Prosím o pomoc
Napsal: 17 úno 2015 20:30
Dobrý den,
mám problém s noťasem, seká se mi, je strašně pomalý a když jsem na internetu, vyskakují mi různá blikající okýnka. Nevím co s tím mám dělat. Děkuji
Logfile of random's system information tool 1.10 (written by random/random)
Run by Ludmila at 2015-02-17 20:16:50
Microsoft Windows 8.1 Pro
System drive C: has 188 GB (62%) free of 305 GB
Total RAM: 4063 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:16:52, on 17. 2. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 8\RealTimeProtector.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Ludmila.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpp ... 6LECLB67CX
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpp ... 6LECLB67CX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hpp ... 6LECLB67CX
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: unniSales - {2fc13d76-b3f3-448f-9c62-291791e40bfc} - C:\Program Files (x86)\unniSales\3acDGrqBtxPH2B.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Browser Extensions - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\Coupons.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll
O2 - BHO: unoisales - {36f49069-9c4c-442f-972b-c20c8a82b16a} - C:\Program Files (x86)\unoisales\LShme7KbyJ26TI.dll
O2 - BHO: EXstiRaCoupon - {683259eb-ea41-4ae7-99eb-c6cb4ad718a0} - C:\Program Files (x86)\EXstiRaCoupon\ii95AC2WAAOCWz.dll
O2 - BHO: DownSoave - {6cbc9859-091e-49a3-9f61-377a37e5d3fe} - C:\Program Files (x86)\DownSoave\z7KbA44dJtDXY8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: CoupExittensiion - {88c799ef-d052-48ea-886f-c1cf5db47e04} - C:\Program Files (x86)\CoupExittensiion\kWAGFRVoCEdaAV.dll
O2 - BHO: DigiCoUppono - {8c0ef73b-a419-4321-ae4c-05b31b2f095a} - C:\Program Files (x86)\DigiCoUppono\FFgnjDW1aFKQiH.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Advanced SystemCare Surfing Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPlugin_Protection.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: NeWSavErr - {ee39e7c8-3016-4236-8d7e-ec66f6fc2440} - C:\Program Files (x86)\NeWSavErr\5TwbDKCQsK92sq.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [ADSKAppManager] "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKCU\..\Run: [Search Protection] "C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.EXE" /autostart
O4 - HKCU\..\Run: [Browser Extensions] "C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\BEHelper.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTRAY.EXE"
O4 - Startup: Zoner Photo Studio 17 Pro Full with License Key.lnk = C:\ProgramData\{bb6ce422-9c71-9bbf-bb6c-ce4229c7908a}\Zoner Photo Studio 17 Pro Full with License Key.exe
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12806 bytes
======Listing Processes======
wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe"
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\libraryproc\libraryproc.dll",serv
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\libraryproc\libraryproc.dll",serv
"C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\terminusdefender\terminusdefender.dll",serv
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\terminusdefender\terminusdefender.dll",serv
dashost.exe {a082ef9e-96cf-46d0-8bfd9902c1e5ab7c}
"C:\Program Files (x86)\XTab\ProtectService.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
taskhostex.exe
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe" /Task
C:\Windows\Explorer.EXE
"C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.exe" /autostart
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /systemstart /autostart
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\RealTimeProtector.exe" /RunCurUs
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" -mode=scheduled
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe" /starttips
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3652.0.145432041\1582893279" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,39 --gpu-vendor-id=0x1002 --gpu-device-id=0x95c2 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.97.10.6 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.3.1687360796\7700191" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.4.497998299\2068613100" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.5.88253450\1013153905" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.6.1974413910\596643292" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.7.2079518127\1275371451" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.8.439552920\1246939970" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.11.353880850\110870221" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3652.12.1555101293\1892157486" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SHA1ToolbarUIJune2016/Warning/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.24.698124734\986836716" /prefetch:673131151
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 5ACFC7EF-07C5-D730-2A14-9C9E58950318 -Reinvoke
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe11_ Global\UsGthrCtrlFltPipeMssGthrPipe11 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SHA1ToolbarUIJune2016/Warning/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.25.1584005921\1091970015" /prefetch:673131151
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Ludmila\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\ASC8_SkipUac_Ludmila.job - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /SkipUac
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Uninstaller_SkipUac_Administrator.job - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
C:\Windows\tasks\Uninstaller_SkipUac_Ludmila.job - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-02-06 2471744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1c6c33e2-1352-4504-a07b-50f096a6295a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2fc13d76-b3f3-448f-9c62-291791e40bfc}]
unniSales - C:\Program Files (x86)\unniSales\3acDGrqBtxPH2B.x64.dll [2015-01-28 699904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-01-21 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\Coupons64.dll [2014-12-08 729552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36f49069-9c4c-442f-972b-c20c8a82b16a}]
unoisales - C:\Program Files (x86)\unoisales\LShme7KbyJ26TI.x64.dll [2015-01-28 699904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{683259eb-ea41-4ae7-99eb-c6cb4ad718a0}]
EXstiRaCoupon - C:\Program Files (x86)\EXstiRaCoupon\ii95AC2WAAOCWz.x64.dll [2015-02-05 708096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6cbc9859-091e-49a3-9f61-377a37e5d3fe}]
DownSoave - C:\Program Files (x86)\DownSoave\z7KbA44dJtDXY8.x64.dll [2015-02-06 708096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c799ef-d052-48ea-886f-c1cf5db47e04}]
CoupExittensiion - C:\Program Files (x86)\CoupExittensiion\kWAGFRVoCEdaAV.x64.dll [2015-02-05 708096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8c0ef73b-a419-4321-ae4c-05b31b2f095a}]
DigiCoUppono - C:\Program Files (x86)\DigiCoUppono\FFgnjDW1aFKQiH.x64.dll [2015-02-15 703488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-01-21 2334928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ee39e7c8-3016-4236-8d7e-ec66f6fc2440}]
NeWSavErr - C:\Program Files (x86)\NeWSavErr\5TwbDKCQsK92sq.x64.dll [2015-02-15 703488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f9199a96-0230-4c91-baf5-913a3b26973e}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2fc13d76-b3f3-448f-9c62-291791e40bfc}]
unniSales - C:\Program Files (x86)\unniSales\3acDGrqBtxPH2B.dll [2015-01-28 561664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-11-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\Coupons.dll [2014-12-08 608720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\XTab\SupTab.dll [2014-12-29 513680]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36f49069-9c4c-442f-972b-c20c8a82b16a}]
