Pomalý NTB, vyskakující okna - hruza
Napsal: 09 led 2015 20:28
Prosím o kontrolu logu
Logfile of random's system information tool 1.10 (written by random/random)
Run by Filip at 2015-01-09 19:52:44
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 4 GB (7%) free of 60 GB
Total RAM: 4026 MB (7% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:56:49, on 9.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe
C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\Filip\AppData\Roaming\Browser Extensions\CouponsHelper.exe
C:\Users\Filip\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.18.6\dsrlte.exe
C:\Users\Filip\AppData\Roaming\Search Protection\SP.exe
C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PCSuite.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Yawtix\bin\Yawtix.expext.exe
C:\Users\Filip\AppData\Local\Temp\~nsu.tmp\Au_.exe
D:\Download\RSIT.exe
C:\Program Files (x86)\trend micro\Filip.exe
C:\Users\Filip\AppData\Local\Temp\~nsu.tmp\Bu_.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... m?affID=na
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... kId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Extensions - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Filip\AppData\Roaming\Browser Extensions\Coupons.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [SpeedItupFree] "C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe"
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Browser Extensions] "C:\Users\Filip\AppData\Roaming\Browser Extensions\CouponsHelper.exe"
O4 - HKCU\..\Run: [Yahoo! Search] C:\Users\Filip\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.18.6\dsrlte.exe
O4 - HKCU\..\Run: [Search Protection] "C:\Users\Filip\AppData\Roaming\Search Protection\SP.EXE" /autostart
O4 - HKCU\..\Run: [S60 PC Suite Tray] "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PCSuite.exe" -onlytray
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_167_ActiveX.exe -update activex
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Samsung.PCSync] "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Samsung.PCSync] "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog (User 'Default user')
O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout FDM - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video FDM - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané FDM - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše FDM - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Just Develop It - C:\Program Files (x86)\MyPC Backup\BackupStack.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MaintainerSvc5.70.609258 - Unknown owner - C:\ProgramData\dfed7653-07f4-44f2-abaa-a70c946c17c3\maintainer.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: ShopperPro Update (SPBIUpd) - ShopperPro - C:\Program Files\Common Files\ShopperPro\spbiu.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Yawtix - Unknown owner - C:\Program Files (x86)\Yawtix\updateYawtix.exe
O23 - Service: Util Yawtix - Unknown owner - C:\Program Files (x86)\Yawtix\bin\utilYawtix.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11467 bytes
======Scheduled tasks folder======
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-1.job - C:\Program Files (x86)\Object Browser\Object Browser-codedownloader.exe /XbItjrAs /jwRJw=task /nDFKEHvF='Object Browser' /ZXacAtCfK=32850 /uTauHmn='000037' /HNjTQtEr='0' /UHxssHkt='0' /BnDQkZo=51062B776DF44FE7BEA938E76308CC49IE /wyAOrlqa=e1c72331b84dfca9879c3f199edc72fc /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399396324 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /imrGDm /FfuPo='http://update.clientdemostack.com/ie_co ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-3.job - C:\Program Files (x86)\Object Browser\6b144b32-e986-48bc-9bb6-1646fce85034-3.exe /bindBsrEt=ZhQicFqQIY7dHOVb4ydqgjnwD29L7owvUVWNCT4TXiXGbnzISEf4iNZt+hU5Zy6BzutQ6OAuR7+uHmGrucX/CG2NjaTe+rXhN3lMmcv/TEzZFYqme+e6Z4GlA1/aGBRDYjGHRBXUT2A354hBN0s9QTVmQWtI4DYDkwOXx/NTjd27zhxPT/9dkbXzDr+sI/ZaSVAKW6Ef/YwCNYgzQepze2/+PIflf02vcgFZQdMfEA9bN3v5+LjZHvbolMaaK6iyATG7NIHqSuESMIVz2mYGkfWHQ391puEBBuyQG3VpNiI06aw3FG6Nk4zDkMcXoHnzFPDMCZISxC0BxMaElevpentGsVHO38vJkwYdNr7U4RLfP0u6gMlt3Vi10+XwOqJKmGQCKbPRcXrimYVCKk2e13ypfnWogfKYNLqTe4SUm874r68RJg/MdYsJVEc98JJ37HV0c+k9VKFU7Q8vXi9wCazp9eC67VqkMJ9Flq2AIGSqJpsM2c7qkuO/8TP1YKUnu+VauxSrjmatMHC1TwUKarvMakEp+wQH8R7nBdKvMEObeYGVnI+dDGT5pLW4R0izvc4vp6IvL4fGRr+j7paxNuSVbGGzojj3ZuRMfvowyFWoPw70aLwVFXTrwH7VPrtxKRWLLgfLbUmlUx/ohWrGBi1Feu+tiJDs5UHhzGfPvFQhaHuMyjqi6pt94TwlAq205J5QrwlaQ5AcAMspFw2pu5A3tUNtBeY5Ln3WRazVa4Uh1bq8Z33Ptfmas4F/PTG50wJ0YodWnUnyoRxf+bl2VJNRsh0eMSownO/jc9qLrmtBqDKGsxQehyXUKFN4147MitNA/A/8aGHqPGoInEvEzrdwEIP+47nU+zYVI2HMQmJs++BV/HAxH5ssOcpdNljCnB97Ct9GssBDEA5SqRjgHWlXd+iSjQNfce+YlDCnJ/amGZkZNESFmNqqE5tK/WIckP2SVNyB8ofSiJejOQ/aCWz5zLmtkO+36C9YCrw7IH9eCWjWCE24/ZqgRRv+nkLkLDyofSDOPygC8vNC0j22PVaMfOvu3BmsqjRwKcMXBji9JppV+gz96PFz2patq7DvKouzHbDSGtZjqnSZdAXBZ+OzAGCmk+JkF48QzkCcotZ15UzbEc1/7/3BpPC4j3FtVqOB6byCuJxFf2xzZ1Opuw0MEgu30YV9b91LswDu+3MnhSLCaYADM84v09uSbWqDUqaIIUp9yaC7gNoymRFEl1+tfUxQfmKSq/UMG2wRa9zt2oehG9ClDIqfazFka52aP5PJ1wDhS3UUfWQSbw8ZfPhRYhGJ7epC5QJABzMhf4ptU8nCgTs9nPaWLOzjS3zK5zdOYD6DaJ1vxMFXlKW/4A==
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-4.job - C:\Program Files (x86)\Object Browser\6b144b32-e986-48bc-9bb6-1646fce85034-4.exe /tHElyyqlh /nDFKEHvF='Object Browser' /dRXMBsvX='C:\Program Files (x86)\Object Browser\32850.xpi' /ZXacAtCfK=32850 /uTauHmn='000037' /HNjTQtEr='0' /UHxssHkt='0' /BnDQkZo=51062B776DF44FE7BEA938E76308CC49IE /wyAOrlqa=e1c72331b84dfca9879c3f199edc72fc /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399396324 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /BlPZbawtG=300 /VkWzPLiu=9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com /RITMpzHCc=0.94 /EanFJu=a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850 /otcnIO=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /32850.rdf /CENtcehQ='Object Browser' /HRgNUxz='Browser enhancer' /KNDKPQiZl='Object Browser' /mJxJJLh=ff /imrGDm /ClHIrTxJ /LDIPo /FfuPo='http://update.clientdemostack.com/ff_ag ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-5.job - C:\Program Files (x86)\Object Browser\6b144b32-e986-48bc-9bb6-1646fce85034-5.exe /rawdata=qRg2kSNifPEagJjx67jGXtuwSbGRp2p7o93u3Df4OYbmMwFTMYl/iF3RMVa+6+a/xskvFXVmFayyRL0zoMOZQijl74NOEXrvB8quE4MVAq3m3wU2l1Yak8jvjsgpi5dRwUZj1RbDN0Y0cRZ3RkUV/76LiDLk0dGJGLHOlrT0lydL8vatnbEDAc1wt83XOPRtKymrlGSY9CSNWVNSDuRh5lwI/ef0gmtEC0UNoHuMlfbaWckiWZabvA+R4DwcRb/79HcSNRPnWNu/q3lV2m2SIjkzKUk9DS5zp/7CK6UT+nhp6Cc01An6AIeA1G4VaTjog9DJ9vR9EHN+jrFVFRR4Q3LAmerJiPe4rIcVjyv5pbX2fHjeDsPH7MtK63cA2QNyEHkIMNvJ1Hx6vUuJ1OUfQLUwNHdW7sRHQP1iAXxZElK9OD4Jfp6hohgM7BmUP0nqZ81L2UmgFtZQGP986hY/jgGuMVUcmHZHY/uH/BHlee1YtYD55p9tyTHMkLLubq8ynzvegOej5XD0SBCDmXi/rE/zuICx+PJWljZnJdxxluAuXErsE56KFm0S+qwQLphgb6mJv/cxy5TX/dSsDW6OF0lL7OHACuepS7mSMSB80XJr2gxX0gmWnEFp0lsz1Bouc2ecIItjy4Ly7uDiLvZ5/sb3YPIEQlJSJfEoCgmcylhZKEG8z6dVR1qulJz0QW0WbJlkaG7kcE03kvLN/xp0/YoYxOTbhHt9GPHQs7UX2MqUYx/DSJL9MpP/OagXtIvfx/kQeZO6ygO7+iDqcIuYH40diFi9jKrQApzt8D6c5ZX1I6k5ywKIAAowlgepEgcw+XjHUv8P0hk/2UtfSL00PQ==
