Stránka 1 z 2

Vir - samovolné otevírání nových oken s reklamou v chrome

Napsal: 22 pro 2014 18:10
od Mara
Zdravím, stále se mi otevírá při prohlížení v chromu nové okno s různou reklamou, naskakují mi boční lišty atd. Windows defender nic nenašel a doplňky nainstalované nemám. Děkuji za pomoc

Logfile of random's system information tool 1.10 (written by random/random)
Run by Neli at 2014-12-22 18:09:12
Microsoft Windows 8.1 Pro
System drive C: has 37 GB (32%) free of 114 GB
Total RAM: 16333 MB (80% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:09:15, on 22. 12. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Neli.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... 774603C52C
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... 774603C52C
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&t ... 774603C52C
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: 166090e0f32601317e4e5118752c52d60061752 - {11111111-1111-1111-1111-110611171152} - (no file)
O2 - BHO: e62a1271b6524ab3b4f60ca546d3b4d20065781 - {11111111-1111-1111-1111-110611571181} - C:\Program Files (x86)\HDQ-1.2cV15.12\HDQ-1.2cV15.12-bho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ADSKAppManager] "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Spotify] "C:\Users\Neli\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Neli\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Neli\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Startup: Dropbox.lnk = Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Network Server.lnk = C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: McNeel Update Service 5.0 (McNeelUpdate) - Robert McNeel & Associates - C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe
O23 - Service: mental ray Satellite for Autodesk 3ds Max 2015 64-bit (mi-raysat_3dsmax2015_64) - Unknown owner - D:\3DS MAX 2015\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11620 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {1577D25A-4007-4B5D-A9D9-1D33FB631D19}
"C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-6.exe" /rawdata=XDvWBG5NcbFQhvp+MRBnlR9Fm+kNkvLwTsOgSz0osU345XCmVmVXvQFKxt8537vS/OEVb2HPsSwWOPlmeSGFiwcoof6uc1CCu8v35MwHijWqxRnMRoVUV8JmPuTQitqzHm+KREZHHf7HE3K0rwd5Lh9PmwQhbZ3vQ2E3jr3H1EFUP92Fg5GgA9ItqREMfTnQDiwNtEa4qE/pNPtXEdpAxj1yHy9Zk83vprw+6jZsIWftvOJX1osPbjn33GXgmB+yeQ55y35uWJLqlRR3lRnUHtgJCdqqKz811ARyjb228Zx655R4fLl6ln+gTrC432D1K4AFVAdaQWtH410CLZ89dwUH6pkw9Ac0yIPRCeK4CBvEQvaWuJgLVh9e4sMxb3fWbNzHhCBPwcvGZTtAcqxs4s2gKhUbwtbX8USHFYQ7iI78AsaPpf2A4r/tol5BO4sxWvISFgZR1AfUPJjW5zT/rudRhm6QOqR/ZqXe0RNa1Gg/DnplPL5Wk2OZ1t9y+3GeGr66IXtNC7UrJxRau8rJyjQ17YxqOWGapRtSEqMLngrgrkZh2GxTxDEypgpuA5fJPLLzH0yco4K0HecxWi1AOW1h6xgInPcxk7kZ+nFT7zBMYJYNIiGjJ84iY3T74FsnZAyddGd++F4ih9UwwKJwIU2G5Zzfp/IGy9MeSgEhMaGayR56IDTzDkRWtOIUQqT/qzqak80B1Qu0zW1Z5XzwMm6iF1lRTr/bEnRStGUTfZC4a2EsthN2+eUxT6C/wC31YyoWt11FYJM2zt+tZx+J+Sqql2ofoD+EHccal6TKohsVMXIoJ281IFmeFUzP+sP4Lykoy9q2UOTKj/t7gllvhjo/PscujollTsr8h8E+OeaX7GhQWd5QZsyoAp8WPpaG50BUetjKAdGHiKFJA9loLP7qdPTKkzkYUM05t0Sp1h7ZtDdXYAS6eB4mD7zv5S5U3+W8HigxB7M/1MDPmhpN00Q0bCBmfN7KI0jF7FVcIwwTkEEOLcv+QNu6+PHdVqYUXwK1YUOM4dPp8ugMOlaJD3k4dtYPhq39lN9FJQUsYiWpou3cGFKk9gnOmIW42kBs2ybQI+ZJkYHGtc7cPMdHC26FkeUObz/5cCAJyQOyGDAXfjIP+apwojJac3VbG/b8h42MJGGZJGKj7B038ijTi5JGPIhc/5JEQ/PEFIC9qgYDwMV4h7efscFzywZYFdKO5JZC4dXWRgAJfkRq8pWmPMcFuRxW+fFFp1+s2GVNvXNUj1ASa2IeDFDedtT8uduwe6iYiuCCBkNB+krCqaQzd6QRWHOzLSkR5/VSrSjF8Y/bYZ8ymhkuDnDqyBOuIKfxITzeH0F8NRHzc34RCje9llew5rsb8s7WlmrKao0/Pdkj2nLJFwNxXN1jwEsTo1LyqiPtAosdNZ/0ZGb5hznLbhH8ZabzfSnya0CVBaCPsJzT0Jg3qztzLrI2SkwJhOVeByriU61AMK2XXZvTYGhiXvHpqiExmxQz111u6zxlLkGBs4AEb4jO6Do60sx7HG9IZg/pXziP3XYhGzhBzr+dfobYJ6ahKuyDXsFzdR1n8mMdNfItfXcfm6moWNnfHBgDOm9TiWDTm3w1wMWNtM/1AUPW3bsf/bv3JA5hSCM3NdtzeNl6mUiNfOveUcPRSuACAaeZBwrg/LLOvG5gs0GzfW7HatZ5f5wOObxfwGjH0pQwUFOawupZsr4xk79msdW2xR8wnXz9cL9S11iAJYciSZ2yhAc6XQ6sWt3FALSFVUpuPgAzXtQUZalYJOBjbi7PxYlnm/g6OKqdR3y+oWeMUdT7hEczhvHqTr0IkSRWR6pLMgNJe75A8LyzRiV/BwnUNAQ9v2CYzt5EvXOhaoY+p2LqD35jOWJwysbLO4H2Xkv+VUcXae1fzJX3dqQe/ONO23kiV8eYj4CHLiK5RR3skRNiqXfuSS+kU+s/aQUQUzws2MdUrq/96ewsglkEJ8CJrP/J3GJsXhBHzcwHCynrHqqgPpEcd78QbIEgk8e7i7kLUZXyqXl8+5djbfxyDvHlk+QADJMmbPvAQ7B+pOUeL/z/aK9Ly9dpkC5EumDK2hVGIg4KxpJ6t5q26oyXpaGhr3MJO+Xlni5bHHOoPpzqeYT7ZUAUEBMqoFxXKDeLM+3zTFrjd7EgEUT8orknnjX0QBaFqd7qs35bWGf4fbIUCda/Gee3P1YTm6+JxILHWciB6xcgY01O+eWeOy1z1C5SmX9u+bE50tfSkK6sJ3M9v7FY+iYP962J+zGtl/cS4WprYhS8IR4okb25Y9kTriNk4F4/9U7OYdHhkZOkF2GvjjiXnOr/pj2Iy/8tSuFzGCUwLKfxmxWvk66mN//3iDl0S0diCXBOW7aCgzTt3M7KEZEDnHTgcdVHKFoNecAfS00wpHx1h+ItDZ2fkpYn0qNsEDjrEqVgeSU7uZV8jIHDkloW6i9yF2cT8yd69nu6jYRemPheh2ahJTR4xH/ZTEyTGJTMBjUzqMkd934VdP26H3mgYi4AhzC2FQLFnghXirD4YsvJXVdGN17Lsuh3W1y0
"C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe"
"C:\Program Files (x86)\HDQ-1.2cV15.12\543c437f-b796-4197-8e13-ac6886c590a4.exe" /agentregpath='HDQ-1.2cV15.12' /appid=65781 /srcid='002413' /subid='0' /zdata='0' /bic=11A72F67875A431B8BB2EA739F8C900DIE /verifier=640f5fba7d2564e55438cb2c0bb5ba79 /installerversion=1_35_11_26 /installationtime=1418665456 /statsdomain=http://stats.newstaticinfosrv.com /errorsdomain=http://errors.newstaticinfosrv.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newstaticinfosrv.com /runfrom='task' /externallog=''
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe"
dashost.exe {76c338a5-c36e-47ff-9cbf0f68fd4ebe16}
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22dba4c9-0108-4ee0-bedd-2c448956492e 1
\??\C:\WINDOWS\system32\conhost.exe 0x4

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet

C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
taskhostex.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Hewlett-Packard\HP Wireless Comfort Desktop\TSR\xDaemon.exe"
"C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-590cc83d-c197-420a-b963-f01f8dfe3a2d -SystemEventPortName:HostProcess-3591a581-15a1-4d97-9933-89cdd8936eb8 -IoCancelEventPortName:HostProcess-2c8f2cd3-0a0d-45af-95e4-0d169f2d5473 -NonStateChangingEventPortName:HostProcess-9c4ff9e5-82de-49f5-a350-b31525fdfee2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:359b9f7e-144b-4d6a-934a-6a68b7f99a11 -DeviceGroupId:WpdFsGroup
"C:\Users\Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe" /home
explorer.exe
C:\WINDOWS\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {9BA05972-F6A8-11CF-A442-00A0C90A8F39} -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.mystartsearch.com/?type=sc&t ... 774603C52C
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2996.0.721394132\1648701896" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38,46 --gpu-vendor-id=0x10de --gpu-device-id=0x1380 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3523 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2996.2.1315074101\518816428" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2996.3.107860929\631552921" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2996.4.941343520\1458176620" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2996.5.1944744620\1936788443" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2996.9.721716070\1257252553" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2996.11.1820940086\316308258" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2996.14.1933550718\1809685940" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2996.15.473898931\1019795047" /prefetch:673131151
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe160_ Global\UsGthrCtrlFltPipeMssGthrPipe160 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

"C:\WINDOWS\system32\SearchFilterHost.exe" 0 568 572 580 65536 576
"C:\Users\Neli\Downloads\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\ThumbnailExtractionHost.exe -Embedding