unoisales - C:\Program Files (x86)\unoisales\LShme7KbyJ26TI.dll [2015-01-28 561664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{683259eb-ea41-4ae7-99eb-c6cb4ad718a0}]
EXstiRaCoupon - C:\Program Files (x86)\EXstiRaCoupon\ii95AC2WAAOCWz.dll [2015-02-05 564736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6cbc9859-091e-49a3-9f61-377a37e5d3fe}]
DownSoave - C:\Program Files (x86)\DownSoave\z7KbA44dJtDXY8.dll [2015-02-06 564736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2015-01-05 462752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c799ef-d052-48ea-886f-c1cf5db47e04}]
CoupExittensiion - C:\Program Files (x86)\CoupExittensiion\kWAGFRVoCEdaAV.dll [2015-02-05 564736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8c0ef73b-a419-4321-ae4c-05b31b2f095a}]
DigiCoUppono - C:\Program Files (x86)\DigiCoUppono\FFgnjDW1aFKQiH.dll [2015-02-15 565248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Surfing Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPlugin_Protection.dll [2014-10-17 669984]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-01-21 1729744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2015-01-05 171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ee39e7c8-3016-4236-8d7e-ec66f6fc2440}]
NeWSavErr - C:\Program Files (x86)\NeWSavErr\5TwbDKCQsK92sq.dll [2015-02-15 565248]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-03-25 2726728]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19 557768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"=C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.EXE [2015-01-16 1128760]
"Browser Extensions"=C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\BEHelper.exe [2014-12-08 965584]
"Advanced SystemCare 8"=C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe [2015-01-20 2428704]
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTRAY.EXE [2014-12-19 458456]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"ADSKAppManager"=C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [2014-12-05 493960]
"CanonSolutionMenuEx"=C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-04-02 1185112]
"IObit Malware Fighter"=C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [2015-01-27 5768480]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2015-01-07 2694320]
C:\Users\Ludmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Zoner Photo Studio 17 Pro Full with License Key.lnk - C:\ProgramData\{bb6ce422-9c71-9bbf-bb6c-ce4229c7908a}\Zoner Photo Studio 17 Pro Full with License Key.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StartMenuService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\str]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-02-17 20:15:19 ----D---- C:\rsit
2015-02-17 20:15:19 ----D---- C:\Program Files\trend micro
2015-02-16 06:38:09 ----D---- C:\Program Files\Zoner
2015-02-15 13:47:24 ----D---- C:\Program Files (x86)\EExstRRaCuoupon
2015-02-15 13:45:14 ----D---- C:\Program Files (x86)\NeWSavErr
2015-02-15 13:44:54 ----D---- C:\Program Files (x86)\AllSaaver
2015-02-15 13:44:43 ----D---- C:\Program Files (x86)\One Number
2015-02-15 13:42:41 ----D---- C:\Program Files (x86)\DigiCoUppono
2015-02-15 13:42:26 ----D---- C:\Program Files (x86)\50CoUpons
2015-02-13 20:50:17 ----D---- C:\ProgramData\Extreme Blocker
2015-02-13 20:32:29 ----D---- C:\Program Files (x86)\TerminusDefender
2015-02-11 14:47:56 ----SHD---- C:\Config.Msi
2015-02-10 22:50:54 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-02-10 22:50:54 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-02-10 22:50:54 ----A---- C:\Windows\system32\schannel.dll
2015-02-10 22:50:54 ----A---- C:\Windows\system32\scesrv.dll
2015-02-10 22:50:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-10 22:50:53 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-02-10 22:50:53 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-02-10 22:50:53 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-02-10 22:50:53 ----A---- C:\Windows\system32\ntdll.dll
2015-02-10 22:50:50 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-10 22:50:49 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-02-10 22:50:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-10 22:50:49 ----A---- C:\Windows\system32\certcli.dll
2015-02-10 22:50:46 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-02-10 22:50:46 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-10 22:50:40 ----A---- C:\Windows\system32\mshtml.dll
2015-02-10 22:50:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-02-10 22:50:30 ----A---- C:\Windows\system32\ieframe.dll
2015-02-10 22:50:28 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-02-10 22:50:27 ----A---- C:\Windows\system32\jscript9.dll
2015-02-10 22:50:26 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-02-10 22:50:26 ----A---- C:\Windows\system32\iertutil.dll
2015-02-10 22:50:25 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-02-10 22:50:25 ----A---- C:\Windows\system32\jscript.dll
2015-02-10 22:50:24 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-02-10 22:50:24 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-02-10 22:50:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-02-10 22:50:24 ----A---- C:\Windows\system32\wininet.dll
2015-02-10 22:50:24 ----A---- C:\Windows\system32\vbscript.dll
2015-02-10 22:50:23 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-02-10 22:50:22 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-02-10 22:50:22 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-10 22:50:21 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-10 22:50:20 ----D---- C:\Program Files (x86)\LibraryProc
2015-02-10 22:50:20 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-10 22:50:19 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-02-10 22:50:18 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-10 22:50:18 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-10 22:50:16 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-02-10 22:50:16 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-02-10 22:50:16 ----A---- C:\Windows\system32\webcheck.dll
2015-02-10 22:50:15 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-02-10 22:50:15 ----A---- C:\Windows\system32\urlmon.dll
2015-02-10 22:50:15 ----A---- C:\Windows\system32\actxprxy.dll
2015-02-10 22:50:14 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-02-10 22:50:14 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-10 22:50:14 ----A---- C:\Windows\system32\inetcomm.dll
2015-02-10 22:50:12 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-02-10 22:50:12 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-02-10 22:50:12 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-10 22:49:30 ----A---- C:\Windows\system32\sppobjs.dll
2015-02-10 22:48:59 ----A---- C:\Windows\system32\generaltel.dll
2015-02-10 22:48:59 ----A---- C:\Windows\system32\appraiser.dll
2015-02-10 22:48:59 ----A---- C:\Windows\system32\aeinv.dll
2015-02-10 22:48:58 ----A---- C:\Windows\system32\invagent.dll
2015-02-10 22:48:58 ----A---- C:\Windows\system32\devinv.dll
2015-02-10 22:48:51 ----A---- C:\Windows\system32\aepdu.dll
2015-02-10 22:48:44 ----A---- C:\Windows\system32\win32k.sys
2015-02-06 21:13:38 ----D---- C:\Program Files\Realtek
2015-02-06 21:13:37 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-02-06 21:11:55 ----A---- C:\Windows\system32\YamahaAE.dll
2015-02-06 21:11:55 ----A---- C:\Windows\system32\WavesGUILib64.dll
2015-02-06 21:11:54 ----A---- C:\Windows\system32\tossaeapo64.dll
