E7lNFG4IDTlgphkOK9o8bz6GAIZTPaS5fW78PWJ4DH53l3W+qJOB777+I4OJ5FUVjP6vXJofcfMKZG+78qNupoZS5sN6vb4g+4GebjPBsQQ9x1s+WqLVsCAcAC8NBIP7F7SuKw=
C:\Windows\tasks\fd74a172-49f3-4b56-9556-083971d5629d-5.job - C:\Program Files (x86)\Sense\fd74a172-49f3-4b56-9556-083971d5629d-5.exe /rawdata=ljDKYv7SOfoyQZf8n5btBIEHlvKu9darPa3JSVHMk4bY5ZxI4DfrqMioWLzfgNqctpBwtcF/LZWEh0tWk4xCihRltrfILjF5hlZl2+i6l7bAvcwf/ozPz10GMCgMBI46LCcMxqns9m0llsiJawn8/7isg7sxCD8wmWU1gEqJj8AcTE7fRJBzHxaq4/l1rT1OyjC8ul6mYQPMQc/XC1vMH1jtRxUbaTM18fbly5rRigV23KBrVZJ/XPjURaxNLKMVhIKLjex0BiWpqvFKHPiij4LcDOARUIFSzhY3Ey3xEezNqZUcCzB2mOFYF//B2agBDgiA2YvpuZoElyaAG6PRoURMb2jbOOFuluPwVxDN7TQW5cMdWAzsGFHFLCnU3hSCcLfks8ECdS6Pf2nk7zbkvvJp2KVySUzaoyP1fnSboJjMkE69Q+NiJWbOrCNO1sY6kIphrsPD07oU9dR+G8jG7lN2YHvhHIb0AKzqaVp8eysPBBRuexBAAq1UDwZujN97CFwl0P2+hjyEIppVYYshuPbNONBJrfCYJvwrys85pq7GHZSZ7ahQJotwWlD1urUw/4Qy16IZyWfOm9ucqmIpdpkz80gPK7/eWNywBB0xQAFIwTF2QbdV3uGjV20xuIH81FvD8m4zzGUNj4EOlGGb4cSHtYY9yImQtk9NU/o+N8ILUcaJeS3zwl6js+LdddPRK/B4vgF1HxucCBQACtQT6Y0tpDX0yrwusA/RG8s+jctxj2GZ8WpH5CeGg2wP5h3Ta+asLInEPcdmrp2GrEDFu+Czy93kTEr9PZXVftgBSBKaSmRs0n4JWmYdLkZkaVvlMiN9P8VW40vv3wjOxeVGdrmUPUOaKwbEUtOC89pAbmyjsfbWxRNxehPQyg+pySy9z/DQZmFaXxhO16QayHanwXIf9hYyAVxb/7HdPvTdpMgDGMfvispzSjsWhI+9mWDMyo5n4rZP8USoEtgdj6KhpcG5CL8z+QRJbhd7IcX+RycJ49IVrglShNCpD4gpQgT5xOpp5NadXxL4ao6GACVc3Lrq1ZFU0WgouE+L2M1bImQI+JPswQkD49hg19TiUyb6nsXZqG5/IhoClmv0zHPvtDddAhOQ8DipLPszjHYfaJzoi1TBM8p3thhpDY5gl+vnveHtO5Ls+tWTgVAG9M8G96dhzkt4tdEPj+15lamb3o8=
C:\Windows\tasks\fd74a172-49f3-4b56-9556-083971d5629d-5_user.job - C:\Program Files (x86)\Sense\fd74a172-49f3-4b56-9556-083971d5629d-5.exe /rawdata=ljDKYv7SOfoyQZf8n5btBIEHlvKu9darPa3JSVHMk4bY5ZxI4DfrqMioWLzfgNqctpBwtcF/LZWEh0tWk4xCihRltrfILjF5hlZl2+i6l7bAvcwf/ozPz10GMCgMBI46LCcMxqns9m0llsiJawn8/7isg7sxCD8wmWU1gEqJj8AcTE7fRJBzHxaq4/l1rT1OyjC8ul6mYQPMQc/XC1vMH1jtRxUbaTM18fbly5rRigV23KBrVZJ/XPjURaxNLKMVhIKLjex0BiWpqvFKHPiij4LcDOARUIFSzhY3Ey3xEezNqZUcCzB2mOFYF//B2agBDgiA2YvpuZoElyaAG6PRoURMb2jbOOFuluPwVxDN7TQW5cMdWAzsGFHFLCnU3hSCcLfks8ECdS6Pf2nk7zbkvvJp2KVySUzaoyP1fnSboJjMkE69Q+NiJWbOrCNO1sY6kIphrsPD07oU9dR+G8jG7lN2YHvhHIb0AKzqaVp8eysPBBRuexBAAq1UDwZujN97CFwl0P2+hjyEIppVYYshuPbNONBJrfCYJvwrys85pq7GHZSZ7ahQJotwWlD1urUw/4Qy16IZyWfOm9ucqmIpdpkz80gPK7/eWNywBB0xQAFIwTF2QbdV3uGjV20xuIH81FvD8m4zzGUNj4EOlGGb4cSHtYY9yImQtk9NU/o+N8ILUcaJeS3zwl6js+LdddPRK/B4vgF1HxucCBQACtQT6Y0tpDX0yrwusA/RG8s+jctxj2GZ8WpH5CeGg2wP5h3Ta+asLInEPcdmrp2GrEDFu+Czy93kTEr9PZXVftgBSBKaSmRs0n4JWmYdLkZkaVvlMiN9P8VW40vv3wjOxeVGdrmUPUOaKwbEUtOC89pAbmyjsfbWxRNxehPQyg+pySy9z/DQZmFaXxhO16QayHanwXIf9hYyAVxb/7HdPvTdpMgDGMfvispzSjsWhI+9mWDMyo5n4rZP8USoEtgdj6KhpcG5CL8z+QRJbhd7IcX+RycJ49IVrglShNCpD4gpQgT5ZHkuY2e5c0l0q4OmpxVNccLplFmYGbKI/dRn7VUCR0k5peylz469YisyuoNlmQJ7LbptJegLa8gDdI4estyx1mmZpSp2OKWvj2QEYZPG2zDLDx5Qo8RED1JJw0F+GUgD5kPTJFzsNvgBgnaHcdqiUQVEXXvvSFq8R30NN0w0imm5DK6AO57Fs1USik8HKUXmHBvLstVXlLpkvYEDMkznO0XgMH1kVJoxASbXc20vU/yfYSqyZLvbvQDwW5zL1a+wQd9Yb6FiCUmfInLjVZuEbRDpxypP73R+kTiIWpGOLKbvMvlgIg688+nm0/vjytI6+MJXqOXBbB5JP+6Ck79hoA==
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1463186153-2632091326-3034755131-1001Core.job - C:\Users\sef\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1463186153-2632091326-3034755131-1001UA.job - C:\Users\sef\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129}]
