Stránka 1 z 2

Omniboxes

Napsal: 19 úno 2015 20:58
od koltmen
Zdravím,
po instalování nějakých věcí k wifi routeru se do všech prohlížečů dostal omniboxes. I po prozkoumání mnoha rad a tipů se nepodařilo omniboxes odstranit. Nějaké rady prosím?

Díky za odpověď.

Re: Omniboxes

Napsal: 19 úno 2015 21:31
od Rudy

Re: Omniboxes

Napsal: 20 úno 2015 08:37
od koltmen
FRST se mi nepodařilo zprovoznit i když jsem postupoval dle návodu. Zasílám log z RSIT.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Olda at 2015-02-20 08:30:24
Microsoft Windows 8.1 Pro
System drive C: has 55 GB (48%) free of 114 GB
Total RAM: 8071 MB (81% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:30:29, on 20. 2. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Olda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
C:\Program Files (x86)\Cobian Backup 11\Cobian.exe
C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\trend micro\Olda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\XTab\SupTab.dll
O2 - BHO: taKeorleave - {3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9} - (no file)
O2 - BHO: 7SSave - {79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9} - (no file)
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Cobian Backup 11] "C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
O4 - HKLM\..\RunOnce: [PreRun] C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\WINDOWS\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GIGABYTE Adjust (gadjservice) - Unknown owner - C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - NVIDIA Corporation - (no file)
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - NVIDIA Corporation - (no file)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: IHProtect Service - XTab system - C:\Program Files (x86)\XTab\ProtectService.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Smart TimeLock Service (Smart TimeLock) - Gigabyte Technology CO., LTD. - C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - SysTool PasSame LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 11548 bytes

======Listing Processes======





wininit.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {54D0C822-2B63-4160-9F34-E49A050A1BF0}
"C:\Program Files (x86)\Internet Speed Checker\ed907198-32b3-4fea-af47-5b24cf186cd2-1-6.exe" /rawdata=sYLfmFwDDFTPUCqn4CBqejp3V0N50JN9o70LdFD+k/w0MyJD20iyF4hQkwEwOuQW3KrYkXswbXyXFPNj440YcMcYWXcJJ226dPOI5UVQN5A1XtKlP8ztF/S7uCB71fUEmZ3JCwnp9+27qoKMTzbcpu1iTpKhemsmkzvZaknojg6T3fN3pyge76P6jl9jOt8kbbjfbqmkOVyfqgZJMoiNFxv8w4nmttWkhYi85He4Ct5m4rbw2W72XOUWJJ6Z8poqmRGr54e8EjMLdIPv/pFF72LfDjKvmERtqjxYwHiGqOHWfOCL6D9yIYDDi6eKWtkCIOYRyJ3RhbdYOi89SR1ptiK1G2YCIJsQopBeK0V6nlj7Cs1svJiQlpbthIVpT0lvpG9yIrBlLcpJDoPCdt62IcqycEE6YT++MYT6xA8r5wawiVW3iykujHm34Iq290rMniIG2W4uWskn6F3/VvXfTSgbzMXieO/smIuMmL0yThFCYchnnJrJh1bSPYzidgw7jqCVH9GtVEQRrIz9+0vpCyZ2mCH6Rkg6+qImf2nBXLzXjFvjyKp1HRirIWPkz63LkC0N7/TTkdvysVYbMrKSYBEZ9oG7gQPOxwiDcJRwTNAU0i2DchAK//Dhl2hAumdCmRKe9rXswgiQHH1p4tXoJlqKy4vJliaRmTFWCg/nzztetClguPtCpl0IFq2O/Ofdyg7OLUa1M8Z3o4JChkfzFeWq8Cukobx9diTEdRtp97jZC6gRmWeCZHgZtZ08hyfYRMb+UeZvDaNvxmPyovHFTWr5CIU6wPDw8HJC/GcMEW4do/a3yxhy0719CAAa5UuEpHRWcZwRX2im5+xxkP2NUVjdyHes/coCm+p/LHixabKQmjdhg2KTB85JRMhKDu+lIXAvzf6+0350u9y/EC7ZPBBFcdRAWetC+9fDFSrY+AKdarN2YOo3KwKq8PU6m7Tir2rzznL0+53rt78gckQYAIyJcEyLJjU31Ipv6hads3hW/SvEf+a/jjlSQwer5XhrgWbCh+j4bUmM8fuRWCt2quINH7/05u1KdGgBaTg8XV5mYpkKe3Vpm3J39zbMxbzfw2gL68ScAbqd/9+fgkuPKlhWrDxZFmnMO5FiUeYHbM//LaPXzlzxsR8Va7JpD9VErDsS9KOg6CgtAh+9R1R1mzNrx8MyxlPmXzWFCAk3zwRJN9H3krunJdUUqyvxi2fJfmDAsXuiSfcbwVgbVgmEPGg3Paqdk33u/JQq/o9P9jcAidiRqEGLq1xhpbd9QrkM/iJJN9NDpeKGv4eSR8OXp9dfpZf5ty6k5ERfWSyKpw9GuOQon3svBNafIQCrAH8Z+fYil+KwMAfMEHH+BYnCkA==
c:\programdata\bsoft\sw-booster\SW-Booster.exe /schedule /profile "c:\programdata\bsoft\sw-booster\838872563.ini"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe"
"C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe"
dashost.exe {20bdfeb8-f32f-4f91-bd9ba8ae84a5e099}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files (x86)\XTab\ProtectService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 4a98a798-1a3a-4644-ac2a-48b2c3fc0d03 1
\??\C:\WINDOWS\system32\conhost.exe 0x4

C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
-hiberboot
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
taskhostex.exe
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Users\Olda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1