2015-02-06 21:11:54 ----A---- C:\Windows\system32\toseaeapo64.dll
2015-02-06 21:11:54 ----A---- C:\Windows\system32\tosasfapo64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tosade.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tepeqapo64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tadefxapo264.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tadefxapo.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSWOW64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSTSX64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSTSH64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSHP64.dll
2015-02-06 21:11:52 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRRPTR64.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRCOM64.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRCOM.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRAPO64.dll
2015-02-06 21:11:51 ----A---- C:\Windows\system32\sltech64.dll
2015-02-06 21:11:51 ----A---- C:\Windows\system32\slprp64.dll
2015-02-06 21:11:51 ----A---- C:\Windows\system32\slcnt64.dll
2015-02-06 21:11:50 ----A---- C:\Windows\system32\sl3apo64.dll
2015-02-06 21:11:50 ----A---- C:\Windows\system32\SFSS_APO.dll
2015-02-06 21:11:49 ----A---- C:\Windows\system32\SFNHK64.dll
2015-02-06 21:11:49 ----A---- C:\Windows\system32\SFCOM64.dll
2015-02-06 21:11:48 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2015-02-06 21:11:48 ----A---- C:\Windows\system32\SFAPO64.dll
2015-02-06 21:11:48 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2015-02-06 21:11:47 ----A---- C:\Windows\system32\RtPgEx64.dll
2015-02-06 21:11:45 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2015-02-06 21:11:43 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2015-02-06 21:11:42 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2015-02-06 21:11:42 ----A---- C:\Windows\system32\RtkCfg64.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RtkApi64.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEEP64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEEL64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEEG64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEED64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RtDataProc64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\RTCOM64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\RP3DHT64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\RP3DAA64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2015-02-06 21:11:38 ----A---- C:\Windows\system32\RltkAPO64.dll
2015-02-06 21:11:38 ----A---- C:\Windows\system32\RCoRes64.dat
2015-02-06 21:11:37 ----A---- C:\Windows\system32\RCoInstII64.dll
2015-02-06 21:11:36 ----A---- C:\Windows\system32\R4EEP64A.dll
2015-02-06 21:11:36 ----A---- C:\Windows\system32\R4EEL64A.dll
2015-02-06 21:11:36 ----A---- C:\Windows\system32\R4EEG64A.dll
2015-02-06 21:11:35 ----A---- C:\Windows\system32\R4EED64A.dll
2015-02-06 21:11:35 ----A---- C:\Windows\system32\R4EEA64A.dll
2015-02-06 21:11:35 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2015-02-06 21:11:34 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2015-02-06 21:11:34 ----A---- C:\Windows\system32\MISS_APO.dll
2015-02-06 21:11:32 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2015-02-06 21:11:30 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2015-02-06 21:11:30 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2015-02-06 21:11:30 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2015-02-06 21:11:29 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\KAAPORT64.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\FMAPO64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPP64A.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPO64A.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPD64A.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPA64.dll
2015-02-06 21:11:22 ----A---- C:\Windows\system32\CX64APO.dll
2015-02-06 21:11:22 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-02-06 21:11:22 ----A---- C:\Windows\system32\audioLibVc.dll
2015-02-06 21:11:21 ----A---- C:\Windows\system32\AERTAR64.dll
2015-02-06 21:11:21 ----A---- C:\Windows\system32\AERTAC64.dll
2015-02-06 21:11:21 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2015-02-06 21:10:26 ----A---- C:\Windows\system32\SmartDefragBootTime.exe
2015-02-06 21:10:24 ----A---- C:\Windows\system32\IObitSmartDefragExtension.dll
2015-02-06 21:10:13 ----A---- C:\Windows\system32\IObitSmartDefragExtension.dll20150206211024.dll
2015-02-06 21:07:38 ----D---- C:\ProgramData\a98cacfa00005776
2015-02-06 21:01:25 ----D---- C:\Program Files\Synaptics
2015-02-06 21:01:14 ----A---- C:\Windows\system32\WdfCoInstaller01011.dll
2015-02-06 21:00:55 ----A---- C:\Windows\system32\drivers\Smb_driver_Intel.sys
2015-02-06 20:53:59 ----D---- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-02-06 18:07:59 ----D---- C:\Program Files (x86)\BeStSeaveFoarYou
2015-02-06 18:07:48 ----D---- C:\Program Files (x86)\DownSoave
2015-02-06 18:07:26 ----D---- C:\Program Files (x86)\Scroll Button
2015-02-06 17:20:08 ----D---- C:\Program Files (x86)\Remote Torrent Adder
2015-02-06 17:18:45 ----D---- C:\Program Files (x86)\DEAlExpResS
2015-02-06 17:17:20 ----D---- C:\ProgramData\nkbfdlbjlnhgchfeajggocjpkfnbghno
2015-02-05 20:01:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-02-05 19:01:36 ----D---- C:\Program Files (x86)\CoupExittensiion
2015-02-05 19:01:17 ----D---- C:\Program Files (x86)\EXstiRaCoupon
2015-02-04 23:20:44 ----D---- C:\Program Files (x86)\GReautSavE4U
2015-02-03 22:39:25 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2015-02-03 21:30:59 ----D---- C:\Program Files\Adobe
2015-02-03 21:23:44 ----D---- C:\Program Files\Common Files\Adobe
2015-02-03 19:01:19 ----D---- C:\output
2015-02-01 10:54:40 ----D---- C:\Users\Ludmila\AppData\Roaming\Skype
2015-02-01 10:54:00 ----RD---- C:\Program Files (x86)\Skype
2015-02-01 10:53:39 ----D---- C:\ProgramData\Skype
2015-02-01 04:38:11 ----D---- C:\Users\Ludmila\AppData\Roaming\IRender
2015-02-01 04:35:47 ----D---- C:\Users\Ludmila\AppData\Roaming\Render Plus Systems
2015-02-01 04:35:47 ----D---- C:\ProgramData\Render Plus Systems
2015-02-01 04:35:46 ----D---- C:\Users\Ludmila\AppData\Roaming\SunScape
2015-02-01 04:35:46 ----D---- C:\Users\Ludmila\AppData\Roaming\RPS
2015-02-01 04:31:15 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-02-01 04:30:13 ----D---- C:\Program Files (x86)\Render Plus Systems
2015-01-28 17:06:55 ----D---- C:\Users\Ludmila\AppData\Roaming\Zoner
2015-01-28 17:06:51 ----D---- C:\ProgramData\Zoner
2015-01-28 16:59:49 ----D---- C:\Program Files (x86)\unoisales
2015-01-28 16:59:33 ----D---- C:\ProgramData\jhlfkcpeaanbdfjnlpgknjcimdkjfpmh
2015-01-28 16:58:42 ----D---- C:\ProgramData\{bb6ce422-9c71-9bbf-bb6c-ce4229c7908a}
2015-01-28 16:56:59 ----D---- C:\Program Files (x86)\Voicify
2015-01-28 16:55:54 ----D---- C:\Program Files (x86)\unniSales
2015-01-28 16:55:26 ----D---- C:\ProgramData\12883306088122721519
2015-01-28 16:55:22 ----D---- C:\Program Files (x86)\unisaales
2015-01-28 16:54:37 ----D---- C:\ProgramData\bloofafkbjahbhdoikkecknijjmobeoj
2015-01-28 16:53:48 ----D---- C:\ProgramData\{ed35e8ae-d3a5-cde0-ed35-5e8aed3aa2bb}
2015-01-27 05:53:25 ----D---- C:\Users\Ludmila\AppData\Roaming\pdfforge
2015-01-27 05:53:21 ----A---- C:\Windows\system32\pdfcmon.dll
2015-01-27 05:53:19 ----D---- C:\Program Files\PDFCreator
2015-01-26 15:21:04 ----HD---- C:\ProgramData\CanonIJSolutionMenuEX
2015-01-26 15:20:59 ----HD---- C:\ProgramData\CanonIJEPPEX2
2015-01-26 15:20:59 ----HD---- C:\ProgramData\CanonEPP
2015-01-26 15:20:58 ----HD---- C:\ProgramData\CanonIJMyPrinter
2015-01-26 15:20:51 ----D---- C:\ProgramData\CanonIJPLM
2015-01-26 15:18:37 ----A---- C:\Windows\SYSWOW64\CNC280U.dll