======Scheduled tasks folder======

C:\WINDOWS\tasks\411a1d27-7478-44b4-8e65-733920f016e2.job - C:\Program Files (x86)\Internet Speed Checker\411a1d27-7478-44b4-8e65-733920f016e2.exe 001726 11A72F67875A431B8BB2EA739F8C900DIE 61752 1418665582 93-0,102-0,178-288,179-288,180-288,223-288,263-24 Internet Speed Checker
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-1.job - C:\Program Files (x86)\Internet Speed Checker\Internet Speed Checker-codedownloader.exe /rawdata=ZUItHPgJG4+ITSffUvbg67rrztIlFqpkb9OCXauBouUxlFywlTmmwPv4qmQ+AV2oGwl34yZVIkTYgOW95U3NpPegFKvxe8bUqcuzH7B+7MdFe7dDlmpsDluXT1xhvh53pPaojtGC41XpMNCBuRD6XHhLYfLm/NET4OI3+zR/lQ8PWaew2L8m+4R40f/zT0U2Q2P+K3P5aRAhj40onC+0SPq2D7o90Jcb27Pnw34hsJ3M6eKDrE4opOQh4JBByJl4ehLJ8OR9sGETqGiUr7qqmcOlemCttdrW9z5KaCDvnDp1Qeoet5Zv4jQlNUE19qEMeI2u0XqCqvUZdhw6xJuut3IOGxKrhvjgnnvo1VINfiqoUXV8ZMQ4WC0zr+URpVvBPvTQU59d6hqFAgVytyVMRXUEdN/AOjxgt1uti/NUgG7W6EnQbN9wDJ0CbAeCtKQ5Y7uAp0VgMwp7s9kfgKm3m9x5+jEvfulZJQ6aYxD4OvOHLWwM/CxRi4Iv0gLpmdXbIQLX5aZyl+ao/aX3BUH/xzONpZLbIVkhUm4GjtO0yxLiDI/uFnBSM0qn7Upz/3fVUJ74nDay9nE6t71O7d+vFX1i2MidPM6i19nlYEtur7x9+BXtzxIYLJckMakAvjjX2HPEElvRqCWg93cW/5MZtE8d+iA8Qqw1L89v+ycIBr5yX2oUXBiC3izuoGI2uO6RbPKaWKuJ5MFubf8ZCkIC7RWqXTDB7OAM5GiVdHN7v1BYASlMaOuIcg7ijNnArdkD78ekkrg1+A0YfoMghmiq2gUnbyCu1QrPSNbOahR4sd2GgOVpMPZTZSnv19dOTWTwXFKh4YGRTQ8QpB01gwpF9we3bSqKbGubGrMRJoQrkruF+AR4XZBj6QxUWagDY0BV8U7kQHt5I2I5VKGyhUlw5Ls4AoPMt2I7oyZS7PFbk7NulZsAxPZROv2xHR+v0SZzSTxFkYPlAvAgxT7qXnmpevAd4wu9efd5ZKR3P/Dx0S36dbUsMy2FnVU9H5n4nSCiCHDO3OA4dMnDO00WQI8V0byfKuutxizMR7cMUjuDeI8mrEAs+LOgIV9xUSckXEMXq9aVykU8/aB8Cx0YJhKF7l0Ylep3QrXEs9kvo8P0jrcQ5NzbMOdIsysOSAWoUStH8f3MB3MCukUWSkCrEpsWFI/g7RbISZPU4g+A9T8h9ygDkELMuw8Bn2Ehgoq+F+toAXxxzUGWvrzf2aSayM5n4p+C5UQnr82juEYwgwfdmii8kDIIXDVaeObkSDID2MNENuJxa1fNo9p+MdPSbyVdgOwuc54uZ2UDf8Kpc0eGmmvAgJCbWHj48pMhEm2/UYHu4CVErroqbAwY/Nt5srAGOVi49snKgrFP8xV+WsR3WnnYJgP/1g6c5w4T41ZuceiPhN+xDXopWq5dSt3qAJ0H8behXSeQYGb2NIqV0ie353DrOQvIXQpozBJvTv7/Tyw78JTs8/iui2P+qEPOxIAsrrPS7TniHFaoHV9wa49GP+sqHNWdHYqoNBLXtMjXOmI7
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-11.job - C:\Program Files (x86)\Internet Speed Checker\4b481524-b745-4c69-8f20-85a6f7bf363e-11.exe /rawdata=ont1yOYfonaJRj5RfBZxfd71Rq6RrGsDtHV4pZjQOAV3vzf/K7/Ct8NJyNuZD7ANP0slRv4N1XkEfm3dM3zL/wg5JWYxr8N5BVGfVQC0cr/i9AOwhSAucUqjVYYRmtNJR+CPmXcoSQjrlGQAEeT3vgLsnKEBDL5WlSzH4s2COtzDTI7iEBHInNZtGWFtdVKV9UmZhVVwpWy8SH0iFUSHWoU+SXsYGQ+tsk2IVSDS8atzRPZGCzxzs/99vF7bjttnbrGu5XWB4+hwLpjFe8XDEIxvygiYtGo7Gn3LEFtrp2wAEhFk6W/YOsOJfCY7Fl6Fx4vwODzgMHFy/zis+Eux4GpgN/LNNMYqFiIjvx3XLNV9Zz9sTkPQspf2lZhYXTmfCH4GFc8VrNiysPJR4FG8M4AkUnV+jkh7G+F4d0rzm0e6Lg1X+zvuMce6zPLv+VPUW+EaoM7nkQMfTHtWnhMn9p4VDgYYOB7SaFlbw6zATj7qElz82o5HsKloUymKuZazUxigGcWh/QgRT6mMAGGkeIXqpeWvKzTYuZgHUdy86CEFx4P5rO4MoQ/js+GNV0+XagM9hW7y/o7cXg0eRdCfJuUvBz/E4y2lvIEfEi/84lIt67nPp3oWKQ494R3mzN8YZBvzs2a3ygR4e8HCeWHZrTHbPL/gwhexnv1gbGpMKzesBNe5+mBsgCeeM5xqln9C7GwfNQwmZkHvJ2punerDjNg9r2fVujCIELBXLvCcl+sQbHR3lnLJQ2r7HhiCgnwODBiqZv29zbsoU1jv4tuj+LGbcPFDMILrZG7f6GOAhdW41hDzaVSbIdavKo/WgvnHUwmvfy46aKd/GFwpLM1Y+7ePAtyVfggJ7OrEEg2ttB/FRPJdX2vqIrm9Qpl0Lu/I+b6NgrKGcg6nFEzxUwCfRMifFnJSHSAzGXd08hRZJbZ6m6ixh5+psD6OV2vqiKEglt1a60cNRqb+QH69acpC/F3aN3nwz0Qh/bou2w+NzGR4kbcktUK5IXEnJQX4y29dmrdnjM0Qy3GyU21RnYmje/LEbRXN0+p1J9meHcJ+0I2yDq49VcqucF7yXRk1nZmlDBVpjOdYzGYWxaAFcU3Hy/up5tjaSXiICXyjLY1sV4RiVvsb/fS8JzKwMR4e3lbf3K8kgFhJjegs4yiCGlR0ZLpHcyxkqyvrpCY1iUugPqU/PMQCXxgN21cIGmqBTMVwt7BLPtI5/PtHcwcgbNuKQ35+KxPPsPJjI5tdyM39UbQlxho606AWRPSnekQ+Nc8MElEV9MyRaCmYTmbmwitVG0GgUHNyQ8w/KcVNlyCW1vOXAhypiKcmeP0QoSkWe62Yy+mktyEfq5aQtSfs6mEBagFx3Q/6gXHkO43i8KMdhvRgcE5CZS1svKCrLVa08qym767WBG0qMh9Gf6e05DNi18zlboVysZcD1BH8fFqj7Qy0z6vmjc5Pu7D9RKTd6gF3XbYFCJHTJH5Go+aygruKkWjSHnBZe2fhJ6t85Qwgi5QuF3TvHhB04lGX0avdZaDprSQBAyUH6L+yQOnN9G43S2UWCfmHV021g0HP8qICmR23pGnj4gIFMIZKsvbqXvCzR4kz932Zclw6dd7EngtU4qGEjIx5/V+xw/QmnWbHAuxDSk8QzXPU4IARZALY2KteQk1WzuS2fYe/f3JFxlYsm1Lz43Q5a4UGqJ/Fcqr8K6sVgF/McoZeGHlYKfafojZrExJmczf3+LQTDzpB1SyKgUelGTFV5JpWmmQunnhxGSDYJmV1m+kI+zQVlZDLevP95CEVgZbwV+xmGDEVmc8nLa2YVY+69NutVsQ1VehCzwpksDTXIQ7q+WalGoNWXuWjY65MbG5bCgAeU39yRhPL9SS1Hm7T2gEAEiwY07M6vNsj/JMHa2PTRbZOS5pyNabVZ4MIAjcV3CbKASZJmymURsQWijs1lwfkb5lZ9YlIq4Zq3aoll23PhtnKUVIsP2ztPnD3sunCLtVL7uYTchGPrUjdtIFLYj8UyAIW5n3XNx5Ms2RqiQyo6s6mfWFmeSylru1kPZudTMRd6D4lpvHjWla1HVChwGUrW8ubWTchzkJgh10P8Fh0ZVA+W8hlpprHHNA/cErJPjx1wsf0LCZNt3N47LmFzcyN/cRqHpp0kjA5wlASN90w6Ry9fNwCXsoDrLhlEBGy72pIYfTeL2afg8BixRt/NSprLN5fGycFUgCsxJ7XQa0yqkckWOxX5W9SKgr831a650i+Yb3OX36+WTJ+1arjiZbjs1bTzmQGQG6+2dhQ69WT8apMO9rGAFf3Tu80cyWnkeiCabDJ4HZmmh2KzN37kEMlnhPQfx4KKuKNJfzM14pp18vT9nXQ3G/EtXzgJyrrbKuyn7m4liAN7Q==
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-2.job - C:\Program Files (x86)\Internet Speed Checker\4b481524-b745-4c69-8f20-85a6f7bf363e-2.exe /rawdata=bwqgnZXBdhys1de+ULBxiFXHj3VTFXtTvafNFMB7W6ckVuaGLZPgb5gmlTBMpSylNFiimxRHZcVoE3jSBZ2xbhvz/l21Zr1MrEpk2GVM6apCICvhYiT7S6rK2uMFNccFEgasHSGmSsNOySrlkF8sF8JZ0mCg8tM+DHEzKrNl/Tkg/9SRONQkuE5fIVQHnRsJOfmlTODg0nkj/cTOOZYAITQ0uJcuxiyXvgARV6/EzJFTCw6SVMpwP1RBWYbk6vnJXATFF7SalKUfP6SSv2QM+3ZYuKlB9VeMsArTdVNJL/XgKdzhNup0XSmTn/xPAD54FIodynQ6Ysb5VeKSPiHPuYkKnYoP/mNpR9PpkWIhnl47qTDnPXMVhOfJz48b3vG9q8Ur6LSyTN/MjYri/TmmXPs9PqJFU/K7fZmj3gkVokojay7CYM5ii52QdjoeY3r4HTffiOZKLHKML9RoEgDtyiAyoKnU4AlGPFVrHqTaB146qAW6Coi29IulMEKE+i3bYh8JBDC0DMqOvB/0sRgovVPrK3aaIWehp/aScWWdXdsC+rs1032ELpcI49kLggMVAnOgNy3MOU5PZNEkdbpN/XT+dEv4cJMM2p/DrlyILkw3bd6xWTMxbsR8xeAuxcep7HnHYinLqIiM6MjFxu6RP3NT96dF8k/Y+q5eglhbdA4+hv7/tZ41DZdpeLz/sOtjfydJQVXq8WryjAeMS4JF1qyAMWgcsqsC75CeOEKHQ7Y3JnqQvQ7egPLTi724QhyfUKk7sgmBTUFPdgL/dRrM2a35uSkLKHqYtsCPDIvYPDaC0jPSA2scBtgmH2e0p0NzzavPJw4HO2dDq044QjmGWw==
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-4.job - C:\Program Files (x86)\Internet Speed Checker\4b481524-b745-4c69-8f20-85a6f7bf363e-4.exe /rawdata=v2Bt7cZMpdDABLLWCXC9u859J3krO7Jxq2usYTmhwob8kydjDlG5bwe/Frsmx7fQ/TGtncOkf5o5aWfCqdj4Nl/fTxnh3xRMFOcPwAvbwEi+tj5H9JeK0gpjA1FUAiFbUtTD9YeaQeTTT4IJrCZIT4jSMjoqg7tEgp54mq+ViE2FN5O4giAsrmREDYmv5Np7/eM6IHo0P9M2yVtmSZWbgST5YM1BFKYhO81oa7I08PWXVm5aTwx2YW6BDjwtROh+4tqt1BArj3EmDmeZb9dwZaM75AIqGql/lHn0pzfJxxVF7d/dQpbaP5i9e6AI4lagCNRb+ot2CWRdsULn9RlWmm9Z24Fc8Ov7VI2mfHB5Pk835b0Av+0SYzNAHXc90UDzpVdWQOZSkrRdXUHaole/GlSUjXhuKFq57JKdC6al3KHuuWQ5C+Um/eMUyejQ0P3BE6RLS4Zn3DDLKJeG8vDpB/eNB2q8lSpS4hg+SgSAQlFqBZw0AVhQcZQn1YgmYIN6MeBWqwO8QXMJEr09KDqdhOrPkPFSzGhvrosJb7/Fg8XKMrG0slZk5FtY032n1KdIuszEIMu1pmiwZxZZtgLQBfUpaf+E2ALd7D9UkcnLLws8r3lkqqIe+3csZhbd8gVq+ENHBHFXUr7hy7wUxzBi6AlS/8mO0SNqmaTbaXwX+456SgBjEhAkIlvL0AqEkxA6Nz0UmrC21JzDQyO1/1IHq7fR6vdiS+LNhqndHVXmiuDEJB4GBldNcCJ1ImB3eA284/xVS8iU0NMm9SHHkdTvAb+DVQEkN0nNIqdepuCr16EPI99Z3F21+lPdrjuHy5YupfU7TNW7bJ+FE8UorUwmTxrmRbApSCBeT4TXk8BCAFl9sm8x1o2BnHKzRMgUwXXvVQSqoxuXlG+RHyNDNgck3im/W1EGuYU13tbYw0i7NtpNjPNWefOQtDZvryW7AuBxBOa7YFqSFUkjPeHHpIpROP/rtjjXZGTrRmh/N+3YqFprBQV3cf6eSO0MC3E97lEOBmAUai4dfodC7o0Pp9cbi8d/y5SwOdDkcKtI4Ej2xfxxjHeZ+ReDC9C0yTWdc6NW2MmOjg7Xi6UHbPrz8y7yJ/k/ey3KstdWl7zZObUtOuOvFNUwGv1ibernu+Z+x1IZuLntpCQACg/TGXo6xKSCHdtctrhh4+5H7xkqg3c8OUp5tS6qbZTbGW5E+8spHdbz63YzjIkLk36WlbvzyIFWr/HtRGcynAeG6A+JArJDk2rt1hJjF7g+s935tjS6DVkUtErrZkBGQdEoosQhjUgE5ZqiYHcgW8Mm2E3dSgVpmou/t7YZRV54ublXtXlHoDOh3wNgV5PXnyVZQK94wNdw0WbsoHJ9l1V1+pPQPxq5NkLfd0Uq4jzOXy367UpaeQiBUvhPKSNFkCnyiNq8z3qaxtQZrLWavl1+U3L6eO185EUPSQJdZmJivvMMu8ztcFi9aCmEeOe/J8sBYqahy8rY3/pSFzmZxl/HLSnC2aBIu0neOfr/Ikj5KZgBexmPe2sLxMJrZvh8lLK8NkF9n+00gwjp/xB5TfsXk1pBL+7BqUbBsR4UGwbKN8/LGA3CaHmk9Ias5cijkc9dabkrtBGXwSFrKzLNeNJio+JhtFZzM4B+ufy7ob5lrmvKOgaa8OftGF6mnSFx+nNRmH2glyHPe0LgUW6liYdI2ongYiAXsh7AUA9B0mup3TMmuJLksZGv2DSwtMVmCgNW3y7kIQVYrPoh1QlSTjBimhbuBnOFDnniw/2XLjxKzh2bZQvE+ERRrz3LvoJqYzRVxGJT1ASoTj2H4uivUFuDlXZAngPRDLfUmH32pH4pVu8ESaXvbVQxiNejb6bYPyfzoAjLqd1/+A==
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-5.job - C:\Program Files (x86)\Internet Speed Checker\4b481524-b745-4c69-8f20-85a6f7bf363e-5.exe /rawdata=EC6/dE26zwYHoSwS1TeJl5BbAJptGsQxKLtkQ+SqO2K0rGxPjILtUkdgIHXowqkSqRYvCRFFZod9Fs8oVZM36AuBHAdufR2SZuWPK/LprXTcOPxW+8ftQmSsm1Hryt28zOH9lxOvgJasZgfvb28WrNpfS8C1ubv091Yh6Bbaqj9bZC1N4KmWsLDVw1PPi2PGOptvEFuVFjl8s7j73y7THlVq8Tgu0b/kVR0bhpqu3DzeWqdJEGEwOfmpHymp5k6oY+8YP+Ib4/hqV4fDE0Nyb+1SKpnKgoYBpW8CcpOYuXWQzxto7IzMufmX5zVSy58bl1EjKZzGSC8yMMEZHCLEr4SzKjPF0Olg1STUAZtj03bgkSlkBgUU+Co4U7uu4C93eNKNpp3A+hHB6DbmQq2fnE3OcmzeZS3M/q1946YHlu/Lr9GUkGR2S9J27tzhAF1o1rbArBwWOFnhjSn6MK82J1XwLNwps3YkPsx0GWcJ7jXYbU10PnSwqyVrszgliBGoDb5DMEsiw6xGAze4HLxRALxHWMLdCS8N6yTiEZPkNsH6nZW2k7YaBMM7AFHLcaRRoNbwJYIqEHz57Yb+07c3kVF6Rat2vgiag3/tA3lzjVSiBhFSChlgvpy69iEMg/y7TAERZsvCAez64dzXgjLR5cpQjWo0df8Y/M2ZlnoU1nJIFtBKy2YMFui0Gytj4rJoe/BFF8X6pLqp1hQyqEDwnFA35W/dzMGzLa1C8RPCbvFmlfsuDO/U0xVrv2OffgNY9jrKXnFL9fzv4V320ByE/i7v27/eGHj7APG9uTFUGfTfeCPhPbEAAcVHcmj9exCB0/LxkhWDzI95IN4TpYRtJY3oZqN7BEsupJnj49ul2zLZhOsqwd8li7S1iuYGCbA1PreeZTcgOLufC5fjS4luerTJ4ogHHcNEW/YvhoH0L+TUK9hAB6RMmZMuemDySpu7+XG5HFCNHKFaSPuTyF1ChUBnt0/hGngII/13pEWmxubcvHHVPnG5uOp7UVdnVIbv
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-5_user.job - C:\Program Files (x86)\Internet Speed Checker\4b481524-b745-4c69-8f20-85a6f7bf363e-5.exe /rawdata=EC6/dE26zwYHoSwS1TeJl5BbAJptGsQxKLtkQ+SqO2K0rGxPjILtUkdgIHXowqkSqRYvCRFFZod9Fs8oVZM36AuBHAdufR2SZuWPK/LprXTcOPxW+8ftQmSsm1Hryt28zOH9lxOvgJasZgfvb28WrNpfS8C1ubv091Yh6Bbaqj9bZC1N4KmWsLDVw1PPi2PGOptvEFuVFjl8s7j73y7THlVq8Tgu0b/kVR0bhpqu3DzeWqdJEGEwOfmpHymp5k6oY+8YP+Ib4/hqV4fDE0Nyb+1SKpnKgoYBpW8CcpOYuXWQzxto7IzMufmX5zVSy58bl1EjKZzGSC8yMMEZHCLEr4SzKjPF0Olg1STUAZtj03bgkSlkBgUU+Co4U7uu4C93eNKNpp3A+hHB6DbmQq2fnE3OcmzeZS3M/q1946YHlu/Lr9GUkGR2S9J27tzhAF1o1rbArBwWOFnhjSn6MK82J1XwLNwps3YkPsx0GWcJ7jXYbU10PnSwqyVrszgliBGoDb5DMEsiw6xGAze4HLxRALxHWMLdCS8N6yTiEZPkNsH6nZW2k7YaBMM7AFHLcaRRoNbwJYIqEHz57Yb+07c3kVF6Rat2vgiag3/tA3lzjVSiBhFSChlgvpy69iEMg/y7TAERZsvCAez64dzXgjLR5cpQjWo0df8Y/M2ZlnoU1nJIFtBKy2YMFui0Gytj4rJoe/BFF8X6pLqp1hQyqEDwnFA35W/dzMGzLa1C8RPCbvFmlfsuDO/U0xVrv2OffgNY9jrKXnFL9fzv4V320ByE/i7v27/eGHj7APG9uTFUGfTfeCPhPbEAAcVHcmj9exCB0/LxkhWDzI95IN4TpYRtJX8NS8aNeYzaLSMy9TbgKn9CxKlLezTCtpEefbt0vTOp5mCpqSZJVT6Rujr4AeRmu0tVKjjgb71J3xB9MFdSP0oSv83IEVUavWpvPeiEMk2JzPgY8ZcqzFVqOHO1VyLpx9bWkzz/P04b5NAQ/suZKtoGjiuoEHlDKKrth9Yr0jZ+
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-6.job - C:\Program Files (x86)\Internet Speed Checker\4b481524-b745-4c69-8f20-85a6f7bf363e-6.exe /rawdata=fbW+VjhdJFmnWcmjYygV5VLmGAXcQBFs8skCIKc4A8vmsod/56mdwXV0AkgtBrEShY/9Noyc2K7U/+jpKrhvl6COmcNndFSAXLLiTwIzFFzyYK2uoT8pdtx3eHnJj28sBE10m/2xLV7xRlDb6W35RRSzCpUc7kE3LQtuWFdcwGJvWduBXPDr+1SNpnxweT5PN+W9AL/tEmMzQB13PdFA86VXVkDmUpK0XV1B2qJXvxpUlI14bihaueySnQumpdyh7rlkOQvlJv3jFMno0ND9wROkS0uGZ9wwyyiXhvLw6Qf3jQdqvJUqUuIYPkoEgEJRagWcNAFYUHGUJ9WIJmCDejHgVqsDvEFzCRK9PSg6nYTqz5DxUsxob66LCW+/xYPFyjKxtLJWZORbWNN9p9SnSLrMxCDLtaZosGcWWbYC0AX1KWn/hNgC3ew/VJHJyy8LPK95ZKqiHvt3LGYW3fIFavhDRwRxV1K+4cu8FMcwYugJUv/JjtEjapmk22l8F/uOWgPigVG0/9+/02g8vhFwywh6fZNaZKJBdyvwn4W91ym5QiCDU0Xs4WGD/q2HzHTr1tZtLF4btWFTO5+IIzkkjN0MRSwmuZTj6YDl5ARWaKjRNI0mVqQo/8pOS9z2regFIEQdNWvsc/2WupTmN6tfTUyZ2mC1P1O8oC4DOee1a0Gdgpr4YRTQkldnn9N9RRCNRNfeLwlkoZQP/64d59l/WStxP1XtFgH2jrLGg2uAD48BtmtQunV7DRkGp29uXmoMjes8hzWZTwBV+6eyz5o4V3h/MIih0VN/GEN6FXXcBs6RkS4TQvvYV7o/Ya51/ORKXexBjDo1bKeBXZ1eg941W3QzSLlp9wHJaGuVLZ2abswAllKgUDiT35bKGXdkNQ+JoflEO2wZ8THQQ7zgTam6OLShLUsuVB5u0ndz7PEIgsFYXO/ahLX6nYzusSEzO0khgIgMjWDFs2QRpKjeo5ivQV59QEKacX+CQGjXN7rIKU2h7fHf0xoivdosK/u6nbz5v5yiZwyxofJDIZGxkatMdI8xg41Wtkfl3iR000U0GIwSld3OB1eE+88oM2R28IWYP6i169yC3FKhoz0OeujOmlkRyZvzECMQXHWU3OAOJykHPRwiwBnLV2GUjuUCjD+r+FeyCmCxr8VpPr02RWLw4xBgU6k3i93aGRDWCtrk2EuUKPI9pjaVvt/ROcB4gJp40OSdmMtk4+yg7WyydZgerT2T8CHmghTDYRizrGgC/6m+X7BMcoGdcHWg5dwIt7rq0ukt6PjMtpb3nrkCMOf11b7UCP/ijtaSSp8SJsNyDlhJ+gxlLz8M7z6U/tvJh7mbgm5eUT7n65bo942Yol9PJzj+vtstrsjEBKMuiGxYLgL3PCjDuf5jKP4aS4kEBcQrTehdEXyUYTJ31IN7rUuIeeZxOxWRfTvkBmRonAaLuw9l6ZwvNfOYwAkxONYN4T7CDL36B17jKQv2WbmH9UfcLEPpzz8xoSVB+I9cu+TwOkFxuE6J7RvhMR1Qr6bJs6qmijTrYu9hF1vCam+HHKU1FcSrHjzg3imltmSUX/F4D4mDKWY/k7MCf06ADAtS7C/U1vUztR4yxisG0LU1gZqNqSrDEG1Zk1kdubK+djNeN+2TNwQhC7I1EFxF0CS2AFsuwBtwOi26Xq3gp0FSRL4l8hcpRDpP2vHfQEQNFNlhhy8BsrlOAdJl3q2seHXXno2WnOeYfzMHG9IBjH+BJvZtywU77lW94BsvcUfNZvCyNCfhURSK0CmpslE3+BDNkunnTFjRdfCpmHMYy9DB6z0NnzjEVBncV3Ymb/VaRZ91KzgGbayc9p3PWeDdswJxScg4d/4CFYQ5Yt4d0r6rhnBrWioE95cTuOql44VWU7uu1bA9wSfGwGuYal6gyx5IBVq77IX/BYWXyxwm49RBY38ApAL0s58IBqN2VTIPF6SspGKihgF3dRbyoqfIk4GCWA7Q3LMkY2Jq7IwmaohgZzjxRtioou/HR5p6CiAkzt2KP3yRPwWa3MI6cdEt4f2FN2YsRapFekcBhjOVgucU9DW4jWVasIDnvHfj3cNIQKN3uowUZ6mf4TU1tC2BG6fGBPGa+cO+qeOHe7ryWY1h+mawBOcGvkrZNp527Y8gv7WNAyMvz4czSC/jr2vT56GnZ7FIC0cDlUa6lg55BlPwxf20nwWqNQME1yTY3Fo3WkFVpgR1FxWdhsGxWa4tdEXHazMkPXf9U6mfZ9zmsz7oFMI2AqIzLJcXzmoOMCuwASS9CcT4DzOeC0xKbInoQDejXB8vEnVbJh7mBZQO8LqoVD97LYlc63jvOtGAqR3J4RU03E7ZizYRK3wP3Lar7L0Qk9fqpJewJSzdSe4Mp87SyvkO0pIquW2Yxk4/nTOTVI6DI+4bcZrz8w/NqTf8NZE+cYJ3IIMEl0UEemnMeAEsEyMKf22zWqiVGtNBoHncCzqaid4vhqzCJibt22IeyhEuFybI3Le40KT7R9vmQZ/E6b78fZet2dFziyf9BhltIRqJ72VAhi+bRKnZwt3xXtJAiiaZ