"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe"
"C:\Program Files (x86)\Opera\opera.exe" http://www.omniboxes.com/?type=sc&ts=14 ... EAD929489B
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Users\Olda\AppData\Local\Opera\Opera\temporary_downloads\RSITx64.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" -startup
C:\WINDOWS\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\WINDOWS\tasks\782b78a4-a860-4fe3-a9de-bd902d48b8a0-10_user.job - C:\Program Files (x86)\CinemaP-1.9cV16.02\782b78a4-a860-4fe3-a9de-bd902d48b8a0-10.exe /rawdata=XWR0ejofG/K0KxIBZLdCP/DN1NCVZL4CB5uddgEVyregGESu/vCy8LEfCmArHh5ryBaYPLdNW1VM6399fIT0z/gJ1bPEkQRnNqg8qWkM+y3ld2nIRa8lMMkaTXp32HhF30naQVSMUrX9ZXfzh4H0kH9k0oyq9fQCtKfg3hou81FnqzXv8RJ5ucnH152ay6XvYZ3Fg6TaeGVDKKHJ3nvmAep/7FKv1esiuXT3JXE3+W/EV56ANqUXl+LMyW5md36vQS+TDzGLlC+aGuiq3+WbZIUSGzUKAxXsJ+VvVeZoRE1g4l2zqDbRmU5syUtNajlNXFEBIUL5w7s4hXnXzMO4VR4Ae5y8Xjzudx1bKEnNYad64Y5qwYsK6g0Ug95YKaZKEmfDTibLQiapD9A17xxcXYuKObZ67Uxbil1GI+lEdfxybbeECtimab1NsXWNzlHgX6zYftR4VFnmtFyGKtkLYuGTHSEt9OrDND4yzy132zYTb655rF8mmSCvBKS+h453jG90YfRzJMnbPj9D2h8UQ7XwBJ1XDu/AnAP1BYyQ/rXciY7Uo1YaDvkiZJifcDp1hBAs8os7Rr6yLRo6ZJ5pdK1CzViWLQcqb7qM/31+D+rQBRVrVkFtrRUc0mgo6KXWFZmoBgRTYOQONU+b9D9Jj7TrpIUQ8ofYhvKI8R0+hqQceKADfIkgvl2r6RghqrtUvG+JJZaHRPw/tHYDAi8R5qNhKH4dxCWQCknAWz7IRC2rbGiSmIuxKzqtMErINxLXUOn02j9QyH+libIF0UYBiFFnNN8HDcM6TdEGHMHg2RUq0CfZncJhdygK2LO8KTxf+xSRfxnDQwOKZlnGErcCKA==
C:\WINDOWS\tasks\782b78a4-a860-4fe3-a9de-bd902d48b8a0-5_user.job - C:\Program Files (x86)\CinemaP-1.9cV16.02\782b78a4-a860-4fe3-a9de-bd902d48b8a0-5.exe /rawdata=ft7nCIgDO3W/0qi1puiwuRDcFX3WFQQ1U0k07eNUDT2xlKMznghEZS6fw6KtxVlrOmY6QYhmkynnCfJCqjOQCeKcCoc1QQ676AdGvgg8nRwi6Fo8MhT4DeCs9FrEpUYSJMdP10JXcIwsrG/j0PYjPzOpAcL3Y+g2YpaD/W6P/1qA/81yuEU6LsBJuEX3sY3SOMKgXdXMIAnZ5QGPDuypsQCRTuH6ib4Z+wPd6ogdS3r70zwJ++RBHTHa6oOt6ieMH7AMtI7pRAW19xYpLqA+2K5e/aAfaKZA0J2EVeKYuHcp9w7+X9IyhrRZ83M7TC6ebkjD284rxTFlekbimAErjMXtCan19obmHcHwu8aJbJ8WfLYRtFbL9Vb1r6o1+a3i6TTburyQniuQq4FIH7xhZaD/Vtq9Zmu4pWPw6Me+RqmQ7+GZzLqlwzuzeFD5BGdQm9oO4wSnQ8+g3ph4WI26eQJ1liMPG4EsRU5eOo8TKhZpUHP4Y0eaHR4vc6TZeWFDZQeLYaCVVrpoxx3O6yZJGvIMujOo0X0YICJVG0/zK/AQkTeU3xGKIjPTLwV/7zdBLxRA/u8srVA8qYbxEvjOAe+EvyLAf/hYVDgSvEZ/9GdwWF8vAaTF70FrprOJrbKvSvl4F1KVk4/jo1VFckcwU8/dBzXCuw7MPsa42saEs8mhOVXMdoInyQdt8ApRBuF5f8mR+HYZrAUfaP0mQeBQukZwQtdEMdLCne7jXtc6QGVmpgkyxpW+yFqiL9PUWvzORItILNNLg0GbhLhLoKPuQMhFu3s4q690vHP+7skPknpLkB6URCvDt7oxcI9OVBQSwmqmrHh5W/6z2/ESs0a/y6buh17rDOMsyELwJvBm/KZbtoHzpr3zR8PKV5iXXqkSuqfDaEpOEei39RUOi1jMhNwY3gFn2C+qS7MHeMG87tu9yABXU+fO8Chx8VoC40U2C7xXzLvX5TaX1mYY7Q9krmLIwsFKKbcbJTUSDkuajm3wqXc4vqgln8b8jXGOclJ9
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\ASC7_SkipUac_Olda.job - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe /SkipUac
C:\WINDOWS\tasks\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-1-6.job - C:\Program Files (x86)\SavePass 1.1\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-1-6.exe /rawdata=bYtACsPMl+CfT3R2y47DTBDNc9Ub91TTl/AZ98JzfFVXfIou7NJTXK+k2J+LWGZPgVG9XZoIx2PRGakd8koupj8c6elJAtdLTFwkp2u8Hexn5Kn9Dj94d8Jv2jEmGvdSv2C5/qhjPbmForFtddahvbXKgLd03ikmto7Dx4mpVRUyuc7bg1tB5840wFffz5AKJZT83Z+1WszFQt9ucRPJowwZIy9h9dfeFtzzCdS1x+jJaE+d70hbUODmLToGXNlkBzhbLuVvzyWbE8sfGZ5OlQNkhjCdxi+ztvuTLF7l9YxvcbR+mk1r0TQ5Jv7xpEc/8VmbBKxeI40FHtGjf6qk5brS5jW/TWbC41aSkgsZju6TwqXUyE7ScFc9/7rRCumk/LKzpiSLMW0oVJuM28RL0aH67a3hNesQ/mZjWBM80ysOjX+V6ZOoT1Q3AjEnfx0NtvsxthwQSgBR8kVbZpNjg3cqSv4c56MVCO1Ky7W7SSDV7MW8XYjm9yQMJBNE8Ee4mPisr+uM7GAzwZT6RZksCWUWIkECLnE5OABjl7ZpTfRX30IOr8KMq3f6pVniA0TKB65mh1ze8GMxTBzMNATsOtRAhdqRTV/FgrVJBe7eiBDORTdn/Ny9jXXmd0rIOcq0aOTWNf9Y7o+nIX+6Vf2TNSEN0TjheXPiQI/hBb2ItkNhp+tf9/HPEz0S7b0bXm00kqzR6bNDhc/CQ/I82lnxoMs8+uKIYj/eiatXiP253KZv0K6qjmSLKkMNviCjeSk4RrV/tCKJzNcfuXvifWd7oHiJB7qjAqPBABOrpZYNdQ6gy4BUMlCIcYbly8f2VW2s9vaY5mVK7McnXz3IOUOzQ3iuHz113v8WOjhXeyLlr3R3I7hbWle4gC8dzo1mIueof5iw7mrYfWAP00YuwVO5p3ii22CGu8qt513o91lk95T9wff6FWBuSWUqqNCofcAk/yh0Lf4i2JRCrIlAzN+9MPumXGRCVDZq7XK0zZmbptMRfCQCa0c8Rk2V3z5o1s3VezvESRsRLX73RTS8M+PF6J8dgy1Ypokvu49AzWEA0G0hD7rjCExU2WIH5elo007jHtcHIbZ6A6l+BTHnPsCBrcjlhigeKkXGz3K/TGNyiwh7ABP9ITbmCjH6TsQYvBwFbZ8YBwxi+R0P5Fju+p88hgxWTKlMxQD2+R+NAaD5wd8kH3qGVKzu8fSOouYKAjfveumhCOwy1DZfrJUENRdYOgplEIx53o/eMCYbzc8pyg8HYL1oD54i9CWzVUuNF8k5renEFjH/BnWbrAQ7KckLMHB4FdZvCuCSIAqxDSJ+sdViOQifVdZLzTJWD6rPDgoJWCt0YUbqETKvpEdGEocZrA==
C:\WINDOWS\tasks\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-1-7.job - C:\Program Files (x86)\SavePass 1.1\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-1-7.exe /rawdata=HrtC0sscl4HELcOCC6PZs7dSZlo036SSMhD7mcZ3sPRpl3NZXs0/ulThK/cwwiFrMiNeN5pgAT+1aS4wHPtUmaHWkavgUNsOlm47kbF2S8bs8mqZewT4HQavx4BEH9tZUxru6I5eSWhj+dRKRkGDvyv7NxSecLMuWYdjlNqaUxpojw/OvILP91P3KmfpNG4J44Ouv2wCxa6eWL8UfA/dP8OiXxJwizQM7OdVmvuQE7XW1Bdju380AfyxN1B5umz+GE/Vu4c8vcooejqhbif+BGScCdNppeFsNa/H8IUMMEagwc8N6vjxqIzZR7FlGK29l54EepGDCnw2w139wkbNo54P4v11cLNILjrO178e7zubjSMsgeClWAhy8AqKGoX3N5dxQcDjnI9+zZxMN7Q6eeccK/EqxxOsUkqJ5OzJlHNKILfQcW5QPZjhfnJmwXd0c4wtXYknE66sHIqYN9MMeigyoGaqErV9oj3fMw5Dz/MGCa5wz7wRrNtxK4oSCaENVNeHtL1fOzsSTgTvGwx8ISb865jtIMj/1FsEmYJawGrzq2JYLNo14j+pS9Sw09O0SAp4or6g7SsKioB5XKa+7rHUaDy/n2yoeeM7XAYOz7w6Sv29G2GcUKYD1SCp9EmbGMDGuMHa7KQ3c6n5XohWn7nQN2AjDP8ilUJg5OG7bZ+mR+9lEkvB0o5TSBwKeN8rGZj1GVqgWsYTuZERoMoh+nWFPOejgm6e1Z+yadHd1irh0e1CILX9ejZgfQ9rsvSUBoDpzb8TohrsCdt3qNDfhs+svAaw2vaCMMwpxzEENa3kfImIY8ggxL8HVRhC1I9ZdzS7UE4AwJir/vOeQ01KDMeKo1a+k7q9OHjj0nbAlKPdzC7VNMus6UYNrg/SAf046NV1Do67S5mjNSkvbKiU6BdBO4WjzM9ByUPh2bAsLIkkxuftxZBIuYVr9d7Y46g6xBufrRsTooaSMNTH4KHbSbrYGuvHpYtdmkyFIl4a9VubHSwRK+Pfhykwsqf7H1dhWtzAFFsgHYDxW0PSz4Ni70Ij/7Ou14+bdLybUDkBSE8g0igkQzfk08evT362iQ2wMpe06cefS0o7K3Kr8XHHrJ2ImpatSjzJQJiiQFRBxc6pY8vuCjzqmsOaiCkRWzeDZzTK9DsGZ/wSN943TvLi7UXxVMqYIUKkber1RuwE855eiLnHptgGKsmJjJoiSsxit4gjnv18SBE1LkC0URhiUvd3UDTeiWsSzzHK1YSUwQ4xn6MqD9N+yBKx9+x4Y+eaSRxsxlfaPI6Zl/iiPMY+fc3kUJFDLqYxSAYeeQHA1ofuGFqfa9ITOgvBx0cGry38HyQNIx07IlOideTxlQIYIgQl04udzUfXO6gZY6Irfgp2+eev3BMaJFQMAPBmVnFyk+gnDY4yrbZ92GlGUDv9hBpW5sFHMaPJaOf+DFlEbd7dOztTt2skt9LSM3pOLSf6vomr/1ukLgDugyaQZr5XPrnazT3KYpR7l/uL/bk2CvKnXHrD7h3yowXrhiJgN5y5
C:\WINDOWS\tasks\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-10_user.job - C:\Program Files (x86)\SavePass 1.1\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-10.exe /rawdata=MyQyFYFC5xVQwB9tlP+HYvvegzjF3m2fYxUiLIpk0ll7aatFcyzV68g2HLzdymN/hpave3tlXPe+3CuP+NQpo2LHc65qZw8keB5cFe23qB0Fyy6VBdHdJS+5E3bd4K6UX+E7ZxHE9ge0nfD1geeOZNLaJHOkwxEfnbY1TRc4K2K+Bkhqg1YY1YX98MuMMt6YRMGYJN8xJxvjqbzMhrlv5ml2BRadweIVllUa3n6L4EZ4apiqlsJd/EgzdEeym72+y9/C5Gewxor5qFXeXWH001G2WfSEzz+HoNpI4XZpkp1p/Kxi0y+AlU3mWZF8CKtTpNRisG3ni6H0mzfHw9Xq4F9yfrlAbysbB7D6R+h1REBnfye5crREDF9PLKvNSAwYPgG6mhAzzE4d3FF4myreYp+3E1ePy/X3v7pBFy4SkVxqDV9xy4MB5/DIdK5oiQ8n92dpkgTxVND53JX8YybGC5n3EGL1LJzJzk60/row79uz5xCp66y1BSfKiWgY3d3JoWEBDHESFta3dhDRmiJXfWLDSmWDQyRIse0BbS4VQ/X2o2dpwkIcomn5CcCQCDrk7XFKRf5Cwi1w8yT4b9gqq+yNvRqBLrLVF1LOU9aBgaMM+20UYtjpgbOctrU1cCOqD9AJFjcMNeodzluCiJm/lImrONW6yYMSUwZzt1A8SX1XE7yQcho2EHlebWiusyp8hG8iHwQZnYoldKnKwyJaFVEwRxOys2DlOFWI5iiDBcATjQxoUTVGT8t6+qq2lAk9diqhxt2pwAdc0eoKQY/G9e85ViaIlyLrA+nkDsdvVmFP+uzLIBo9AfsTisIK/CjPeLUHAK9pyMjhutZA6C8Kjg==