2015-01-26 15:18:36 ----A---- C:\Windows\system32\CNC280I.dll
2015-01-26 15:18:36 ----A---- C:\Windows\system32\CNC280C.dll
2015-01-26 15:15:49 ----D---- C:\ProgramData\CanonIJMSetup
2015-01-26 15:14:24 ----D---- C:\Program Files\Common Files\CANON
2015-01-26 15:14:16 ----D---- C:\ProgramData\CanonIJWSpt
2015-01-26 15:12:15 ----D---- C:\Program Files\Canon
2015-01-26 15:11:16 ----HD---- C:\ProgramData\CanonBJ
2015-01-26 15:11:01 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2015-01-26 15:10:55 ----A---- C:\Windows\SYSWOW64\CNHMCA.dll
2015-01-26 15:10:55 ----A---- C:\Windows\SYSWOW64\CNC280L.dll
2015-01-26 15:10:55 ----A---- C:\Windows\system32\CNC280L.dll
2015-01-26 15:10:54 ----A---- C:\Windows\system32\CNHMCA6.dll
2015-01-26 15:10:34 ----A---- C:\Windows\system32\CNMLMAA.DLL
2015-01-26 15:10:28 ----A---- C:\Windows\system32\CNC280O.dll
2015-01-26 15:10:22 ----A---- C:\Windows\system32\CNMIUAA.DLL
2015-01-26 15:10:07 ----HD---- C:\Program Files\CanonBJ
2015-01-26 15:08:32 ----D---- C:\Program Files (x86)\Canon
======List of files/folders modified in the last 1 month======
2015-02-17 20:16:08 ----D---- C:\Windows\Prefetch
2015-02-17 20:15:19 ----RD---- C:\Program Files
2015-02-17 20:00:00 ----D---- C:\Windows\system32\sru
2015-02-17 19:51:09 ----D---- C:\Windows\system32\config
2015-02-17 19:47:37 ----D---- C:\Windows\Temp
2015-02-17 19:47:37 ----D---- C:\Windows\AppReadiness
2015-02-17 19:40:41 ----RD---- C:\Windows\System32
2015-02-17 19:40:41 ----D---- C:\Windows\Inf
2015-02-17 19:40:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-17 10:30:29 ----D---- C:\Windows\CbsTemp
2015-02-17 10:30:27 ----D---- C:\Windows\system32\catroot2
2015-02-17 10:30:21 ----D---- C:\Windows\WinSxS
2015-02-16 14:18:11 ----D---- C:\Windows\Microsoft.NET
2015-02-16 14:04:44 ----D---- C:\Windows\rescache
2015-02-16 14:02:47 ----D---- C:\Windows\debug
2015-02-16 13:51:53 ----D---- C:\Windows
2015-02-16 11:07:25 ----D---- C:\Windows\system32\Tasks
2015-02-16 11:07:24 ----D---- C:\Windows\Tasks
2015-02-16 11:07:08 ----D---- C:\Users\Ludmila\AppData\Roaming\ProductData
2015-02-16 10:55:27 ----D---- C:\Windows\SysWOW64
2015-02-16 10:55:26 ----D---- C:\Windows\system32\drivers
2015-02-15 22:48:50 ----RD---- C:\Windows\assembly
2015-02-15 15:52:01 ----SHD---- C:\System Volume Information
2015-02-15 14:18:14 ----D---- C:\Windows\SoftwareDistribution
2015-02-15 13:47:24 ----RD---- C:\Program Files (x86)
2015-02-15 13:31:51 ----HD---- C:\ProgramData
2015-02-15 13:27:10 ----D---- C:\Program Files (x86)\IObit
2015-02-15 13:26:30 ----SHD---- C:\Windows\Installer
2015-02-15 13:20:24 ----D---- C:\ProgramData\Microsoft Help
2015-02-13 21:15:25 ----D---- C:\Users\Ludmila\AppData\Roaming\IObit
2015-02-11 14:34:16 ----D---- C:\Windows\system32\MRT
2015-02-11 14:24:25 ----A---- C:\Windows\system32\MRT.exe
2015-02-11 14:21:42 ----A---- C:\Windows\win.ini
2015-02-11 14:16:02 ----SD---- C:\Windows\system32\CompatTel
2015-02-11 14:16:01 ----D---- C:\Windows\system32\appraiser
2015-02-11 13:19:26 ----HD---- C:\Program Files\WindowsApps
2015-02-11 04:46:32 ----D---- C:\Windows\system32\wdi
2015-02-10 22:13:04 ----D---- C:\ProgramData\ProductData
2015-02-07 01:03:23 ----D---- C:\Windows\system32\NDF
2015-02-06 21:53:26 ----D---- C:\Windows\system32\catroot
2015-02-06 21:13:28 ----D---- C:\Windows\system32\DriverStore
2015-02-06 20:53:47 ----D---- C:\Program Files (x86)\Common Files
2015-02-06 20:50:46 ----D---- C:\ProgramData\IObit
2015-02-03 23:35:02 ----D---- C:\Users\Ludmila\AppData\Roaming\Adobe
2015-02-03 22:09:42 ----D---- C:\Program Files (x86)\Adobe
2015-02-03 21:23:44 ----D---- C:\Program Files\Common Files
2015-02-03 21:22:47 ----D---- C:\ProgramData\Adobe
2015-02-03 20:32:44 ----D---- C:\ProgramData\Package Cache
2015-02-01 04:18:45 ----D---- C:\Users\Ludmila\AppData\Roaming\Abvent_Artlantis5
2015-02-01 03:56:28 ----D---- C:\Program Files\Artlantis Studio 5
2015-01-27 05:41:56 ----D---- C:\Windows\system32\FxsTmp
2015-01-26 15:16:50 ----RSD---- C:\Windows\Media
2015-01-26 15:16:47 ----D---- C:\Windows\twain_32
2015-01-22 00:36:15 ----RD---- C:\Windows\ToastData
2015-01-22 00:36:09 ----D---- C:\Windows\SYSWOW64\setup
2015-01-22 00:36:09 ----D---- C:\Windows\system32\setup
2015-01-22 00:36:09 ----D---- C:\Windows\system32\en-US
2015-01-22 00:36:09 ----D---- C:\Windows\system32\cs-CZ
2015-01-22 00:36:08 ----D---- C:\Windows\apppatch
2015-01-22 00:36:02 ----RD---- C:\Windows\ImmersiveControlPanel
2015-01-22 00:36:01 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 Wof;Windows Overlay File System Filter Driver; C:\Windows\system32\drivers\Wof.sys [2014-03-13 157016]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2015-01-05 26528]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-06-19 11926016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-06-19 360448]
R3 FileMonitor;FileMonitor; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2014-11-10 23048]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2015-02-06 4263128]
R3 NETwNs64;@netwns64.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2013-06-18 8604672]
R3 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2014-11-10 34848]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-02-06 31472]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2013-06-18 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2013-06-18 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2013-06-18 740864]
R3 UrlFilter;UrlFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2014-11-10 23016]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-01-17 212736]
S3 dg_ssudbus;@oem4.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 ssudmdm;@oem5.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2015-01-17 44544]
S3 WinDivert1.1;WinDivert1.1; \??\C:\Program Files\KMSpico\WinDivert.sys [2015-01-05 35376]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\Windows\System32\drivers\WinUsb.sys [2013-08-22 78848]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2014-12-05 599944]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AdvancedSystemCareService8;Advanced SystemCare Service 8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [2014-11-04 815392]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2014-02-07 31192]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 da3f04c5;TerminusDefender; C:\Windows\syswow64\rundll32.exe [2015-01-17 51200]
R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [2014-12-29 158864]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]
R2 IMFservice;IMF Service; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2015-01-27 344864]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2015-01-16 2724128]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2015-01-07 473088]
S2 163ac2d4;LibraryProc; C:\Windows\syswow64\rundll32.exe [2015-01-17 51200]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-05 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-01-17 38792]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2015-01-17 1357104]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-05 116648]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
-----------------EOF-----------------
mám problém s noťasem, seká se mi, je strašně pomalý a když jsem na internetu, vyskakují mi různá blikající okýnka. Nevím co s tím mám dělat. Děkuji
Logfile of random's system information tool 1.10 (written by random/random)
Run by Ludmila at 2015-02-17 20:16:50
Microsoft Windows 8.1 Pro
System drive C: has 188 GB (62%) free of 305 GB
Total RAM: 4063 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:16:52, on 17. 2. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 8\RealTimeProtector.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Ludmila.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpp ... 6LECLB67CX