C:\WINDOWS\tasks\4b481524-b745-4c69-8f20-85a6f7bf363e-7.job - C:\Program Files (x86)\Internet Speed Checker\4b481524-b745-4c69-8f20-85a6f7bf363e-7.exe /rawdata=T/59NdXHeRv0NoVbxZgjDDWqWoGPz/NI0Fi+z2tJnW7tWZpJn8XyiT1IEF5K5ybftvxXFy6kARqFhZS+MYpZoigMCaPwj2hsCvhr4dsz2cEyhNVGpeXH2dcTgcKfzdXqmosDdpYgABM3g3t87Ui0r383lO+RPyQBfA0w6MasKGZuAriIehpAQPG+FntYoL6OpjtVGByQWMwFsDebDHVwwK6QH/RBGpKxsb/kR9P08s7quNRCofWtmkuFpQFWi1DDzZWbNSZ/Rt/7HwnkUAPQznwPzt9v2+d9nEhQYyqNjMGJxKWkoRY+fKueCWiwaVulVU1UNsM2inWpTs+KKjAZFRvxR66YbMeslcsSpjWzQRkinIw2WPyDlq8n20CW4J+ut0lDRmsv6dakP4LgCWy3+W9eD9sqHI1U64bxsoDJxJB83vrRVoxEOkFb95LiSDYweCf56k+LvSyyMzjxelPOfxm3cMmyzzPZtBwrzRStXs918B//YsF3rTvPaIKq3KfMMhc3W+iJk+Y62NfWkPM5u0VyONDOUYbr+94P8c0gtlyQsVU2i9ebx06JtkdqRIvBiNtvc3sZqoXO0TntEH4c1X+fn0SZ4uWFfZzaInJbL6X/zr+JbczgnKZgB7k8cPogt8X4Oh2dnRqSv60eJqUcN12wtN88QKK5m8wuCmQzgegBWU2bmIRtobfJ70r5MDcybeANrf/2aDhD99DbMBsBR81YC1nSbHU2GsIRXMXz1WAb1A1bUZgqSrvZvN093kTQaq4h3C1UsFkaCJ4T2NvhkGDxfke3LlNFMoz3pV+8QDYwOrlGfQ3TBLXA/tunwTSsE8+1I7pu/e8gY/1uVxDJ51SosYfasijWLEnX//ql8iq1BvOsKCqOZTENfq9msKo4Iy86RF/xLXljNdKZVg/DhPrmnbrKQkv3XtXlgpzAnkoA3RiNkiMY7cX66I6ly1CBn+DRND1nMKlhaljI91S171PMx9s5+KMlqvsqMs0LExrQralW05QUST6fUrb7m9vPBS1HhlLhX2J7+oD9+wsGC48O5t2iDeBLA2dVEobX8X5UklODKnuO/8HUpBNMMhDZVgXWm+ACXaVr1731m3ArP2JErmbEmYUJMg6Vdliuyrc59dc8+wOV+gChNz0U6fY2oFpIYm5GlTELmok+vL8n4zeMxedc3dwZco2McvojzEONg7qtRlizTR5LXp/89TYA7X4y6C0rcm5KQLe2xtiYa/cFl6whOX7FHQbALmdBAIa7A459u+zQD7IdGFL1w5t8va/8J+0F4yPfYSx7b4RWHsqsXq4sVbCuqH2pD62jLg6NpxiT1GXO73FHsPlnOa+MHjj6QxuYcgi79/UKX2ANux8AyZOZ/FRCEnZvM1luBDNsaH72VeMnHBYUSqlHVUno2icULPwuT5pGoRYj9zrzCNQ1VV68sSsGap5I6ye5HvcBZNflYMQBX0j6u+SHHbPIKEfPY7t86f6GmZqi3Ze+L5uWOrkv9OcTBUcs3x/lW+1VeDM0luqUMUs6xwe+b0EXrmYwqbyakJtZmT16By8npp1hoyUgukyCjDxw7Co9R6bRT321ivlYdPpNlHy7oHrnXxeeA5oml9gQRtUdgTwlf1YjlcyVnTtH4cHAbsw9ZhfDgDYXkq9OaC+vDnzATgNXsY0Zs1jfzSV5pOdLWgLmC2qSb6WNORmgyqZrP1tJ66irMp71s5y4gyZWwI0doTlnGJ1+Sw2TG46GMbx6OwSw0tdHlbtnTzumxIycEu2Vw/++c/OwRFJvV9FsGsXOEVhC4hh1d+a+c2feCIEX6EHwbacgFTaKSUa9/xy9CT6oAZIAjEtAw68jRbFOwIscsMPS8hiuKQJlp+BLmmjO58YmB24cfym3UjL4817eSbFXq4Cxq/QgKGwBaRqUjq51zg2cEwjq0MsNO140xZqZPqBCBWaxHj7EYyEUknVvxIzI2kmaihhRDhC09BwIOrZFzNhrbY0T+u8qn+TBCGacIcVx2wQypyjmjj+1qNWyImH0F3oIg+tymm+hhNiWzOdcFqv5JXPOkAPwCZseATJO8JC0XQXrSwIbTA8aVbORG/hXEKieZ3PHAmE3enmycOYAbfMUEQlyGltc8u/uZO62yazfapL50j45g4kMgGH2gR6/nlNAsDOtCpoOPB+UWNw1qdTHWjQNK0UWtdaAodwRjKTjkuC2uJvHdNYvcwhydLMBXdwkI94MNQDh0ZF3pgWOm2pynJcWGISx9z3mpGvSHzEW+XvvGj8fPgl9S/IaFZsxEefZhAspXOFa/L+JmQCKc79rytuP6Douxnw8xpLHkM/kLH1FgcCsOe+fHryjjwiX0BA+UuMlYHnk3bRcJRBCAtg7mSgB8BqUYmT5kQBJb/HvKIWxOKDKaD+BX1D6wDNFk+aBm/nBn/MZ8T7t/mUL6YXuevDty81Ue8t4dfFnEt+vCsNs5c7662vAu1G8MLx3xxiTkWGFz7PB1cG5c5pMtjNRzcFl0aseAQFe4WLQGf6kelzLRS2YyQijaT3Cial7DGD1eivPSfUJUQ08y0WSeiPD
C:\WINDOWS\tasks\543c437f-b796-4197-8e13-ac6886c590a4.job - C:\Program Files (x86)\HDQ-1.2cV15.12\543c437f-b796-4197-8e13-ac6886c590a4.exe /agentregpath='HDQ-1.2cV15.12' /appid=65781 /srcid='002413' /subid='0' /zdata='0' /bic=11A72F67875A431B8BB2EA739F8C900DIE /verifier=640f5fba7d2564e55438cb2c0bb5ba79 /installerversion=1_35_11_26 /installationtime=1418665456 /statsdomain=http://stats.newstaticinfosrv.com /errorsdomain=http://errors.newstaticinfosrv.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newstaticinfosrv.com /runfrom='task' /externallog=''
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-1.job - C:\Program Files (x86)\HDQ-1.2cV15.12\HDQ-1.2cV15.12-codedownloader.exe /rawdata=Jas+OiPvZeWeKSqHQex53XEd3u5WoRBr7m3znQfxO3CBF5imaO7C9n3oc797tlCyInCLgZrcDcmgtiu/mkprT+y0S1kBxxxDvWrAVAiHLKICxibvUwe94XIV9qz8Gy6d3u+ciB4iTytKYudnAlUxxjkC7D82VQHnSq8ggie2sQ1Bpk3GWfQGouls1+0aHW4rbkKI39d38oSNOLVuiNGGn8jXfLxg2cSnz34YnZWqmg56mPSFqW/3wT+i+zUuSa4jeGKI/CIrSCSs+hBBrfyU7QCdCz/VgyV83DdB6Z9TlsgFM8CVvPxmJDLPuHADZm0ww4gsnDikJvR/VqUkD5d/NB6A7IQ1teHh7U02F/NdoJZ1hA6DmkSTdEf+yFSXPlx4+I/W2Gy9yCdZv33I4pEVuYLytYtv7ycfUQPZ09VlouKil4ajJmXPFrmmR+RAHX2mHlfH+kMKvj+ggubhIncikYPJ0OFoix5rgclzl3MJKIPM2yUMDwoAgP1CCVPe55xnds35pyQjzPJ/Kz6sr0FTIeJWxwGgUpNgqMqKD+AKl312OOIRl3ZZDNLWUKNUY+ZhslHQZUtS5kYUdyBDk4bb0oxVfqpf4Hf4Pnq89nW0AzXeTlFp36D9KJpRXei0u9BXGTQQRZ8Ii28GVw+aSr8ltGn8QWHClRl/rs4O6KKY4PsvjjKRowi22BelhRi6XG/5avt0sMk4WjXWSnrajRTW0u0pZz3/dlSFXxpNWF511NTlJui/DZxuz3Ai9uEYs7mQNuPd5OXrgHQyLDNhmcMP0PN0aHCFM5g0hOW7BD3Lv13huW0UuHcxF2oA9uPTFBZBBFgQQt1mcgi/hjjXXLFgVplPbtyDw0RXAt+hgFbwdUoltUAAEHvXInXqhNU4W+qUXmJMsP+Z4MvY1T8Ax7svxJeQ8ggOOZz14tBMmbIQ2X1WPP8unDqv5GXBoECihjAqYvWJVkCbIh4n1N4s98lBSsqKkdG8Qk7iCo4w4+nkc3J7BCycptq9HnKkU/oZJXRPn+tmDqxKcvkI07Iy1zER6utgRx5Sz3rMt5SCeU4qFWu73x4ZDtoBreYsQVkPNO8b026mdYRMJWY5h5Z6InaG+gkatOI3fqcuuQq04OfrMU1dBXFAOeWDXQ6Y+Or9xLuD4eRc3dDsa3F5pnGf2sL992Eun9ipHOng3oCssSqW2Rhk4QvE7vp5xZWEJhAnh1YpRY1ERoL1ZjQF/NA2e1sxZGskAv/SEl7taKqQolfq3Yoqa8v4tStjb4LpicimEL9CiCyyXexLTGcfpkeIDPtnbLMaVUFApeK/1O2y8wp6l46Myi++hN2aKC0xCDhwc5d6dM+UH3RyU28p7H3oUD2pYg==
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-11.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-11.exe /rawdata=GpRSOmg+9l2TXKdiKgaF8rZIbbDfJEgA/lHdCzHgQGFhlDD0XX8XuI1sBcKNdgg0dw8tXA0OsMJHwZMSq/l+V27OwkSKEVSytl9QbOgE7cB6JqLvpql8MWdX2Yzp9021DDFJcXDg7+qc4H7YN2MHx7CtmgfQpfKBqQHJvEj0xfoDm41khLZjvB/ReDB3b2AcYtajcVGcIZjR1FsGU5qryRQilydyLB2RzwQmRIHJD7WZzKRDJEKM6dwfIKSy7bbLwc0HBnUHX3nPY4AT7vFDa9Bfw+mD+FEeNOSa5kCFnvdQxgrMdzdxDUdd7g1KdKcp5W8WdW/popS5g3chfZddKGvDopmEHiteLUVhqg3cYuHi1D/I6GJMiAytGmOpVbm9GFRDigdsVRLFf4vGG6i4RrtCJoOLHS1if1sPdHjjIs9AnjBGm5P+cAr5uumvz8RX94Zf/sdGvOXoVP5b+z13WTeMDaiGK827VsvFw7TbGJ3h+XBM7mGrx0LTPOUZYeZ2lZneqtrC6GcsCz5/++k/vBXCUZpGphmIweefmnfnU2/2Jg2RDW7hnpmbXdtSJa+XQ07TpFLJR4YzGcm/33hyl4pjkhmfllUYZv+Fx2+xkgrf58dS5bIjaC+sQF8kJlrGv97/7DfQPRVw9k37/YB6obvjOyQWW34cFgQ6cPhG1a8nCPCRiKUxUVPhcI+s7o8KheRIrXA6vwuOjMaWhBfPqs7NPlsL7AqiEa1KYEiWdmgb0DxCDbmS0M/xCOOf3EbDH7off1bVDSc/JGA4QlAIQTQa9r8Z9+SEVj+XmeKhlWmSEq+j12BkeGNJdgjEnD1e6ll7bRcB9VHaCgB/4dI2brA5DSif5QQLl83KsmeH9yI4qsmruFPF/FkQDqmxpYbqhG2IVzmPYM7p7/KxTM0hKVq9Jr3yfv/89H01Jq0FsPaGWtkxRUSyUQ1tDc2S8ImAszLMHoXkfO7vistNVSuxWDwXJ4VHP0iXwmbrvdgGA917eT3SR91j15fLgvC5Id5eLsnZSLjDJn+PHqnkC38MPFFb1zjsBMf6GYTkrTsYVj3C5WKLBlYtdSSeLtT4hECJRJrkLC0myEOyzBuIcn7XoMPGz5x28zC6yiFsGY5/7fLpudWOBiqNXciYHZIUM4P1y7PlbStfzQZ5R/b7lh1xEp02G2bUA9Nkh7GAQDjmNDBfKYw7hGhQSU+Sw6E6nhxk+Gg+W+RtWsZycS8tzy8v83w4A+oI6/Fxs/gm3T8mMYn2+xLr6DdbvAPTvRHLK3Fz3mrGQmz3xl2lUzWAxHkLTcllJDg5WEGv3vmD5bf61YZ64y9LvAYfN7ilVA+AGgLEWloKp5fZmjPkhgZCZ313CX3DVMIuY5qvYbWFObBRUiQZkF5H6J/U8g33HFMeC70GMmEhhna+0UqabEE47+ZOM0uUmjyPzyMcOyCUYYFghXxPoOgpYyyUNAy5VuTSMsFJH0nTKDCp3cdCbX8+wneX4Qhru5e5XAGhNwwPZrmFsDdW5x8teGt+fJ66Lp8IXjGxCuucdOoqDeBZa0rdJsQT78+SCNm2IDijyWJYS+dCy65fTNFKpA5Z6pIJggctwuuTHleruoV2ub49GlK4X0X8sd1sGFIrfCNsddYeVxaSpWmdjtQott1pTzzZbYwlx5lN/pqZ1n10fsNvxssaknGtuwvY9kpen3WMj90WxPwNFV+zg8ztDojU4468Z5tt6zz+9lAyfK7BKc7oeIRuD1tQY4C8CW9ZwaG8UMTKs7AHWMNGrRw3Rj65Qup2JGRlrjjrLh5gKg9NysjMMYbRSJqcuBR/+vQm07J5yXrsUTA4Q3w4wC2O5Yts/NFOKRrhbS3l2iotouV/okh8J+aoFA+tSyUd7KmpJJBj3z1DCB+8lokOnDV9XEVxLRs8D8cwoB8vrI1Bh/RIIdbEDo4iOkCAwOXKjVdwSHZq7syt884xTEt1mPHRR6N/6LYmAeNcFYobNm3q/qJEKQ8h9qgArqurTY1jRyjVpjmVmmatuejEA9avdwqhJDRMKg8AXk6KyiYwLEy3VyLD2JR8XLbdoova0+tKKa53ZuEz6vznN8bcom/TuSokN0awrnr1OavEqs21AkALJ518A7Hy5l6XNh6vbp418GUSOEv4kDEh8m3ra9fQ0f8mIAHmS3rj1Tm/pEVMV8ioa55TskTLImMR3oLcP23QRs+UGzefZSPbh3yFDOVvIFeeQeaqHwfDTKziAc62gJtGVD+EKCrM2B6x2UB42+sPNGxrRhxk7TdH95a7RAWnkzotLigjUbRXCj06bKjOanB84c7kvvf7b5jIwntJOWoG4LDQ7poYWoUtfCG4O+UUWLlHQRSuK9BlMK5b900BgPDX11H+9jgMe6j/uiqjXw==
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-2.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-2.exe /rawdata=chia/D+eLVPZFshPaMvVUM9oQsUIarGEZ883rXLtARmK4E3unBhRddHlgQfxAlmYfA751ZvifyyMIQVDZT2c3EJLWxmLKnomUxlPdM9vfUzDrxkEPeobIHd3ZHMRdx+k1Br4LNmeEXhCSLANCvJs2RCpWeA55LmyaPFjDCm+2/pwdiDYqMSok5hd/QdhheNeTYmARPwVLq5Y+AxWUbsBwMLVM9l0wM9nh0ADikxctmZU3UrNgP7BJUo7cgLWD7b7w1ZpaM4dE6Ez1iZs8Q0C3djJQJWQxST3r2ws/zUUOFFCsHpY1JlfAEfj97actuowCgoIjw45CFQQCunKINFXCFB6GIoFiKeApd6gwruf/IIvI9XwI66fOnqOZ8a2YJgo37yv/6gQ0xq1+RCJm6wmhXxg5Psyh1RdGuHhuBNDC0hzHBIpotOyjKXhtDeitGBRtJLPVarxQstVO1ARChuthufhoCIkIz3g1v3MlA26WYyR9Xd88wTuFeShX12QVB6/OKDGqGuIxrI29RPE5nTwAHrlHP3u8kyAoZi7F1h243J5fB8KSav/PKkMFCPzUPHdho4w2QR0Pw2r9HpyUnGEtSPracU8kOihT5KRJL6ijthq/54EIAVWLEc7EuwSPCj/DpmYx8ELokXowc/3EwcTZJspuZwtpV7l4JZLkQkSqeuqn7SPN5BmbbZdNT8hoXPZ5dCavliRzezHSBYK33fOueYpsGiPyDcA4eI5C8DPwDCeOGAvLf/lrLSQjm9yuytHz14qBVdb7TS5JkgihYVGysCc785eSlB5x5eweBHU7T1u5uTYnmQRycn4DrRjTkJySdUNyC0CXfmOYqHa1XWfPg==
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-3.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-3.exe /rawdata=if8jVdKwCy1nWqmSCiGNPoLFws02RUe5kGRS22XIchjsBDsGxVqbEtctI1CdnlnncmW9uxxKz+G+8pQeSbBeePCWnFzLymg26qFgQqg2QDg5Ix7mwrGMncoGdli2CKjycg/0S30AV+dzj32AlWn9VgoL106gsE5i5S6ve0B4Euivy2oBC+hj6BPsa3jD9bWAsxJcoV9aYXFeeHMAItO8804j1Vh12YUUiz/XgepW9fG8SZkal3cJn1d99lJyCkjVCK6qJa30dMFbMwiRF0AxF+g9b2Hoy5ci7PheWOl6pEEG7X2bIgQLQCxVayHBie3zsRHrcrv12E52hH3M0wmgSCgO1SD/8Ezw1eJ5nVMc7ygacEM55RHJDooT7lmNGFVV5XZW78QtTOzAG8BbGdmyom7hapvad++3hPsINKmGMfCtyosyrGv1f66Fzn6ZArXYnijmLnhh5v0ptD/fgkOkJ8v6mtn0pW5PW69m9uOq3OWvnLowH3u3EmFHG69G1r2Apr/cfJNoZPE0W9QHGf9ojQGhrYNAjrS6o2xtzxGAtGmSzxbxFZeILqc7++KB42QNJBSsM0XKRuqLfJ/pRdEXLwNSdKk94nWcSoI3NseiRGwfdjguKCA1sR0P9VYpPv2Zppg+oUL8Q2tjMv3T99xl52Rvi9YdznlBQ76i+5DmYswhBWPUV4A4HNM8Q1YCty2dmV8gDcNJS16CVpqSvzKJv4Sz/b8tSQgCsyLaGJ6/TrW/ACH/9tMzi+E4Eis05ETiAnc3Vh2RaZvGHHEg8YIlKLEEWS0Q5/G84aELqoYiKS1nxkkQfHQMdL7PPkR7OqJhTTLrLEhAqHQOYX637mhKZJsWRj+FFP/QevRocO2MPxwAlu0oiXMMo5ef/RGIvYhO808KJMx2RVjYuA0iQf9uI2plY6pHE5JFs07WiPHXGVnfENWU5Qp98z6Hh3AQk3CsZz8plGL3xlJd32qscNlXpDNWFXTrakrmtWW2jZDWqq9yu0H6tVA7mPEUhfNyfINjlHrvk8PF7aro2rZmtkKJbnc1Ij3vTafBuskTekL3dGxBU+HnCdhaB7ZYbxd0GMdkuYolUfG3swzm3jlfgYmhQwlxC+Jrh+SgNxPiuOZHTny8AkwrWzYqlg2MSS4snpSWR3BhJQjBFB5UU8YTpxOuQDo/eO0CzhCDYtHuteh7X/6yE0bh8iN/MMkgSKiCGRfigO/lg+hXwDZBtarnSost5OOkLaG+Uk+Ze3tJpCqFFc7+sQ6ZI3YyxRRK+lt1XuyoEFsFj39aaVr7r6lkPKYWgyJcjZSN0jZGtTNkHkIQ8aDz5g6MzuKJ55XuStLeZKj4ZGPX60XtGoAUbVEkrbzPFIsFdsPe9YnlazBSIRDly0OeU1YUJ+gIkJwbeQrlPyesac1hJyBIgFuLvEtfKA90vw3AWW/H+V7bWxz6Jm3FZt9blEqCWvzbtrbhtZjrmi52Iq31Y9Thz8Efk52ANydKSKx4n5qjkzDbBu8UWgGk054tWn5+K0iku+crR2LN4lxir09+bsGr9O3lucXhHrZVPO625/q8s976m5TFVUmtM31WcgPEOx32P7YsmH8o8snOMl19uufjjG9LXroPSB5uZl4TNAywRFhROqPoTU0mIfJxEOzsuYVEw3BP5gEW0SwP2f+BSey9kYvdhbFP5uKemC8opNoQafh1BfjE+Zmwync5did61H9wihpb02+O+Q8w6X0S7RCtVbvUrnCqh032VvohOGBCsrJi933h9Ft2TPrtokPQRVsVDD2D1/gCyI+JW31PhoEt0WPvLjMtxBZAB0DlKqTUSlyLR0lWinl4fr9cjCGQWcFp6ZQDHNgJAGogP9+LnrLPO25djuYmrEOYEQ==