C:\WINDOWS\tasks\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-11.job - C:\Program Files (x86)\SavePass 1.1\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-11.exe /rawdata=LJ3Lny2W5UFyULA9kDPDqPkBeGKLgBsQ8MR4L2OsFzd27ZQlcRqElbd+SRb5SwsYjulEvT7PrAgh7JoeSX5/MpZZ6NAtnHvuIDPt/OuAITOUZ7e7EfSJ5U4RK4KGliDE/x6jOBMCkPUpUGy6tfuzh0Q/+wDHmKUkk8Umyn0DVdo7GacfCQCzaTJWPhbEoV6sXieByk/ttRdDpVgTNKNVZ3FTLCkgl06RjzsFefUgw9RiScgAFD8WdON6zDr5CaNwY0JP5juspqADG8guSQklM9KKtUOE3O58s14xttElSr/rQYid1Q1lmrLGeWepMHliX5xb+4b+d6y43FJ4b9OO+qZ/shE7DiQpAclwu/Vd3Gx7Go8eirQxOEnAJJnvpautlmB/3ug7zmsk2qxBw9KCqIPcU9oa3asSS8mrP7pWsnoHwkMwTVHTgNY3Y6PhLkTFJRz2FfmN9FcwXPQZV6YdiP03ps9tTVOpIBMok3EaB1Q4Wse4Td+XPAyDURhvqlBeb2uYFxXu+01a+HlLy5Tnyl+YgrGR5cAm9Rh2tZyKQpNm2uvzrSaFhTDEr75mjPzSdZQxmGjfBEu47OvDP+ex8dfbXtZn1Jvkq9lorqzOr3ORllc6Y3xDhkyHJbi6HeN+xF+PgmUW7iURLCLr18lO1lPnMPIJ9kSkq/jDXgZpqE5obrSPKUpkelUjRd0i/IFIL/3O5CQew+s9fVwa53hXVLOC67BZqmxEgpjodI03GqrmNKO8Xuf/+44++QDymCKZxmFCVxwHtkHGjbPCHSyUtZzHV//arf1sZgD0q+Uqho5MnRWFLFqxjbxYDbhA5qvqLWEmfFrfNgbMp49Wq9+yUISz5Kd/QLaKyLm/Ts0L3NO5QR7BWLYHwvWiwhz8JoImnxuQUuus7Sbu+F1tluZB5RHdg402ljIt/ph5xK3/h4m8SXNuo+KYU6z7aAZFD/sygN+9RFGyFggYbhEQF2hgHexQodMm6m05SUIX7ausomV76PAETxHKtdaa8tHhEQWgANHcn7wJB7gUsDdmYZih85rSRZQVGKUMX/sIh4OmrnNv2g0ZN3RaRpSNXf35idVPuHsJl3+hAqP4/9x2G2EsLOnj68BGPCc+h4i9F79eHOHTslz/vaJOfkRSJK0bjoLn9YLZ0z5HIe0y8PE2cfWK5xxtADT4do0LtsllkZipOoNl9C5VoXcwZ7Hew1y5Uk5c8OtAftPDZniRIjhrV2pHN/UKLjkQRD/CWMPb8PZPiDZwwjn8r8mWmOsrx4tqXP0CPQqr9lUAtoAqs0nvXjGPD034DJhP/sGMPvdXg10yLhIosqMJFAziruQKzPXzXObizB3SgURx7emyN6Q+6ZQc/DGe/nVXLwl6Y87OuMMX1QWUAQEnxC6ODu8MWzBoo2StGRVTBpLn8LjI/0MMa+waSVrgPLGtYX5Jdd+7qMNgD2cgY3X+WesZA09bQZSw8gpC6xHWZh/ahJ9XPb/GhmiafTYS742b4lNW1w+1G0GMwKo5SJGQfkfRB4l9mRMLlvNXCBpZwDevCqe85NfPIvaQ1Pf7i1gxcnnLF1OR3OFrWFXPZR9Kad0KzQJ+Pqe3C7yHUKLLn9zj8I9B1j1Oxj7oDaEwG+wTiyEKKxgNogs7LASVTVu5wxUNh/L11ss0iaR4T1R+aYrGaPHrxM3XUC78oX9LYUud8kimHgbvp4KvEpRD4S7uThAlSKVFlQFg9UUqqAFBb8boKdGNR+i2SHk2WHvXv45qOB227SeDfrEspuir00SWOJMIeu2xBOyTIsYVGDdiRjqBTUy3/XZUCqFp5XDK/spPvJNlAlPZhSrds+K3ddQQ2qaafFDDPZrJJwITgRjJe+f2RYhAVGfFA8CdCm1dOh/Bcwr4VdjOXIBh1DMaph0E1T8reIz0oBuhmzoUO+0rSTytWegNSbywEjbK7bK+dFcoS4GhhZklMRsssXSeefuCQLgPblvcWuqURg0Q6uXA09C5HnNYQWZC/9HG3fyb7qawDYly+gfI6cgQ8tEWUPnoCeGWfe1cm2ucf7xGBQ44KDatLmjkg/Fr2Rla4gNtft2HsUlFKzuCmKxwyYIaOHV5Zevi6N/IEpF7qKTEoGfotrAPluw7S21aPHITmRunAXHp5kVstsvUsCs5tOxKbrWpCAPolZ4z5SGHlF8AO55+z4D10/B3sy9lREMjzdgp/t1clsuMF8wcmBxoBRsteUcpRw0XYcuC5MChc+w9hk9gjPTEDqBttDebqEWn7StAltyQJSdUI5J4v7BAZk2bvYKk/ZUpNYZ7aiSyeOPwrPIYr5TFbueaxOmnXekccHaYNkbdkGbxFlYPfMzIyQgJ1n3EirStSM6wuZ0nG3cuG3UlZJ1D3JvFRDYmnzJUwA==
C:\WINDOWS\tasks\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-5.job - C:\Program Files (x86)\SavePass 1.1\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-5.exe /rawdata=THno82tuMvgiEyAw6UUh5bCK0thcRV1QGNRINPISnMIGRJ1g/yud0Lq4NF2UoRhqhu1k+7zBnqw9pdhw/sWR+6R/qbPCFoTBlAEusvdTlE6EDkgyTqILltUmsY85q/9IuKFW6Ic8rosEtv0EYOOXc3pppFaKwkGkz7WFDS4q8naJTno6OJrDjA7+OajSlcet3MRhEPI2JOp2/Hswd/sK+9wl5XA1HfJWHtn0GPgnW1t+A/9XH7SLxbdcvVP13PJC1jsFEws68Df4+uAtoPQck1XxO8Tvnvc+BzyxEg3/r4hbLLd1l/KNGaj8ms2Zs8BcIqP5CWrowbskPGU/sLAzUKNFftcjNLrw0hhOPqWwY9Q6QzODSsba3AHWIJlnVy/HiIGk6uvH4QwvN/BqYXZ1yraI8c1Hu4X9/8RYm7GB9h+JeaUYKay9NRq1DuobSnTd+ianRZP/Z+T9EGWNGzdH2HmNRqLvtdn9LhOKP6vsm5PVzWZ1dGCNSvf6aCX/kx5PuIHheejYYaQ1y0efgyz+eNOc7rrjkR6j2zk1UF3uFGuKJdSCNY2Z/1ONOk5wkMvBDzMVBMKAw4JCtZ+ZIU3uBpMLi66qe5ERYYMN6WklagXJjNYAtf7uzI942QxTj9Z+1ixu1Z8Y0KMUhkieoz0beMXOsgba7mCVg6D38Gg28hl3ouyxo5daR5lWD92Uzlg6clvmF7XhSN9rmQdlSRg8G0ExHeoBQH7jY3PpIse2l+B89sQ9b519WJ7APA7dlJ+iePPDtasQhOVVSuts4z5Tpgk3Opymq/a7h8LGp3esacWy+WlkTbhT8ONfNXb4brXDDspV5PfW13HyLbORTymJ41FAJrIvNHpR9k55ZWFTcsfskzU7PcuNJMQx7lHDmX+pVTh00b3iD5+qo9/KM+o2d6C1nLkpPVuKNBBVDF3ggxLjN/myarLIvW7LMa/pUZNTXqvXvn6iUqeWUIzbbajRbYFaVr7dNuUZZM5dQQZRQ7Py5dnbGk+QFdDDHVGVD+6/
C:\WINDOWS\tasks\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-5_user.job - C:\Program Files (x86)\SavePass 1.1\c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-5.exe /rawdata=THno82tuMvgiEyAw6UUh5bCK0thcRV1QGNRINPISnMIGRJ1g/yud0Lq4NF2UoRhqhu1k+7zBnqw9pdhw/sWR+6R/qbPCFoTBlAEusvdTlE6EDkgyTqILltUmsY85q/9IuKFW6Ic8rosEtv0EYOOXc3pppFaKwkGkz7WFDS4q8naJTno6OJrDjA7+OajSlcet3MRhEPI2JOp2/Hswd/sK+9wl5XA1HfJWHtn0GPgnW1t+A/9XH7SLxbdcvVP13PJC1jsFEws68Df4+uAtoPQck1XxO8Tvnvc+BzyxEg3/r4hbLLd1l/KNGaj8ms2Zs8BcIqP5CWrowbskPGU/sLAzUKNFftcjNLrw0hhOPqWwY9Q6QzODSsba3AHWIJlnVy/HiIGk6uvH4QwvN/BqYXZ1yraI8c1Hu4X9/8RYm7GB9h+JeaUYKay9NRq1DuobSnTd+ianRZP/Z+T9EGWNGzdH2HmNRqLvtdn9LhOKP6vsm5PVzWZ1dGCNSvf6aCX/kx5PuIHheejYYaQ1y0efgyz+eNOc7rrjkR6j2zk1UF3uFGuKJdSCNY2Z/1ONOk5wkMvBDzMVBMKAw4JCtZ+ZIU3uBpMLi66qe5ERYYMN6WklagXJjNYAtf7uzI942QxTj9Z+1ixu1Z8Y0KMUhkieoz0beMXOsgba7mCVg6D38Gg28hl3ouyxo5daR5lWD92Uzlg6clvmF7XhSN9rmQdlSRg8G0ExHeoBQH7jY3PpIse2l+B89sQ9b519WJ7APA7dlJ+iePPDtasQhOVVSuts4z5Tpgk3Opymq/a7h8LGp3esacWy+WlkTbhT8ONfNXb4brXDDspV5PfW13HyLbORTymJ43EwX3/eQ5ZFKmIaOEmIdZQaGErNlXm5/mICivj1mnkziEtAX6qAz8p7A86otWaddRAE2YxTZquL37z1NOjLXwpKPoOFzUI9eZ8l8eiY5mBE8TGSPb6ozRKOSqit67dT48P4D2NhDhsltRLhn+NdLZswUYoX8rUfa5y1ltevKpkt
C:\WINDOWS\tasks\cb91448f-4adb-4089-8201-e3e4cf11763a-5_user.job - C:\Program Files (x86)\GoHD\cb91448f-4adb-4089-8201-e3e4cf11763a-5.exe /rawdata=tDDKrHDRV8ZAtgtB765ovaAzPitLc/JC9dvuEd7eRtj+8c/LOR5VZ110pOivmnJBXvrj85jOUtN8Ya1Ga0Xbb5dEl3AmOOjRkg6eyks6tWtpGJfcbXWjIy/eLZXczC26OSYccLUEj2vfkbSmX4aAa+n7JUzL271aRNQnXUyxe8+QLkJ7EH3iCLe90g+TFhucVvDC9eSuxeDdVOI20M6MkGhCLIllkx/QuCg/MzZ3CvsWeOeXWnb9g+Suwwrw/33Nz+eusVs7i/GyEK5fdluMELjxC7ZGbF+TZjlE52wJX5F1fSTr61WfE5QMLKA6cLxQafH8yPfCS0l6DW5D13MEsjDEe4XClhKwzmkP/U+lg3Ye2vNB+epQP65NO49VpvnLdE8CEkofyMN/N3qQXJT4SKTfodupkIXWwnRLlFNytPdj8SArT4YzV06fDfQ2RfN5VTq+dO8E8VPCuWxuYuYw4oEDtr2p/3N0RahTi1qhpZjHeBTeXnA/f708cehRBeD1nryRpNWv0Tg8XLd6nlsxJzFkVlBlE7n0UDVRJT1sYLc4IMxn/a1X7RMDBhig3OKhLq2QbV6VGtQRkjLKPfPzG4zf9ajLVXYoWGdaJSOnFYXjUMoKTrR/V0ccq34Vu7NPonToRJBK6K8oi+1rNAoBxxT0o4HmKEcrp/7vVotPVo8r5u5dbRrZU/Usxf35eLfvtS7k74AXJ2oX3/Vs22vSIb/3ZyhyjFzJLXJBWlbctoVl0wPtSnbIZArMr6OJwHdbb9i0aMRC2IrfnNL/MeWt1Q1usUStlvFWsT25FtenHPkoTqhtn75D0mKQjfB3JA60rBaJaFcGe3nrrjnwgymghRXDjaXsuhpAPwXdRf6oZbo5M5T35d51ZAorcZHhe3R6WlhIlwhhGcY8ieSeH+QH10dof/t8+ejQq3bLZLjrqeiLv/jG5mEa97DOb5poZDCa7NvLnNJ3iD/I4NH4eVy7UMRUs+XSMLsTsxzozGuMsXWT7qCRwepXEuUAif/3XZi8vWVL1EKe135I/midmOLj0Byx82nXi05K/C6vmmwRnYDPYsgbTWaxiLl1Q7VswXgeHaAn7Z//ahRq2r1zYa3NcaT0Ww30xTKe1iLZ9sfm6mqDITV265EF6Rphp2L8gXuK70GyVuLz/GSwZWqod7pdt3mt7CfD1tDhK6vRWZYHlYg=
C:\WINDOWS\tasks\ed907198-32b3-4fea-af47-5b24cf186cd2-1-6.job - C:\Program Files (x86)\Internet Speed Checker\ed907198-32b3-4fea-af47-5b24cf186cd2-1-6.exe /rawdata=sYLfmFwDDFTPUCqn4CBqejp3V0N50JN9o70LdFD+k/w0MyJD20iyF4hQkwEwOuQW3KrYkXswbXyXFPNj440YcMcYWXcJJ226dPOI5UVQN5A1XtKlP8ztF/S7uCB71fUEmZ3JCwnp9+27qoKMTzbcpu1iTpKhemsmkzvZaknojg6T3fN3pyge76P6jl9jOt8kbbjfbqmkOVyfqgZJMoiNFxv8w4nmttWkhYi85He4Ct5m4rbw2W72XOUWJJ6Z8poqmRGr54e8EjMLdIPv/pFF72LfDjKvmERtqjxYwHiGqOHWfOCL6D9yIYDDi6eKWtkCIOYRyJ3RhbdYOi89SR1ptiK1G2YCIJsQopBeK0V6nlj7Cs1svJiQlpbthIVpT0lvpG9yIrBlLcpJDoPCdt62IcqycEE6YT++MYT6xA8r5wawiVW3iykujHm34Iq290rMniIG2W4uWskn6F3/VvXfTSgbzMXieO/smIuMmL0yThFCYchnnJrJh1bSPYzidgw7jqCVH9GtVEQRrIz9+0vpCyZ2mCH6Rkg6+qImf2nBXLzXjFvjyKp1HRirIWPkz63LkC0N7/TTkdvysVYbMrKSYBEZ9oG7gQPOxwiDcJRwTNAU0i2DchAK//Dhl2hAumdCmRKe9rXswgiQHH1p4tXoJlqKy4vJliaRmTFWCg/nzztetClguPtCpl0IFq2O/Ofdyg7OLUa1M8Z3o4JChkfzFeWq8Cukobx9diTEdRtp97jZC6gRmWeCZHgZtZ08hyfYRMb+UeZvDaNvxmPyovHFTWr5CIU6wPDw8HJC/GcMEW4do/a3yxhy0719CAAa5UuEpHRWcZwRX2im5+xxkP2NUVjdyHes/coCm+p/LHixabKQmjdhg2KTB85JRMhKDu+lIXAvzf6+0350u9y/EC7ZPBBFcdRAWetC+9fDFSrY+AKdarN2YOo3KwKq8PU6m7Tir2rzznL0+53rt78gckQYAIyJcEyLJjU31Ipv6hads3hW/SvEf+a/jjlSQwer5XhrgWbCh+j4bUmM8fuRWCt2quINH7/05u1KdGgBaTg8XV5mYpkKe3Vpm3J39zbMxbzfw2gL68ScAbqd/9+fgkuPKlhWrDxZFmnMO5FiUeYHbM//LaPXzlzxsR8Va7JpD9VErDsS9KOg6CgtAh+9R1R1mzNrx8MyxlPmXzWFCAk3zwRJN9H3krunJdUUqyvxi2fJfmDAsXuiSfcbwVgbVgmEPGg3Paqdk33u/JQq/o9P9jcAidiRqEGLq1xhpbd9QrkM/iJJN9NDpeKGv4eSR8OXp9dfpZf5ty6k5ERfWSyKpw9GuOQon3svBNafIQCrAH8Z+fYil+KwMAfMEHH+BYnCkA==