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpp ... 6LECLB67CX
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hpp ... 6LECLB67CX
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: unniSales - {2fc13d76-b3f3-448f-9c62-291791e40bfc} - C:\Program Files (x86)\unniSales\3acDGrqBtxPH2B.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Browser Extensions - {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\Coupons.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll
O2 - BHO: unoisales - {36f49069-9c4c-442f-972b-c20c8a82b16a} - C:\Program Files (x86)\unoisales\LShme7KbyJ26TI.dll
O2 - BHO: EXstiRaCoupon - {683259eb-ea41-4ae7-99eb-c6cb4ad718a0} - C:\Program Files (x86)\EXstiRaCoupon\ii95AC2WAAOCWz.dll
O2 - BHO: DownSoave - {6cbc9859-091e-49a3-9f61-377a37e5d3fe} - C:\Program Files (x86)\DownSoave\z7KbA44dJtDXY8.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: CoupExittensiion - {88c799ef-d052-48ea-886f-c1cf5db47e04} - C:\Program Files (x86)\CoupExittensiion\kWAGFRVoCEdaAV.dll
O2 - BHO: DigiCoUppono - {8c0ef73b-a419-4321-ae4c-05b31b2f095a} - C:\Program Files (x86)\DigiCoUppono\FFgnjDW1aFKQiH.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Advanced SystemCare Surfing Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPlugin_Protection.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: NeWSavErr - {ee39e7c8-3016-4236-8d7e-ec66f6fc2440} - C:\Program Files (x86)\NeWSavErr\5TwbDKCQsK92sq.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [ADSKAppManager] "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKCU\..\Run: [Search Protection] "C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.EXE" /autostart
O4 - HKCU\..\Run: [Browser Extensions] "C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\BEHelper.exe"
O4 - HKCU\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTRAY.EXE"
O4 - Startup: Zoner Photo Studio 17 Pro Full with License Key.lnk = C:\ProgramData\{bb6ce422-9c71-9bbf-bb6c-ce4229c7908a}\Zoner Photo Studio 17 Pro Full with License Key.exe
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Autodesk Application Manager Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12806 bytes
======Listing Processes======
wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe"
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\libraryproc\libraryproc.dll",serv
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\libraryproc\libraryproc.dll",serv
"C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\terminusdefender\terminusdefender.dll",serv
"C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\terminusdefender\terminusdefender.dll",serv
dashost.exe {a082ef9e-96cf-46d0-8bfd9902c1e5ab7c}
"C:\Program Files (x86)\XTab\ProtectService.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\WinLogon.exe -SpecialSession
-hiberboot
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
taskhostex.exe
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe" /Task
C:\Windows\Explorer.EXE
"C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.exe" /autostart
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /systemstart /autostart
"C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 8\RealTimeProtector.exe" /RunCurUs
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" -mode=scheduled
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe" /starttips
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3652.0.145432041\1582893279" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,18,39 --gpu-vendor-id=0x1002 --gpu-device-id=0x95c2 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.97.10.6 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.3.1687360796\7700191" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.4.497998299\2068613100" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.5.88253450\1013153905" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.6.1974413910\596643292" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.7.2079518127\1275371451" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.8.439552920\1246939970" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.11.353880850\110870221" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3652.12.1555101293\1892157486" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SHA1ToolbarUIJune2016/Warning/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.24.698124734\986836716" /prefetch:673131151
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 5ACFC7EF-07C5-D730-2A14-9C9E58950318 -Reinvoke
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe11_ Global\UsGthrCtrlFltPipeMssGthrPipe11 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Bootstrap/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Dev_NonMonotonicity_Experiment/PasswordGeneration/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledNewRTO/RememberCertificateErrorDecisions/Default/SHA1ToolbarUIJune2016/Warning/SPDY/Control/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_15/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3652.25.1584005921\1091970015" /prefetch:673131151
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Ludmila\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\ASC8_SkipUac_Ludmila.job - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /SkipUac
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Uninstaller_SkipUac_Administrator.job - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
C:\Windows\tasks\Uninstaller_SkipUac_Ludmila.job - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-02-06 2471744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1c6c33e2-1352-4504-a07b-50f096a6295a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2fc13d76-b3f3-448f-9c62-291791e40bfc}]
unniSales - C:\Program Files (x86)\unniSales\3acDGrqBtxPH2B.x64.dll [2015-01-28 699904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-01-21 218776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\Coupons64.dll [2014-12-08 729552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36f49069-9c4c-442f-972b-c20c8a82b16a}]
unoisales - C:\Program Files (x86)\unoisales\LShme7KbyJ26TI.x64.dll [2015-01-28 699904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{683259eb-ea41-4ae7-99eb-c6cb4ad718a0}]
EXstiRaCoupon - C:\Program Files (x86)\EXstiRaCoupon\ii95AC2WAAOCWz.x64.dll [2015-02-05 708096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6cbc9859-091e-49a3-9f61-377a37e5d3fe}]
DownSoave - C:\Program Files (x86)\DownSoave\z7KbA44dJtDXY8.x64.dll [2015-02-06 708096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c799ef-d052-48ea-886f-c1cf5db47e04}]
CoupExittensiion - C:\Program Files (x86)\CoupExittensiion\kWAGFRVoCEdaAV.x64.dll [2015-02-05 708096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8c0ef73b-a419-4321-ae4c-05b31b2f095a}]
DigiCoUppono - C:\Program Files (x86)\DigiCoUppono\FFgnjDW1aFKQiH.x64.dll [2015-02-15 703488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-01-21 2334928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ee39e7c8-3016-4236-8d7e-ec66f6fc2440}]
NeWSavErr - C:\Program Files (x86)\NeWSavErr\5TwbDKCQsK92sq.x64.dll [2015-02-15 703488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f9199a96-0230-4c91-baf5-913a3b26973e}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2fc13d76-b3f3-448f-9c62-291791e40bfc}]
unniSales - C:\Program Files (x86)\unniSales\3acDGrqBtxPH2B.dll [2015-01-28 561664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-11-12 153248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