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-4.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-4.exe /rawdata=d/kan5apxG8hBJ7yxC4YSGpRlabyhRfuULIHbT6YVr3Lr0yKjoogtsgI4pxYdbCKcKw1nvm3NrEkwiM/1X5K8eQp3PZJjgjzUesD0LyZmenVqByJewQtL2umQJ9e4UbFDkcrAwpdhn6qu/brkHQFMlW4oT/2OvujqdzzvvN4aDgZj286LGHx1p6SpQBmVwlHZ0W00brTpTrgwMGCoqAKkwfdOIqvZqmnHbVdNzK4LkZlzLN7KBfz38DWkkcW0p9ag3WhTsiroJz5WinGlMoxNCYisbWOGKNb9DmI3/MHNP5qL8dLNTbQNGcVszBhsvByNeeHvrL+u0feO0DV63rJlyB4UcGXH4UoT7/uedlugw0lxgQFaLuCED4St3dzBABPbF3eoFRUeIVXzMABpKOnOJ1PC9kbf6GTSaWqlFAdxZT/H+IY/GKgoFMWhtxvsDSL1Z2uOw9FSMmx9wvLLogPGJGfCTxe8dXI32in/CEpcJDfNr/UHT2n/HFfSJNcnTsjLIadC2Ab7B43co9ulx117FoLkTkOfD/3OCpIMjja0jF9EVRFNuTLmLpHc7QNLgio9Flr4VnFBpRbZXm3L7MoISGkKE3/e/CQrR9dg5zx5NQqX2/zA9fETgNHz89mzPUbfg3aE79caA7xRsUf+6r+BEhW3cnUVavNa+SQykVq7PVsZIXtQasCq/ljIhu3OJwhKMMyvnJuUZgnBKDIHFqs7Df8OqYgIxi/kPiCdIUWl3/yGIV87M9XiKBwEcDZsNBHC3aml2iHDtygTFsahzA2QB/LN+G/mMf0sqnBj4k1YDpeS7MjFlZTmdRFHLMOD54+YvqKaOnotvy1Fz6fFTfgn8HNX43Y4UeYaX47f64w97CfDXunUEHqfX+7BchvDg4Ppymruz84rx0KAxeHDuE24xfWNZsuiYVo3xeJhGHo5r+y22ZMIq4Qzs5lme43S8IH8Bn9Nck73fsNIVZOyUXmDFqReJuRa/A6+PBMWN/4U4T3/9LlhSS+eFFepQ335CFMr8GWhpIPiM7BZNtnr9rpnY4pNXP1G3KlRyKXSyWzq3KT21QS9wro9W/j+5zd07RDSsC9qwcAi+/BmuwQGd2hoSKg6KcdAeSZAS8pD15JR2gFObZ8Iz7ncK1f5jzpkAQpD8MoNsW34jBpme0d0xLuZMvbs8s0vH9mPmXJXV7ZmZUFcv13xJ597WsUJAae0AKA0b49SFozdz4Fgk/pvEtSZMF7QIHLK15w8T6dss1If1dn/AefE8YU+HebVqdocDmBpovOmryW5N2iHlQJnGEJycmYCp6PakYFMIrUimCHhr3/gcTu9SA1H7nfzX7QosuiNIfGGjBl93eaD3p/FluhRzNxIFya3o3sr82T2v/pMRe0rrCgi0vfs8YnzoXtJiwQxT+VnIaoE/CpXy2dSwo/Vt1pkQvPSmVSbbTXyc7QCtr+yGNvZbZIxrwsoKDLAW6hjmjgWgjecuz4UQ7mkiP/NPjfj4btY6ugi/8jyKof07t+2of655C7c9IqtWGIumEuwcANOhzdRMfhWWH5ABedXml7Rgy4nbg4TxXlBeJvAx/AvCBl/SQSaWgTplg5tmjBEmipuXPrFLdxzJXzBJetZngPUMJ3TmTdYeG0tYMea7YmqrEQ1wzPl/+zuEVTxlF3k8TTvT2hajgT3rHFnbqtJiVG/BqIiH9lCGaVHnMs3tuVviaB36RPyH+vtDxRFZ9uODKAOBbq+ukzuDNmje/bBHrDhirbZzJWR4s0wIK5V0m7pghfDgMvnsSlo5qVFcxmEQ94vQKLaAG5elVC8QOrdDgjeePeguAONV0BYUvusQTLzdk31AoidoK/BB/GQNMRHmUxfLt15cPjbh02MBjmiQ==
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-5.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-5.exe /rawdata=upViUfi4wovdW6Uch4H95FZcWnIgxrVWcuHTECGDUmY86Yc5B1/6ce2IL8Sz39n50nHYnNHC/z6XX7ZPjgrf75PNbskYbJBZHWy8zgD2YUtbaSA8Qs3q9jIH8c7+CGg2P28j+/CAt9/m9YuCIj4Hat/i+6TKOpb/bdiOFkseV1aThauAmhOAhjQrzRahnEvqMagqU1AplZP6b1rT+T+UtSYrqKkXm13jcewtgNkhI1HmiLwUWMfWNhaNdTl8AbPh2Wh5h/8zkoEPzYNcABrm3B7GjrFIegtFK6RwrjbjLxQsd6D1+2ag0Wjw++dTcye/RDRovRjSu+fk5QpGjSMTiHdxuElhPfxcE2i8sj7C8Wyq6F6y28VZP78M7Zu0yamST+HNjxvGncZ9wa9SDESI3fjTAX2JCBPYfScJwZHq6K0Y+KbRH8w+hURriUa40J16PKgt/o2AEbpisF2y9EcLdN8/arE/FVpdWl5NZaz0iVHgq/mDg+hc23cNDqeDkE2KDgKMt+/uyGfl5sBrtfMctlDs1MrjVhST5BYgyWffDM1XEfuWcv2P6HKpJgDkpXBFPIsODe/CYEgnzxQgJPIIsToviyu47QLfRzcx56AO87E7g+48fG0uS/bpDNnfWV7Lsv/7AvkpDodaan7mIMsJocBzCaDmBi/BBaxzbF42MAoyIR8cPgpelok/aHOUQi0x+G3hMxQNnc1yb6RG4HFwBgJ1paCAT4nUT6NI93TsytzaX/5D3b5ELRwPuEfodYZPn7OnzIVz5FvlDz8WMtoqTpJBZJnHASsjxaBKvzeHBWl7+qdAhz5E1W0eP9XHkN8AB3fS97MEio5u/trlUFxcUo3hhC/UKNSgeTc0LBOwfsP2S28zAdIrTLYfVNPxjQw/L0Lftm8D70lKA+Zp04uX+ugO3W9KA4yjra50ofmQG8bofiGYBn2sVqUFOXhjA+y/TmEq7XyAhWd4kOo1gH759cQwu2ZamrX8fngy5DifpKKzuj+QhS4Bw7NcEqPjWzR5
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-5_user.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-5.exe /rawdata=upViUfi4wovdW6Uch4H95FZcWnIgxrVWcuHTECGDUmY86Yc5B1/6ce2IL8Sz39n50nHYnNHC/z6XX7ZPjgrf75PNbskYbJBZHWy8zgD2YUtbaSA8Qs3q9jIH8c7+CGg2P28j+/CAt9/m9YuCIj4Hat/i+6TKOpb/bdiOFkseV1aThauAmhOAhjQrzRahnEvqMagqU1AplZP6b1rT+T+UtSYrqKkXm13jcewtgNkhI1HmiLwUWMfWNhaNdTl8AbPh2Wh5h/8zkoEPzYNcABrm3B7GjrFIegtFK6RwrjbjLxQsd6D1+2ag0Wjw++dTcye/RDRovRjSu+fk5QpGjSMTiHdxuElhPfxcE2i8sj7C8Wyq6F6y28VZP78M7Zu0yamST+HNjxvGncZ9wa9SDESI3fjTAX2JCBPYfScJwZHq6K0Y+KbRH8w+hURriUa40J16PKgt/o2AEbpisF2y9EcLdN8/arE/FVpdWl5NZaz0iVHgq/mDg+hc23cNDqeDkE2KDgKMt+/uyGfl5sBrtfMctlDs1MrjVhST5BYgyWffDM1XEfuWcv2P6HKpJgDkpXBFPIsODe/CYEgnzxQgJPIIsToviyu47QLfRzcx56AO87E7g+48fG0uS/bpDNnfWV7Lsv/7AvkpDodaan7mIMsJocBzCaDmBi/BBaxzbF42MAoyIR8cPgpelok/aHOUQi0x+G3hMxQNnc1yb6RG4HFwBgJ1paCAT4nUT6NI93TsytzaX/5D3b5ELRwPuEfodYZPn7OnzIVz5FvlDz8WMtoqTpJBZJnHASsjxaBKvzeHBWl7+qdAhz5E1W0eP9XHkN8AB3fS97MEio5u/trlUFxcUiQa2OYflKyLKBXkd5AKEPKW4YhjPDltWcNEwF0gzvWGgRBf6U5r3ldYdAR0BbD/XaArr53hNAsInzihNAR49iL2JIpURUZJSW04HqKR5I4WV0mwqexrzq4Y9jsABUeSlB6Y63zstMmktn/pwm4zFBRbzevEJ0bjZuLmPM22tGAK
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-6.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-6.exe /rawdata=XDvWBG5NcbFQhvp+MRBnlR9Fm+kNkvLwTsOgSz0osU345XCmVmVXvQFKxt8537vS/OEVb2HPsSwWOPlmeSGFiwcoof6uc1CCu8v35MwHijWqxRnMRoVUV8JmPuTQitqzHm+KREZHHf7HE3K0rwd5Lh9PmwQhbZ3vQ2E3jr3H1EFUP92Fg5GgA9ItqREMfTnQDiwNtEa4qE/pNPtXEdpAxj1yHy9Zk83vprw+6jZsIWftvOJX1osPbjn33GXgmB+yeQ55y35uWJLqlRR3lRnUHtgJCdqqKz811ARyjb228Zx655R4fLl6ln+gTrC432D1K4AFVAdaQWtH410CLZ89dwUH6pkw9Ac0yIPRCeK4CBvEQvaWuJgLVh9e4sMxb3fWbNzHhCBPwcvGZTtAcqxs4s2gKhUbwtbX8USHFYQ7iI78AsaPpf2A4r/tol5BO4sxWvISFgZR1AfUPJjW5zT/rudRhm6QOqR/ZqXe0RNa1Gg/DnplPL5Wk2OZ1t9y+3GeGr66IXtNC7UrJxRau8rJyjQ17YxqOWGapRtSEqMLngrgrkZh2GxTxDEypgpuA5fJPLLzH0yco4K0HecxWi1AOW1h6xgInPcxk7kZ+nFT7zBMYJYNIiGjJ84iY3T74FsnZAyddGd++F4ih9UwwKJwIU2G5Zzfp/IGy9MeSgEhMaGayR56IDTzDkRWtOIUQqT/qzqak80B1Qu0zW1Z5XzwMm6iF1lRTr/bEnRStGUTfZC4a2EsthN2+eUxT6C/wC31YyoWt11FYJM2zt+tZx+J+Sqql2ofoD+EHccal6TKohsVMXIoJ281IFmeFUzP+sP4Lykoy9q2UOTKj/t7gllvhjo/PscujollTsr8h8E+OeaX7GhQWd5QZsyoAp8WPpaG50BUetjKAdGHiKFJA9loLP7qdPTKkzkYUM05t0Sp1h7ZtDdXYAS6eB4mD7zv5S5U3+W8HigxB7M/1MDPmhpN00Q0bCBmfN7KI0jF7FVcIwwTkEEOLcv+QNu6+PHdVqYUXwK1YUOM4dPp8ugMOlaJD3k4dtYPhq39lN9FJQUsYiWpou3cGFKk9gnOmIW42kBs2ybQI+ZJkYHGtc7cPMdHC26FkeUObz/5cCAJyQOyGDAXfjIP+apwojJac3VbG/b8h42MJGGZJGKj7B038ijTi5JGPIhc/5JEQ/PEFIC9qgYDwMV4h7efscFzywZYFdKO5JZC4dXWRgAJfkRq8pWmPMcFuRxW+fFFp1+s2GVNvXNUj1ASa2IeDFDedtT8uduwe6iYiuCCBkNB+krCqaQzd6QRWHOzLSkR5/VSrSjF8Y/bYZ8ymhkuDnDqyBOuIKfxITzeH0F8NRHzc34RCje9llew5rsb8s7WlmrKao0/Pdkj2nLJFwNxXN1jwEsTo1LyqiPtAosdNZ/0ZGb5hznLbhH8ZabzfSnya0CVBaCPsJzT0Jg3qztzLrI2SkwJhOVeByriU61AMK2XXZvTYGhiXvHpqiExmxQz111u6zxlLkGBs4AEb4jO6Do60sx7HG9IZg/pXziP3XYhGzhBzr+dfobYJ6ahKuyDXsFzdR1n8mMdNfItfXcfm6moWNnfHBgDOm9TiWDTm3w1wMWNtM/1AUPW3bsf/bv3JA5hSCM3NdtzeNl6mUiNfOveUcPRSuACAaeZBwrg/LLOvG5gs0GzfW7HatZ5f5wOObxfwGjH0pQwUFOawupZsr4xk79msdW2xR8wnXz9cL9S11iAJYciSZ2yhAc6XQ6sWt3FALSFVUpuPgAzXtQUZalYJOBjbi7PxYlnm/g6OKqdR3y+oWeMUdT7hEczhvHqTr0IkSRWR6pLMgNJe75A8LyzRiV/BwnUNAQ9v2CYzt5EvXOhaoY+p2LqD35jOWJwysbLO4H2Xkv+VUcXae1fzJX3dqQe/ONO23kiV8eYj4CHLiK5RR3skRNiqXfuSS+kU+s/aQUQUzws2MdUrq/96ewsglkEJ8CJrP/J3GJsXhBHzcwHCynrHqqgPpEcd78QbIEgk8e7i7kLUZXyqXl8+5djbfxyDvHlk+QADJMmbPvAQ7B+pOUeL/z/aK9Ly9dpkC5EumDK2hVGIg4KxpJ6t5q26oyXpaGhr3MJO+Xlni5bHHOoPpzqeYT7ZUAUEBMqoFxXKDeLM+3zTFrjd7EgEUT8orknnjX0QBaFqd7qs35bWGf4fbIUCda/Gee3P1YTm6+JxILHWciB6xcgY01O+eWeOy1z1C5SmX9u+bE50tfSkK6sJ3M9v7FY+iYP962J+zGtl/cS4WprYhS8IR4okb25Y9kTriNk4F4/9U7OYdHhkZOkF2GvjjiXnOr/pj2Iy/8tSuFzGCUwLKfxmxWvk66mN//3iDl0S0diCXBOW7aCgzTt3M7KEZEDnHTgcdVHKFoNecAfS00wpHx1h+ItDZ2fkpYn0qNsEDjrEqVgeSU7uZV8jIHDkloW6i9yF2cT8yd69nu6jYRemPheh2ahJTR4xH/ZTEyTGJTMBjUzqMkd934VdP26H3mgYi4AhzC2FQLFnghXirD4YsvJXVdGN17Lsuh3W1y0
C:\WINDOWS\tasks\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-7.job - C:\Program Files (x86)\HDQ-1.2cV15.12\83c86d1a-3b58-4462-9f06-a3a5a11a3f77-7.exe /rawdata=Mg3PVnFO1JDhF1Pe92BSMjuhKrixmGTFIqytMwn0QvA/X3RhfcjvkU1Yx/IfWGhLcaB45jA9VstV95AVMFfvGd9wBPfUNf+KOrpySWopef23DR6E4kKjdq2Z/3G/CoGxRDfOx6FurcoGscmJkMheWokttmE497z/adg6NXN8oUiNoWfRHJT5NXzUf/T+q1VeTWzJu/7hzvcQ0LljsmgI6YYrJwL8pEdj1cp7qctwg5uksBa4st2d7plU5fCQ7xgMadMD5YOUoMzukztrwLIYASjgL82mH38g3xYrfUF0b+Zjj3UPEgG9QuckxuO2dUyA2GREW9sPNX/5K/OEIjYa2FARzD0iqnp2VpVCLnCbmtKZEAOTdec9W0AHb42SN7dkfl3n8VWtCWsHmCtH0Jxs6YfgfiUlJR16T4iU6GNy3nY0T9vhCMzTaNulty/qUesk+2kBaRZbRq6DeAJGj1YHNVyVbVE7kNwmv8QFdDsRkfL2Q7J6PsmFQLDoNQj5YORIQa3FZIidhiQaz/sr6hKhUiOVfcwCfbR2TqYHmyTEMzmjyOr9Hb/HGKpEkV64Wme5cXih9ZqU0QIqHWsjVTgrVS2bzX+PO0/9d8GcUL4XBf0AHqqZ+z4kzVYKRP4sttVvsgF8UiGcVJqXCzvzjrD9DEp6MwEJcSalSaJd/28OpVVB+l1txfCARJfZVhyx74iM/3tXFp/RwG2jhID+C+xcQRO+t0H7MEe2kTdaR4BO9H0tEu9G/GFtz41V7qPH8YM8ybSVP42geGHv+pLl51EK52VkO3JJ4beoQxu6I02f6/J1sCuGTn1pbrgufhkMioegBol2E145jnK4oDNVvy9OVbE285oENAYyOmXYP/fZzXpgZWHo8sUyLZ22W5zu7XpQ5WjkZca78GC+COR2/M41PGHesLBhoY3LIKBJRSaYyIM+byCoOoyZHxpc7Bx1Djb2L0G+OR1X+c7GhGjWBdhdfgCT8HWGCf+Sd9ugSnbIPVOHTY4nMPnQYMPXb7rnAB7tQIzcdk+I+sdWfFQMZsmq7Dwa+G5MOlLBhaHgxAzfhZgYhqce6XpxILv/h5tPNl440sD0joBM7uBH8w7vTo1W6MSTHpGYJiEH7EGgTUyrcAtNpdYkrSHfx9p0Zh2RiQ+tSwHxQfg5AbqH9uwLLzKzdsf5eGHeacDc+gb0/5mnAly6z7ABbvDg6kdhxY/lpegOdwwL6rDxcZNSn/MG9GFlLlo6We/eyolYXVwusfaniI6PjvnH+s1182E+NxWDg8Ej74D2ShK7w0wSGJ1XniW8soDnDMqAkx5eE3D5Kifmy7bUnW4YS8DVPVunvMNkiYM8I9DR3dkbOITNeVH4wEGW/LQcVBdUEDpKlcj5dO/qY4YQDarK6YboiRIGtjusJxn35SPKYUYRRO8cFwtBIQ490R2Q7KpT2Ur2qGLMC5+7HXa/1DvmnXiazQfhC/qPtNSQPHti+hNsOe+515sGFp0NzUGAl4Pfg1wVGfXln4xqzgs0hqQIHea9FUFzJGxkodvinFnWaq0N51CYgQWhdal9Z9jxsJQ6DRpEQjj6GnTgFSe26OP5vket/Dda4nNQjvrWLcpWtvHMrTdWXyYF/VjxDwh+Whvfal35k5DLvyOeeiP0mBwHwYS0gDy/JKkk0iOXwD79S5GFMo+gE2I+EfxiAvvhbY/TceJ/ckpuOPHmvAEk/y2kMIsum0091kAL/ZalRWNsXQUHrDgbZLA4i/e/5HdoE0dzNoLRHCotSibf88uqmQ2JIU6GlxX8SCIowWN+4eN+dA3YfQZn3+9s/hDnZtUf3RaBg0tF78OblqnMtC9G0S1TO8kDeveRk/WAIpkojNVSCXxevyYq/5nJ91hRkpZ//igH/TH09ZmmHo3fXG0TKni7sDgyOkNIZvEYuKJv5FH3t6HwivPq6FoKnfyMdLikAk32acFf2ynP8PhohC6P8t3lu3pxAm9qLAWzkgo6gcNcJkY/EgOA+6IXK2fM9iqH92GqV2E4S1P5Wl5UaId0pHnndDZAuN1DrIW6hHCeLMi3W9QBH/W3V0I5waAydQC5HLj3qVOt9TaENexuicTTODXo9tGHRneqBBQFq4eR9X25ONvbRPXaTZR8dlIQYV9WjeHzxdSLhhvL30zPRFTzSfLfLNKn+tbqqvmhFiOZeNjtsrwF+HeQQFwwzEQR7BNGRka90stU7SB8eVBKu9RQN2VLJc8LK4efn5TuCRv43G8oXt7cx/Twcr/LDfUZfnivQop1O+45oMe/F47fUvg1U1oetE1jFhMCrCgLY03gMJUjfZJVpK8mq9+rWuCoa0IcvCUYgEB+556PkweP/DfmyMXoBGxhTfYlhp2FOYqceHJepyHJHXDyTCM2DpCazA==
C:\WINDOWS\tasks\cec04017-1719-4172-bc0d-e3d4886b6f18.job - C:\Program Files (x86)\HDQ-1.2cV15.12\cec04017-1719-4172-bc0d-e3d4886b6f18.exe 002413 11A72F67875A431B8BB2EA739F8C900DIE 65781 1418665456 93-0,102-0,178-288,179-288,180-288,223-288,263-24 HDQ-1.2cV15.12
C:\WINDOWS\tasks\ecbdb8af-7f91-4be0-b523-97ea7cd9c70b.job - C:\Program Files (x86)\Internet Speed Checker\ecbdb8af-7f91-4be0-b523-97ea7cd9c70b.exe /agentregpath='Internet Speed Checker' /appid=61752 /srcid='001726' /subid='0' /zdata='0' /bic=11A72F67875A431B8BB2EA739F8C900DIE /verifier=640f5fba7d2564e55438cb2c0bb5ba79 /installerversion=1_35_11_26 /installationtime=1418665582 /statsdomain=http://stats.newstaticinfosrv.com /errorsdomain=http://errors.newstaticinfosrv.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newstaticinfosrv.com /runfrom='task' /externallog=''
C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3867520272-1177344532-2789452036-1001Core.job - C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}]
HDQ-1.2cV15.12 - C:\Program Files (x86)\HDQ-1.2cV15.12\HDQ-1.2cV15.12-bho64.dll [2014-12-15 930272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}]
HDQ-1.2cV15.12 - C:\Program Files (x86)\HDQ-1.2cV15.12\HDQ-1.2cV15.12-bho.dll [2014-12-15 744416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-04 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-04 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-06-27 7191768]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-09-17 2460488]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-09-17 2799784]
"HP Input Device Main Program"=C:\Program Files\Hewlett-Packard\HP Wireless Comfort Desktop\TSR\xDaemon.exe [2008-10-16 530432]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Spotify"=C:\Users\Neli\AppData\Roaming\Spotify\Spotify.exe [2014-12-15 6737976]
"Spotify Web Helper"=C:\Users\Neli\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-12-15 1676344]
"Akamai NetSession Interface"=C:\Users\Neli\AppData\Local\Akamai\netsession_win.exe [2014-10-29 4673432]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2013-02-05 1081224]
"DAEMON Tools Lite"=D:\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Facebook Update"=C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-12-16 138096]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-06-04 676608]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2013-03-08 506864]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-11-20 1021128]
"ADSKAppManager"=C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [2014-09-04 488328]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Network Server.lnk - C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe

C:\Users\Neli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open -
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-12-22 18:09:12 ----D---- C:\rsit
2014-12-22 18:09:12 ----D---- C:\Program Files\trend micro
2014-12-22 18:07:43 ----D---- C:\FRST
2014-12-16 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe
2014-12-16 17:27:25 ----A---- C:\WINDOWS\system32\poqexec.exe
2014-12-15 20:04:09 ----A---- C:\autoexec.bat
2014-12-15 18:49:38 ----A---- C:\WINDOWS\system32\drivers\{ad5dee5e-a585-4286-892c-fc27ac63cd14}Gw64.sys
2014-12-15 18:46:44 ----D---- C:\Program Files (x86)\5ed62cb3-a818-4fd2-8ca5-592214a27582
2014-12-15 18:44:58 ----A---- C:\Users\Neli\AppData\Roaming\ZG.exe
2014-12-15 18:44:41 ----D---- C:\Program Files (x86)\4c9d1e66-0169-442a-82b8-bb5316244060
2014-12-15 18:44:25 ----A---- C:\Users\Neli\AppData\Roaming\KGKSJMI.exe
2014-12-15 18:44:23 ----D---- C:\Program Files (x86)\globalUpdate
2014-12-15 18:44:19 ----D---- C:\Program Files (x86)\HDQ-1.2cV15.12
2014-12-15 18:43:20 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-12-15 18:43:10 ----D---- C:\ProgramData\WindowsMangerProtect
2014-12-15 18:43:03 ----D---- C:\Users\Neli\AppData\Roaming\mystartsearch
2014-12-15 18:42:18 ----D---- C:\Program Files (x86)\Seznam.cz
2014-12-15 18:42:08 ----D---- C:\Users\Neli\AppData\Roaming\Seznam.cz
2014-12-15 16:01:56 ----D---- C:\Program Files\Chaos Group
2014-12-15 16:01:13 ----D---- C:\Program Files\Common Files\ChaosGroup
2014-12-11 13:45:11 ----D---- C:\WINDOWS\system32\appraiser
2014-12-10 19:12:56 ----A---- C:\WINDOWS\system32\crypt32.dll
2014-12-10 19:12:55 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2014-12-10 09:27:30 ----A---- C:\WINDOWS\SYSWOW64\DeviceSetupStatusProvider.dll
2014-12-10 09:27:30 ----A---- C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2014-12-10 09:27:29 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-12-10 09:27:28 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-12-10 09:27:27 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\system32\wininet.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\webcheck.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\jscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\inetcomm.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\iepeers.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-12-10 09:27:23 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2014-12-10 09:27:22 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\invagent.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\generaltel.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\devinv.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\appraiser.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aepic.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aepdu.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aeinv.dll
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\sdbus.sys
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\intelpep.sys
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\dumpsd.sys
2014-12-10 09:27:14 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2014-12-04 17:38:21 ----D---- C:\ProgramData\Sun
2014-12-04 17:38:20 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2014-12-04 17:38:12 ----D---- C:\ProgramData\Oracle
2014-12-04 17:38:11 ----D---- C:\Program Files (x86)\Java
2014-12-04 17:26:22 ----D---- C:\Program Files\PDF Split And Merge Basic
2014-12-04 17:24:23 ----D---- C:\PDF_Split_and_Merge_Basic_64bit_v2
2014-11-25 15:55:30 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_7.dll
2014-11-25 15:55:30 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_5.dll
2014-11-25 15:55:30 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_7.dll
2014-11-25 15:55:30 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2014-11-25 15:55:30 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2014-11-25 15:55:30 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2014-11-25 15:55:29 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_43.dll
2014-11-25 15:55:29 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_43.dll
2014-11-25 15:55:29 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_43.dll
2014-11-25 15:55:29 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2014-11-25 15:55:29 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2014-11-25 15:55:29 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2014-11-25 15:55:28 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2014-11-25 15:55:28 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2014-11-25 15:55:28 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2014-11-25 15:55:28 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2014-11-24 23:42:28 ----D---- C:\Users\Neli\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2014-11-23 08:32:24 ----D---- C:\Program Files (x86)\McNeelUpdate