C:\WINDOWS\tasks\ed907198-32b3-4fea-af47-5b24cf186cd2-1-7.job - C:\Program Files (x86)\Internet Speed Checker\ed907198-32b3-4fea-af47-5b24cf186cd2-1-7.exe /rawdata=NYUXERMGPscDxBzm0rZAA1vpp70YmI4Iqk6/3VVuAFPpGG8FN04G/UAoG+H6jrfUBKmAp2qOsanMO9u8jLP2rpu6VYw5+8sanhy2IM0agq9k+o4tetWhBfr+HlSMAp6LgYJE7vtxSH6XSGQo4/no+H9K0vNdQuLyMkd47NQyhecAVc3gMdQjs96BgB3lhYalaHh19rNarx7vax1zBI5vU0IAaZSPdMnKg4VILfRRc5giU/SuiJL7u2rr5TZmxi4yWCJ/k3vNdvy8ItIxUseo2+NiYvm5CBrjcxJo6m1ZJrp6yMiJmq9fUrAGTebBaAxMVG0BJP5gv5gkfC0Efev1hbmQ6rq0dwcKcnkbSjA41VHRIdmguGBteGIB6IwZiwxtySGiVLbkaQmH0WFvhMpuW4JM1ihv2Q4cSnO2qwuarNNvT2iPBvSVmrmK10WywPQAUaBR1mB60/e2gCIOcFoyKKzxYPCrFmsuLYdrINf13TyRSwjcGgFbtPkE0ZGygvhQghX36LRymS5Ea2URWcx3kdH/6zqcoCBKQK4ll34W3OuLaiX2j/u4Z7Or2sCmjr6nlf4vTAdHpLlD1dxU3TY/3IMi4j79AmY1oIZDUJSf9hJaNeoXaOohnz3F+6N3ZjiMui5oj4tjFeLut9bjN20xcdq46vrwX8DQ1TcS2yPXG6/BVXa/IMGfX5hGEYPoTB5zQc4WOvm/sHvVdE2TyNLCtPMSVrj1lcPmDOT4l2ZY2VOg40Ut6yi/k/+ym6oDfO6KCrrYAi6VtdcDZzWbxwqtO1FuHzw20N/ZVR172kok/SeozVVRpMf0Su2otT6iNc/2MMv7VH9yM2usOlUsrUlz0aDdXZidMgmLK6me7oM1r0L4VixcYiT0+WN4COmInCUYjQ7mAcC2N+XMHxLyGBy2bCVB/Z9zVkPgMMVAOCJy58benJFVcpWmEu7TXG45+XlpV3LHY3II9v3JAyYSHydGsdONMQaGXuEceg+JH7MitJ57s1egItkz4cV6E8pHS8thUsOOUoCjEXxSBOdIZEDgza+GhVG37/L3dktPiB75LRTwgLJ1SyCyiDd4tnsGZhCkoiTFiZQ4mqpfqpUYnUXaxXhYTm1it86cPqyD6fhUo5D8Uc4N/fw50YO3H9aWtBDvadd1SokMUqAJfkPRYjpJ26nvUq01UGkTE8MQ7uUPHlpNBYGiBi5/Nma+I8oyv8s2WkdQqLDLlwtwSdAo8rPz5uTQ0ovix0M5lcbOTW60Aq/rPmZ0rkVAFfKn48wqTKwc44e9Tom5IaRuRocgkIo5iGFrV3IU7H1x+hcgDdBJdE9B6eWUyq1Cke5BB1uTNitDPMI7ozzC2K/cTL7njSl+7UbVi6NM6hqloWSrK7KXXZpkvN773kaq5UPKS8eeD4GkrXZGPRCtAFl4x11XhNoJ9eS4PGCg3sd6B6C9aqw1xUP+NE1FD/4bGRpQU3PIfpJ/NxvgIjGbAOXwAYGzzGguCepmK2egxcakdhwknnkUGAQmv3ruI0mH4vWMLbdmTDAL
C:\WINDOWS\tasks\ed907198-32b3-4fea-af47-5b24cf186cd2-10_user.job - C:\Program Files (x86)\Internet Speed Checker\ed907198-32b3-4fea-af47-5b24cf186cd2-10.exe /rawdata=cOospbfIPAjgks4d4yNErfXrHfhxdMxkwHO/SqlRi8mawGL/gOaBEBxTZlN6AJefqbcED8N3fizoCaqSMTGxc6Z2m3W58y207B/FO1oOZxPKeX0Xvo+N09X8osZGuMLxImD3HrSpvVYv26idQMkX1qW6JwIo3ZL6kygwykoV5ph9zONSBV4/RbwlbMQMKQosaqDWgl01QDzv/tUho+QMetdKMJ6as2GLJr6KtoZ6bx8qf/HWLe8W4/ay9ee/IRpxfAuaFv+ThU7DmeaxUjGMQofPpe+xQzF8h9uA5dTocULx1lTolbIXrO+Pac2ZyB/PVmGGKRm/nQLzDi2YI7wueB48YoU900Nku8GNvhqeYAOvb973vIAVkahotik4vxTiLTNAPRbjI2UtM+XBBhXF/vmZj/D+sipPB2oZXGTIsdHnxGmEc9DhcKQLPAsBavAQNEex7hbPoNdPLwPEgZil8fleW8IqFYx88I9hhbSElPkx3EvUGoFEG/5c9zIADAAXSe4B2pgmNcLFqsJ0uQp9VywyJUbv/irLa1Xc4KYhhoW6bE/4tD/BWbfDgrWjT95eQzISNFkVSKZuqzDHSK6+/kFGv2fsOR6ZMrsYgSau7d0P/PBI5PYDiIBNIle8qWng5QyeuZaVUA8baPdYae4KGnmlrjB6IzoLCDQx1sof0jWqGUHuSQbk6dJGg7sVLkflrXoiFClKID+Axx3Rbnbw1BtUSjTSxRzjK6Zta0YRoVyf5dYrSkM5b+XT7bkKqVHdu8iHyX55346kmbT+HaGEOPyh9nynqqt8lsSbRXu/WgJpDc3sNOn3ZC75LXupn/F1GVZe+gRF4fU1cuvqc0yIHw==
C:\WINDOWS\tasks\ed907198-32b3-4fea-af47-5b24cf186cd2-11.job - C:\Program Files (x86)\Internet Speed Checker\ed907198-32b3-4fea-af47-5b24cf186cd2-11.exe /rawdata=ont1yOYfonaJRj5RfBZxfd71Rq6RrGsDtHV4pZjQOAV3vzf/K7/Ct8NJyNuZD7ANP0slRv4N1XkEfm3dM3zL/wg5JWYxr8N5BVGfVQC0cr/i9AOwhSAucUqjVYYRmtNJR+CPmXcoSQjrlGQAEeT3vgLsnKEBDL5WlSzH4s2COtwA2o5987N/i261BKIT8NygFWdjjjCcfAQN0SQrzn5Ad8jx65xir7XRk6esKZ/uAl8Xdo9N19YYYseaOHoXlT1pSFgMWtDmhyAj4SC+tPEXtynktii0sD9btvNOsp8rdg1rTtViU7HyEX0/KmAwI43x3vchjBhQ62VlXZEnCrSXuwBVzeAx1COz3oGAHeWFhqVoeHX2s1qvHu9rHXMEjm9TQgBplI90ycqDhUgt9FFzmCJT9K6Ikvu7auvlNmbGLjJYIn+Te812/Lwi0jFSx6jb42Ji+bkIGuNzEmjqbVkmunrIyImar19SsAZN5sFoDExUbQEk/mC/mCR8LQR96/WFuZDqurR3BwpyeRtKMDjVUdEh2aC4YG14YgHojBmLDG3JIaJUtuRpCYfRYW+Eym5bgkzWKG/ZDhxKc7arC5qs029PaI8G9JWauYrXRbLA9ABRoFHWYHrT97aAIg5wWjIorPFg8KsWay4th2sg1/XdPJFLCNwaAVu0+QTRkbKC+FCByWz6J38nX1KYd1r8a5VA3xP8Dh10a1FD1mpM4YXTvgRXu0YQnNN8sdMTzjKR6jH3TG4P7rmQnErgAtfQMAsQ0aI22gvIAG0gv1hTHcy2/E6C94AxERQH6ez4OaNQOQAZS7FrAur8ZVwFYktSRvyDZStsDTOrvtMAkzvCosK++2M41+VvqyZSwc6MYR9QJqBBhuVFtF+POyNAd/30GYf2cgy+8ptClRJVkVlWDV7qhsOfd3kwoLgdQ2C/8YJrCUh9Hp8qa4xPy0YOv5o8YRKGffqqmW0ctjRRyxsBVUWWb+6RtcgetRB5EA2iTDDekXHCSNhvVgxPusCfHsnWa4RiizSubT+oAQ0JItTOUBlC9hplkPwMIq5/0nt9QLOd2OvVjr4G6ASv+aYRZHZjaOHdANv1cNEZHDTN2ww4lOPD0TSV9GBEsvFud2VY1Lrx/BgthJR7+BGNrKNmb6agLgfBWUrREHYFR67pJ0uQTK3iPnf9YziyLkJnGAA1xBzVm+Ws7LarUVopj95GwOOb5cXa1gGW7Oh7HFX9LEPhE+AMGTY2sckEhPK5EeK5fCjFEruAkEGw7UwYnE4+SSUpgzamzgoimv1ATAAjYlfC3okwGs/B7kM0V9C2/GgL/eMtj2dgZazTR7BgCzqlmMJrEz7kix8m2Iu2iVrp7pJJ91B0FLk2P3C5xFr2lVUnUikLe/EwNnElbdP+EXw5wtot2nNGbOKy90cyLGbSdN3eML/NrVpyCO6Z2xCqXaUDaNGGyoMyTlxcfz/emIWBHkXh/PkggruN7IXkpJf/gk6IObSQoZmUCREEme5UhN4Q8JBZG50LGlgV7usOHJQwhu4aBBO6MDP2kjp5owMegpfFzNFSBQZjRj2A7Em7Z/85GtOtpMbqGfe/ZsTjbjvnIztie4KInrVpfY1Ej3jxQ9V2SA1Yi+fhPRcjZ4DKLNkvtw0qqANrv5F6JYWjDSFr7h5Qs9ZzdQx8q5lxuQexuUnv1mvvNpQGpte6BfTjQd6p98G9yQmu22rfrTrU1SJP+oYsaBNAVWOqQlQEvwXYdA/c2lBM87kggk6kHZ4RiReAH6RYgLDTWFJhxN/HvGMubX5VwGcGIDD+9Bu83PuqTY97k8sqM55Wt6Ul/f93OuLYY8PCApc6QWLUPbPs9/EggR8VY4KQNVGvD3Nb9ZMRmOUhB2Z6jlVNz2/YxFz9rRl+QpzbOEBoiMTx93Lkd/BhfjlZDIlGvxta5ZPav+7iPQkSTftF3/4zpfQq3hSpJYKRtc5/oiyUYj5Uqy5GqJQh742Ib2LF9H7bfRN0xtK6WWuLgDmdOtOPQYpA70uhqHf/Onx9F8/z7t8Oklxj3sCu8z/EYkrfp/aBH4QAD6dF3r6Xtq3dfHpeUM1SFx52gePAPAlPgMVb+u9S//NEwFVbb8J15h6+3e9etqJ6C7RQrcyBybcZQwLvRwO3Bpb8kzN5ff7QyyazaxsC4sj+VzUUdGEsdjDWO+PNV2g6tLom2P/eW3o3kkZGMmMwQc8LPaP91Rx2M0x+6PgcoPHB5tJSIEF8J3D8ZhDBwMkG12PX2mRe6YFl3OBF3VaOzX/2fI0lNNJfv2FHjOS1bAylxxDoFV/VI0+Nssuf2Lm/KSeZN3rwi8QsACPqTmAICjZ7jQfhZ5fPT0KaZu43ADq8K0UnLF5+6UkcfxEAKxrzLrt6p1C5UPUFMw==
C:\WINDOWS\tasks\ed907198-32b3-4fea-af47-5b24cf186cd2-5.job - C:\Program Files (x86)\Internet Speed Checker\ed907198-32b3-4fea-af47-5b24cf186cd2-5.exe /rawdata=oCw4ruikuZzqjpdfc9EEiOCPZAn39sJcrSFldpwgoAGrzdSTkXeghTfBn2a4UAme81ZGtf1LNrRS5zwmGZjkWwH0jm90kXxae06VgG6PTI8f197E9W+79DJcwgY7yMIU9QmEZ6VaeFdFExYceaKLn8xgQlOClt6yKv+u9qQ3cGpkZBLgt6oSVfRP8/uULCT9lCg9jmtl4TZrQujmPmyiyiyK/IR6YBo+acUnH+m2TFzyqRV5PhPY+cRd5Q2+OU0Ydc5nQO8d41ktgjdyGf6NO0rXzlQxPyfOXZqkXR2CgrGv2PJuWwcosRa1nP/iu6+bEtv2gf450p1rqPiueLaTk0lpwYqlXNn5HQ/ER3cxId1GYRYYw9b7DjqY8N15pAwE9W4CTRYN8QhVE16+gxpLbXRggFgQFDhDEVTX7sWrSBZHsYh43e40BcNC/yp2niFXMj5DWIeGFMlKRG6T0hq3TvIHNleusSxxK8lYv2FlI9P5N6zHL2Xs9wdhYCBK5IAGx0ga3zUnjQhVuDuLu2bEHD7cmYFoSpR/tRREjDG0mGl6PifRZROUHZisSC86W7DanVUcgySp9LTJ/0wnfsqRE8OW2KlYWH2Tf5a301/j5iIUdgEey/BnQbQ6COemMVgjeUUiqcypPPvWUWXxlEk1BN1/THEty7N/LgXynSIyW3Gte18uMA3AFzDL0GPlpuFBzrjrtCPDavtf74dnGw1+bgPQ5bwofMODxkJNbYYCWvjbMZa/tlhnnJdCB7nIAc7lB1userrNtPitc9IExR7qUasxc6+b8rfDrinWZ0/VQ3Z8oQ7faj6ByxRDPJxyn9MfL7VeV1hU1za48sjW9aRaxYweWObp6dnv9Cfujc2l4z3y06i9Ye+ibSCH1H0p5M5CFSArY5cGA5UTFz1CQaambxxJFiHHXinY7XJ7+NKQijCQx1PIMUnNqAa0bH6GfJCA8GYWHqRdGZYpuh2BQwupKS8RTgTcZqWvhJoq+cMHvXQss7O/xrIkc0xWVwMnP1tI
C:\WINDOWS\tasks\ed907198-32b3-4fea-af47-5b24cf186cd2-5_user.job - C:\Program Files (x86)\Internet Speed Checker\ed907198-32b3-4fea-af47-5b24cf186cd2-5.exe /rawdata=oCw4ruikuZzqjpdfc9EEiOCPZAn39sJcrSFldpwgoAGrzdSTkXeghTfBn2a4UAme81ZGtf1LNrRS5zwmGZjkWwH0jm90kXxae06VgG6PTI8f197E9W+79DJcwgY7yMIU9QmEZ6VaeFdFExYceaKLn8xgQlOClt6yKv+u9qQ3cGpkZBLgt6oSVfRP8/uULCT9lCg9jmtl4TZrQujmPmyiyiyK/IR6YBo+acUnH+m2TFzyqRV5PhPY+cRd5Q2+OU0Ydc5nQO8d41ktgjdyGf6NO0rXzlQxPyfOXZqkXR2CgrGv2PJuWwcosRa1nP/iu6+bEtv2gf450p1rqPiueLaTk0lpwYqlXNn5HQ/ER3cxId1GYRYYw9b7DjqY8N15pAwE9W4CTRYN8QhVE16+gxpLbXRggFgQFDhDEVTX7sWrSBZHsYh43e40BcNC/yp2niFXMj5DWIeGFMlKRG6T0hq3TvIHNleusSxxK8lYv2FlI9P5N6zHL2Xs9wdhYCBK5IAGx0ga3zUnjQhVuDuLu2bEHD7cmYFoSpR/tRREjDG0mGl6PifRZROUHZisSC86W7DanVUcgySp9LTJ/0wnfsqRE8OW2KlYWH2Tf5a301/j5iIUdgEey/BnQbQ6COemMVgjeUUiqcypPPvWUWXxlEk1BN1/THEty7N/LgXynSIyW3Gte18uMA3AFzDL0GPlpuFBzrjrtCPDavtf74dnGw1+bgPQ5bwofMODxkJNbYYCWvjbMZa/tlhnnJdCB7nIAc7lB1userrNtPitc9IExR7qUasxc6+b8rfDrinWZ0/VQ3Z8oQ7faj6ByxRDPJxyn9MfL7VeV1hU1za48sjW9aRaxVtq9KsuXCBN2MusU1sMPSOheyaxATh0YDL6ckLWvJ16tUqp18/ZHpp2wq1atK5QaiVgZ2NEi8S1IrHqE9gIkUaEjvJA22AuUe174E1Dk2XnwlIC85kkwaQqNeUC8TXccm5LwrI7RfEqFc7kH9eqL5maqWiPDDBO127gOco0uO0A
C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\RegClean Pro_DEFAULT.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -default
C:\WINDOWS\tasks\RegClean Pro_UPDATES.job - C:\Program Files (x86)\RCP\RegCleanPro.exe -updatecheck
C:\WINDOWS\tasks\SW-Booster-S-838872563.job - c:\programdata\bsoft\sw-booster\SW-Booster.exe /schedule /profile "c:\programdata\bsoft\sw-booster\838872563.ini"
C:\WINDOWS\tasks\XTKLK.job - C:\Users\Olda\AppData\Roaming\XTKLK.exe /infocmdline=IQQ6DB9YNRCXJBoMsohjz/Mx0yRuJ0r6MXds+jQtWfcyPwMuJSVRqk2rm/oScfI7es/RG8Pk1+GDI/G3U0WGsAPD9V46hlFOE1FgygXAHaFTYkvGVKDpemEYjpuKh268CupfRnX55W1SMEorCTJkQKvZNDr/Yyu2r5FQrcLom590MY0T+CgrPK8lxNSkwGgaUuXbRhSqtEQHRm2GR3SHX2+3LmA2VZY+2Z9D0Ck/EBxXZFUql1LSBWrvMxUZ3JYgOr7Aogx91Pe4UxOp4pRzm2wDMnvsgVHBahKY1t7K3ANsUFVRgYRvBGbvdVGsOIWPtpQAk4PeRwGPxsUfMQRk5rMvCx2iTmTPRVnIMT5mH8/Frzb+77MkMyNaxGAl+McdD+ScFdVqJZGbzOgDQGcIX7yolyhqXYUZN/4tn+j8df7O8++ZCICo3Wa3x692e5/PK/E5HtX1mmLHOgZAwJJ6fFiMz2x9HL5Lazu4lP4p5iwItYYq7sEhcs4yqe+1yrWi