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-6.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe /rawdata=IPJwSQCR9J0jumI2JPfMlPek+AQ5YimSHYEyvZ1bkzh2Zyqr6CYt8LFRTR8UVpbMlCEKj+VaR2XPzhFIB48qad3x9JGRluaySFbot2W2hrPqQraQM1fw6ZglyHzVJSrI7Zjcen2POmi4vtF9mx1bv1hn4ucTVAIDhJrIlWxMU1JLmoo3yjlRwZzMeI3bZM3pY/yWnFR7LZbB7bB4Zw8VZGmQumu2eZEr88KWAzyJItJtWZsfZhSKiOqsw2rEadysawy+RN14LsUj+tLPf0JHkWNsJ68uJYPnnSDoaT0XNb0MgJm1JouElsWHKf+mKy8sjZjzIFVD5ey7n9NFRiJwII5Zbu5u9LosnMOyiIVS9wqVPT40VbwI7e3ldpKsFygY1POpXiNRc1WUL0e6+rB/SxpCoa74VrwPFqhgXiIJ0MCPROczki19UBpqVytGeyviK+3/ebaEqlUjvOK2/lj9MslSPwGrMdfYkpu2ODwQmu/h/LteloXUxrQowV0RwnA+sZ3IvYHZJg8grK50vPGj78m6it/ugmXCFZuqOQr/bTOYhgB1nbFIrmqDzgRWsbk5AzAW5wiElJiTib+i5Vnage3e5npIRNbb4SjOCyJqAGCeOVe9COmVto7mLPKNlycpVfiA4r4mtMLf9eGL722YfNTcTDTMwb1+uGwdouDjNGQvwlZyNdF4rAC2VYJn/po4/XzCOKNBbJPU4MG4UhQ5IKaLzcVwENkzmu09yjnPBIdUud9jusqZxQWXTZgvZ63FNi2GHgBF6Uyv6xgT6LIkpoejhKzK0REniNGYKuCMxEyvy7J0c4Ds1c6+UYqYw8YBp9zD7df1p2w6Q8Kzq/OKVYZn9h0PBkP9Qz7bKmIM0rYYJmlBoCKw1MtcC/+E5G8rpEmb6uxrPVXSS3E7ubkLXL4xMgBB89Cf+qFyOXmH2aAmFZJhPJEAcY4XfUC6kvhp2FN9agz5jrH85ksBu2snRkDoxp47I48rNb8H6QYzbd6hM5OAtDlc9sDNhAgNhAaKAEFhmcT87SXdM8s9p4vEyp8plbO7netpaScqCYTG+YsWYZY7l+fYgm+6oRinDY13XObJmu8D3SJ3s8fGOVsBX1J1uZ2t78QsEIIgVdPqX8EYWbcSE9at5fCOMQr6NjEmbdEfAR2D7Ijqb8qNKE06NV8t2obhgOTDCWHBp7jSQvs=
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-7.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe /nDFKEHvF='Object Browser' /ZXacAtCfK==32850 /uTauHmn='000037' /HNjTQtEr='0' /UHxssHkt='0' /BnDQkZo=51062B776DF44FE7BEA938E76308CC49IE /wyAOrlqa=e1c72331b84dfca9879c3f199edc72fc /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399396324 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /QxtbgyeC /VrXBqTsrk='nova' /FfuPo='http://update.clientdemostack.com/novar ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /XbItjrAs /jwRJw=task /nDFKEHvF='iWebar' /ZXacAtCfK=35510 /uTauHmn='000170' /HNjTQtEr='0' /UHxssHkt='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrY0FnMCwwMjc0ZWUzYS04MDUyLTRkOTItOGM5OC00Y2VmOGU0MDMzMjUsIiwidW5xIjoiMDI3NGVlM2EtODA1Mi00ZDkyLThjOTgtNGNlZjhlNDAzMzI1In19' /BnDQkZo=C1045640C2C749798BE0CAFBC6B41F9CIE /wyAOrlqa=2f20009adbb1636f10495bccf2de24f9 /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399204595 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /imrGDm /FfuPo='http://update.clientdemostack.com/ie_co ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-3.job - C:\Program Files (x86)\iWebar\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-3.exe /bindBsrEt=DKZ9y+6zOKNgUxRZxgDTfvM4Bq086O+GCx6kdijYgpgU8DmJwjfuctsasbtYbWFvNNl+a71WX7qXqmr04CC5Mj9qw4pzxHuXUNKBm0vBVjXgRqEpFASI/PiZOMkW9ZWBcsbl3XTzH+RBGq1cUdr1hAq12YAkCJ7lhBTBjw/AMhtGy/ImeG5h2yTdvjZ9Xy2Hrlgs9sKm/eNf0ndYbDiWhDJISG+nHTt6Tf2H3MFKiW9LukRkl3LSBMrjAc3nw98YKH/nAYEgk+rLC1W8+wsGRS4df/QlZP1aB6raK/RqR3zoNzfV44zNy8Cnb5RJZA9fkSO/01IPLnE2NjJSGE5y/HyKDwoDbdti+pRR3epmwpkREWtHtYJS012FKPXZMTaEPsaFeFBUjEI0kGP8jG+fyuvI+ov5aB7gXygieADQJVx9ZzoOYgM5DSrC6hDe2vxIZkxEAGLbLWiiQme+EUcLRnubMWmy23S58mpnlpdTur21usPEZALLZ0pJQC65UdknZ+pnxpFBMrYUnGT8u5d9JZRh/99TrTWtk8fTB8YoCzu6MNHUrkbIV4YUPLrS8fk52w+CvoxteT5oMzdLqawBviWZKcTUCQTkDtWL3ipjtnejwoQILIbKc2lFRhTr3fJ0Db5hFetAFOPt40JyIsSASI8Yv0sTFPP5yW8h0VPVDaReQr4FeAZL3O5VbXJ7LSC6qMr4xCnLsB9lgEJBf3HEtNOGaDmmH2VmV+Pd/zZHthaHAOx4R0wWIVixK8KNIGNqM40U4hBq9qpxeyx9Gx0r8FjXfPxGqfmpQdZfKkrXQ29FlL+XI28ehCAhZYUnKz6l8O7UnnRHrEWl1DLJjmgfpCu77u10N2XM+4P8ZLKff5wP0GO8bNYQsENhbzDETchjVu1VLeil+G3TvxFJT6MGz0i2DZgYNaUto1dN4BP/31sYBf88LijiWOEMTnHgaO+DDsY5Hweii7Al2tRuA4LLb5AivL9fkXskeBiVSTk0OvEs+bLNVib0HmGIZUpe+eekUqKyxwnrwE1TTbMHxHTIbr4oFxOeoWLXN+0vsLsygx5Pnjt9URZf5Iqs6OjbhLkT3hzCbvC0ehmDO91FsygUGq5MO1gsy46ExSqPHK+Dcn6cJtWYFyPH24QSacnHD/QyiQNxmseI1yCVc+IGd7hPTgpIze/yczGo9MrkBKoUgdJ026OsmXCaIfbOjjdBonUIXHtYfBb41T2m7j2evpY9wHkIOQTjXlUCjWqbn8rF1AAcCm31tuGk9hd1MBZMGrlDPffD2lQyyC3hiynQi50APiTw5DXAyZ6m5uJBDpdwLREWFGF1Guw6fKVOkiFRgApcJDrEtwMLhakiE70Pcc4meGxDGYyG40CA6tUFEL8ZUeNq/xH5Sv6HTXFm09tnFoZK/q/gCoSYubb0M/pHpU3WlnoNxPcQkoGxdnxRJL8sH4AsjymsPBFvVtprU5pu1V3sVFQvAsmDc5g0R9rinGgSBVva22Bo8VbnzAO3icb/GTW6gTpg+TLQki7ECMl4jtCY
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-4.job - C:\Program Files (x86)\iWebar\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-4.exe /tHElyyqlh /nDFKEHvF='iWebar' /dRXMBsvX='C:\Program Files (x86)\iWebar\35510.xpi' /ZXacAtCfK=35510 /uTauHmn='000170' /HNjTQtEr='0' /UHxssHkt='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrY0FnMCwwMjc0ZWUzYS04MDUyLTRkOTItOGM5OC00Y2VmOGU0MDMzMjUsIiwidW5xIjoiMDI3NGVlM2EtODA1Mi00ZDkyLThjOTgtNGNlZjhlNDAzMzI1In19' /BnDQkZo=C1045640C2C749798BE0CAFBC6B41F9CIE /wyAOrlqa=2f20009adbb1636f10495bccf2de24f9 /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399204595 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /BlPZbawtG=300 /VkWzPLiu=2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com /RITMpzHCc=0.94 /EanFJu=a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510 /otcnIO=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /35510.rdf /CENtcehQ='iWebar' /HRgNUxz='iWebar' /KNDKPQiZl='iWebar' /mJxJJLh=ff /imrGDm /ClHIrTxJ /LDIPo /FfuPo='http://update.clientdemostack.com/ff_ag ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-5.job - C:\Program Files (x86)\iWebar\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-5.exe /rawdata=P/OLZp6sshWY1FK1q9zTnWb3jE+mXhsTd+ds3O8Od+UUWw81plus6TPdYqJOr2pafs95hwoO46yGM66hDvIlJlg3cdnWIG1dAWLWipJk/AuOA24D4/HjNJ5ksxc6yr0EAuFM2OuGP+5T0ys/OhyZOLD+CzOPrrdC4K7B3GDucCxoJh39I0e/7pSMJYMiar2CrhVvGIqg5Qu5RcAW6F4X7OXu0fFIF/F32IF3l/MNxNl1xKYOuS9WA6oC60LhxvzPoRWSwRM6B0LXYq5KY8sqxm0cQweEibzoSIXoRgzJRTsNMEOXa9H7xCl+lN5VJLAYaJBrdTgTEn5i1YrdUtsUNUZRl+G9VHg+FVDNG4728i5RxK0UHUtS5ItrbWiA9sxVto1udByTd+LpB86SNdG90FaJPmGN5Fw3ZkjiyAtdh3CMA5pYvwlDFOs8n3KOXf3LKb0AJToc9x0Tpeno+LmnBTYJ0jwfm/VRFCG2eCK0JMmRlZwj304xefFxK+PlBUcfxhKk0BFPrKZv81NWExYIIqFwshhkmhMT43PeM/wZEBM0AMcg5xNW91CfgkCGj7SAZ+kGs5gqzycRwb6GxOqIVPKDGejNYkNk0ICakYkrBMZ4XSIwFDJZuiX7gbGMwhzy6LMlAvIgTtQOUhKJXXa+nEnRv9hA0YLnIb7N85qfWi+bim04rjeyO9EJ71DWx+gD/0zVQ/ncmMxzW9oU21lko74M57hwfYDC1mq3jEmDL+jhJWMtpyH8JTkgrQfQJNkvkrx1u+qa46A6i4ZqcRqe9hKgnKbaGIAkpJfp/NGMT8CtPb1QPQCJDljJIEvtA9NjpxEeR2q2AYhY416e6BDrEQ+hyAdi0zwbsL2qp/vTYzYAvU71pcQd85DAjiknsPw9jeV5vTU2ZvUlYDWp+LWQHhhD+T7AaA+lkB4yMFQgWZdoZG2bhNDq0rIR6Z3gdrnRq26lNnhegz9/O7nZO95XEQ30AFf9ffRQuLx2Hg9Mllpy8bCeDIer0HQ4PfBLrnoo
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-6.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe /rawdata=uWgVnek3JDNrHJ46Pm0Hcxv+6/3omjGj4Q6JU+by6OkXyNOcgo95XxzcWJIK8euiv48xUsYTREjdfvw1JYsK6wzukziayW26C3oDdl8WjajPpt6JEIfalMPEozQQvAS3QrLCb1pEfIOkyprLp/N2Ni2N1tX66CDtPdZSgKV4L+Kg/OzWin7/+hyq+j91WX0dAvE1iSGRtappxX+uk2CfXz5+v4c4/STas9fK316KGWAKO9oSAq9L40EYtKY7dnFa8aqatTchpsCx4nxc38+taEm+8rVM99AGM6/rHKpM/9hNfGtyLHyVEYC7uUETUTYpaQe90Tb+4/raKZ+9zFHLihC4Vnx7ClNz7eaWF2kyNGBqA/i4e/v1FLeSLIYRqwWfmUFzBQFEDXn9XUOZdF0cFSHpg8iqHMlvHf28L94eWTmz08ZagyiGp2PApMny5P6Q1f8XArimDI0skGDDS8QxCUUfkZmOHJKg9h8+vbEv5JFBSEqESddE6W6VZGLZ8ls4kqgMt5zTmyYrJyDxmovGIZjmFUFcSYrNpnCNRr4Tl/Omjtjly3ZHKKrRv1tHfp4zmrE+fbnaU04DJoEbVtWU+X02isSHOErVCNUUNClTrsofF5UHMV6OnRw5xOdL1O9+P++aXZUxEOpoZGcwIMa3PhDdwax8Is3Jayx3NoGtXZCZUITNV3GWoQvfvB2axY2RlASHwdSeP/Efq4nitmgkrHIg6JYLtzaddDbKUJ+GQznCrmSVU6d4Eo2eiv0ChtY/f+sPLWKQx6JZgkCcnfFaOzpN56LmiIATlp6KKBlgQ8Om4Bkfjr0Bpvt8qSfZbHidfPawpzwYAZyt6wdJXnk70WqQjjLOBSopaFHTBUi2u9oTP2qlOXQUgYLP5tDUNiqjkiMxoVMGA8LM9LDZHZrOptSP/lRGLH/MCYrNUciY13O/3gnCAwMmsamWUhCx7VoTlKW13/pYrAEobVLMMtaxosm2YSkxQPA4GPFleWDn+L2BLGLs9RakVl07aFzZY/39l/NvOf66or8HQ6MUT+W5N/2lofupftei8b8MagonNslcPl7RBvMhPqoHBqpymlf5vPeTf1NpjW7mLY0mt+cwIGD35eXMGSmz6IL3kONzNWHVJg/Hhjk+NBSY7PLqsJezWMKsjOWtGQxCvzZpSphxYIzuVSz1bZmlinwkaOAq+FE=