SavePass 1.1 - C:\Program Files (x86)\SavePass 1.1\SavePass 1.1-bho.dll [2014-11-28 624032]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611811153}]
Sense - C:\Program Files (x86)\Sense\Sense-bho.dll [2014-11-28 746456]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-25 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-25 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"=C:\Program Files\Logitech Gaming Software\LCore.exe [2013-11-14 8292120]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2013-04-03 3684488]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=E:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
"CCEnhancer"=C:\Users\sef\Desktop\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2-mulitlingual\CCEnhancer-4.2.exe [2014-11-26 286208]
"DAEMON Tools Lite"=E:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ControlCenterCount"=C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [2012-03-26 872448]
"Fast Boot"=C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [2012-09-19 764472]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-11-17 767176]
"Raptr"=C:\Program Files (x86)\Raptr\raptrstub.exe [2014-12-08 55568]
C:\Users\sef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
TPUCapture.lnk - E:\Program Files (x86)\TPUCapture\TPUCapture.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-10-10 441856]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"NoAutoRebootWithLoggedOnUsers"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe"="e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe:*:Enabled:PotPlayer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe"="e:\Program Files (x86)\Daum\PotPlayer\PotPlayerMini.exe:*:Enabled:PotPlayer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-12-11 09:39:31 ----DC---- C:\rsit
2014-12-11 09:39:31 ----D---- C:\Program Files\trend micro
2014-12-11 09:30:39 ----SHDC---- C:\$RECYCLE.BIN
2014-12-11 09:30:37 ----D---- C:\Windows\temp
2014-12-11 09:30:35 ----AC---- C:\ComboFix.txt
2014-12-05 09:58:57 ----A---- C:\Windows\SYSWOW64\vp6vfw.dll
2014-12-03 09:58:58 ----D---- C:\Program Files (x86)\SereneScreen
2014-12-03 09:58:58 ----A---- C:\Windows\SYSWOW64\MarineAquarium3.scr
2014-12-01 05:11:24 ----D---- C:\Program Files\BreakPoint Software
2014-12-01 05:10:59 ----D---- C:\Users\sef\AppData\Roaming\BreakPoint Software
2014-12-01 04:48:54 ----D---- C:\ProgramData\Orbit
2014-11-30 04:34:52 ----D---- C:\Users\sef\AppData\Roaming\ATI
2014-11-30 04:34:52 ----D---- C:\ProgramData\ATI
2014-11-29 12:57:15 ----D---- C:\ProgramData\AMD
2014-11-29 12:57:15 ----D---- C:\Program Files (x86)\AMD AVT
2014-11-29 12:57:03 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-29 12:48:42 ----D---- C:\Program Files\ATI
2014-11-29 12:48:24 ----D---- C:\Program Files\ATI Technologies
2014-11-29 12:47:19 ----DC---- C:\AMD
2014-11-29 12:16:38 ----D---- C:\Users\sef\AppData\Roaming\KC Softwares
2014-11-29 12:15:05 ----D---- C:\ProgramData\Binarysense
2014-11-29 04:18:07 ----D---- C:\Program Files (x86)\System Ninja
2014-11-28 20:22:05 ----A---- C:\Windows\winhlp32.exe
2014-11-28 20:22:05 ----A---- C:\Windows\SYSWOW64\ftsrch.dll
2014-11-28 20:22:05 ----A---- C:\Windows\SYSWOW64\ftlx041e.dll