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]
taKeorleave - C:\ProgramData\taKeorleave\3Id5hBYkHZiaz1.x64.dll [2015-01-10 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]
7SSave - C:\ProgramData\7SSave\YjCHajR3O7Nn2U.x64.dll [2015-01-10 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\XTab\SupTab.dll [2015-01-16 210096]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-12-21 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-12-21 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-12-21 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-13 13774040]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-08-07 36352]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-12-13 2824504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2014-05-28 1563440]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
""= []
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
c:\program files (x86)\samsung\kies\kiestrayagent.exe [2014-05-28 310064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SamsungRapidApp]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
c:\program files (x86)\seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2013-03-12 134616]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-11-20 1021128]
"Cobian Backup 11"=C:\Program Files (x86)\Cobian Backup 11\Cobian.exe [2012-12-05 720896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"PreRun"=C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe [2013-04-29 8192]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-12-21 624640]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"VIDC.FPS1"=frapsv64.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw64.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-02-20 08:30:24 ----D---- C:\rsit
2015-02-20 08:30:24 ----D---- C:\Program Files\trend micro
2015-02-19 19:32:55 ----D---- C:\WINDOWS\system32\appmgmt
2015-02-19 19:18:53 ----D---- C:\Program Files (x86)\Enigma Software Group
2015-02-19 19:18:34 ----D---- C:\WINDOWS\027B5748C40941FE949B7B81A8304EF4.TMP
2015-02-19 18:35:22 ----D---- C:\Users\Olda\AppData\Roaming\Malwarebytes
2015-02-19 18:35:12 ----D---- C:\ProgramData\Malwarebytes
2015-02-19 18:35:11 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-02-17 00:55:51 ----A---- C:\WINDOWS\system32\drivers\{955a1491-962c-4a4d-a25b-ddfc77991b58}Gw64.sys
2015-02-17 00:48:26 ----D---- C:\Program Files (x86)\Internet Speed Checker
2015-02-17 00:47:03 ----D---- C:\ProgramData\IHProtectUpDate
2015-02-17 00:47:02 ----D---- C:\Program Files (x86)\XTab
2015-02-17 00:46:55 ----D---- C:\Users\Olda\AppData\Roaming\MiniGet
2015-02-17 00:46:51 ----D---- C:\ProgramData\WindowsMangerProtect
2015-02-17 00:44:46 ----A---- C:\Users\Olda\AppData\Roaming\XTKLK.exe
2015-02-14 21:22:42 ----A---- C:\WINDOWS\system32\drivers\IntcDAud.sys
2015-02-14 21:21:04 ----D---- C:\WINDOWS\LastGood.Tmp
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdagenco64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\drivers\nvhda64v.sys
2015-02-12 11:30:25 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-02-12 11:30:24 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-02-10 23:02:36 ----D---- C:\ProgramData\Package Cache
2015-02-10 20:19:27 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2015-02-10 20:19:27 ----A---- C:\WINDOWS\system32\scesrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\adtschema.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\system32\oleaut32.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\system32\schannel.dll
2015-02-10 20:19:01 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-02-10 20:19:00 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-02-10 20:18:59 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-02-10 20:18:58 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\wininet.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\setup16.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\instnm.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64cpu.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\user.exe
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\invagent.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\devinv.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-02-10 20:18:07 ----A---- C:\WINDOWS\system32\win32k.sys
2015-02-06 11:03:09 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-02-05 08:42:17 ----D---- C:\ProgramData\Block The Ads