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-7.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe /nDFKEHvF='iWebar' /ZXacAtCfK==35510 /uTauHmn='000170' /HNjTQtEr='0' /UHxssHkt='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrY0FnMCwwMjc0ZWUzYS04MDUyLTRkOTItOGM5OC00Y2VmOGU0MDMzMjUsIiwidW5xIjoiMDI3NGVlM2EtODA1Mi00ZDkyLThjOTgtNGNlZjhlNDAzMzI1In19' /BnDQkZo=C1045640C2C749798BE0CAFBC6B41F9CIE /wyAOrlqa=2f20009adbb1636f10495bccf2de24f9 /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399204595 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /QxtbgyeC /VrXBqTsrk='nova' /FfuPo='http://update.clientdemostack.com/novar ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-1.job - C:\Program Files (x86)\Sense\Sense-codedownloader.exe /Rocje /ldwqMeEj=task /BNSOW='Sense' /HZbtpM=48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /RppKetCFK=1.34.4.10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /giKxZUQ=http://js.clientdemostack.com /KnGsmi=ff /YylzXDJkE /comtgSxKp='http://update.clientdemostack.com/ie_co ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-2.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-2.exe /KwLSfiV /BNSOW='Sense' /HZbtpM=48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /DiNzW=11111111-1111-1111-1111-110411821192 /KnGsmi=ff /YylzXDJkE /comtgSxKp='http://update.clientdemostack.com/ie_en ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-3.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-3.exe /sLqHCnF=cxrKCwON28zJdK/JhohZ5jJbQurBWDmtXnsj6GsgM4zVPUasbU4Ez00fK9IqT9ko88ugPGQPSyFX3h3+oyKS7nyKm2jDVjGUtxNKsYN9EAUOZa+7myfsTUKyX+otkrbRzeaP7/s0u/poRn5ct0iDAfYlF0PuAN6KZxvBtCntddoyZbEnS4hXGLGYHDxvsV8c0mDiL1Kil7png8y4yAB0tz/g7o2j5C88hHZAcsIrfavEGjQBG8mbvnbWGDF76vaZ5US2IYIy9ri2y/yYwCCWmyp8lKFhE7khWel8eSTVzCpVfKas+tfTuZE0bHc8xY4NKpm7ut+LOwFlbpRnObOSfTVFjRve1zoN+PYr24bFjU1fxMWw95D6AtJiBS2vKn76ZZzcLH5KbBWqzBz1HfftE2IUtQ/dEgJLf6FcMCYmcOpAzdRUqo4EMhUw044dcv1j4LCOsK6dDr1oXjvTWvbGx7vykZEHM1qRONeNJSeNG7HZsw6daHHejEBygMRjvH+GB0my/GwFYxSVl7icmGc9S/Sxv0j3/B4bocmKULu6MPkXTBQcUdksSjkGJY29URNNusf1K8cZLY0P3G7tCjvvwI06NsnUpLSWP/X1DCpu0UzTIrR6H4nyaZ3hZMn6dbo6IS6g6zBCQ4TV6xv5j2465AZqdMKHZy53Jad5gC1hAOMfj/DQJcrmoUvvFUXCcLjelZRFCaAmFfxgsJsc4raj8nYpruvZQUzeLjQkPkf5xX19v+sA5Ogve++Z/e1a4HLGsfEnrL2uf7XH0BLOCETwmKySDzLRpZA1SPPXRpTAZ3zYh2isrWCEjl8bjWyKSAcYGv+z5puvPGkezUJi7eIev4cf6kAGXMBGmxyCn+gtlf27zr/XAlSPdSNxJuZ550zjfFHF1ydX76W/XOgcWi6vlm+vINvzw7zJc/TrQx6nYifOhWx2CHMdd7aaUV8NDycOB9Bg7YzUbY3IrZzAHfMSXg+EdGXkHzFnx0TBlCqlcQ2PlL97smrmmKVTePZ4dUodMnhqoHpq1bMjgR0ttueAa9NCK1m2RGz6Dq8ck6a2xn9lZK4AVWSl6HGe2ecGiqez8MH6fml3l9Y/LCCGLEjtD/sgDnirrS3hXQNtYAxf1NXy522l3XUFz2RMh7hmc7/ibHcFLszYQOMPkTa6QtFRtzjgvvP880oQmhWQ9CyN9ZuwblTqG6i76tgq80DIO9QPZvA/Dj30UXX1Nx9xPnrNomJqVVq5HNI/hqpTIcK547tv7bFwhKIhslhJkIrDhYTCifXKVhoJY4PmyDWkKG0MziGt+6F6WoFPU0IGB0OUzRmXdfhcY5iT3CuAidfQLV+X4IjrRctfZZ2zDLxcrE6STx5eU76o3izDHDlPxa9QJWXF3oEEr/CVOOPMpQWLzmJph3UHXhxQoC9N7HzY+GKlFm3XxFFQ7Z/40MTJdv2A+Cn3RI7ux3Jeg1KonDRkZB3vUnCZJRCLej9Iwgj7klZgamSkvT90/jykh1Ac+iaR+ptIuZvT1xQ6mrKf1sCmXSoR
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-4.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-4.exe /BhEQVzt /BNSOW='Sense' /Fsqwaryji='C:\Program Files (x86)\Sense\48292.xpi' /HZbtpM=48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /RppKetCFK=1.34.4.10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /cWsUxgAdy=300 /iAKXh=143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com /XKRpiT=0.94 /LAuXjYKUK=a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292 /yZRbmwvPB=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /48292.rdf /ZkXTo='Sense' /bJmfDhS='.' /cuvEJFfx='Object Browser' /KnGsmi=ff /YylzXDJkE /PGivmcuzh /zsilm /comtgSxKp='http://update.clientdemostack.com/ff_ag ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-5.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-5.exe /rawdata=Uq1i5XISAqEgEotbC74hOeC/iDwm/4pHNlfyH18j3I0kz8af2t7h77z8gu7XITVD/g7FqpbyLGSByVSax/c3rtC86lxKel+S9bo07XPWpsvkCU5dkjxKImaP08muPOVDbM3U629do50oc02cSpU2q6Xva11wx1KKk00t/yvAL42yI5SI6GA8HwCSIfMyAXNEVlVWClZNKy3d/9ggx/OkNZYHj3Y4HH7/wMUKkUpsAXhYnChD6YCXXMaOAGagvnxYGQhtzrjJIQlK5knuDs+Tjyvga4wpoI7aYrau9ivc5hTaytWKueyJW7cu9P/5s1FoQi6MAWYyX5KEfb7BbDXZqWF+9uvw94b30c0AN2OHuMxWbfu7beytqOhdty6mzYmYiMerQP1J4A/YbhhO7rCHj6hfAOODN2gjNyUrlAiSVCg9dhR83IKW4/LLXF2spJbavadZuur7MLeL75+YjeO5u2rjAEnJTy98A/eiYJTHK9EBfb8B27YZMmwC8/NmqjvhJN/JLWGCQSVbiJ2I8mUIeV4J+FqapNbRY7ZfilLF2pDOUY2uWfqZ6/u3QvxiRrTSzRBIdVAuL0epIEk+K+YazMVfj1wBYPX07uRtC4odmvyePzQUNq0Tqmc5gKpbQBiEYiuXUEfxrnMcBx4NimLiVBOtx5w1RwTaJWA+oFKNYXIeUD+kQhUjQQXHY+dojwozF/IRmMu+HGD0ry/yjwjRpg+aCj8U977lg4T9yKepQqFQK7PCUAW07Sn3BHdbP4N/3yfB6rA44JdwSrExiHpMGeEWXZNTqO3bD0iAQ1geLzQzWMLDnI36uFXF20GU8PB9vbG5b1zXtr6yloX97IK5RhcylBOvSUci6JjMac74GfymGFKD6Lxaul2wtJ7/eNXfE7FNneBcRnL6PI2sxFtSdKO+DG5+pBXNTvq47CZ1GujVHURFbum0z/f2sd17W2N5wwIUczyMdb84KP3BiysoRI5NC2R4g1B7yU/CWR+US8yZzCEWMXgEwFEkIm/2YaQ4
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-6.job - C:\Program Files (x86)\Sense\Sense-nova.exe /rawdata=HqlHwN04vaLFxdMxmlrMQmQPZdR2YzIA817vjRzlrdmk91kM7LdY+Sz8IjyohMZM1rukfgGDIy48S5yJ/J7Rk7NyGB3xp6dbxq9jkCihKceLLZvWQugMDASEP74IFZKA4XegK42GdE+jh/w2i6QhhOMv+MhDIZ3b8TpvuKPzK3Adgra1WmuFsQtqD9+gr3daojWnxxjtAXcvXGJ2/hkKBYivp5vclW0mrLbFmCgfLyUiibdKC2P/0ZadMngERO7ULLF/2VTo3lL+TrpU49GRCUmRpGE3xKHNK8igOqvX18/eNsf1HNb5ecu0qAy2NV/E3FH9XRsNh/DfF9pyTaRJVydhPEn+QUJDs0WYsfQoXSlHqj+LbfKdKJtVq1rV23IFt+wwmKpqmukhY2q6VwuVOQ2dIKKfsvSdtzab4E7noVm2g9+gmhsfUkGwfnj6i9hTrwmdF2eVLvsO0U6SsafMpNMpfdi1gwobUec8AAtli1SLvd44DS5G4ZUUVvchQR1ixHZAapZjJFNPf+vojJATY2bODZdFg3H2zNj49eFtSHK/20Tr+NsbptGnKbdk5Wic0fky8yVA/vZSYUT9gEWxxK9OJb3m6/77gpExEZpoAVGDjHq5/22WlnPN8Lt8I9zXMR9Oa4dUZyWztfhnpEM7xan8wkq7GpTKxMw3vaKa03GlqebQWmAV2mBSBSFIP3IKY/XS8kli0iS6nQegGldHAVY9J/aGnFG3UjhqvrumRK1xM3nbU9cHZBm42Q7OWdwkXhtj/Vt5jo6QEf9VmhgULALD2Vj/Ccpui+ZNn+5deg/nD8W00nWj9IsJAEJBt6P1bSJCCqXrpkGjwHDYPS59drF/D4lPxf6lRaDWhcXSbvxWcDC/0oqDJCXqQ3jO9gW3rrdHjavKK3VjHK690P/UUvVKOoLEYi9FnZZpMhvqYt+4L6uQhhETgciNboHb2sCu7SmXSaZsizlL8/E583kcfBMTJ6CHydSN/rHdra4arZbwFQN0ziK/WKTOGdffBTbBB4Po614daF/3yVi5Z+p80/Wgyoll7kZrzxVjllX9qrxApVTea84oFFrS+179dIGRf4ABi252vs9xVKBGlFsE6SOZG2PWTh4cC3JXKxJJ/DJjT/ZlzivNPlI91vqdy4JbmVS2Q0gb/1q8l1+a/NQMl0euYcDxutVlIoyp4eW8vDI=
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-7.job - C:\Program Files (x86)\Sense\Sense-nova.exe /BNSOW='Sense' /HZbtpM==48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /RppKetCFK=1.34.4.10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /giKxZUQ=http://js.clientdemostack.com /KnGsmi=ff /QJNTQTUj /GUjBoYkYU='nova' /comtgSxKp='http://update.clientdemostack.com/novar ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\hd37auco.default
prefs.js - "browser.startup.homepage" - "http://rts.dsrlte.com?affID=na"
prefs.js - "keyword.URL" - "https://search.yahoo.com/search?fr=gree ... =238417&p="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\hd37auco.default\extensions\
143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com
2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com
9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
staged
zzoomit@zoom.com
{54FBE89E-C878-46bb-A064-AB327EE26EBC}
{62DD0A97-FDD4-421b-94A5-D1A9434450C7}
{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
{CA8C84C6-3918-41b1-BE77-049B2BDD887C}
{DE1C78C1-2762-47f6-A1D9-1B7866FE7EB4}
C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\hd37auco.default\searchplugins\
dsrlte.xml