======List of files/folders modified in the last 1 month======

2014-12-22 18:09:12 ----RD---- C:\Program Files
2014-12-22 18:09:08 ----D---- C:\WINDOWS\Prefetch
2014-12-22 18:08:47 ----D---- C:\WINDOWS\Temp
2014-12-22 18:07:50 ----D---- C:\Windows
2014-12-22 18:00:00 ----D---- C:\WINDOWS\system32\sru
2014-12-22 17:46:29 ----D---- C:\WINDOWS\Microsoft.NET
2014-12-22 17:08:15 ----D---- C:\WINDOWS\system32\FxsTmp
2014-12-22 16:58:05 ----RD---- C:\WINDOWS\System32
2014-12-22 16:58:05 ----D---- C:\WINDOWS\Inf
2014-12-22 16:58:05 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-22 16:54:23 ----D---- C:\Users\Neli\AppData\Roaming\Dropbox
2014-12-22 16:17:49 ----D---- C:\WINDOWS\SoftwareDistribution
2014-12-22 16:17:49 ----D---- C:\WINDOWS\debug
2014-12-21 22:35:50 ----D---- C:\Users\Neli\AppData\Roaming\vlc
2014-12-19 17:05:11 ----SHD---- C:\System Volume Information
2014-12-19 16:21:45 ----D---- C:\WINDOWS\system32\config
2014-12-19 16:17:22 ----D---- C:\WINDOWS\CbsTemp
2014-12-19 16:17:21 ----D---- C:\WINDOWS\WinSxS
2014-12-19 16:15:48 ----D---- C:\WINDOWS\Tasks
2014-12-19 16:15:48 ----D---- C:\WINDOWS\system32\Tasks
2014-12-18 13:44:02 ----HD---- C:\Program Files\WindowsApps
2014-12-18 13:44:02 ----D---- C:\WINDOWS\AppReadiness
2014-12-18 07:15:22 ----D---- C:\Users\Neli\AppData\Roaming\Spotify
2014-12-16 19:20:41 ----SHD---- C:\WINDOWS\Installer
2014-12-16 18:08:57 ----D---- C:\WINDOWS\SysWOW64
2014-12-15 20:12:29 ----D---- C:\ProgramData\NVIDIA
2014-12-15 20:03:19 ----D---- C:\WINDOWS\system32\drivers
2014-12-15 20:00:33 ----RD---- C:\Program Files (x86)
2014-12-15 19:54:13 ----D---- C:\WINDOWS\Logs
2014-12-15 19:11:17 ----D---- C:\WINDOWS\apppatch
2014-12-15 18:49:39 ----A---- C:\WINDOWS\win.ini
2014-12-15 18:44:48 ----D---- C:\Program Files (x86)\Adobe Download Assistant
2014-12-15 18:44:22 ----SD---- C:\Users\Neli\AppData\Roaming\Microsoft
2014-12-15 18:43:32 ----SD---- C:\ProgramData\Microsoft
2014-12-15 18:43:10 ----HD---- C:\ProgramData
2014-12-15 16:02:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WkWin32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WkExt32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WibuXpm4J32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\wibuKJni.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WkWin64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WkExt64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WibuXpm4J64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\wibuKJni64.dll
2014-12-15 16:01:13 ----D---- C:\Program Files\Common Files
2014-12-12 20:24:42 ----D---- C:\WINDOWS\rescache
2014-12-12 19:24:52 ----D---- C:\WINDOWS\system32\catroot
2014-12-11 13:45:11 ----SD---- C:\WINDOWS\system32\CompatTel
2014-12-11 13:45:10 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-12-11 13:45:10 ----D---- C:\WINDOWS\system32\cs-CZ
2014-12-11 13:45:10 ----D---- C:\WINDOWS\PolicyDefinitions
2014-12-11 13:45:10 ----D---- C:\Program Files\Internet Explorer
2014-12-11 13:45:10 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-11 13:09:48 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2014-12-11 13:09:48 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2014-12-11 13:09:30 ----D---- C:\WINDOWS\system32\MRT
2014-12-11 13:07:54 ----A---- C:\WINDOWS\system32\MRT.exe
2014-12-10 09:27:00 ----D---- C:\WINDOWS\system32\catroot2
2014-12-04 17:38:20 ----D---- C:\Program Files (x86)\Common Files
2014-11-30 11:27:10 ----RSD---- C:\WINDOWS\Fonts
2014-11-26 22:10:48 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-11-25 16:37:22 ----D---- C:\Users\Neli\AppData\Roaming\Autodesk
2014-11-25 16:32:59 ----D---- C:\ProgramData\Autodesk
2014-11-25 16:32:07 ----D---- C:\Program Files\Autodesk
2014-11-25 16:21:11 ----D---- C:\Program Files\Common Files\Autodesk Shared
2014-11-25 15:55:17 ----D---- C:\ProgramData\Package Cache
2014-11-25 15:52:09 ----D---- C:\Autodesk
2014-11-24 23:42:29 ----D---- C:\Users\Neli\AppData\Roaming\Adobe
2014-11-23 08:32:26 ----RD---- C:\WINDOWS\assembly
2014-11-23 08:32:17 ----D---- C:\Program Files\Rhinoceros 5.0 (64-bit)

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\WINDOWS\System32\drivers\amd_sata.sys [2012-11-30 80552]
R0 amd_xata;amd_xata; C:\WINDOWS\System32\drivers\amd_xata.sys [2012-11-30 26280]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-08-19 157016]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey64.sys [2014-12-15 106760]
R3 dtsoftbus01;@oem12.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-08-05 283064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-07-02 3472600]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2012-10-25 13368]
R3 NVHDA;@oem15.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2014-03-20 197408]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-03-20 12708128]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-09-17 19272]
R3 nvvad_WaveExtensible;@oem22.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2014-09-04 597896]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-06-04 361984]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-12-13 12288]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-09-17 1148744]
R2 McNeelUpdate;McNeel Update Service 5.0; C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [2012-10-25 67752]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2013-02-20 161264]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-09-17 1795912]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-09-17 19439944]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-03-04 922968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-17 411936]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2014-12-15 485888]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-12-15 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08 116648]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-10-17 1357104]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-12-15 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 mi-raysat_3dsmax2015_64;mental ray Satellite for Autodesk 3ds Max 2015 64-bit; D:\3DS MAX 2015\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [2011-09-15 86016]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 22 pro 2014 18:22
od Rudy
Zdravím!
Spusťte njeprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 23 pro 2014 09:46
od Mara
Některá nevyžádaná okna stále přetrvávají.