======List of files/folders modified in the last 1 month======

2015-02-20 08:30:24 ----RD---- C:\Program Files
2015-02-20 08:30:01 ----D---- C:\WINDOWS\system32\sru
2015-02-20 01:44:46 ----D---- C:\WINDOWS\Temp
2015-02-20 01:44:44 ----D---- C:\WINDOWS\system32\Tasks
2015-02-20 01:24:00 ----RD---- C:\WINDOWS\System32
2015-02-20 01:24:00 ----D---- C:\WINDOWS\Inf
2015-02-20 01:24:00 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-20 01:15:47 ----D---- C:\ProgramData\NVIDIA
2015-02-20 01:04:58 ----D---- C:\Windows
2015-02-20 01:04:54 ----D---- C:\WINDOWS\system32\catroot2
2015-02-20 01:03:48 ----D---- C:\Users\Olda\AppData\Roaming\uTorrent
2015-02-20 01:01:11 ----D---- C:\WINDOWS\system32\config
2015-02-20 01:01:10 ----D---- C:\WINDOWS\system32\wbem
2015-02-20 01:00:50 ----D---- C:\WINDOWS\Tasks
2015-02-20 01:00:50 ----D---- C:\WINDOWS\SysWOW64
2015-02-20 01:00:50 ----D---- C:\WINDOWS\system32\drivers\etc
2015-02-20 01:00:44 ----HD---- C:\Program Files\WindowsApps
2015-02-20 01:00:30 ----D---- C:\WINDOWS\registration
2015-02-20 01:00:29 ----SD---- C:\Users\Olda\AppData\Roaming\Microsoft
2015-02-20 01:00:29 ----D---- C:\WINDOWS\Microsoft.NET
2015-02-20 01:00:28 ----RD---- C:\Program Files (x86)
2015-02-20 00:59:50 ----SHD---- C:\System Volume Information
2015-02-20 00:47:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-02-20 00:47:11 ----D---- C:\WINDOWS\debug
2015-02-20 00:45:13 ----D---- C:\WINDOWS\Prefetch
2015-02-19 19:34:08 ----HD---- C:\Config.Msi
2015-02-19 19:18:33 ----D---- C:\Program Files (x86)\Common Files
2015-02-19 19:17:24 ----D---- C:\WINDOWS\system32\drivers
2015-02-19 19:06:51 ----D---- C:\ProgramData\7SSave
2015-02-19 19:06:41 ----D---- C:\ProgramData\taKeorleave
2015-02-19 18:55:11 ----D---- C:\ProgramData\Assistant
2015-02-19 18:53:34 ----D---- C:\WINDOWS\PCHEALTH
2015-02-19 18:52:53 ----D---- C:\ProgramData\RegularDeals
2015-02-19 18:52:53 ----D---- C:\ProgramData\BitSaver
2015-02-19 18:35:12 ----HD---- C:\ProgramData
2015-02-18 20:06:53 ----D---- C:\WINDOWS\AppReadiness
2015-02-18 00:24:13 ----D---- C:\WINDOWS\rescache
2015-02-17 00:55:50 ----A---- C:\WINDOWS\win.ini
2015-02-17 00:48:34 ----SHD---- C:\WINDOWS\Installer
2015-02-16 00:09:04 ----D---- C:\ProgramData\DVD Shrink
2015-02-14 21:24:21 ----D---- C:\WINDOWS\system32\catroot
2015-02-14 21:22:54 ----D---- C:\WINDOWS\system32\DriverStore
2015-02-13 10:47:19 ----D---- C:\ProgramData\ProductData
2015-02-13 10:43:15 ----D---- C:\WINDOWS\CbsTemp
2015-02-13 10:43:10 ----D---- C:\WINDOWS\WinSxS
2015-02-11 00:35:36 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\system32\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\apppatch
2015-02-10 23:02:21 ----D---- C:\ProgramData\Microsoft Help
2015-02-10 23:02:04 ----D---- C:\WINDOWS\system32\MRT
2015-02-10 22:59:03 ----A---- C:\WINDOWS\system32\MRT.exe
2015-02-10 22:58:02 ----SD---- C:\WINDOWS\system32\CompatTel
2015-02-10 22:58:02 ----D---- C:\WINDOWS\system32\appraiser
2015-02-01 10:14:36 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2015-01-31 20:52:44 ----D---- C:\Program Files (x86)\MSI Afterburner
2015-01-30 00:55:16 ----D---- C:\Users\Olda\AppData\Roaming\DAEMON Tools Lite
2015-01-21 15:19:22 ----D---- C:\The KMPlayer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-08-07 644968]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2013-12-24 21184]
R1 AppleCharger;AppleCharger; C:\WINDOWS\system32\DRIVERS\AppleCharger.sys [2013-02-19 21584]
R1 dtsoftbus01;@oem28.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-01-04 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [2014-09-19 27552]
R2 PfFilter;PfFilter; \??\C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys [2013-04-03 39504]
R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys [2015-02-20 25640]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-12-21 4216320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-01-13 4263128]
R3 IntcDAud;@oem107.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-02-14 455440]
R3 iwdbus;@oem14.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-15 27032]
R3 MEIx64;@oem101.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-12-22 118272]
R3 NVHDA;@oem55.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-02-14 195728]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-11-13 13213512]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;@oem104.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RTCore64;RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2014-05-19 13480]
R3 RTL8168;@oem12.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2015-01-13 874712]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2014-12-22 31472]
S1 UsbCharger;UsbCharger; C:\WINDOWS\system32\DRIVERS\UsbCharger.sys [2013-05-06 21584]
S3 dg_ssudbus;@oem61.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-04-11 110336]
S3 dot4;@oem15.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 151968]
S3 Dot4Print;@oem16.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 27040]
S3 dot4usb;@oem15.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 49056]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-09-10 25640]
S3 etocdrv;etocdrv; \??\C:\WINDOWS\syswow64\etocdrv.sys []
S3 intaud_WaveExtensible;@oem13.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-15 39320]
S3 MBAMSwissArmy;MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys []
S3 nmwcd;@oem77.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;@oem82.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;@oem78.inf,%ServiceDisplayName%;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;@oem83.inf,%ServiceDisplayName%;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 ssudmdm;@oem64.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-04-11 206080]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2013-08-22 33280]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-12-05 67584]
R2 gadjservice;GIGABYTE Adjust; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [2014-04-16 16384]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-08-07 15720]
R2 IHProtect Service;IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [2015-01-16 158896]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-16 169432]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-16 390616]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-11-12 934032]
R2 Smart TimeLock;Smart TimeLock Service; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [2013-02-22 102400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-11-12 409800]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
S2 699fd52f;Assistant; C:\WINDOWS\syswow64\rundll32.exe [2013-08-22 49664]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440]
S3 AppleChargerSrv;AppleChargerSrv; C:\WINDOWS\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-12-21 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-27 194032]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]