yahoo_ff.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Filip\AppData\Roaming\Browser Extensions\Coupons.dll [2014-10-20 610152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-06 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
Free Download Manager - C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2014-04-22 365056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-06 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"NPSStartup"= []
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe [2014-12-23 3224576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"=C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe [2012-01-02 102400]
"SpeedItupFree"=C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe []
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe [2014-12-23 3224576]
"Free Download Manager"=C:\Program Files (x86)\Free Download Manager\fdm.exe [2014-04-29 6980096]
"uTorrent"=C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe [2014-11-23 1385808]
"Browser Extensions"=C:\Users\Filip\AppData\Roaming\Browser Extensions\CouponsHelper.exe [2014-10-20 967528]
"Yahoo! Search"=C:\Users\Filip\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.18.6\dsrlte.exe [2015-01-08 634576]
"Search Protection"=C:\Users\Filip\AppData\Roaming\Search Protection\SP.EXE [2015-01-05 1127736]
"S60 PC Suite Tray"=C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PCSuite.exe [2008-12-06 699392]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_167_ActiveX.exe [2014-09-30 854704]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-01-09 19:52:49 ----D---- C:\Program Files (x86)\trend micro
2015-01-09 19:52:43 ----D---- C:\rsit
2015-01-09 19:36:56 ----D---- C:\ProgramData\ESET
2014-12-25 08:58:38 ----D---- C:\Users\Filip\AppData\Roaming\ASP
2014-12-25 08:41:37 ----D---- C:\Users\Filip\AppData\Roaming\WebTest
2014-12-17 23:05:23 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2014-12-12 10:46:08 ----A---- C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-12 10:45:58 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-12-12 10:45:58 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-12-12 10:45:58 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-12-12 10:45:56 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-12-12 10:45:56 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\jscript9.dll
======List of files/folders modified in the last 1 month======
2015-01-09 19:56:38 ----D---- C:\Windows\Temp
2015-01-09 19:56:26 ----D---- C:\Users\Filip\AppData\Roaming\uTorrent
2015-01-09 19:56:05 ----D---- C:\Program Files (x86)\YTDownloader
2015-01-09 19:52:49 ----RD---- C:\Program Files (x86)
2015-01-09 19:49:04 ----A---- C:\Windows\win.ini
2015-01-09 19:45:27 ----D---- C:\Program Files (x86)\RCP
2015-01-09 19:45:26 ----D---- C:\Windows\Tasks
2015-01-09 19:44:59 ----D---- C:\Program Files (x86)\iWebar
2015-01-09 19:44:46 ----D---- C:\Program Files (x86)\Object Browser
2015-01-09 19:44:40 ----D---- C:\ProgramData\ShopperPro
2015-01-09 19:44:30 ----D---- C:\Program Files (x86)\Yawtix
2015-01-09 19:44:26 ----D---- C:\Program Files (x86)\Sense
2015-01-09 19:41:00 ----SHD---- C:\Windows\Installer
2015-01-09 19:39:32 ----D---- C:\Windows\inf
2015-01-09 19:36:56 ----RD---- C:\Program Files
2015-01-09 19:36:56 ----HD---- C:\ProgramData
2015-01-09 19:36:43 ----D---- C:\Windows\System32
2015-01-09 19:34:57 ----SHD---- C:\System Volume Information
2015-01-09 19:22:55 ----D---- C:\ProgramData\dfed7653-07f4-44f2-abaa-a70c946c17c3
2015-01-09 19:09:34 ----D---- C:\Windows\SpeedItup Free
2015-01-09 19:09:31 ----D---- C:\Program Files (x86)\SpeedItup Free
2015-01-09 19:05:24 ----D---- C:\Users\Filip\AppData\Roaming\Free Download Manager
2015-01-09 19:02:25 ----D---- C:\Downloads
2015-01-09 18:57:51 ----D---- C:\ProgramData\Systweak
2015-01-09 18:53:32 ----D---- C:\Windows\Prefetch
2015-01-09 18:53:07 ----D---- C:\Program Files (x86)\MyPC Backup
2015-01-08 19:36:28 ----D---- C:\Windows\SysWOW64
2015-01-08 19:36:26 ----D---- C:\Windows\Software Display
2015-01-08 19:36:26 ----D---- C:\Program Files (x86)\Software Display
2015-01-08 19:02:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-25 08:41:35 ----D---- C:\Program Files (x86)\Mozilla Firefox.bak
2014-12-25 08:40:24 ----D---- C:\Users\Filip\AppData\Roaming\systweak
2014-12-24 13:04:48 ----D---- C:\Program Files (x86)\ShopperPro
2014-12-24 12:58:01 ----D---- C:\Users\Filip\AppData\Roaming\Search Protection
2014-12-18 03:00:44 ----D---- C:\Windows\winsxs
2014-12-13 04:02:47 ----D---- C:\Windows\rescache
2014-12-13 03:24:13 ----D---- C:\Windows\SysWOW64\en-US
2014-12-13 03:24:13 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-12-13 03:24:12 ----D---- C:\Windows\PolicyDefinitions
2014-12-13 03:24:12 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-13 03:08:54 ----D---- C:\ProgramData\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys []
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64;{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64; C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64.sys []
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}w64;{16d667ee-6782-4b21-81df-8ded8ebc3868}w64; C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}w64.sys []
R1 {dc8e5bae-111b-483b-81ef-852b5b72d3ef}w64;{dc8e5bae-111b-483b-81ef-852b5b72d3ef}w64; C:\Windows\system32\drivers\{dc8e5bae-111b-483b-81ef-852b5b72d3ef}w64.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys []
R2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [2013-12-20 58728]
R2 SPDRIVER_1.38.0.1437;SPDRIVER_1.38.0.1437; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.sys [2014-12-23 52584]
R3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys []
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys []
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys []
R3 SPBIUpdd;ShopperPro UpdateD; \??\C:\Program Files\Common Files\ShopperPro\spbiw.sys [2014-12-23 41856]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
S0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys []
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys []
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2012-01-02 16392]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 BackupStack;Computer Backup (MyPC Backup); C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2014-11-25 53320]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2014-09-30 1343920]
R2 MaintainerSvc5.70.609258;MaintainerSvc5.70.609258; C:\ProgramData\dfed7653-07f4-44f2-abaa-a70c946c17c3\maintainer.exe [2015-01-09 123672]
R2 SPBIUpd;ShopperPro Update; C:\Program Files\Common Files\ShopperPro\spbiu.exe [2014-12-23 2346880]
R2 Update Yawtix;Update Yawtix; C:\Program Files (x86)\Yawtix\updateYawtix.exe [2015-01-09 529176]
R2 Util Yawtix;Util Yawtix; C:\Program Files (x86)\Yawtix\bin\utilYawtix.exe [2015-01-09 529176]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-30 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21 107912]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-12-09 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Filip at 2015-01-09 19:52:44
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 4 GB (7%) free of 60 GB
Total RAM: 4026 MB (7% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:56:49, on 9.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe
C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\Filip\AppData\Roaming\Browser Extensions\CouponsHelper.exe