# AdwCleaner v4.106 - Report created 23/12/2014 at 09:43:28
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 8.1 Pro (64 bits)
# Username : Neli - NELI
# Running from : C:\Users\Neli\Desktop\adwcleaner_4.106.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : WindowsMangerProtect
Service Deleted : {ad5dee5e-a585-4286-892c-fc27ac63cd14}Gw64

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\HDQ-1.2cV15.12
Folder Deleted : C:\Users\Neli\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Neli\AppData\Roaming\mystartsearch
Folder Deleted : C:\Users\Neli\AppData\Local\Google\Chrome\User Data\Default\Extensions\eagomcfjiefffhpaejnlpjccikpipdoe
File Deleted : C:\WINDOWS\System32\drivers\{ad5dee5e-a585-4286-892c-fc27ac63cd14}Gw64.sys
File Deleted : C:\Users\Neli\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Neli\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Neli\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\Neli\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : 411a1d27-7478-44b4-8e65-733920f016e2
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-1
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-11
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-2
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-4
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-5
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-5_user
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-6
Task Deleted : 4b481524-b745-4c69-8f20-85a6f7bf363e-7
Task Deleted : 543c437f-b796-4197-8e13-ac6886c590a4
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-1
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-11
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-2
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-3
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-4
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-5
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-5_user
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-6
Task Deleted : 83c86d1a-3b58-4462-9f06-a3a5a11a3f77-7
Task Deleted : cec04017-1719-4172-bc0d-e3d4886b6f18
Task Deleted : ecbdb8af-7f91-4be0-b523-97ea7cd9c70b

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Neli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Neli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Neli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Neli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611571181}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572281}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175552}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575581}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176652}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576681}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644574481}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78955067-e366-4482-a580-a24c6ebc15db}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc2520ee-3c12-44bc-9ad5-dafc27c5b9ab}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611571181}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572281}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175552}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575581}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176652}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576681}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78955067-e366-4482-a580-a24c6ebc15db}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{dc2520ee-3c12-44bc-9ad5-dafc27c5b9ab}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Speed Checker
Key Deleted : HKCU\Software\AppDataLow\Software\HDQ-1.2cV15.12
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware
Key Deleted : HKLM\SOFTWARE\Internet Speed Checker
Key Deleted : HKLM\SOFTWARE\HDQ-1.2cV15.12
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDQ-1.2cV15.12
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17416

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v39.0.2171.95


*************************

AdwCleaner[R0].txt - [14431 octets] - [23/12/2014 09:42:28]
AdwCleaner[S0].txt - [13121 octets] - [23/12/2014 09:43:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13182 octets] ##########

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 23 pro 2014 14:33
od Rudy
Také jsme ještě neskončili. :) Dejte nový log RSIT.

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 27 pro 2014 14:03
od Mara
Logfile of random's system information tool 1.10 (written by random/random)
Run by Neli at 2014-12-27 14:02:47
Microsoft Windows 8.1 Pro
System drive C: has 40 GB (35%) free of 114 GB
Total RAM: 16333 MB (86% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:02:49, on 27. 12. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Neli.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: 166090e0f32601317e4e5118752c52d60061752 - {11111111-1111-1111-1111-110611171152} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [ADSKAppManager] "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Spotify] "C:\Users\Neli\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Neli\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Neli\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Startup: Dropbox.lnk = Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Network Server.lnk = C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: McNeel Update Service 5.0 (McNeelUpdate) - Robert McNeel & Associates - C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe
O23 - Service: mental ray Satellite for Autodesk 3ds Max 2015 64-bit (mi-raysat_3dsmax2015_64) - Unknown owner - D:\3DS MAX 2015\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9825 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
dashost.exe {ce647837-cecc-493c-9b8f115a109d12d4}
"C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe"
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc

"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22dba4c9-0108-4ee0-bedd-2c448956492e 1
\??\C:\WINDOWS\system32\conhost.exe 0x4

C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-11948c48-8bda-4cdf-8f7f-8d35ec1bb6ee -SystemEventPortName:HostProcess-744ffea0-badf-41f1-959c-5989c19ac248 -IoCancelEventPortName:HostProcess-4aae9a63-785f-41e6-bbcb-384138d34b4e -NonStateChangingEventPortName:HostProcess-4abf48e7-33fc-4c10-9bd7-f44955dafc15 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:cd1a6dc5-8c5f-4d71-9d5c-c1d0f829d750 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Windows Media Player\wmpnetwk.exe"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
taskhostex.exe
\??\C:\WINDOWS\system32\conhost.exe 0x4
taskeng.exe {7F1CF097-A408-4517-83A7-893C97036324}
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\WINDOWS\system32\wbem\wmiprvse.exe

"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s

"C:\Program Files\Hewlett-Packard\HP Wireless Comfort Desktop\TSR\xDaemon.exe"
"C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2880.0.288278778\1658386266" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38,46 --gpu-vendor-id=0x10de --gpu-device-id=0x1380 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3523 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2880.2.1173173767\711397178" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2880.3.1750008186\1816273059" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2880.4.611993683\296117480" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2880.5.1089857664\963119910" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="2880.9.278479720\2030009402" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="2880.10.890251831\455650860" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
C:\WINDOWS\system32\msiexec.exe /V
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Neli\Downloads\RSITx64 (1).exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3867520272-1177344532-2789452036-1001Core.job - C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-04 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-04 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-06-27 7191768]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-09-17 2460488]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-09-17 2799784]
"HP Input Device Main Program"=C:\Program Files\Hewlett-Packard\HP Wireless Comfort Desktop\TSR\xDaemon.exe [2008-10-16 530432]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Spotify"=C:\Users\Neli\AppData\Roaming\Spotify\Spotify.exe [2014-12-15 6737976]
"Spotify Web Helper"=C:\Users\Neli\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-12-15 1676344]
"Akamai NetSession Interface"=C:\Users\Neli\AppData\Local\Akamai\netsession_win.exe [2014-10-29 4673432]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2013-02-05 1081224]
"DAEMON Tools Lite"=D:\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Facebook Update"=C:\Users\Neli\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-12-16 138096]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-06-04 676608]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2013-03-08 506864]
"ADSKAppManager"=C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [2014-09-04 488328]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Network Server.lnk - C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe

C:\Users\Neli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open -
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-12-23 09:42:21 ----D---- C:\AdwCleaner
2014-12-22 18:09:12 ----D---- C:\rsit
2014-12-22 18:09:12 ----D---- C:\Program Files\trend micro
2014-12-22 18:07:43 ----D---- C:\FRST
2014-12-16 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe
2014-12-16 17:27:25 ----A---- C:\WINDOWS\system32\poqexec.exe
2014-12-15 20:04:09 ----A---- C:\autoexec.bat
2014-12-15 18:46:44 ----D---- C:\Program Files (x86)\5ed62cb3-a818-4fd2-8ca5-592214a27582
2014-12-15 18:44:58 ----A---- C:\Users\Neli\AppData\Roaming\ZG.exe
2014-12-15 18:44:41 ----D---- C:\Program Files (x86)\4c9d1e66-0169-442a-82b8-bb5316244060
2014-12-15 18:44:25 ----A---- C:\Users\Neli\AppData\Roaming\KGKSJMI.exe
2014-12-15 18:43:20 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-12-15 18:42:18 ----D---- C:\Program Files (x86)\Seznam.cz
2014-12-15 18:42:08 ----D---- C:\Users\Neli\AppData\Roaming\Seznam.cz
2014-12-15 16:01:56 ----D---- C:\Program Files\Chaos Group
2014-12-15 16:01:13 ----D---- C:\Program Files\Common Files\ChaosGroup
2014-12-11 13:45:11 ----D---- C:\WINDOWS\system32\appraiser
2014-12-10 19:12:56 ----A---- C:\WINDOWS\system32\crypt32.dll
2014-12-10 19:12:55 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2014-12-10 09:27:30 ----A---- C:\WINDOWS\SYSWOW64\DeviceSetupStatusProvider.dll
2014-12-10 09:27:30 ----A---- C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2014-12-10 09:27:29 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-12-10 09:27:28 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-12-10 09:27:27 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\system32\wininet.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\webcheck.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\jscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\inetcomm.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\iepeers.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-12-10 09:27:23 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2014-12-10 09:27:22 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\invagent.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\generaltel.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\devinv.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\appraiser.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aepic.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aepdu.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aeinv.dll
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\sdbus.sys
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\intelpep.sys
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\dumpsd.sys
2014-12-10 09:27:14 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2014-12-04 17:38:21 ----D---- C:\ProgramData\Sun
2014-12-04 17:38:20 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2014-12-04 17:38:12 ----D---- C:\ProgramData\Oracle
2014-12-04 17:38:11 ----D---- C:\Program Files (x86)\Java
2014-12-04 17:26:22 ----D---- C:\Program Files\PDF Split And Merge Basic
2014-12-04 17:24:23 ----D---- C:\PDF_Split_and_Merge_Basic_64bit_v2

======List of files/folders modified in the last 1 month======

2014-12-27 14:01:50 ----D---- C:\WINDOWS\Prefetch
2014-12-27 14:01:16 ----SHD---- C:\WINDOWS\Installer
2014-12-27 14:01:16 ----D---- C:\WINDOWS\Temp
2014-12-27 14:01:16 ----D---- C:\WINDOWS\system32\Tasks
2014-12-27 14:00:46 ----D---- C:\WINDOWS\AppReadiness
2014-12-24 16:09:53 ----D---- C:\WINDOWS\system32\sru
2014-12-24 06:03:18 ----D---- C:\WINDOWS\system32\config
2014-12-24 05:58:57 ----D---- C:\WINDOWS\Microsoft.NET
2014-12-23 13:50:26 ----D---- C:\WINDOWS\WinSxS
2014-12-23 13:17:11 ----RD---- C:\WINDOWS\System32
2014-12-23 13:17:11 ----D---- C:\WINDOWS\Inf
2014-12-23 13:17:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-23 09:44:14 ----D---- C:\ProgramData\NVIDIA
2014-12-23 09:44:07 ----D---- C:\Windows
2014-12-23 09:43:35 ----D---- C:\WINDOWS\Tasks
2014-12-23 09:43:33 ----RD---- C:\Program Files (x86)
2014-12-23 09:43:33 ----HD---- C:\ProgramData
2014-12-23 09:43:33 ----D---- C:\WINDOWS\system32\drivers
2014-12-23 09:39:19 ----D---- C:\Users\Neli\AppData\Roaming\Spotify
2014-12-22 23:24:13 ----D---- C:\Users\Neli\AppData\Roaming\vlc
2014-12-22 21:57:06 ----D---- C:\WINDOWS\SoftwareDistribution
2014-12-22 18:09:12 ----RD---- C:\Program Files
2014-12-22 17:46:19 ----D---- C:\WINDOWS\debug
2014-12-22 17:08:24 ----D---- C:\WINDOWS\system32\FxsTmp
2014-12-22 16:54:23 ----D---- C:\Users\Neli\AppData\Roaming\Dropbox
2014-12-19 17:05:11 ----SHD---- C:\System Volume Information
2014-12-19 16:17:22 ----D---- C:\WINDOWS\CbsTemp
2014-12-18 13:44:02 ----HD---- C:\Program Files\WindowsApps
2014-12-16 18:08:57 ----D---- C:\WINDOWS\SysWOW64
2014-12-15 19:54:13 ----D---- C:\WINDOWS\Logs
2014-12-15 19:11:17 ----D---- C:\WINDOWS\apppatch
2014-12-15 18:49:39 ----A---- C:\WINDOWS\win.ini
2014-12-15 18:44:48 ----D---- C:\Program Files (x86)\Adobe Download Assistant
2014-12-15 18:44:22 ----SD---- C:\Users\Neli\AppData\Roaming\Microsoft
2014-12-15 18:43:32 ----SD---- C:\ProgramData\Microsoft
2014-12-15 16:02:18 ----D---- C:\WINDOWS\system32\DriverStore
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WkWin32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WkExt32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WibuXpm4J32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\wibuKJni.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WkWin64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WkExt64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WibuXpm4J64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\wibuKJni64.dll
2014-12-15 16:01:13 ----D---- C:\Program Files\Common Files
2014-12-12 20:24:42 ----D---- C:\WINDOWS\rescache
2014-12-12 19:24:52 ----D---- C:\WINDOWS\system32\catroot
2014-12-11 13:45:11 ----SD---- C:\WINDOWS\system32\CompatTel
2014-12-11 13:45:10 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-12-11 13:45:10 ----D---- C:\WINDOWS\system32\cs-CZ
2014-12-11 13:45:10 ----D---- C:\WINDOWS\PolicyDefinitions
2014-12-11 13:45:10 ----D---- C:\Program Files\Internet Explorer
2014-12-11 13:45:10 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-11 13:09:48 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2014-12-11 13:09:48 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2014-12-11 13:09:30 ----D---- C:\WINDOWS\system32\MRT
2014-12-11 13:07:54 ----A---- C:\WINDOWS\system32\MRT.exe
2014-12-10 09:27:00 ----D---- C:\WINDOWS\system32\catroot2
2014-12-04 17:38:20 ----D---- C:\Program Files (x86)\Common Files
2014-11-30 11:27:10 ----RSD---- C:\WINDOWS\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\WINDOWS\System32\drivers\amd_sata.sys [2012-11-30 80552]
R0 amd_xata;amd_xata; C:\WINDOWS\System32\drivers\amd_xata.sys [2012-11-30 26280]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-08-19 157016]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey64.sys [2014-12-15 106760]
R3 dtsoftbus01;@oem12.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-08-05 283064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-07-02 3472600]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2012-10-25 13368]
R3 NVHDA;@oem15.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2014-03-20 197408]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-03-20 12708128]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-09-17 19272]
R3 nvvad_WaveExtensible;@oem22.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2014-09-04 597896]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-06-04 361984]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-12-13 12288]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-09-17 1148744]
R2 McNeelUpdate;McNeel Update Service 5.0; C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [2012-10-25 67752]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2013-02-20 161264]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-09-17 1795912]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-09-17 19439944]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-03-04 922968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-17 411936]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08 116648]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-10-17 1357104]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 mi-raysat_3dsmax2015_64;mental ray Satellite for Autodesk 3ds Max 2015 64-bit; D:\3DS MAX 2015\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [2011-09-15 86016]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 27 pro 2014 16:31
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Users\Neli\AppData\Local\Akamai
C:\Users\Neli\AppData\Local\Facebook\Update
C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3867520272-1177344532-2789452036-1001Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"=-
"Facebook Update"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytmp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 29 pro 2014 19:51
od Mara
Logfile of random's system information tool 1.10 (written by random/random)
Run by Neli at 2014-12-29 19:51:00
Microsoft Windows 8.1 Pro
System drive C: has 34 GB (30%) free of 114 GB
Total RAM: 16333 MB (87% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:51:02, on 29. 12. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Neli.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [ADSKAppManager] "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Spotify] "C:\Users\Neli\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Neli\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: Dropbox.lnk = Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Network Server.lnk = C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: McNeel Update Service 5.0 (McNeelUpdate) - Robert McNeel & Associates - C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe
O23 - Service: mental ray Satellite for Autodesk 3ds Max 2015 64-bit (mi-raysat_3dsmax2015_64) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9781 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spoolsv.exe
taskhostex.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {52921064-FF13-4C06-B437-73EEDCBF5185}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
dashost.exe {d0fb51ba-5840-4d3e-8dec06685bcff194}
"C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe"
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22dba4c9-0108-4ee0-bedd-2c448956492e 1
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
ngservice.exe pipeserver
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-48405d58-bcc8-4a5d-aa65-89d07aa5a710 -SystemEventPortName:HostProcess-b7aa9930-0515-41c2-a5ea-10eb9179814e -IoCancelEventPortName:HostProcess-2af06f15-ef45-4963-a661-501733ad666f -NonStateChangingEventPortName:HostProcess-f32f9686-a621-4cfc-8e16-7086cbe865ea -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:19f9446a-9def-4096-9863-7bcf06d62473 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\WINDOWS\system32\vssvc.exe
C:\WINDOWS\System32\svchost.exe -k swprv
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Hewlett-Packard\HP Wireless Comfort Desktop\TSR\xDaemon.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5272.0.990715287\2077394048" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38,46 --gpu-vendor-id=0x10de --gpu-device-id=0x1380 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3523 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5272.2.975418675\1619024435" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5272.3.1439078207\1970667589" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5272.4.359393475\963397087" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5272.5.544958173\1101811426" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/QueryBoundaryExperiment_Stable_R6_Postperiod/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_49/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="5272.8.1541464715\949630040" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="5272.9.2034083461\1582182069" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702