-----------------EOF-----------------

Re: Omniboxes

Napsal: 20 úno 2015 17:12
od Rudy
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Omniboxes

Napsal: 21 úno 2015 12:41
od koltmen
Zde log z AdwCleaneru:

# AdwCleaner v4.111 - Logfile created 21/02/2015 at 12:38:55
# Updated 18/02/2015 by Xplode
# Database : 2015-02-18.3 [Local]
# Operating system : Windows 8.1 Pro (x64)
# Username : Olda - PCČKO
# Running from : C:\Users\Olda\Desktop\adwcleaner_4.111.exe
# Option : Cleaning

***** [ Services ] *****

[#] Service Deleted : 699fd52f
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : WindowsMangerProtect
Service Deleted : IHProtect Service
Service Deleted : {955a1491-962c-4a4d-a25b-ddfc77991b58}Gw64

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Assistant
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\RegClean
Folder Deleted : C:\ProgramData\Systweak
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\IHProtectUpDate
Folder Deleted : C:\ProgramData\takeorleave
Folder Deleted : C:\ProgramData\SafeWeb
Folder Deleted : C:\ProgramData\50Coupons
Folder Deleted : C:\ProgramData\7SSave
Folder Deleted : C:\ProgramData\AllCheapPriuce
Folder Deleted : C:\ProgramData\BitSaver
Folder Deleted : C:\ProgramData\Browser AdBlocker
Folder Deleted : C:\ProgramData\FindoBestDeal
Folder Deleted : C:\ProgramData\GrieatSave4U
Folder Deleted : C:\ProgramData\RaNNdomPrice
Folder Deleted : C:\ProgramData\RegularDeals
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\ProgramData\66f2df5e1a95af50
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\SmartTweak
Folder Deleted : C:\Program Files (x86)\sw-booster
Folder Deleted : C:\Program Files (x86)\Internet Speed Checker
Folder Deleted : C:\Program Files (x86)\XTab
Folder Deleted : C:\Program Files (x86)\SafeWeb
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\AllSaveR
Folder Deleted : C:\Program Files (x86)\BestSaveForYou
Folder Deleted : C:\Program Files (x86)\SaaveLoots
Folder Deleted : C:\Users\Olda\AppData\Local\Temp\Cyti Web
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Ivanka\AppData\Local\torch
Folder Deleted : C:\Users\Olda\AppData\Local\Conduit
Folder Deleted : C:\Users\Olda\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Olda\AppData\Local\torch
Folder Deleted : C:\Users\Olda\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Olda\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Olda\AppData\LocalLow\VideoDownloadConverter_4zEI
Folder Deleted : C:\Users\Olda\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Olda\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Olda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
Folder Deleted : C:\Users\Olda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Ivanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Olda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Ivanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Olda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Ivanka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bbglkiiiofelplniblholffbhhjmdhhi
Folder Deleted : C:\Users\Olda\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bbglkiiiofelplniblholffbhhjmdhhi
Folder Deleted : C:\Users\Olda\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
Folder Deleted : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Ivanka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Olda\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Ivanka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Olda\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Olda\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbglkiiiofelplniblholffbhhjmdhhi
Folder Deleted : C:\Users\Olda\AppData\Roaming\Opera Software\Opera Stable\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
Folder Deleted : C:\Users\Ivanka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bbglkiiiofelplniblholffbhhjmdhhi
Folder Deleted : C:\Users\Olda\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bbglkiiiofelplniblholffbhhjmdhhi
Folder Deleted : C:\Users\Olda\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\akaelkiagnbfcccfnmbimdbplecgbikh
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Ivanka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Olda\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ajfmpjengifeppehjampapfjfilodbki
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Ivanka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
Folder Deleted : C:\Users\Olda\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\pjlpjnhfbbnoaledmhoofkkphclamigi
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\WINDOWS\System32\sasnative64.exe
File Deleted : C:\WINDOWS\System32\drivers\{955a1491-962c-4a4d-a25b-ddfc77991b58}Gw64.sys
File Deleted : C:\Users\Olda\AppData\Roaming\LiveSupport.exe_log.txt
File Deleted : C:\Users\Olda\AppData\Roaming\regsvr32.exe_log.txt

***** [ Scheduled tasks ] *****

Task Deleted : BackgroundContainer Startup Task
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : RegClean Pro_DEFAULT
Task Deleted : RegClean Pro_UPDATES
Task Deleted : 782b78a4-a860-4fe3-a9de-bd902d48b8a0-10_user
Task Deleted : 782b78a4-a860-4fe3-a9de-bd902d48b8a0-5_user
Task Deleted : c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-1-6
Task Deleted : c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-1-7
Task Deleted : c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-10_user
Task Deleted : c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-11
Task Deleted : c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-5
Task Deleted : c33e8093-7e1b-4561-a5a6-1fd11fefb9bc-5_user
Task Deleted : cb91448f-4adb-4089-8201-e3e4cf11763a-5_user
Task Deleted : ed907198-32b3-4fea-af47-5b24cf186cd2-1-6
Task Deleted : ed907198-32b3-4fea-af47-5b24cf186cd2-1-7
Task Deleted : ed907198-32b3-4fea-af47-5b24cf186cd2-10_user
Task Deleted : ed907198-32b3-4fea-af47-5b24cf186cd2-11
Task Deleted : ed907198-32b3-4fea-af47-5b24cf186cd2-5
Task Deleted : ed907198-32b3-4fea-af47-5b24cf186cd2-5_user
Task Deleted : SW-Booster-S-838872563

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd
Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT3289075
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-838872563
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{699fd52f}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289075
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A75BE48D-BF58-4A8B-B96C-F9A09DFB9844}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Funmoods
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Myfree Codec
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\Tbccint_HKLM
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\GoHD
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\Myfree Codec
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\SW-Booster
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\Internet Speed Checker
Key Deleted : HKLM\SOFTWARE\IHProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8E8C2E2D-7F21-2CF5-0ADB-64935121ECF0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A1D3F9E-73B5-95EC-1233-6646E1358965}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Speed Checker
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Your Software Deals_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{45606A90-3363-3A3B-1C15-C40E77F4DAA0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B5DB572D-EA87-D3B0-08F6-4D153EA6A783}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CF987D06-1DCF-7B36-5B43-13BC8699C44C}
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\systweak
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Google Chrome v

[C:\Users\Olda\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Homepage] : hxxp://search.gboxapp.com/

-\\ Chromium v


-\\ Comodo Dragon v


-\\ Opera v0.0.0.0


-\\ Chrome Canary v


*************************

AdwCleaner[R0].txt - [22119 bytes] - [21/02/2015 12:37:40]
AdwCleaner[R1].txt - [22178 bytes] - [21/02/2015 12:38:46]
AdwCleaner[S0].txt - [21216 bytes] - [21/02/2015 12:38:55]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [21276 bytes] ##########

Re: Omniboxes

Napsal: 21 úno 2015 12:53
od Rudy
Dejte nový log RSIT.

Re: Omniboxes

Napsal: 21 úno 2015 13:13
od koltmen
Logfile of random's system information tool 1.10 (written by random/random)
Run by Olda at 2015-02-21 13:11:57
Microsoft Windows 8.1 Pro
System drive C: has 55 GB (48%) free of 114 GB
Total RAM: 8071 MB (81% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:12:00, on 21. 2. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe
C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
C:\Program Files (x86)\Cobian Backup 11\Cobian.exe
C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\trend micro\Olda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: taKeorleave - {3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9} - (no file)
O2 - BHO: 7SSave - {79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9} - (no file)
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Cobian Backup 11] "C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
O4 - HKLM\..\RunOnce: [PreRun] C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\WINDOWS\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GIGABYTE Adjust (gadjservice) - Unknown owner - C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Smart TimeLock Service (Smart TimeLock) - Gigabyte Technology CO., LTD. - C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 10882 bytes

======Listing Processes======






wininit.exe
winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe"
"C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe"
dashost.exe {8de0dd56-9791-4bd2-86007eed82b75e2a}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\WINDOWS\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 4a98a798-1a3a-4644-ac2a-48b2c3fc0d03 1
\??\C:\WINDOWS\system32\conhost.exe 0x4

taskeng.exe {C933FC8B-309B-44C0-AB66-874D823A6F64}
taskhostex.exe
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\WINDOWS\Explorer.EXE
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" -startup
"C:\Program Files (x86)\Opera\opera.exe" http://www.omniboxes.com/?type=sc&ts=14 ... EAD929489B
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Olda\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\ASC7_SkipUac_Olda.job - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe /SkipUac
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\XTKLK.job - C:\Users\Olda\AppData\Roaming\XTKLK.exe /infocmdline=IQQ6DB9YNRCXJBoMsohjz/Mx0yRuJ0r6MXds+jQtWfcyPwMuJSVRqk2rm/oScfI7es/RG8Pk1+GDI/G3U0WGsAPD9V46hlFOE1FgygXAHaFTYkvGVKDpemEYjpuKh268CupfRnX55W1SMEorCTJkQKvZNDr/Yyu2r5FQrcLom590MY0T+CgrPK8lxNSkwGgaUuXbRhSqtEQHRm2GR3SHX2+3LmA2VZY+2Z9D0Ck/EBxXZFUql1LSBWrvMxUZ3JYgOr7Aogx91Pe4UxOp4pRzm2wDMnvsgVHBahKY1t7K3ANsUFVRgYRvBGbvdVGsOIWPtpQAk4PeRwGPxsUfMQRk5rMvCx2iTmTPRVnIMT5mH8/Frzb+77MkMyNaxGAl+McdD+ScFdVqJZGbzOgDQGcIX7yolyhqXYUZN/4tn+j8df7O8++ZCICo3Wa3x692e5/PK/E5HtX1mmLHOgZAwJJ6fFiMz2x9HL5Lazu4lP4p5iwItYYq7sEhcs4yqe+1yrWi