C:\Users\Filip\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.18.6\dsrlte.exe
C:\Users\Filip\AppData\Roaming\Search Protection\SP.exe
C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PCSuite.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Yawtix\bin\Yawtix.expext.exe
C:\Users\Filip\AppData\Local\Temp\~nsu.tmp\Au_.exe
D:\Download\RSIT.exe
C:\Program Files (x86)\trend micro\Filip.exe
C:\Users\Filip\AppData\Local\Temp\~nsu.tmp\Bu_.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... m?affID=na
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... kId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Extensions - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Filip\AppData\Roaming\Browser Extensions\Coupons.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [SpeedItupFree] "C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe"
O4 - HKCU\..\Run: [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Browser Extensions] "C:\Users\Filip\AppData\Roaming\Browser Extensions\CouponsHelper.exe"
O4 - HKCU\..\Run: [Yahoo! Search] C:\Users\Filip\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.18.6\dsrlte.exe
O4 - HKCU\..\Run: [Search Protection] "C:\Users\Filip\AppData\Roaming\Search Protection\SP.EXE" /autostart
O4 - HKCU\..\Run: [S60 PC Suite Tray] "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PCSuite.exe" -onlytray
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_167_ActiveX.exe -update activex
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Samsung.PCSync] "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Samsung.PCSync] "C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog (User 'Default user')
O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout FDM - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout video FDM - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Stáhnout vybrané FDM - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše FDM - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Just Develop It - C:\Program Files (x86)\MyPC Backup\BackupStack.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MaintainerSvc5.70.609258 - Unknown owner - C:\ProgramData\dfed7653-07f4-44f2-abaa-a70c946c17c3\maintainer.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: ShopperPro Update (SPBIUpd) - ShopperPro - C:\Program Files\Common Files\ShopperPro\spbiu.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Yawtix - Unknown owner - C:\Program Files (x86)\Yawtix\updateYawtix.exe
O23 - Service: Util Yawtix - Unknown owner - C:\Program Files (x86)\Yawtix\bin\utilYawtix.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11467 bytes
======Scheduled tasks folder======
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-1.job - C:\Program Files (x86)\Object Browser\Object Browser-codedownloader.exe /XbItjrAs /jwRJw=task /nDFKEHvF='Object Browser' /ZXacAtCfK=32850 /uTauHmn='000037' /HNjTQtEr='0' /UHxssHkt='0' /BnDQkZo=51062B776DF44FE7BEA938E76308CC49IE /wyAOrlqa=e1c72331b84dfca9879c3f199edc72fc /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399396324 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /imrGDm /FfuPo='http://update.clientdemostack.com/ie_co ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-3.job - C:\Program Files (x86)\Object Browser\6b144b32-e986-48bc-9bb6-1646fce85034-3.exe /bindBsrEt=ZhQicFqQIY7dHOVb4ydqgjnwD29L7owvUVWNCT4TXiXGbnzISEf4iNZt+hU5Zy6BzutQ6OAuR7+uHmGrucX/CG2NjaTe+rXhN3lMmcv/TEzZFYqme+e6Z4GlA1/aGBRDYjGHRBXUT2A354hBN0s9QTVmQWtI4DYDkwOXx/NTjd27zhxPT/9dkbXzDr+sI/ZaSVAKW6Ef/YwCNYgzQepze2/+PIflf02vcgFZQdMfEA9bN3v5+LjZHvbolMaaK6iyATG7NIHqSuESMIVz2mYGkfWHQ391puEBBuyQG3VpNiI06aw3FG6Nk4zDkMcXoHnzFPDMCZISxC0BxMaElevpentGsVHO38vJkwYdNr7U4RLfP0u6gMlt3Vi10+XwOqJKmGQCKbPRcXrimYVCKk2e13ypfnWogfKYNLqTe4SUm874r68RJg/MdYsJVEc98JJ37HV0c+k9VKFU7Q8vXi9wCazp9eC67VqkMJ9Flq2AIGSqJpsM2c7qkuO/8TP1YKUnu+VauxSrjmatMHC1TwUKarvMakEp+wQH8R7nBdKvMEObeYGVnI+dDGT5pLW4R0izvc4vp6IvL4fGRr+j7paxNuSVbGGzojj3ZuRMfvowyFWoPw70aLwVFXTrwH7VPrtxKRWLLgfLbUmlUx/ohWrGBi1Feu+tiJDs5UHhzGfPvFQhaHuMyjqi6pt94TwlAq205J5QrwlaQ5AcAMspFw2pu5A3tUNtBeY5Ln3WRazVa4Uh1bq8Z33Ptfmas4F/PTG50wJ0YodWnUnyoRxf+bl2VJNRsh0eMSownO/jc9qLrmtBqDKGsxQehyXUKFN4147MitNA/A/8aGHqPGoInEvEzrdwEIP+47nU+zYVI2HMQmJs++BV/HAxH5ssOcpdNljCnB97Ct9GssBDEA5SqRjgHWlXd+iSjQNfce+YlDCnJ/amGZkZNESFmNqqE5tK/WIckP2SVNyB8ofSiJejOQ/aCWz5zLmtkO+36C9YCrw7IH9eCWjWCE24/ZqgRRv+nkLkLDyofSDOPygC8vNC0j22PVaMfOvu3BmsqjRwKcMXBji9JppV+gz96PFz2patq7DvKouzHbDSGtZjqnSZdAXBZ+OzAGCmk+JkF48QzkCcotZ15UzbEc1/7/3BpPC4j3FtVqOB6byCuJxFf2xzZ1Opuw0MEgu30YV9b91LswDu+3MnhSLCaYADM84v09uSbWqDUqaIIUp9yaC7gNoymRFEl1+tfUxQfmKSq/UMG2wRa9zt2oehG9ClDIqfazFka52aP5PJ1wDhS3UUfWQSbw8ZfPhRYhGJ7epC5QJABzMhf4ptU8nCgTs9nPaWLOzjS3zK5zdOYD6DaJ1vxMFXlKW/4A==
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-4.job - C:\Program Files (x86)\Object Browser\6b144b32-e986-48bc-9bb6-1646fce85034-4.exe /tHElyyqlh /nDFKEHvF='Object Browser' /dRXMBsvX='C:\Program Files (x86)\Object Browser\32850.xpi' /ZXacAtCfK=32850 /uTauHmn='000037' /HNjTQtEr='0' /UHxssHkt='0' /BnDQkZo=51062B776DF44FE7BEA938E76308CC49IE /wyAOrlqa=e1c72331b84dfca9879c3f199edc72fc /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399396324 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /BlPZbawtG=300 /VkWzPLiu=9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com /RITMpzHCc=0.94 /EanFJu=a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850 /otcnIO=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /32850.rdf /CENtcehQ='Object Browser' /HRgNUxz='Browser enhancer' /KNDKPQiZl='Object Browser' /mJxJJLh=ff /imrGDm /ClHIrTxJ /LDIPo /FfuPo='http://update.clientdemostack.com/ff_ag ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-5.job - C:\Program Files (x86)\Object Browser\6b144b32-e986-48bc-9bb6-1646fce85034-5.exe /rawdata=qRg2kSNifPEagJjx67jGXtuwSbGRp2p7o93u3Df4OYbmMwFTMYl/iF3RMVa+6+a/xskvFXVmFayyRL0zoMOZQijl74NOEXrvB8quE4MVAq3m3wU2l1Yak8jvjsgpi5dRwUZj1RbDN0Y0cRZ3RkUV/76LiDLk0dGJGLHOlrT0lydL8vatnbEDAc1wt83XOPRtKymrlGSY9CSNWVNSDuRh5lwI/ef0gmtEC0UNoHuMlfbaWckiWZabvA+R4DwcRb/79HcSNRPnWNu/q3lV2m2SIjkzKUk9DS5zp/7CK6UT+nhp6Cc01An6AIeA1G4VaTjog9DJ9vR9EHN+jrFVFRR4Q3LAmerJiPe4rIcVjyv5pbX2fHjeDsPH7MtK63cA2QNyEHkIMNvJ1Hx6vUuJ1OUfQLUwNHdW7sRHQP1iAXxZElK9OD4Jfp6hohgM7BmUP0nqZ81L2UmgFtZQGP986hY/jgGuMVUcmHZHY/uH/BHlee1YtYD55p9tyTHMkLLubq8ynzvegOej5XD0SBCDmXi/rE/zuICx+PJWljZnJdxxluAuXErsE56KFm0S+qwQLphgb6mJv/cxy5TX/dSsDW6OF0lL7OHACuepS7mSMSB80XJr2gxX0gmWnEFp0lsz1Bouc2ecIItjy4Ly7uDiLvZ5/sb3YPIEQlJSJfEoCgmcylhZKEG8z6dVR1qulJz0QW0WbJlkaG7kcE03kvLN/xp0/YoYxOTbhHt9GPHQs7UX2MqUYx/DSJL9MpP/OagXtIvfx/kQeZO6ygO7+iDqcIuYH40diFi9jKrQApzt8D6c5ZX1I6k5ywKIAAowlgepEgcw+XjHUv8P0hk/2UtfSL00PQ==
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-6.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe /rawdata=IPJwSQCR9J0jumI2JPfMlPek+AQ5YimSHYEyvZ1bkzh2Zyqr6CYt8LFRTR8UVpbMlCEKj+VaR2XPzhFIB48qad3x9JGRluaySFbot2W2hrPqQraQM1fw6ZglyHzVJSrI7Zjcen2POmi4vtF9mx1bv1hn4ucTVAIDhJrIlWxMU1JLmoo3yjlRwZzMeI3bZM3pY/yWnFR7LZbB7bB4Zw8VZGmQumu2eZEr88KWAzyJItJtWZsfZhSKiOqsw2rEadysawy+RN14LsUj+tLPf0JHkWNsJ68uJYPnnSDoaT0XNb0MgJm1JouElsWHKf+mKy8sjZjzIFVD5ey7n9NFRiJwII5Zbu5u9LosnMOyiIVS9wqVPT40VbwI7e3ldpKsFygY1POpXiNRc1WUL0e6+rB/SxpCoa74VrwPFqhgXiIJ0MCPROczki19UBpqVytGeyviK+3/ebaEqlUjvOK2/lj9MslSPwGrMdfYkpu2ODwQmu/h/LteloXUxrQowV0RwnA+sZ3IvYHZJg8grK50vPGj78m6it/ugmXCFZuqOQr/bTOYhgB1nbFIrmqDzgRWsbk5AzAW5wiElJiTib+i5Vnage3e5npIRNbb4SjOCyJqAGCeOVe9COmVto7mLPKNlycpVfiA4r4mtMLf9eGL722YfNTcTDTMwb1+uGwdouDjNGQvwlZyNdF4rAC2VYJn/po4/XzCOKNBbJPU4MG4UhQ5IKaLzcVwENkzmu09yjnPBIdUud9jusqZxQWXTZgvZ63FNi2GHgBF6Uyv6xgT6LIkpoejhKzK0REniNGYKuCMxEyvy7J0c4Ds1c6+UYqYw8YBp9zD7df1p2w6Q8Kzq/OKVYZn9h0PBkP9Qz7bKmIM0rYYJmlBoCKw1MtcC/+E5G8rpEmb6uxrPVXSS3E7ubkLXL4xMgBB89Cf+qFyOXmH2aAmFZJhPJEAcY4XfUC6kvhp2FN9agz5jrH85ksBu2snRkDoxp47I48rNb8H6QYzbd6hM5OAtDlc9sDNhAgNhAaKAEFhmcT87SXdM8s9p4vEyp8plbO7netpaScqCYTG+YsWYZY7l+fYgm+6oRinDY13XObJmu8D3SJ3s8fGOVsBX1J1uZ2t78QsEIIgVdPqX8EYWbcSE9at5fCOMQr6NjEmbdEfAR2D7Ijqb8qNKE06NV8t2obhgOTDCWHBp7jSQvs=