"C:\Program Files\Windows Media Player\wmpnetwk.exe"

C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Neli\Downloads\RSITx64.exe"
C:\WINDOWS\System32\ThumbnailExtractionHost.exe -Embedding
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 580 584 592 65536 588

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171152}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-27 705448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-04 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-27 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-04 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2013-06-27 7191768]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-09-17 2460488]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-09-17 2799784]
"HP Input Device Main Program"=C:\Program Files\Hewlett-Packard\HP Wireless Comfort Desktop\TSR\xDaemon.exe [2008-10-16 530432]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Spotify"=C:\Users\Neli\AppData\Roaming\Spotify\Spotify.exe [2014-12-15 6737976]
"Spotify Web Helper"=C:\Users\Neli\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-12-15 1676344]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2013-02-05 1081224]
"DAEMON Tools Lite"=D:\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-06-04 676608]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2013-03-08 506864]
"ADSKAppManager"=C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [2014-09-04 488328]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-12-27 5226600]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Network Server.lnk - C:\Program Files (x86)\WIBUKEY\Server\WkSvMgr.exe

C:\Users\Neli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Neli\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open -
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-12-29 19:47:54 ----D---- C:\_OTM
2014-12-27 15:48:24 ----D---- C:\Users\Neli\AppData\Roaming\AVAST Software
2014-12-27 15:26:10 ----D---- C:\WINDOWS\SYSWOW64\vbox
2014-12-27 15:26:10 ----D---- C:\WINDOWS\system32\vbox
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswStm.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswsnx.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswRdr2.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\drivers\aswHwid.sys
2014-12-27 15:25:58 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-12-27 15:25:56 ----A---- C:\WINDOWS\avastSS.scr
2014-12-27 15:24:36 ----D---- C:\Program Files\AVAST Software
2014-12-27 15:24:05 ----D---- C:\ProgramData\AVAST Software
2014-12-27 15:12:07 ----D---- C:\Program Files\Chaos Group
2014-12-27 14:11:36 ----A---- C:\Program Files\plugin.ini
2014-12-27 14:11:31 ----D---- C:\Program Files\scripts
2014-12-23 09:42:21 ----D---- C:\AdwCleaner
2014-12-22 18:09:12 ----D---- C:\rsit
2014-12-22 18:09:12 ----D---- C:\Program Files\trend micro
2014-12-22 18:07:43 ----D---- C:\FRST
2014-12-16 17:27:25 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe
2014-12-16 17:27:25 ----A---- C:\WINDOWS\system32\poqexec.exe
2014-12-15 20:04:09 ----A---- C:\autoexec.bat
2014-12-15 18:46:44 ----D---- C:\Program Files (x86)\5ed62cb3-a818-4fd2-8ca5-592214a27582
2014-12-15 18:44:58 ----A---- C:\Users\Neli\AppData\Roaming\ZG.exe
2014-12-15 18:44:41 ----D---- C:\Program Files (x86)\4c9d1e66-0169-442a-82b8-bb5316244060
2014-12-15 18:44:25 ----A---- C:\Users\Neli\AppData\Roaming\KGKSJMI.exe
2014-12-15 18:43:20 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-12-15 18:42:18 ----D---- C:\Program Files (x86)\Seznam.cz
2014-12-15 18:42:08 ----D---- C:\Users\Neli\AppData\Roaming\Seznam.cz
2014-12-15 16:01:13 ----D---- C:\Program Files\Common Files\ChaosGroup
2014-12-11 13:45:11 ----D---- C:\WINDOWS\system32\appraiser
2014-12-10 19:12:56 ----A---- C:\WINDOWS\system32\crypt32.dll
2014-12-10 19:12:55 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2014-12-10 09:27:30 ----A---- C:\WINDOWS\SYSWOW64\DeviceSetupStatusProvider.dll
2014-12-10 09:27:30 ----A---- C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2014-12-10 09:27:29 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-12-10 09:27:28 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-12-10 09:27:27 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\system32\wininet.dll
2014-12-10 09:27:26 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-12-10 09:27:25 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\webcheck.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\jscript.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\inetcomm.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\iepeers.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-12-10 09:27:24 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-12-10 09:27:23 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2014-12-10 09:27:22 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\invagent.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\generaltel.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\devinv.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\appraiser.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aepic.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aepdu.dll
2014-12-10 09:27:15 ----A---- C:\WINDOWS\system32\aeinv.dll
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\sdbus.sys
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\intelpep.sys
2014-12-10 09:27:14 ----AC---- C:\WINDOWS\system32\drivers\dumpsd.sys
2014-12-10 09:27:14 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2014-12-04 17:38:21 ----D---- C:\ProgramData\Sun
2014-12-04 17:38:20 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2014-12-04 17:38:12 ----D---- C:\ProgramData\Oracle
2014-12-04 17:38:11 ----D---- C:\Program Files (x86)\Java
2014-12-04 17:26:22 ----D---- C:\Program Files\PDF Split And Merge Basic
2014-12-04 17:24:23 ----D---- C:\PDF_Split_and_Merge_Basic_64bit_v2

======List of files/folders modified in the last 1 month======

2014-12-29 19:48:58 ----RD---- C:\WINDOWS\System32
2014-12-29 19:48:48 ----D---- C:\ProgramData\NVIDIA
2014-12-29 19:47:57 ----D---- C:\WINDOWS\Tasks
2014-12-29 19:47:41 ----D---- C:\WINDOWS\Prefetch
2014-12-29 19:28:39 ----D---- C:\WINDOWS\Temp
2014-12-29 19:02:00 ----D---- C:\WINDOWS\system32\sru
2014-12-29 18:31:07 ----D---- C:\WINDOWS\system32\config
2014-12-29 18:29:27 ----D---- C:\WINDOWS\Microsoft.NET
2014-12-29 18:24:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-29 18:24:28 ----D---- C:\WINDOWS\Inf
2014-12-29 18:18:14 ----D---- C:\WINDOWS\system32\drivers
2014-12-29 18:17:41 ----D---- C:\WINDOWS\system32\Tasks
2014-12-27 20:39:20 ----D---- C:\Users\Neli\AppData\Roaming\Dropbox
2014-12-27 15:26:17 ----SHD---- C:\System Volume Information
2014-12-27 15:26:10 ----D---- C:\WINDOWS\SysWOW64
2014-12-27 15:26:08 ----D---- C:\WINDOWS\system32\DriverStore
2014-12-27 15:25:58 ----D---- C:\WINDOWS\WinSxS
2014-12-27 15:25:57 ----D---- C:\Windows
2014-12-27 15:24:36 ----RD---- C:\Program Files
2014-12-27 15:24:05 ----HD---- C:\ProgramData
2014-12-27 15:10:28 ----SHD---- C:\WINDOWS\Installer
2014-12-27 15:07:49 ----D---- C:\ProgramData\Autodesk
2014-12-27 15:06:01 ----D---- C:\Program Files\Common Files\Autodesk Shared
2014-12-27 15:03:52 ----D---- C:\Program Files (x86)\Autodesk
2014-12-27 14:57:41 ----D---- C:\Program Files\Autodesk
2014-12-27 14:54:48 ----D---- C:\WINDOWS\Logs
2014-12-27 14:00:46 ----D---- C:\WINDOWS\AppReadiness
2014-12-23 09:43:33 ----RD---- C:\Program Files (x86)
2014-12-23 09:39:19 ----D---- C:\Users\Neli\AppData\Roaming\Spotify
2014-12-22 23:24:13 ----D---- C:\Users\Neli\AppData\Roaming\vlc
2014-12-22 21:57:06 ----D---- C:\WINDOWS\SoftwareDistribution
2014-12-22 17:46:19 ----D---- C:\WINDOWS\debug
2014-12-22 17:08:24 ----D---- C:\WINDOWS\system32\FxsTmp
2014-12-19 16:17:22 ----D---- C:\WINDOWS\CbsTemp
2014-12-18 13:44:02 ----HD---- C:\Program Files\WindowsApps
2014-12-15 19:11:17 ----D---- C:\WINDOWS\apppatch
2014-12-15 18:49:39 ----A---- C:\WINDOWS\win.ini
2014-12-15 18:44:48 ----D---- C:\Program Files (x86)\Adobe Download Assistant
2014-12-15 18:44:22 ----SD---- C:\Users\Neli\AppData\Roaming\Microsoft
2014-12-15 18:43:32 ----SD---- C:\ProgramData\Microsoft
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WkWin32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WkExt32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\WibuXpm4J32.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\SYSWOW64\wibuKJni.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WkWin64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WkExt64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\WibuXpm4J64.dll
2014-12-15 16:02:06 ----A---- C:\WINDOWS\system32\wibuKJni64.dll
2014-12-15 16:01:13 ----D---- C:\Program Files\Common Files
2014-12-12 20:24:42 ----D---- C:\WINDOWS\rescache
2014-12-12 19:24:52 ----D---- C:\WINDOWS\system32\catroot
2014-12-11 13:45:11 ----SD---- C:\WINDOWS\system32\CompatTel
2014-12-11 13:45:10 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-12-11 13:45:10 ----D---- C:\WINDOWS\system32\cs-CZ
2014-12-11 13:45:10 ----D---- C:\WINDOWS\PolicyDefinitions
2014-12-11 13:45:10 ----D---- C:\Program Files\Internet Explorer
2014-12-11 13:45:10 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-11 13:09:48 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2014-12-11 13:09:48 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2014-12-11 13:09:30 ----D---- C:\WINDOWS\system32\MRT
2014-12-11 13:07:54 ----A---- C:\WINDOWS\system32\MRT.exe
2014-12-10 09:27:00 ----D---- C:\WINDOWS\system32\catroot2
2014-12-04 17:38:20 ----D---- C:\Program Files (x86)\Common Files
2014-11-30 11:27:10 ----RSD---- C:\WINDOWS\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amd_sata;amd_sata; C:\WINDOWS\System32\drivers\amd_sata.sys [2012-11-30 80552]
R0 amd_xata;amd_xata; C:\WINDOWS\System32\drivers\amd_xata.sys [2012-11-30 26280]
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-12-27 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-12-27 267632]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-12-27 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-12-27 1050432]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-12-27 436624]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-04-09 57472]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-12-27 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-12-27 83280]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-12-27 116728]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-12-27 271752]
R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\WibuKey64.sys [2014-12-15 106760]
R3 dtsoftbus01;@oem12.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-08-05 283064]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-07-02 3472600]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2012-10-25 13368]
R3 NVHDA;@oem15.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2014-03-20 197408]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-03-20 12708128]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-09-17 19272]
R3 nvvad_WaveExtensible;@oem22.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2014-09-04 597896]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-06-04 361984]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-12-13 12288]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-12-27 50344]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-09-17 1148744]
R2 McNeelUpdate;McNeel Update Service 5.0; C:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe [2012-10-25 67752]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2013-02-20 161264]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-09-17 1795912]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-09-17 19439944]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-03-04 922968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-17 411936]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-12-27 4012248]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08 116648]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-10-17 1357104]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-08 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 mi-raysat_3dsmax2015_64;mental ray Satellite for Autodesk 3ds Max 2015 64-bit; C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [2011-09-15 86016]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 29 pro 2014 20:26
od Rudy
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 30 pro 2014 19:35
od Mara
Mám pocit, že už jen zde na fóru vyskakuje reklama v novém okně. Konkrétně https://www.gametwist.com/web/Display?p ... _P28251045

Možná se to bude dít i jinde, ale stává se mi to zatím jen tady. Nejsem si tedy jist, že je kompletně uklizeno.

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 30 pro 2014 20:35
od Rudy
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 30 pro 2014 21:42
od Mara
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 30. 12. 2014
Scan Time: 21:30:16
Logfile: tet.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2014.12.30.08
Rootkit Database: v2014.12.29.02
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Neli

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 417348
Time Elapsed: 7 min, 24 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 5
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HDQ-1.2cV15.12-nv, , [659baebbbac21d19a5395d84ea1a57a9],
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HDQ-1.2cV15.12-nv, , [0ff185e49ede5ed8a43b60819d671ee2],
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HDQ-1.2cV15.12, , [f20e84e5d1ab85b1825e1ac72ed6d42c],
PUP.Optional.InternetSpeedChecker, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Internet Speed Checker, , [cb353a2f5329072f80519cdbd1327a86],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3867520272-1177344532-2789452036-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HDQ-1.2cV15.12-nv, , [05fb70f9a6d640f607d805dc0ff5d927],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 6
PUP.Optional.CrossRider.A, C:\Users\Neli\AppData\Roaming\KGKSJMI.exe, , [44bc92d70e6e142296d40cab778e04fc],
PUP.Optional.CrossRider.A, C:\Users\Neli\AppData\Roaming\ZG.exe, , [2cd4b6b3c0bc999d3436a710a75ed927],
PUP.Optional.Nova.A, C:\Program Files (x86)\4c9d1e66-0169-442a-82b8-bb5316244060\db24eb51-5be6-483c-9bc9-2051d8550d06.dll, , [e9177eebe6967eb83aa4ec1332cf6b95],
PUP.Optional.Nova.A, C:\Program Files (x86)\5ed62cb3-a818-4fd2-8ca5-592214a27582\0d9d6926-5bf9-450d-b310-49f529bb309a.dll, , [5fa199d05923af874e9013ec28d917e9],
PUP.Optional.Nova.A, C:\Program Files (x86)\5ed62cb3-a818-4fd2-8ca5-592214a27582\bf405267-f108-40f3-bfe3-49e85a6ffb95.dll, , [b64a3930a1db5cdafce228d7ba47b050],
PUP.Optional.Nova.A, C:\Program Files (x86)\Adobe Download Assistant\7e9c0794-da48-467f-b3a8-6c94197bfe9c.dll, , [2fd1ce9b5c2015214c92f6091ee32fd1],

Physical Sectors: 0
(No malicious items detected)


(end)

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 30 pro 2014 22:10
od Rudy
Vše, co MBAM nalezl, smažte.

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 01 led 2015 16:52
od Mara
po smazání už nevyskakují určité typy oken, ale teď se mi ještě jedno otevřelo...jinde zatím zkouším




Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 1. 1. 2015
Scan Time: 16:40:30
Logfile: jj.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.01.02
Rootkit Database: v2014.12.30.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Neli

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 418569
Time Elapsed: 7 min, 31 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 01 led 2015 17:42
od Rudy
Log je již OK. Nastala změna nyní?

Re: Vir - samovolné otevírání nových oken s reklamou v chrom

Napsal: 01 led 2015 22:07
od Mara
okna stále vyskakují tu na fóru i jinde