2014-11-28 20:22:05 ----A---- C:\Windows\SYSWOW64\ftlx0411.dll
2014-11-28 20:22:05 ----A---- C:\Windows\system32\ftsrch.dll
2014-11-28 20:22:05 ----A---- C:\Windows\system32\ftlx041e.dll
2014-11-28 20:22:05 ----A---- C:\Windows\system32\ftlx0411.dll
2014-11-28 11:50:39 ----D---- C:\Program Files\DVD Maker
2014-11-28 05:37:46 ----D---- C:\Program Files (x86)\Sense
2014-11-28 05:36:18 ----D---- C:\Program Files (x86)\SavePass 1.1
2014-11-28 05:24:01 ----D---- C:\Program Files (x86)\7-Zip
2014-11-25 22:57:42 ----D---- C:\Program Files (x86)\QuickTime
2014-11-25 17:57:10 ----D---- C:\Users\sef\AppData\Roaming\Oracle
2014-11-17 21:16:20 ----A---- C:\Windows\system32\amdhcp64.dll
2014-11-17 21:16:18 ----A---- C:\Windows\SYSWOW64\amdhcp32.dll
2014-11-17 21:16:16 ----A---- C:\Windows\system32\atimpc64.dll
2014-11-17 21:16:16 ----A---- C:\Windows\system32\amdpcom64.dll
2014-11-17 21:16:14 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2014-11-17 21:16:14 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2014-11-17 21:16:00 ----A---- C:\Windows\system32\atiuxp64.dll
2014-11-17 21:15:58 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2014-11-17 21:15:56 ----A---- C:\Windows\system32\atiu9p64.dll
2014-11-17 21:15:54 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2014-11-17 21:15:50 ----A---- C:\Windows\system32\aticfx64.dll
2014-11-17 21:15:46 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2014-11-17 21:15:40 ----A---- C:\Windows\system32\atidxx64.dll
2014-11-17 21:15:36 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2014-11-17 21:15:28 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2014-11-17 21:15:22 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2014-11-17 21:15:14 ----A---- C:\Windows\system32\atiumd6a.dll
2014-11-17 21:15:10 ----A---- C:\Windows\system32\atiumd64.dll
2014-11-17 21:13:08 ----A---- C:\Windows\system32\drivers\amdacpksd.sys
2014-11-17 21:11:26 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2014-11-17 20:57:26 ----A---- C:\Windows\system32\clinfo.exe
2014-11-17 20:57:14 ----A---- C:\Windows\SYSWOW64\amdocl_ld32.exe
2014-11-17 20:57:14 ----A---- C:\Windows\SYSWOW64\amdocl_as32.exe
2014-11-17 20:57:14 ----A---- C:\Windows\system32\amdocl_ld64.exe
2014-11-17 20:57:14 ----A---- C:\Windows\system32\amdocl_as64.exe
2014-11-17 20:57:10 ----A---- C:\Windows\system32\OpenVideo64.dll
2014-11-17 20:57:04 ----A---- C:\Windows\SYSWOW64\OpenVideo.dll
2014-11-17 20:56:58 ----A---- C:\Windows\system32\OVDecode64.dll
2014-11-17 20:56:54 ----A---- C:\Windows\SYSWOW64\OVDecode.dll
2014-11-17 20:56:48 ----A---- C:\Windows\system32\amdocl64.dll
2014-11-17 20:53:38 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2014-11-17 20:50:40 ----A---- C:\Windows\system32\OpenCL.dll
2014-11-17 20:50:36 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2014-11-17 20:12:02 ----A---- C:\Windows\system32\mantle64.dll
2014-11-17 20:11:42 ----A---- C:\Windows\SYSWOW64\mantle32.dll
2014-11-17 20:11:18 ----A---- C:\Windows\system32\amdmantle64.dll
2014-11-17 20:10:32 ----A---- C:\Windows\system32\atio6axx.dll
2014-11-17 19:54:42 ----A---- C:\Windows\SYSWOW64\amdmantle32.dll
2014-11-17 19:49:02 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2014-11-17 19:40:28 ----A---- C:\Windows\system32\mantleaxl64.dll