C:\Windows\tasks\6b144b32-e986-48bc-9bb6-1646fce85034-7.job - C:\Program Files (x86)\Object Browser\Object Browser-nova.exe /nDFKEHvF='Object Browser' /ZXacAtCfK==32850 /uTauHmn='000037' /HNjTQtEr='0' /UHxssHkt='0' /BnDQkZo=51062B776DF44FE7BEA938E76308CC49IE /wyAOrlqa=e1c72331b84dfca9879c3f199edc72fc /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399396324 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /QxtbgyeC /VrXBqTsrk='nova' /FfuPo='http://update.clientdemostack.com/novar ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /XbItjrAs /jwRJw=task /nDFKEHvF='iWebar' /ZXacAtCfK=35510 /uTauHmn='000170' /HNjTQtEr='0' /UHxssHkt='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrY0FnMCwwMjc0ZWUzYS04MDUyLTRkOTItOGM5OC00Y2VmOGU0MDMzMjUsIiwidW5xIjoiMDI3NGVlM2EtODA1Mi00ZDkyLThjOTgtNGNlZjhlNDAzMzI1In19' /BnDQkZo=C1045640C2C749798BE0CAFBC6B41F9CIE /wyAOrlqa=2f20009adbb1636f10495bccf2de24f9 /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399204595 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /imrGDm /FfuPo='http://update.clientdemostack.com/ie_co ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-3.job - C:\Program Files (x86)\iWebar\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-3.exe /bindBsrEt=DKZ9y+6zOKNgUxRZxgDTfvM4Bq086O+GCx6kdijYgpgU8DmJwjfuctsasbtYbWFvNNl+a71WX7qXqmr04CC5Mj9qw4pzxHuXUNKBm0vBVjXgRqEpFASI/PiZOMkW9ZWBcsbl3XTzH+RBGq1cUdr1hAq12YAkCJ7lhBTBjw/AMhtGy/ImeG5h2yTdvjZ9Xy2Hrlgs9sKm/eNf0ndYbDiWhDJISG+nHTt6Tf2H3MFKiW9LukRkl3LSBMrjAc3nw98YKH/nAYEgk+rLC1W8+wsGRS4df/QlZP1aB6raK/RqR3zoNzfV44zNy8Cnb5RJZA9fkSO/01IPLnE2NjJSGE5y/HyKDwoDbdti+pRR3epmwpkREWtHtYJS012FKPXZMTaEPsaFeFBUjEI0kGP8jG+fyuvI+ov5aB7gXygieADQJVx9ZzoOYgM5DSrC6hDe2vxIZkxEAGLbLWiiQme+EUcLRnubMWmy23S58mpnlpdTur21usPEZALLZ0pJQC65UdknZ+pnxpFBMrYUnGT8u5d9JZRh/99TrTWtk8fTB8YoCzu6MNHUrkbIV4YUPLrS8fk52w+CvoxteT5oMzdLqawBviWZKcTUCQTkDtWL3ipjtnejwoQILIbKc2lFRhTr3fJ0Db5hFetAFOPt40JyIsSASI8Yv0sTFPP5yW8h0VPVDaReQr4FeAZL3O5VbXJ7LSC6qMr4xCnLsB9lgEJBf3HEtNOGaDmmH2VmV+Pd/zZHthaHAOx4R0wWIVixK8KNIGNqM40U4hBq9qpxeyx9Gx0r8FjXfPxGqfmpQdZfKkrXQ29FlL+XI28ehCAhZYUnKz6l8O7UnnRHrEWl1DLJjmgfpCu77u10N2XM+4P8ZLKff5wP0GO8bNYQsENhbzDETchjVu1VLeil+G3TvxFJT6MGz0i2DZgYNaUto1dN4BP/31sYBf88LijiWOEMTnHgaO+DDsY5Hweii7Al2tRuA4LLb5AivL9fkXskeBiVSTk0OvEs+bLNVib0HmGIZUpe+eekUqKyxwnrwE1TTbMHxHTIbr4oFxOeoWLXN+0vsLsygx5Pnjt9URZf5Iqs6OjbhLkT3hzCbvC0ehmDO91FsygUGq5MO1gsy46ExSqPHK+Dcn6cJtWYFyPH24QSacnHD/QyiQNxmseI1yCVc+IGd7hPTgpIze/yczGo9MrkBKoUgdJ026OsmXCaIfbOjjdBonUIXHtYfBb41T2m7j2evpY9wHkIOQTjXlUCjWqbn8rF1AAcCm31tuGk9hd1MBZMGrlDPffD2lQyyC3hiynQi50APiTw5DXAyZ6m5uJBDpdwLREWFGF1Guw6fKVOkiFRgApcJDrEtwMLhakiE70Pcc4meGxDGYyG40CA6tUFEL8ZUeNq/xH5Sv6HTXFm09tnFoZK/q/gCoSYubb0M/pHpU3WlnoNxPcQkoGxdnxRJL8sH4AsjymsPBFvVtprU5pu1V3sVFQvAsmDc5g0R9rinGgSBVva22Bo8VbnzAO3icb/GTW6gTpg+TLQki7ECMl4jtCY
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-4.job - C:\Program Files (x86)\iWebar\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-4.exe /tHElyyqlh /nDFKEHvF='iWebar' /dRXMBsvX='C:\Program Files (x86)\iWebar\35510.xpi' /ZXacAtCfK=35510 /uTauHmn='000170' /HNjTQtEr='0' /UHxssHkt='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrY0FnMCwwMjc0ZWUzYS04MDUyLTRkOTItOGM5OC00Y2VmOGU0MDMzMjUsIiwidW5xIjoiMDI3NGVlM2EtODA1Mi00ZDkyLThjOTgtNGNlZjhlNDAzMzI1In19' /BnDQkZo=C1045640C2C749798BE0CAFBC6B41F9CIE /wyAOrlqa=2f20009adbb1636f10495bccf2de24f9 /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399204595 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /BlPZbawtG=300 /VkWzPLiu=2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com /RITMpzHCc=0.94 /EanFJu=a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510 /otcnIO=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /35510.rdf /CENtcehQ='iWebar' /HRgNUxz='iWebar' /KNDKPQiZl='iWebar' /mJxJJLh=ff /imrGDm /ClHIrTxJ /LDIPo /FfuPo='http://update.clientdemostack.com/ff_ag ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-5.job - C:\Program Files (x86)\iWebar\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-5.exe /rawdata=P/OLZp6sshWY1FK1q9zTnWb3jE+mXhsTd+ds3O8Od+UUWw81plus6TPdYqJOr2pafs95hwoO46yGM66hDvIlJlg3cdnWIG1dAWLWipJk/AuOA24D4/HjNJ5ksxc6yr0EAuFM2OuGP+5T0ys/OhyZOLD+CzOPrrdC4K7B3GDucCxoJh39I0e/7pSMJYMiar2CrhVvGIqg5Qu5RcAW6F4X7OXu0fFIF/F32IF3l/MNxNl1xKYOuS9WA6oC60LhxvzPoRWSwRM6B0LXYq5KY8sqxm0cQweEibzoSIXoRgzJRTsNMEOXa9H7xCl+lN5VJLAYaJBrdTgTEn5i1YrdUtsUNUZRl+G9VHg+FVDNG4728i5RxK0UHUtS5ItrbWiA9sxVto1udByTd+LpB86SNdG90FaJPmGN5Fw3ZkjiyAtdh3CMA5pYvwlDFOs8n3KOXf3LKb0AJToc9x0Tpeno+LmnBTYJ0jwfm/VRFCG2eCK0JMmRlZwj304xefFxK+PlBUcfxhKk0BFPrKZv81NWExYIIqFwshhkmhMT43PeM/wZEBM0AMcg5xNW91CfgkCGj7SAZ+kGs5gqzycRwb6GxOqIVPKDGejNYkNk0ICakYkrBMZ4XSIwFDJZuiX7gbGMwhzy6LMlAvIgTtQOUhKJXXa+nEnRv9hA0YLnIb7N85qfWi+bim04rjeyO9EJ71DWx+gD/0zVQ/ncmMxzW9oU21lko74M57hwfYDC1mq3jEmDL+jhJWMtpyH8JTkgrQfQJNkvkrx1u+qa46A6i4ZqcRqe9hKgnKbaGIAkpJfp/NGMT8CtPb1QPQCJDljJIEvtA9NjpxEeR2q2AYhY416e6BDrEQ+hyAdi0zwbsL2qp/vTYzYAvU71pcQd85DAjiknsPw9jeV5vTU2ZvUlYDWp+LWQHhhD+T7AaA+lkB4yMFQgWZdoZG2bhNDq0rIR6Z3gdrnRq26lNnhegz9/O7nZO95XEQ30AFf9ffRQuLx2Hg9Mllpy8bCeDIer0HQ4PfBLrnoo
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-6.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe /rawdata=uWgVnek3JDNrHJ46Pm0Hcxv+6/3omjGj4Q6JU+by6OkXyNOcgo95XxzcWJIK8euiv48xUsYTREjdfvw1JYsK6wzukziayW26C3oDdl8WjajPpt6JEIfalMPEozQQvAS3QrLCb1pEfIOkyprLp/N2Ni2N1tX66CDtPdZSgKV4L+Kg/OzWin7/+hyq+j91WX0dAvE1iSGRtappxX+uk2CfXz5+v4c4/STas9fK316KGWAKO9oSAq9L40EYtKY7dnFa8aqatTchpsCx4nxc38+taEm+8rVM99AGM6/rHKpM/9hNfGtyLHyVEYC7uUETUTYpaQe90Tb+4/raKZ+9zFHLihC4Vnx7ClNz7eaWF2kyNGBqA/i4e/v1FLeSLIYRqwWfmUFzBQFEDXn9XUOZdF0cFSHpg8iqHMlvHf28L94eWTmz08ZagyiGp2PApMny5P6Q1f8XArimDI0skGDDS8QxCUUfkZmOHJKg9h8+vbEv5JFBSEqESddE6W6VZGLZ8ls4kqgMt5zTmyYrJyDxmovGIZjmFUFcSYrNpnCNRr4Tl/Omjtjly3ZHKKrRv1tHfp4zmrE+fbnaU04DJoEbVtWU+X02isSHOErVCNUUNClTrsofF5UHMV6OnRw5xOdL1O9+P++aXZUxEOpoZGcwIMa3PhDdwax8Is3Jayx3NoGtXZCZUITNV3GWoQvfvB2axY2RlASHwdSeP/Efq4nitmgkrHIg6JYLtzaddDbKUJ+GQznCrmSVU6d4Eo2eiv0ChtY/f+sPLWKQx6JZgkCcnfFaOzpN56LmiIATlp6KKBlgQ8Om4Bkfjr0Bpvt8qSfZbHidfPawpzwYAZyt6wdJXnk70WqQjjLOBSopaFHTBUi2u9oTP2qlOXQUgYLP5tDUNiqjkiMxoVMGA8LM9LDZHZrOptSP/lRGLH/MCYrNUciY13O/3gnCAwMmsamWUhCx7VoTlKW13/pYrAEobVLMMtaxosm2YSkxQPA4GPFleWDn+L2BLGLs9RakVl07aFzZY/39l/NvOf66or8HQ6MUT+W5N/2lofupftei8b8MagonNslcPl7RBvMhPqoHBqpymlf5vPeTf1NpjW7mLY0mt+cwIGD35eXMGSmz6IL3kONzNWHVJg/Hhjk+NBSY7PLqsJezWMKsjOWtGQxCvzZpSphxYIzuVSz1bZmlinwkaOAq+FE=