Browser Extensions - C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\Coupons.dll [2014-12-08 608720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\XTab\SupTab.dll [2014-12-29 513680]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36f49069-9c4c-442f-972b-c20c8a82b16a}]
unoisales - C:\Program Files (x86)\unoisales\LShme7KbyJ26TI.dll [2015-01-28 561664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{683259eb-ea41-4ae7-99eb-c6cb4ad718a0}]
EXstiRaCoupon - C:\Program Files (x86)\EXstiRaCoupon\ii95AC2WAAOCWz.dll [2015-02-05 564736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6cbc9859-091e-49a3-9f61-377a37e5d3fe}]
DownSoave - C:\Program Files (x86)\DownSoave\z7KbA44dJtDXY8.dll [2015-02-06 564736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2015-01-05 462752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c799ef-d052-48ea-886f-c1cf5db47e04}]
CoupExittensiion - C:\Program Files (x86)\CoupExittensiion\kWAGFRVoCEdaAV.dll [2015-02-05 564736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8c0ef73b-a419-4321-ae4c-05b31b2f095a}]
DigiCoUppono - C:\Program Files (x86)\DigiCoUppono\FFgnjDW1aFKQiH.dll [2015-02-15 565248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Surfing Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPlugin_Protection.dll [2014-10-17 669984]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-01-21 1729744]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2015-01-05 171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ee39e7c8-3016-4236-8d7e-ec66f6fc2440}]
NeWSavErr - C:\Program Files (x86)\NeWSavErr\5TwbDKCQsK92sq.dll [2015-02-15 565248]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-03-25 2726728]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19 557768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"=C:\Users\Ludmila\AppData\Roaming\Search Protection\SP.EXE [2015-01-16 1128760]
"Browser Extensions"=C:\Users\Ludmila\AppData\Roaming\BrowserExtensions\BEHelper.exe [2014-12-08 965584]
"Advanced SystemCare 8"=C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe [2015-01-20 2428704]
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTRAY.EXE [2014-12-19 458456]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"ADSKAppManager"=C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [2014-12-05 493960]
"CanonSolutionMenuEx"=C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-04-02 1185112]
"IObit Malware Fighter"=C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [2015-01-27 5768480]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2015-01-07 2694320]
C:\Users\Ludmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Zoner Photo Studio 17 Pro Full with License Key.lnk - C:\ProgramData\{bb6ce422-9c71-9bbf-bb6c-ce4229c7908a}\Zoner Photo Studio 17 Pro Full with License Key.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StartMenuService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\str]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-02-17 20:15:19 ----D---- C:\rsit
2015-02-17 20:15:19 ----D---- C:\Program Files\trend micro
2015-02-16 06:38:09 ----D---- C:\Program Files\Zoner
2015-02-15 13:47:24 ----D---- C:\Program Files (x86)\EExstRRaCuoupon
2015-02-15 13:45:14 ----D---- C:\Program Files (x86)\NeWSavErr
2015-02-15 13:44:54 ----D---- C:\Program Files (x86)\AllSaaver
2015-02-15 13:44:43 ----D---- C:\Program Files (x86)\One Number
2015-02-15 13:42:41 ----D---- C:\Program Files (x86)\DigiCoUppono
2015-02-15 13:42:26 ----D---- C:\Program Files (x86)\50CoUpons
2015-02-13 20:50:17 ----D---- C:\ProgramData\Extreme Blocker
2015-02-13 20:32:29 ----D---- C:\Program Files (x86)\TerminusDefender
2015-02-11 14:47:56 ----SHD---- C:\Config.Msi
2015-02-10 22:50:54 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-02-10 22:50:54 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-02-10 22:50:54 ----A---- C:\Windows\system32\schannel.dll
2015-02-10 22:50:54 ----A---- C:\Windows\system32\scesrv.dll
2015-02-10 22:50:54 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-10 22:50:53 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-02-10 22:50:53 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-02-10 22:50:53 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-02-10 22:50:53 ----A---- C:\Windows\system32\ntdll.dll
2015-02-10 22:50:50 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-10 22:50:49 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-02-10 22:50:49 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-10 22:50:49 ----A---- C:\Windows\system32\certcli.dll
2015-02-10 22:50:46 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-02-10 22:50:46 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-10 22:50:40 ----A---- C:\Windows\system32\mshtml.dll
2015-02-10 22:50:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-02-10 22:50:30 ----A---- C:\Windows\system32\ieframe.dll
2015-02-10 22:50:28 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-02-10 22:50:27 ----A---- C:\Windows\system32\jscript9.dll
2015-02-10 22:50:26 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-02-10 22:50:26 ----A---- C:\Windows\system32\iertutil.dll
2015-02-10 22:50:25 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-02-10 22:50:25 ----A---- C:\Windows\system32\jscript.dll
2015-02-10 22:50:24 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-02-10 22:50:24 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-02-10 22:50:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-02-10 22:50:24 ----A---- C:\Windows\system32\wininet.dll
2015-02-10 22:50:24 ----A---- C:\Windows\system32\vbscript.dll
2015-02-10 22:50:23 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-02-10 22:50:22 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-02-10 22:50:22 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-10 22:50:21 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-10 22:50:20 ----D---- C:\Program Files (x86)\LibraryProc
2015-02-10 22:50:20 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-10 22:50:19 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-02-10 22:50:18 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-10 22:50:18 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-10 22:50:16 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-02-10 22:50:16 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-02-10 22:50:16 ----A---- C:\Windows\system32\webcheck.dll
2015-02-10 22:50:15 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-02-10 22:50:15 ----A---- C:\Windows\system32\urlmon.dll
2015-02-10 22:50:15 ----A---- C:\Windows\system32\actxprxy.dll
2015-02-10 22:50:14 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-02-10 22:50:14 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-10 22:50:14 ----A---- C:\Windows\system32\inetcomm.dll
2015-02-10 22:50:12 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-02-10 22:50:12 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-02-10 22:50:12 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-10 22:49:30 ----A---- C:\Windows\system32\sppobjs.dll
2015-02-10 22:48:59 ----A---- C:\Windows\system32\generaltel.dll
2015-02-10 22:48:59 ----A---- C:\Windows\system32\appraiser.dll
2015-02-10 22:48:59 ----A---- C:\Windows\system32\aeinv.dll
2015-02-10 22:48:58 ----A---- C:\Windows\system32\invagent.dll
2015-02-10 22:48:58 ----A---- C:\Windows\system32\devinv.dll
2015-02-10 22:48:51 ----A---- C:\Windows\system32\aepdu.dll
2015-02-10 22:48:44 ----A---- C:\Windows\system32\win32k.sys
2015-02-06 21:13:38 ----D---- C:\Program Files\Realtek
2015-02-06 21:13:37 ----D---- C:\Windows\SYSWOW64\RTCOM
2015-02-06 21:11:55 ----A---- C:\Windows\system32\YamahaAE.dll
2015-02-06 21:11:55 ----A---- C:\Windows\system32\WavesGUILib64.dll
2015-02-06 21:11:54 ----A---- C:\Windows\system32\tossaeapo64.dll