2014-11-17 19:40:16 ----A---- C:\Windows\SYSWOW64\mantleaxl32.dll
2014-11-17 19:40:00 ----A---- C:\Windows\system32\atiapfxx.exe
2014-11-17 19:39:52 ----A---- C:\Windows\system32\aticalrt64.dll
2014-11-17 19:39:50 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2014-11-17 19:39:42 ----A---- C:\Windows\system32\aticalcl64.dll
2014-11-17 19:39:40 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2014-11-17 19:39:26 ----A---- C:\Windows\system32\aticaldd64.dll
2014-11-17 19:36:06 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2014-11-17 19:22:08 ----A---- C:\Windows\system32\atidemgy.dll
2014-11-17 19:21:56 ----A---- C:\Windows\system32\atimuixx.dll
2014-11-17 19:21:48 ----A---- C:\Windows\system32\atieclxx.exe
2014-11-17 19:21:10 ----A---- C:\Windows\system32\atiesrxx.exe
2014-11-17 19:20:06 ----A---- C:\Windows\system32\atitmm64.dll
2014-11-17 19:17:06 ----A---- C:\Windows\system32\amdmmcl6.dll
2014-11-17 19:17:00 ----A---- C:\Windows\SYSWOW64\amdmmcl.dll
2014-11-17 19:10:00 ----A---- C:\Windows\SYSWOW64\ativvsvl.dat
2014-11-17 19:10:00 ----A---- C:\Windows\SYSWOW64\ativvsva.dat
2014-11-17 19:10:00 ----A---- C:\Windows\system32\ativvsvl.dat
2014-11-17 19:10:00 ----A---- C:\Windows\system32\ativvsva.dat
2014-11-17 19:06:04 ----A---- C:\Windows\system32\coinst_14.30.dll
2014-11-17 18:55:12 ----A---- C:\Windows\system32\atiadlxx.dll
2014-11-17 18:55:00 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2014-11-17 18:54:46 ----A---- C:\Windows\system32\atig6pxx.dll
2014-11-17 18:54:44 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2014-11-17 18:54:44 ----A---- C:\Windows\system32\atiglpxx.dll
2014-11-17 18:54:40 ----A---- C:\Windows\system32\atig6txx.dll
2014-11-17 18:54:26 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2014-11-17 18:54:12 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2014-11-17 18:52:18 ----A---- C:\Windows\system32\amdave64.dll
2014-11-17 18:52:12 ----A---- C:\Windows\SYSWOW64\amdave32.dll
2014-11-17 18:52:00 ----A---- C:\Windows\system32\atisamu64.dll
2014-11-17 18:51:56 ----A---- C:\Windows\SYSWOW64\atisamu32.dll
2014-11-17 18:49:40 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2014-11-17 15:08:00 ----A---- C:\Windows\system32\kdbsdk64.dll
2014-11-17 15:03:08 ----A---- C:\Windows\SYSWOW64\kdbsdk32.dll
======List of files/folders modified in the last 1 month======
2014-12-11 09:39:42 ----D---- C:\Windows\Prefetch
2014-12-11 09:39:31 ----RD---- C:\Program Files
2014-12-11 09:30:38 ----DC---- C:\Qoobox
2014-12-11 09:30:37 ----D---- C:\Windows
2014-12-11 09:29:31 ----C---- C:\Windows\system.ini
2014-12-11 07:47:59 ----D---- C:\Windows\system32\config
2014-12-11 06:59:01 ----D---- C:\Windows\SYSWOW64\drivers
2014-12-11 06:59:01 ----D---- C:\Windows\SysWOW64
2014-12-11 06:59:01 ----D---- C:\Windows\AppPatch
2014-12-11 06:59:01 ----D---- C:\Program Files (x86)\Common Files
2014-12-11 06:44:17 ----D---- C:\Windows\System32
2014-12-11 06:44:17 ----D---- C:\Windows\inf
2014-12-11 06:44:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-11 06:41:43 ----D---- C:\Windows\system32\catroot2
2014-12-11 06:41:42 ----SHD---- C:\System Volume Information
2014-12-11 06:41:20 ----D---- C:\Windows\system32\drivers
2014-12-11 06:41:11 ----D---- C:\Windows\SoftwareDistribution