C:\Windows\tasks\6ec23ea0-6ec8-40dc-b686-74a437d9d25f-7.job - C:\Program Files (x86)\iWebar\iWebar-nova.exe /nDFKEHvF='iWebar' /ZXacAtCfK==35510 /uTauHmn='000170' /HNjTQtEr='0' /UHxssHkt='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrY0FnMCwwMjc0ZWUzYS04MDUyLTRkOTItOGM5OC00Y2VmOGU0MDMzMjUsIiwidW5xIjoiMDI3NGVlM2EtODA1Mi00ZDkyLThjOTgtNGNlZjhlNDAzMzI1In19' /BnDQkZo=C1045640C2C749798BE0CAFBC6B41F9CIE /wyAOrlqa=2f20009adbb1636f10495bccf2de24f9 /bGMKndn=1_34_04_10 /lyzLXka=1.34.4.10 /VAcPC=1399204595 /KCjIuLgj=http://stats.clientdemostack.com /GOEwt=http://errors.clientdemostack.com /IsMeKTU=http://js.clientdemostack.com /mJxJJLh=ff /QxtbgyeC /VrXBqTsrk='nova' /FfuPo='http://update.clientdemostack.com/novar ... pdate.json' /jwRJw='task' /rfptHS=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-1.job - C:\Program Files (x86)\Sense\Sense-codedownloader.exe /Rocje /ldwqMeEj=task /BNSOW='Sense' /HZbtpM=48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /RppKetCFK=1.34.4.10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /giKxZUQ=http://js.clientdemostack.com /KnGsmi=ff /YylzXDJkE /comtgSxKp='http://update.clientdemostack.com/ie_co ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-2.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-2.exe /KwLSfiV /BNSOW='Sense' /HZbtpM=48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /DiNzW=11111111-1111-1111-1111-110411821192 /KnGsmi=ff /YylzXDJkE /comtgSxKp='http://update.clientdemostack.com/ie_en ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-3.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-3.exe /sLqHCnF=cxrKCwON28zJdK/JhohZ5jJbQurBWDmtXnsj6GsgM4zVPUasbU4Ez00fK9IqT9ko88ugPGQPSyFX3h3+oyKS7nyKm2jDVjGUtxNKsYN9EAUOZa+7myfsTUKyX+otkrbRzeaP7/s0u/poRn5ct0iDAfYlF0PuAN6KZxvBtCntddoyZbEnS4hXGLGYHDxvsV8c0mDiL1Kil7png8y4yAB0tz/g7o2j5C88hHZAcsIrfavEGjQBG8mbvnbWGDF76vaZ5US2IYIy9ri2y/yYwCCWmyp8lKFhE7khWel8eSTVzCpVfKas+tfTuZE0bHc8xY4NKpm7ut+LOwFlbpRnObOSfTVFjRve1zoN+PYr24bFjU1fxMWw95D6AtJiBS2vKn76ZZzcLH5KbBWqzBz1HfftE2IUtQ/dEgJLf6FcMCYmcOpAzdRUqo4EMhUw044dcv1j4LCOsK6dDr1oXjvTWvbGx7vykZEHM1qRONeNJSeNG7HZsw6daHHejEBygMRjvH+GB0my/GwFYxSVl7icmGc9S/Sxv0j3/B4bocmKULu6MPkXTBQcUdksSjkGJY29URNNusf1K8cZLY0P3G7tCjvvwI06NsnUpLSWP/X1DCpu0UzTIrR6H4nyaZ3hZMn6dbo6IS6g6zBCQ4TV6xv5j2465AZqdMKHZy53Jad5gC1hAOMfj/DQJcrmoUvvFUXCcLjelZRFCaAmFfxgsJsc4raj8nYpruvZQUzeLjQkPkf5xX19v+sA5Ogve++Z/e1a4HLGsfEnrL2uf7XH0BLOCETwmKySDzLRpZA1SPPXRpTAZ3zYh2isrWCEjl8bjWyKSAcYGv+z5puvPGkezUJi7eIev4cf6kAGXMBGmxyCn+gtlf27zr/XAlSPdSNxJuZ550zjfFHF1ydX76W/XOgcWi6vlm+vINvzw7zJc/TrQx6nYifOhWx2CHMdd7aaUV8NDycOB9Bg7YzUbY3IrZzAHfMSXg+EdGXkHzFnx0TBlCqlcQ2PlL97smrmmKVTePZ4dUodMnhqoHpq1bMjgR0ttueAa9NCK1m2RGz6Dq8ck6a2xn9lZK4AVWSl6HGe2ecGiqez8MH6fml3l9Y/LCCGLEjtD/sgDnirrS3hXQNtYAxf1NXy522l3XUFz2RMh7hmc7/ibHcFLszYQOMPkTa6QtFRtzjgvvP880oQmhWQ9CyN9ZuwblTqG6i76tgq80DIO9QPZvA/Dj30UXX1Nx9xPnrNomJqVVq5HNI/hqpTIcK547tv7bFwhKIhslhJkIrDhYTCifXKVhoJY4PmyDWkKG0MziGt+6F6WoFPU0IGB0OUzRmXdfhcY5iT3CuAidfQLV+X4IjrRctfZZ2zDLxcrE6STx5eU76o3izDHDlPxa9QJWXF3oEEr/CVOOPMpQWLzmJph3UHXhxQoC9N7HzY+GKlFm3XxFFQ7Z/40MTJdv2A+Cn3RI7ux3Jeg1KonDRkZB3vUnCZJRCLej9Iwgj7klZgamSkvT90/jykh1Ac+iaR+ptIuZvT1xQ6mrKf1sCmXSoR
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-4.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-4.exe /BhEQVzt /BNSOW='Sense' /Fsqwaryji='C:\Program Files (x86)\Sense\48292.xpi' /HZbtpM=48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /RppKetCFK=1.34.4.10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /cWsUxgAdy=300 /iAKXh=143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com /XKRpiT=0.94 /LAuXjYKUK=a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292 /yZRbmwvPB=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /48292.rdf /ZkXTo='Sense' /bJmfDhS='.' /cuvEJFfx='Object Browser' /KnGsmi=ff /YylzXDJkE /PGivmcuzh /zsilm /comtgSxKp='http://update.clientdemostack.com/ff_ag ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-5.job - C:\Program Files (x86)\Sense\f3c825f8-dc21-4793-9f24-12a483c004ae-5.exe /rawdata=Uq1i5XISAqEgEotbC74hOeC/iDwm/4pHNlfyH18j3I0kz8af2t7h77z8gu7XITVD/g7FqpbyLGSByVSax/c3rtC86lxKel+S9bo07XPWpsvkCU5dkjxKImaP08muPOVDbM3U629do50oc02cSpU2q6Xva11wx1KKk00t/yvAL42yI5SI6GA8HwCSIfMyAXNEVlVWClZNKy3d/9ggx/OkNZYHj3Y4HH7/wMUKkUpsAXhYnChD6YCXXMaOAGagvnxYGQhtzrjJIQlK5knuDs+Tjyvga4wpoI7aYrau9ivc5hTaytWKueyJW7cu9P/5s1FoQi6MAWYyX5KEfb7BbDXZqWF+9uvw94b30c0AN2OHuMxWbfu7beytqOhdty6mzYmYiMerQP1J4A/YbhhO7rCHj6hfAOODN2gjNyUrlAiSVCg9dhR83IKW4/LLXF2spJbavadZuur7MLeL75+YjeO5u2rjAEnJTy98A/eiYJTHK9EBfb8B27YZMmwC8/NmqjvhJN/JLWGCQSVbiJ2I8mUIeV4J+FqapNbRY7ZfilLF2pDOUY2uWfqZ6/u3QvxiRrTSzRBIdVAuL0epIEk+K+YazMVfj1wBYPX07uRtC4odmvyePzQUNq0Tqmc5gKpbQBiEYiuXUEfxrnMcBx4NimLiVBOtx5w1RwTaJWA+oFKNYXIeUD+kQhUjQQXHY+dojwozF/IRmMu+HGD0ry/yjwjRpg+aCj8U977lg4T9yKepQqFQK7PCUAW07Sn3BHdbP4N/3yfB6rA44JdwSrExiHpMGeEWXZNTqO3bD0iAQ1geLzQzWMLDnI36uFXF20GU8PB9vbG5b1zXtr6yloX97IK5RhcylBOvSUci6JjMac74GfymGFKD6Lxaul2wtJ7/eNXfE7FNneBcRnL6PI2sxFtSdKO+DG5+pBXNTvq47CZ1GujVHURFbum0z/f2sd17W2N5wwIUczyMdb84KP3BiysoRI5NC2R4g1B7yU/CWR+US8yZzCEWMXgEwFEkIm/2YaQ4
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-6.job - C:\Program Files (x86)\Sense\Sense-nova.exe /rawdata=HqlHwN04vaLFxdMxmlrMQmQPZdR2YzIA817vjRzlrdmk91kM7LdY+Sz8IjyohMZM1rukfgGDIy48S5yJ/J7Rk7NyGB3xp6dbxq9jkCihKceLLZvWQugMDASEP74IFZKA4XegK42GdE+jh/w2i6QhhOMv+MhDIZ3b8TpvuKPzK3Adgra1WmuFsQtqD9+gr3daojWnxxjtAXcvXGJ2/hkKBYivp5vclW0mrLbFmCgfLyUiibdKC2P/0ZadMngERO7ULLF/2VTo3lL+TrpU49GRCUmRpGE3xKHNK8igOqvX18/eNsf1HNb5ecu0qAy2NV/E3FH9XRsNh/DfF9pyTaRJVydhPEn+QUJDs0WYsfQoXSlHqj+LbfKdKJtVq1rV23IFt+wwmKpqmukhY2q6VwuVOQ2dIKKfsvSdtzab4E7noVm2g9+gmhsfUkGwfnj6i9hTrwmdF2eVLvsO0U6SsafMpNMpfdi1gwobUec8AAtli1SLvd44DS5G4ZUUVvchQR1ixHZAapZjJFNPf+vojJATY2bODZdFg3H2zNj49eFtSHK/20Tr+NsbptGnKbdk5Wic0fky8yVA/vZSYUT9gEWxxK9OJb3m6/77gpExEZpoAVGDjHq5/22WlnPN8Lt8I9zXMR9Oa4dUZyWztfhnpEM7xan8wkq7GpTKxMw3vaKa03GlqebQWmAV2mBSBSFIP3IKY/XS8kli0iS6nQegGldHAVY9J/aGnFG3UjhqvrumRK1xM3nbU9cHZBm42Q7OWdwkXhtj/Vt5jo6QEf9VmhgULALD2Vj/Ccpui+ZNn+5deg/nD8W00nWj9IsJAEJBt6P1bSJCCqXrpkGjwHDYPS59drF/D4lPxf6lRaDWhcXSbvxWcDC/0oqDJCXqQ3jO9gW3rrdHjavKK3VjHK690P/UUvVKOoLEYi9FnZZpMhvqYt+4L6uQhhETgciNboHb2sCu7SmXSaZsizlL8/E583kcfBMTJ6CHydSN/rHdra4arZbwFQN0ziK/WKTOGdffBTbBB4Po614daF/3yVi5Z+p80/Wgyoll7kZrzxVjllX9qrxApVTea84oFFrS+179dIGRf4ABi252vs9xVKBGlFsE6SOZG2PWTh4cC3JXKxJJ/DJjT/ZlzivNPlI91vqdy4JbmVS2Q0gb/1q8l1+a/NQMl0euYcDxutVlIoyp4eW8vDI=
C:\Windows\tasks\f3c825f8-dc21-4793-9f24-12a483c004ae-7.job - C:\Program Files (x86)\Sense\Sense-nova.exe /BNSOW='Sense' /HZbtpM==48292 /mUUnDGbr='000803' /wtLUN='0' /cDyCH='eyJkYXRhIjp7ImRhdGUiOiJFNTR6YWRrYyxhZjNhNzI5NC05MGViLTQyZjctOTVkYy0zYTBjZDk3OGUzM2MsIiwidW5xIjoiYWYzYTcyOTQtOTBlYi00MmY3LTk1ZGMtM2EwY2Q5NzhlMzNjIn19' /tiPGm=D43439F0E9A341B3B835042FFA07A138IE /ukjYoYsHH=dd10615d7450941667a9a60633b5f8f4 /tOvdulK=1_34_04_10 /RppKetCFK=1.34.4.10 /hsZosTq=1399218750 /czSXVWUv=http://stats.clientdemostack.com /GgxZoSR=http://errors.clientdemostack.com /giKxZUQ=http://js.clientdemostack.com /KnGsmi=ff /QJNTQTUj /GUjBoYkYU='nova' /comtgSxKp='http://update.clientdemostack.com/novar ... pdate.json' /ldwqMeEj='task' /SQYYGPDAa=''
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\hd37auco.default
prefs.js - "browser.startup.homepage" - "http://rts.dsrlte.com?affID=na"
prefs.js - "keyword.URL" - "https://search.yahoo.com/search?fr=gree ... =238417&p="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\hd37auco.default\extensions\
143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com
2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com
9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
staged
zzoomit@zoom.com
{54FBE89E-C878-46bb-A064-AB327EE26EBC}
{62DD0A97-FDD4-421b-94A5-D1A9434450C7}
{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
{CA8C84C6-3918-41b1-BE77-049B2BDD887C}
{DE1C78C1-2762-47f6-A1D9-1B7866FE7EB4}
C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\hd37auco.default\searchplugins\
dsrlte.xml