2015-02-06 21:11:54 ----A---- C:\Windows\system32\toseaeapo64.dll
2015-02-06 21:11:54 ----A---- C:\Windows\system32\tosasfapo64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tosade.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tepeqapo64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tadefxapo264.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\tadefxapo.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSWOW64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSTSX64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSTSH64.dll
2015-02-06 21:11:53 ----A---- C:\Windows\system32\SRSHP64.dll
2015-02-06 21:11:52 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRRPTR64.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRCOM64.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRCOM.dll
2015-02-06 21:11:52 ----A---- C:\Windows\system32\SRAPO64.dll
2015-02-06 21:11:51 ----A---- C:\Windows\system32\sltech64.dll
2015-02-06 21:11:51 ----A---- C:\Windows\system32\slprp64.dll
2015-02-06 21:11:51 ----A---- C:\Windows\system32\slcnt64.dll
2015-02-06 21:11:50 ----A---- C:\Windows\system32\sl3apo64.dll
2015-02-06 21:11:50 ----A---- C:\Windows\system32\SFSS_APO.dll
2015-02-06 21:11:49 ----A---- C:\Windows\system32\SFNHK64.dll
2015-02-06 21:11:49 ----A---- C:\Windows\system32\SFCOM64.dll
2015-02-06 21:11:48 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2015-02-06 21:11:48 ----A---- C:\Windows\system32\SFAPO64.dll
2015-02-06 21:11:48 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2015-02-06 21:11:47 ----A---- C:\Windows\system32\RtPgEx64.dll
2015-02-06 21:11:45 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2015-02-06 21:11:43 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2015-02-06 21:11:42 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2015-02-06 21:11:42 ----A---- C:\Windows\system32\RtkCfg64.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RtkApi64.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEEP64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEEL64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEEG64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RTEED64A.dll
2015-02-06 21:11:41 ----A---- C:\Windows\system32\RtDataProc64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\RTCOM64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\RP3DHT64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\RP3DAA64.dll
2015-02-06 21:11:39 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2015-02-06 21:11:38 ----A---- C:\Windows\system32\RltkAPO64.dll
2015-02-06 21:11:38 ----A---- C:\Windows\system32\RCoRes64.dat
2015-02-06 21:11:37 ----A---- C:\Windows\system32\RCoInstII64.dll
2015-02-06 21:11:36 ----A---- C:\Windows\system32\R4EEP64A.dll
2015-02-06 21:11:36 ----A---- C:\Windows\system32\R4EEL64A.dll
2015-02-06 21:11:36 ----A---- C:\Windows\system32\R4EEG64A.dll
2015-02-06 21:11:35 ----A---- C:\Windows\system32\R4EED64A.dll
2015-02-06 21:11:35 ----A---- C:\Windows\system32\R4EEA64A.dll
2015-02-06 21:11:35 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2015-02-06 21:11:34 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2015-02-06 21:11:34 ----A---- C:\Windows\system32\MISS_APO.dll
2015-02-06 21:11:32 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2015-02-06 21:11:30 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2015-02-06 21:11:30 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2015-02-06 21:11:30 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2015-02-06 21:11:29 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2015-02-06 21:11:28 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\KAAPORT64.dll
2015-02-06 21:11:27 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\FMAPO64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2015-02-06 21:11:25 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2015-02-06 21:11:24 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPP64A.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPO64A.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPD64A.dll
2015-02-06 21:11:23 ----A---- C:\Windows\system32\DDPA64.dll
2015-02-06 21:11:22 ----A---- C:\Windows\system32\CX64APO.dll
2015-02-06 21:11:22 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-02-06 21:11:22 ----A---- C:\Windows\system32\audioLibVc.dll
2015-02-06 21:11:21 ----A---- C:\Windows\system32\AERTAR64.dll
2015-02-06 21:11:21 ----A---- C:\Windows\system32\AERTAC64.dll
2015-02-06 21:11:21 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2015-02-06 21:10:26 ----A---- C:\Windows\system32\SmartDefragBootTime.exe
2015-02-06 21:10:24 ----A---- C:\Windows\system32\IObitSmartDefragExtension.dll
2015-02-06 21:10:13 ----A---- C:\Windows\system32\IObitSmartDefragExtension.dll20150206211024.dll
2015-02-06 21:07:38 ----D---- C:\ProgramData\a98cacfa00005776
2015-02-06 21:01:25 ----D---- C:\Program Files\Synaptics
2015-02-06 21:01:14 ----A---- C:\Windows\system32\WdfCoInstaller01011.dll
2015-02-06 21:00:55 ----A---- C:\Windows\system32\drivers\Smb_driver_Intel.sys
2015-02-06 20:53:59 ----D---- C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-02-06 18:07:59 ----D---- C:\Program Files (x86)\BeStSeaveFoarYou
2015-02-06 18:07:48 ----D---- C:\Program Files (x86)\DownSoave
2015-02-06 18:07:26 ----D---- C:\Program Files (x86)\Scroll Button
2015-02-06 17:20:08 ----D---- C:\Program Files (x86)\Remote Torrent Adder
2015-02-06 17:18:45 ----D---- C:\Program Files (x86)\DEAlExpResS
2015-02-06 17:17:20 ----D---- C:\ProgramData\nkbfdlbjlnhgchfeajggocjpkfnbghno
2015-02-05 20:01:19 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-02-05 19:01:36 ----D---- C:\Program Files (x86)\CoupExittensiion
2015-02-05 19:01:17 ----D---- C:\Program Files (x86)\EXstiRaCoupon
2015-02-04 23:20:44 ----D---- C:\Program Files (x86)\GReautSavE4U
2015-02-03 22:39:25 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2015-02-03 21:30:59 ----D---- C:\Program Files\Adobe
2015-02-03 21:23:44 ----D---- C:\Program Files\Common Files\Adobe
2015-02-03 19:01:19 ----D---- C:\output
2015-02-01 10:54:40 ----D---- C:\Users\Ludmila\AppData\Roaming\Skype
2015-02-01 10:54:00 ----RD---- C:\Program Files (x86)\Skype
2015-02-01 10:53:39 ----D---- C:\ProgramData\Skype
2015-02-01 04:38:11 ----D---- C:\Users\Ludmila\AppData\Roaming\IRender
2015-02-01 04:35:47 ----D---- C:\Users\Ludmila\AppData\Roaming\Render Plus Systems
2015-02-01 04:35:47 ----D---- C:\ProgramData\Render Plus Systems
2015-02-01 04:35:46 ----D---- C:\Users\Ludmila\AppData\Roaming\SunScape
2015-02-01 04:35:46 ----D---- C:\Users\Ludmila\AppData\Roaming\RPS
2015-02-01 04:31:15 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-02-01 04:30:13 ----D---- C:\Program Files (x86)\Render Plus Systems
2015-01-28 17:06:55 ----D---- C:\Users\Ludmila\AppData\Roaming\Zoner
2015-01-28 17:06:51 ----D---- C:\ProgramData\Zoner
2015-01-28 16:59:49 ----D---- C:\Program Files (x86)\unoisales
2015-01-28 16:59:33 ----D---- C:\ProgramData\jhlfkcpeaanbdfjnlpgknjcimdkjfpmh
2015-01-28 16:58:42 ----D---- C:\ProgramData\{bb6ce422-9c71-9bbf-bb6c-ce4229c7908a}
2015-01-28 16:56:59 ----D---- C:\Program Files (x86)\Voicify
2015-01-28 16:55:54 ----D---- C:\Program Files (x86)\unniSales
2015-01-28 16:55:26 ----D---- C:\ProgramData\12883306088122721519
2015-01-28 16:55:22 ----D---- C:\Program Files (x86)\unisaales
2015-01-28 16:54:37 ----D---- C:\ProgramData\bloofafkbjahbhdoikkecknijjmobeoj
2015-01-28 16:53:48 ----D---- C:\ProgramData\{ed35e8ae-d3a5-cde0-ed35-5e8aed3aa2bb}
2015-01-27 05:53:25 ----D---- C:\Users\Ludmila\AppData\Roaming\pdfforge
2015-01-27 05:53:21 ----A---- C:\Windows\system32\pdfcmon.dll
2015-01-27 05:53:19 ----D---- C:\Program Files\PDFCreator
2015-01-26 15:21:04 ----HD---- C:\ProgramData\CanonIJSolutionMenuEX