2014-12-11 06:39:46 ----D---- C:\Program Files (x86)\Raptr
2014-12-11 06:39:36 ----D---- C:\Users\sef\AppData\Roaming\Raptr
2014-12-11 06:38:52 ----D---- C:\Windows\system32\Tasks
2014-12-11 03:24:26 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2014-12-11 02:06:22 ----SHD---- C:\Windows\Installer
2014-12-08 18:08:48 ----D---- C:\ProgramData\Spyware Terminator
2014-12-06 22:10:41 ----D---- C:\Users\sef\AppData\Roaming\DAEMON Tools Lite
2014-12-06 22:10:40 ----D---- C:\Windows\Logs
2014-12-05 15:29:25 ----D---- C:\ProgramData\Moborobo
2014-12-05 09:58:56 ----D---- C:\ProgramData\Package Cache
2014-12-05 02:30:10 ----D---- C:\Windows\SYSWOW64\directx
2014-12-03 09:59:02 ----D---- C:\Users\sef\AppData\Roaming\Marine Aquarium 3
2014-12-03 09:58:58 ----RD---- C:\Program Files (x86)
2014-12-01 04:48:54 ----D---- C:\ProgramData
2014-11-30 04:33:55 ----D---- C:\Windows\system32\catroot
2014-11-29 13:31:39 ----D---- C:\Windows\rescache
2014-11-29 12:56:58 ----D---- C:\Windows\system32\DriverStore
2014-11-29 12:56:42 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-11-29 12:50:44 ----D---- C:\Windows\Tasks
2014-11-29 12:50:13 ----D---- C:\Windows\system32\drivers\etc
2014-11-29 12:49:19 ----D---- C:\Windows\erdnt
2014-11-29 09:46:24 ----D---- C:\Windows\Panther
2014-11-29 09:28:06 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-11-29 09:21:51 ----D---- C:\Program Files (x86)\Canon
2014-11-28 20:22:07 ----D---- C:\Windows\winsxs
2014-11-28 20:22:07 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-11-28 20:22:07 ----D---- C:\Windows\system32\cs-CZ
2014-11-28 20:22:07 ----D---- C:\Windows\cs-CZ
2014-11-28 14:15:30 ----D---- C:\ProgramData\Adobe
2014-11-28 05:36:57 ----D---- C:\Program Files\Common Files\System
2014-11-25 17:12:08 ----D---- C:\Program Files\Java
2014-11-25 17:11:12 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-11-25 17:11:10 ----D---- C:\ProgramData\Oracle
2014-11-25 17:11:09 ----D---- C:\Program Files (x86)\Java
2014-11-20 22:18:07 ----D---- C:\Program Files (x86)\Creative
2014-11-20 22:16:02 ----D---- C:\Program Files (x86)\MSI
2014-11-20 22:15:08 ----D---- C:\Windows\Minidump
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2012-10-18 16440]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-02-22 20464]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2012-10-18 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2012-10-18 13368]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-06-18 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO64A.SYS [2014-01-26 31648]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2013-10-02 51496]
R3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\E:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\kerneld.x64 [2012-08-21 30624]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-17 16756736]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-17 581120]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 bcgame;Nostromo HID Device Minidriver; C:\Windows\system32\drivers\bcgame.sys [2007-08-14 35328]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\Windows\system32\DRIVERS\ikbevent.sys [2012-10-22 20968]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\Windows\system32\DRIVERS\imsevent.sys [2012-10-22 19944]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver; C:\Windows\system32\DRIVERS\ISCTD64.sys [2012-10-22 46016]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