yahoo_ff.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Filip\AppData\Roaming\Browser Extensions\Coupons.dll [2014-10-20 610152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-06 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
Free Download Manager - C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2014-04-22 365056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-06 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"NPSStartup"= []
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe [2014-12-23 3224576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"=C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe [2012-01-02 102400]
"SpeedItupFree"=C:\Program Files (x86)\SpeedItup Free\speeditupfree.exe []
"SPDriver"=C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.exe [2014-12-23 3224576]
"Free Download Manager"=C:\Program Files (x86)\Free Download Manager\fdm.exe [2014-04-29 6980096]
"uTorrent"=C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe [2014-11-23 1385808]
"Browser Extensions"=C:\Users\Filip\AppData\Roaming\Browser Extensions\CouponsHelper.exe [2014-10-20 967528]
"Yahoo! Search"=C:\Users\Filip\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.18.6\dsrlte.exe [2015-01-08 634576]
"Search Protection"=C:\Users\Filip\AppData\Roaming\Search Protection\SP.EXE [2015-01-05 1127736]
"S60 PC Suite Tray"=C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PCSuite.exe [2008-12-06 699392]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_167_ActiveX.exe [2014-09-30 854704]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MyPC Backup.lnk - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-01-09 19:52:49 ----D---- C:\Program Files (x86)\trend micro
2015-01-09 19:52:43 ----D---- C:\rsit
2015-01-09 19:36:56 ----D---- C:\ProgramData\ESET
2014-12-25 08:58:38 ----D---- C:\Users\Filip\AppData\Roaming\ASP
2014-12-25 08:41:37 ----D---- C:\Users\Filip\AppData\Roaming\WebTest
2014-12-17 23:05:23 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2014-12-12 10:46:08 ----A---- C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-12 10:45:58 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-12-12 10:45:58 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-12-12 10:45:58 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-12-12 10:45:57 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-12-12 10:45:56 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-12-12 10:45:56 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-12-12 10:45:55 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-12 10:45:52 ----A---- C:\Windows\SysWOW64\jscript9.dll
======List of files/folders modified in the last 1 month======
2015-01-09 19:56:38 ----D---- C:\Windows\Temp
2015-01-09 19:56:26 ----D---- C:\Users\Filip\AppData\Roaming\uTorrent
2015-01-09 19:56:05 ----D---- C:\Program Files (x86)\YTDownloader
2015-01-09 19:52:49 ----RD---- C:\Program Files (x86)
2015-01-09 19:49:04 ----A---- C:\Windows\win.ini
2015-01-09 19:45:27 ----D---- C:\Program Files (x86)\RCP
2015-01-09 19:45:26 ----D---- C:\Windows\Tasks
2015-01-09 19:44:59 ----D---- C:\Program Files (x86)\iWebar
2015-01-09 19:44:46 ----D---- C:\Program Files (x86)\Object Browser
2015-01-09 19:44:40 ----D---- C:\ProgramData\ShopperPro
2015-01-09 19:44:30 ----D---- C:\Program Files (x86)\Yawtix
2015-01-09 19:44:26 ----D---- C:\Program Files (x86)\Sense
2015-01-09 19:41:00 ----SHD---- C:\Windows\Installer
2015-01-09 19:39:32 ----D---- C:\Windows\inf
2015-01-09 19:36:56 ----RD---- C:\Program Files
2015-01-09 19:36:56 ----HD---- C:\ProgramData
2015-01-09 19:36:43 ----D---- C:\Windows\System32
2015-01-09 19:34:57 ----SHD---- C:\System Volume Information
2015-01-09 19:22:55 ----D---- C:\ProgramData\dfed7653-07f4-44f2-abaa-a70c946c17c3
2015-01-09 19:09:34 ----D---- C:\Windows\SpeedItup Free
2015-01-09 19:09:31 ----D---- C:\Program Files (x86)\SpeedItup Free
2015-01-09 19:05:24 ----D---- C:\Users\Filip\AppData\Roaming\Free Download Manager
2015-01-09 19:02:25 ----D---- C:\Downloads
2015-01-09 18:57:51 ----D---- C:\ProgramData\Systweak
2015-01-09 18:53:32 ----D---- C:\Windows\Prefetch
2015-01-09 18:53:07 ----D---- C:\Program Files (x86)\MyPC Backup
2015-01-08 19:36:28 ----D---- C:\Windows\SysWOW64
2015-01-08 19:36:26 ----D---- C:\Windows\Software Display
2015-01-08 19:36:26 ----D---- C:\Program Files (x86)\Software Display
2015-01-08 19:02:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-25 08:41:35 ----D---- C:\Program Files (x86)\Mozilla Firefox.bak
2014-12-25 08:40:24 ----D---- C:\Users\Filip\AppData\Roaming\systweak
2014-12-24 13:04:48 ----D---- C:\Program Files (x86)\ShopperPro
2014-12-24 12:58:01 ----D---- C:\Users\Filip\AppData\Roaming\Search Protection
2014-12-18 03:00:44 ----D---- C:\Windows\winsxs
2014-12-13 04:02:47 ----D---- C:\Windows\rescache
2014-12-13 03:24:13 ----D---- C:\Windows\SysWOW64\en-US
2014-12-13 03:24:13 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-12-13 03:24:12 ----D---- C:\Windows\PolicyDefinitions
2014-12-13 03:24:12 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-13 03:08:54 ----D---- C:\ProgramData\Microsoft Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys []
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64;{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64; C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw64.sys []
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}w64;{16d667ee-6782-4b21-81df-8ded8ebc3868}w64; C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}w64.sys []
R1 {dc8e5bae-111b-483b-81ef-852b5b72d3ef}w64;{dc8e5bae-111b-483b-81ef-852b5b72d3ef}w64; C:\Windows\system32\drivers\{dc8e5bae-111b-483b-81ef-852b5b72d3ef}w64.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys []
R2 sbmntr;SBMNTR; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [2013-12-20 58728]
R2 SPDRIVER_1.38.0.1437;SPDRIVER_1.38.0.1437; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.38.0.1437\jsdrv.sys [2014-12-23 52584]
R3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys []
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys []
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys []
R3 SPBIUpdd;ShopperPro UpdateD; \??\C:\Program Files\Common Files\ShopperPro\spbiw.sys [2014-12-23 41856]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
S0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys []
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys []
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2012-01-02 16392]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 BackupStack;Computer Backup (MyPC Backup); C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2014-11-25 53320]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2014-09-30 1343920]
R2 MaintainerSvc5.70.609258;MaintainerSvc5.70.609258; C:\ProgramData\dfed7653-07f4-44f2-abaa-a70c946c17c3\maintainer.exe [2015-01-09 123672]
R2 SPBIUpd;ShopperPro Update; C:\Program Files\Common Files\ShopperPro\spbiu.exe [2014-12-23 2346880]
R2 Update Yawtix;Update Yawtix; C:\Program Files (x86)\Yawtix\updateYawtix.exe [2015-01-09 529176]
R2 Util Yawtix;Util Yawtix; C:\Program Files (x86)\Yawtix\bin\utilYawtix.exe [2015-01-09 529176]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-30 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21 107912]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-12-09 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
-----------------EOF-----------------