2015-01-26 15:20:59 ----HD---- C:\ProgramData\CanonIJEPPEX2
2015-01-26 15:20:59 ----HD---- C:\ProgramData\CanonEPP
2015-01-26 15:20:58 ----HD---- C:\ProgramData\CanonIJMyPrinter
2015-01-26 15:20:51 ----D---- C:\ProgramData\CanonIJPLM
2015-01-26 15:18:37 ----A---- C:\Windows\SYSWOW64\CNC280U.dll
2015-01-26 15:18:36 ----A---- C:\Windows\system32\CNC280I.dll
2015-01-26 15:18:36 ----A---- C:\Windows\system32\CNC280C.dll
2015-01-26 15:15:49 ----D---- C:\ProgramData\CanonIJMSetup
2015-01-26 15:14:24 ----D---- C:\Program Files\Common Files\CANON
2015-01-26 15:14:16 ----D---- C:\ProgramData\CanonIJWSpt
2015-01-26 15:12:15 ----D---- C:\Program Files\Canon
2015-01-26 15:11:16 ----HD---- C:\ProgramData\CanonBJ
2015-01-26 15:11:01 ----HD---- C:\Windows\system32\CanonIJ Uninstaller Information
2015-01-26 15:10:55 ----A---- C:\Windows\SYSWOW64\CNHMCA.dll
2015-01-26 15:10:55 ----A---- C:\Windows\SYSWOW64\CNC280L.dll
2015-01-26 15:10:55 ----A---- C:\Windows\system32\CNC280L.dll
2015-01-26 15:10:54 ----A---- C:\Windows\system32\CNHMCA6.dll
2015-01-26 15:10:34 ----A---- C:\Windows\system32\CNMLMAA.DLL
2015-01-26 15:10:28 ----A---- C:\Windows\system32\CNC280O.dll
2015-01-26 15:10:22 ----A---- C:\Windows\system32\CNMIUAA.DLL
2015-01-26 15:10:07 ----HD---- C:\Program Files\CanonBJ
2015-01-26 15:08:32 ----D---- C:\Program Files (x86)\Canon
======List of files/folders modified in the last 1 month======
2015-02-17 20:16:08 ----D---- C:\Windows\Prefetch
2015-02-17 20:15:19 ----RD---- C:\Program Files
2015-02-17 20:00:00 ----D---- C:\Windows\system32\sru
2015-02-17 19:51:09 ----D---- C:\Windows\system32\config
2015-02-17 19:47:37 ----D---- C:\Windows\Temp
2015-02-17 19:47:37 ----D---- C:\Windows\AppReadiness
2015-02-17 19:40:41 ----RD---- C:\Windows\System32
2015-02-17 19:40:41 ----D---- C:\Windows\Inf
2015-02-17 19:40:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-17 10:30:29 ----D---- C:\Windows\CbsTemp
2015-02-17 10:30:27 ----D---- C:\Windows\system32\catroot2
2015-02-17 10:30:21 ----D---- C:\Windows\WinSxS
2015-02-16 14:18:11 ----D---- C:\Windows\Microsoft.NET
2015-02-16 14:04:44 ----D---- C:\Windows\rescache
2015-02-16 14:02:47 ----D---- C:\Windows\debug
2015-02-16 13:51:53 ----D---- C:\Windows
2015-02-16 11:07:25 ----D---- C:\Windows\system32\Tasks
2015-02-16 11:07:24 ----D---- C:\Windows\Tasks
2015-02-16 11:07:08 ----D---- C:\Users\Ludmila\AppData\Roaming\ProductData
2015-02-16 10:55:27 ----D---- C:\Windows\SysWOW64
2015-02-16 10:55:26 ----D---- C:\Windows\system32\drivers
2015-02-15 22:48:50 ----RD---- C:\Windows\assembly
2015-02-15 15:52:01 ----SHD---- C:\System Volume Information
2015-02-15 14:18:14 ----D---- C:\Windows\SoftwareDistribution
2015-02-15 13:47:24 ----RD---- C:\Program Files (x86)
2015-02-15 13:31:51 ----HD---- C:\ProgramData
2015-02-15 13:27:10 ----D---- C:\Program Files (x86)\IObit
2015-02-15 13:26:30 ----SHD---- C:\Windows\Installer
2015-02-15 13:20:24 ----D---- C:\ProgramData\Microsoft Help
2015-02-13 21:15:25 ----D---- C:\Users\Ludmila\AppData\Roaming\IObit
2015-02-11 14:34:16 ----D---- C:\Windows\system32\MRT
2015-02-11 14:24:25 ----A---- C:\Windows\system32\MRT.exe
2015-02-11 14:21:42 ----A---- C:\Windows\win.ini
2015-02-11 14:16:02 ----SD---- C:\Windows\system32\CompatTel
2015-02-11 14:16:01 ----D---- C:\Windows\system32\appraiser
2015-02-11 13:19:26 ----HD---- C:\Program Files\WindowsApps
2015-02-11 04:46:32 ----D---- C:\Windows\system32\wdi
2015-02-10 22:13:04 ----D---- C:\ProgramData\ProductData
2015-02-07 01:03:23 ----D---- C:\Windows\system32\NDF
2015-02-06 21:53:26 ----D---- C:\Windows\system32\catroot
2015-02-06 21:13:28 ----D---- C:\Windows\system32\DriverStore
2015-02-06 20:53:47 ----D---- C:\Program Files (x86)\Common Files
2015-02-06 20:50:46 ----D---- C:\ProgramData\IObit
2015-02-03 23:35:02 ----D---- C:\Users\Ludmila\AppData\Roaming\Adobe
2015-02-03 22:09:42 ----D---- C:\Program Files (x86)\Adobe
2015-02-03 21:23:44 ----D---- C:\Program Files\Common Files
2015-02-03 21:22:47 ----D---- C:\ProgramData\Adobe
2015-02-03 20:32:44 ----D---- C:\ProgramData\Package Cache
2015-02-01 04:18:45 ----D---- C:\Users\Ludmila\AppData\Roaming\Abvent_Artlantis5
2015-02-01 03:56:28 ----D---- C:\Program Files\Artlantis Studio 5
2015-01-27 05:41:56 ----D---- C:\Windows\system32\FxsTmp
2015-01-26 15:16:50 ----RSD---- C:\Windows\Media
2015-01-26 15:16:47 ----D---- C:\Windows\twain_32
2015-01-22 00:36:15 ----RD---- C:\Windows\ToastData
2015-01-22 00:36:09 ----D---- C:\Windows\SYSWOW64\setup
2015-01-22 00:36:09 ----D---- C:\Windows\system32\setup
2015-01-22 00:36:09 ----D---- C:\Windows\system32\en-US
2015-01-22 00:36:09 ----D---- C:\Windows\system32\cs-CZ
2015-01-22 00:36:08 ----D---- C:\Windows\apppatch
2015-01-22 00:36:02 ----RD---- C:\Windows\ImmersiveControlPanel
2015-01-22 00:36:01 ----D---- C:\Windows\system32\wbem
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 Wof;Windows Overlay File System Filter Driver; C:\Windows\system32\drivers\Wof.sys [2014-03-13 157016]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [2015-01-05 26528]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-06-19 11926016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-06-19 360448]
R3 FileMonitor;FileMonitor; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2014-11-10 23048]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2015-02-06 4263128]
R3 NETwNs64;@netwns64.inf,___ %NIC_Service_DispName_WIN7_64%;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2013-06-18 8604672]
R3 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2014-11-10 34848]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2015-02-06 31472]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2013-06-18 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2013-06-18 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2013-06-18 740864]
R3 UrlFilter;UrlFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2014-11-10 23016]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-01-17 212736]
S3 dg_ssudbus;@oem4.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 ssudmdm;@oem5.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2015-01-17 44544]
S3 WinDivert1.1;WinDivert1.1; \??\C:\Program Files\KMSpico\WinDivert.sys [2015-01-05 35376]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\Windows\System32\drivers\WinUsb.sys [2013-08-22 78848]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdAppMgrSvc;Autodesk Application Manager Service; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [2014-12-05 599944]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AdvancedSystemCareService8;Advanced SystemCare Service 8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [2014-11-04 815392]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2014-02-07 31192]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 da3f04c5;TerminusDefender; C:\Windows\syswow64\rundll32.exe [2015-01-17 51200]
R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [2014-12-29 158864]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2010-04-05 116104]
R2 IMFservice;IMF Service; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2015-01-27 344864]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2015-01-16 2724128]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2015-01-07 473088]
S2 163ac2d4;LibraryProc; C:\Windows\syswow64\rundll32.exe [2015-01-17 51200]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-05 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-01-17 38792]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2015-01-17 1357104]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-05 116648]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
-----------------EOF-----------------