R3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [2013-05-30 64280]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2009-11-24 16008]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [2012-10-25 13368]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [2010-10-22 14136]
R3 NTIOLib_FastBoot;NTIOLib_FastBoot; \??\C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [2012-10-26 13368]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-04-10 849992]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2012-10-15 24680]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2012-10-15 52200]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2014-08-07 34032]
R3 vhidmini;Virtual Hid Device; C:\Windows\system32\DRIVERS\vhidmini.sys [2007-09-29 13952]
S2 AODDriver4.1;AODDriver4.1; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys []
S2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys []
S3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2012-01-15 36256]
S3 atillk64;atillk64; \??\C:\Program Files (x86)\GIGABYTE\atBIOS\AtiTool\atillk64.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTCFilterService;USB Networking Driver Filter Service; C:\Windows\system32\DRIVERS\motfilt.sys [2013-03-20 6144]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 cpuz136;cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys []
S3 dc3d;MS Hardware Device Detection Driver (USB); C:\Windows\system32\DRIVERS\dc3d.sys [2011-08-01 52584]
S3 DIRECTIO;DIRECTIO; \??\E:\Program Files\PerformanceTest\DirectIo64.sys [2012-08-13 25704]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 getbus;getbus; \??\C:\Users\sef\AppData\Local\Temp\getbus.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2012-11-02 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2012-11-02 27760]
S3 GPU-Z;GPU-Z; \??\C:\Users\sef\AppData\Local\Temp\GPU-Z.sys []
S3 GPUZ;GPUZ; \??\C:\Windows\TEMP\GPUZ.sys []
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2012-01-15 36256]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-10-10 5343584]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 ipadtst;ipadtst; \??\C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys []
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2013-02-22 358896]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2013-02-22 792560]
S3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys []
S3 motandroidusb;Mot ADB Interface Driver; C:\Windows\System32\Drivers\motoandroid.sys [2013-03-26 32768]
S3 motccgp;Motorola USB Composite Device Driver; C:\Windows\system32\DRIVERS\motccgp.sys [2013-03-19 23552]
S3 motccgpfl;MotCcgpFlService; C:\Windows\system32\DRIVERS\motccgpfl.sys []
S3 MotoSwitchService;MotoSwitch Service; C:\Windows\system32\DRIVERS\motswch.sys [2012-06-08 8832]
S3 Motousbnet;Motorola USB Networking Driver Service; C:\Windows\system32\DRIVERS\Motousbnet.sys [2013-03-19 27648]
S3 motusbdevice;Motorola USB Dev Driver; C:\Windows\system32\DRIVERS\motusbdevice.sys [2013-03-20 12288]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507; \??\E:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys []
S3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2005-03-29 8192]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2011-08-17 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 NTIOLib_1_0_1;NTIOLib_1_0_1; \??\C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [2009-10-05 14136]
S3 NTIOLib_1_0_2;NTIOLib_1_0_2; \??\C:\Program Files (x86)\MSI\ControlCenter\NTIOLib_X64.sys [2012-02-14 13328]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\C:\MSI\MSI SUITE\NTIOLib_X64.sys []
S3 NTIOLib_1_1_S;NTIOLib_1_1_S; \??\C:\MSI\MSI SUITE\Super-Charger\NTIOLib_X64.sys []
S3 NTIOLib_MSISMB_CC;NTIOLib_MSISMB_CC; \??\C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [2012-11-09 13368]
S3 NTIOLib_SuiteFB;NTIOLib_SuiteFB; \??\C:\MSI\MSI SUITE\FastBoot\NTIOLib_X64.sys []
S3 Point64;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 rzendpt;rzendpt; C:\Windows\system32\DRIVERS\rzendpt.sys [2013-11-15 39080]
S3 rzudd;Razer Mouse Driver; C:\Windows\system32\DRIVERS\rzudd.sys [2013-11-15 149160]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-15 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-15 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-15 158320]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 SaiK1709;SaiK1709; C:\Windows\system32\DRIVERS\SaiK1709.sys [2012-09-20 180544]
S3 SaiU1709;SaiU1709; C:\Windows\system32\DRIVERS\SaiU1709.sys [2012-09-20 47168]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2012-08-23 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 TVICHW32;TVICHW32; \??\C:\Program Files (x86)\GIGABYTE\EasyBoost\TVicHW64.sys []
S3 uisp;Logitech USB ICP driver; C:\Windows\System32\Drivers\mtdfu.sys [2014-01-04 17936]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2013-03-18 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-17 239616]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; e:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-08-22 9216]
R2 LPDSVC;@%systemroot%\system32\lpdsvc.dll,-500; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 MoboroboDeviceService;Moborobo Device Service; C:\Program Files (x86)\Moborobo\MoboroboDeviceService.exe [2014-03-28 70952]
R2 MSI_FastBoot;MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [2012-10-26 103992]
R2 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2014-10-24 1730000]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [2014-03-17 162800]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-10-13 76152]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2014-05-07 108032]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-20 116648]
S2 PST Service;PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-20 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-06 111616]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-23 257712]
S4 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-07-27 636952]
S4 ISCTAgent;ISCT Always Updated Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2012-10-22 149032]
S4 OnlineStorageService;OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [2012-07-12 7908664]
S4 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2013-04-03 1149104]
-----------------EOF-----------------