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]
taKeorleave - C:\ProgramData\taKeorleave\3Id5hBYkHZiaz1.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]
7SSave - C:\ProgramData\7SSave\YjCHajR3O7Nn2U.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-12-21 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-12-21 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-12-21 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-13 13774040]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-08-07 36352]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-12-13 2824504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2014-05-28 1563440]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
""= []
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
c:\program files (x86)\samsung\kies\kiestrayagent.exe [2014-05-28 310064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SamsungRapidApp]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
c:\program files (x86)\seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2013-03-12 134616]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-11-20 1021128]
"Cobian Backup 11"=C:\Program Files (x86)\Cobian Backup 11\Cobian.exe [2012-12-05 720896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"PreRun"=C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe [2013-04-29 8192]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-12-21 624640]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"VIDC.FPS1"=frapsv64.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw64.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-02-21 12:36:58 ----D---- C:\AdwCleaner
2015-02-20 08:30:24 ----D---- C:\rsit
2015-02-20 08:30:24 ----D---- C:\Program Files\trend micro
2015-02-19 19:32:55 ----D---- C:\WINDOWS\system32\appmgmt
2015-02-19 19:18:53 ----D---- C:\Program Files (x86)\Enigma Software Group
2015-02-19 19:18:34 ----D---- C:\WINDOWS\027B5748C40941FE949B7B81A8304EF4.TMP
2015-02-19 18:35:22 ----D---- C:\Users\Olda\AppData\Roaming\Malwarebytes
2015-02-19 18:35:12 ----D---- C:\ProgramData\Malwarebytes
2015-02-19 18:35:11 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-02-17 00:46:55 ----D---- C:\Users\Olda\AppData\Roaming\MiniGet
2015-02-17 00:44:46 ----A---- C:\Users\Olda\AppData\Roaming\XTKLK.exe
2015-02-14 21:22:42 ----A---- C:\WINDOWS\system32\drivers\IntcDAud.sys
2015-02-14 21:21:04 ----D---- C:\WINDOWS\LastGood.Tmp
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdagenco64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\drivers\nvhda64v.sys
2015-02-12 11:30:25 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-02-12 11:30:24 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-02-10 23:02:36 ----D---- C:\ProgramData\Package Cache
2015-02-10 20:19:27 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2015-02-10 20:19:27 ----A---- C:\WINDOWS\system32\scesrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\adtschema.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\system32\oleaut32.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\system32\schannel.dll
2015-02-10 20:19:01 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-02-10 20:19:00 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-02-10 20:18:59 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-02-10 20:18:58 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\wininet.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\setup16.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\instnm.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64cpu.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\user.exe
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\invagent.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\devinv.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-02-10 20:18:07 ----A---- C:\WINDOWS\system32\win32k.sys
2015-02-06 11:03:09 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-02-05 08:42:17 ----D---- C:\ProgramData\Block The Ads
2015-01-27 00:23:46 ----A---- C:\WINDOWS\system32\drivers\wdcsam64.sys

======List of files/folders modified in the last 1 month======

2015-02-21 13:00:00 ----D---- C:\WINDOWS\system32\sru
2015-02-21 12:59:32 ----D---- C:\WINDOWS\Temp
2015-02-21 12:59:31 ----D---- C:\WINDOWS\Microsoft.NET
2015-02-21 12:47:30 ----RD---- C:\WINDOWS\System32
2015-02-21 12:47:30 ----D---- C:\WINDOWS\Inf
2015-02-21 12:47:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-21 12:41:03 ----D---- C:\ProgramData\ProductData
2015-02-21 12:39:54 ----D---- C:\ProgramData\NVIDIA
2015-02-21 12:39:03 ----D---- C:\WINDOWS\Tasks
2015-02-21 12:39:03 ----D---- C:\WINDOWS\system32\Tasks
2015-02-21 12:39:02 ----D---- C:\WINDOWS\system32\drivers
2015-02-21 12:39:01 ----RD---- C:\Program Files (x86)
2015-02-21 12:39:00 ----HD---- C:\ProgramData
2015-02-21 11:39:43 ----SHD---- C:\System Volume Information
2015-02-21 11:19:37 ----D---- C:\Users\Olda\AppData\Roaming\uTorrent
2015-02-21 00:28:14 ----D---- C:\WINDOWS\debug
2015-02-20 08:45:17 ----D---- C:\WINDOWS\registration
2015-02-20 08:30:24 ----RD---- C:\Program Files
2015-02-20 01:04:58 ----D---- C:\Windows
2015-02-20 01:04:54 ----D---- C:\WINDOWS\system32\catroot2
2015-02-20 01:01:11 ----D---- C:\WINDOWS\system32\config
2015-02-20 01:01:10 ----D---- C:\WINDOWS\system32\wbem
2015-02-20 01:00:50 ----D---- C:\WINDOWS\SysWOW64
2015-02-20 01:00:50 ----D---- C:\WINDOWS\system32\drivers\etc
2015-02-20 01:00:44 ----HD---- C:\Program Files\WindowsApps
2015-02-20 01:00:29 ----SD---- C:\Users\Olda\AppData\Roaming\Microsoft
2015-02-20 00:47:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-02-20 00:45:13 ----D---- C:\WINDOWS\Prefetch
2015-02-19 19:34:08 ----HD---- C:\Config.Msi
2015-02-19 19:18:33 ----D---- C:\Program Files (x86)\Common Files
2015-02-19 18:53:34 ----D---- C:\WINDOWS\PCHEALTH
2015-02-18 20:06:53 ----D---- C:\WINDOWS\AppReadiness
2015-02-18 00:24:13 ----D---- C:\WINDOWS\rescache
2015-02-17 00:55:50 ----A---- C:\WINDOWS\win.ini
2015-02-17 00:48:34 ----SHD---- C:\WINDOWS\Installer
2015-02-16 00:09:04 ----D---- C:\ProgramData\DVD Shrink
2015-02-14 21:24:21 ----D---- C:\WINDOWS\system32\catroot
2015-02-14 21:22:54 ----D---- C:\WINDOWS\system32\DriverStore
2015-02-13 10:43:15 ----D---- C:\WINDOWS\CbsTemp
2015-02-13 10:43:10 ----D---- C:\WINDOWS\WinSxS
2015-02-11 00:35:36 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\system32\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\apppatch
2015-02-10 23:02:21 ----D---- C:\ProgramData\Microsoft Help
2015-02-10 23:02:04 ----D---- C:\WINDOWS\system32\MRT
2015-02-10 22:59:03 ----A---- C:\WINDOWS\system32\MRT.exe
2015-02-10 22:58:02 ----SD---- C:\WINDOWS\system32\CompatTel
2015-02-10 22:58:02 ----D---- C:\WINDOWS\system32\appraiser
2015-02-01 10:14:36 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2015-01-31 20:52:44 ----D---- C:\Program Files (x86)\MSI Afterburner
2015-01-30 00:55:16 ----D---- C:\Users\Olda\AppData\Roaming\DAEMON Tools Lite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-08-07 644968]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2013-12-24 21184]
R1 AppleCharger;AppleCharger; C:\WINDOWS\system32\DRIVERS\AppleCharger.sys [2013-02-19 21584]
R1 dtsoftbus01;@oem28.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-01-04 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [2014-09-19 27552]
R2 PfFilter;PfFilter; \??\C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys [2013-04-03 39504]
R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys [2015-02-21 25640]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-12-21 4216320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-01-13 4263128]
R3 IntcDAud;@oem107.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-02-14 455440]
R3 iwdbus;@oem14.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-15 27032]
R3 MEIx64;@oem101.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-12-22 118272]
R3 NVHDA;@oem55.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-02-14 195728]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-11-13 13213512]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;@oem104.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RTCore64;RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2014-05-19 13480]
R3 RTL8168;@oem12.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2015-01-13 874712]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2014-12-22 31472]
S1 UsbCharger;UsbCharger; C:\WINDOWS\system32\DRIVERS\UsbCharger.sys [2013-05-06 21584]
S3 dg_ssudbus;@oem61.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-04-11 110336]
S3 dot4;@oem15.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 151968]
S3 Dot4Print;@oem16.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 27040]
S3 dot4usb;@oem15.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 49056]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-09-10 25640]
S3 etocdrv;etocdrv; \??\C:\WINDOWS\syswow64\etocdrv.sys []
S3 intaud_WaveExtensible;@oem13.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-15 39320]
S3 MBAMSwissArmy;MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys []
S3 nmwcd;@oem77.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;@oem82.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;@oem78.inf,%ServiceDisplayName%;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;@oem83.inf,%ServiceDisplayName%;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 ssudmdm;@oem64.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-04-11 206080]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2013-08-22 33280]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-12-05 67584]
R2 gadjservice;GIGABYTE Adjust; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [2014-04-16 16384]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-08-07 15720]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-16 169432]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-16 390616]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-11-12 934032]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
R2 Smart TimeLock;Smart TimeLock Service; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [2013-02-22 102400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-11-12 409800]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440]
S3 AppleChargerSrv;AppleChargerSrv; C:\WINDOWS\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-12-21 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-27 194032]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]

-----------------EOF-----------------

Re: Omniboxes

Napsal: 21 úno 2015 13:36
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\XTKLK.job
C:\Users\Olda\AppData\Roaming\XTKLK.exe
C:\WINDOWS\027B5748C40941FE949B7B81A8304EF4.TMP
C:\WINDOWS\LastGood.Tmp

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]/64

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Doporučuji odinstalovat AdvancedSystemCare. Důvod: http://forum.viry.cz/viewtopic.php?f=14 ... ilit=iobit .

Re: Omniboxes

Napsal: 21 úno 2015 13:46
od koltmen
Přesunuto, zde nový scan z RSIT, ASC zatím ponechávám:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Olda at 2015-02-21 13:41:40
Microsoft Windows 8.1 Pro
System drive C: has 56 GB (49%) free of 114 GB
Total RAM: 8071 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:41:44, on 21. 2. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe
C:\Users\Olda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
C:\Program Files (x86)\Cobian Backup 11\Cobian.exe
C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe
C:\Program Files\trend micro\Olda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Cobian Backup 11] "C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
O4 - HKLM\..\RunOnce: [PreRun] C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\WINDOWS\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GIGABYTE Adjust (gadjservice) - Unknown owner - C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Smart TimeLock Service (Smart TimeLock) - Gigabyte Technology CO., LTD. - C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 10878 bytes

======Listing Processes======






wininit.exe
winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe"
"C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe"
dashost.exe {489f765e-03d0-46a7-b50ab014998212cc}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\WINDOWS\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 4a98a798-1a3a-4644-ac2a-48b2c3fc0d03 1
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe -Embedding


taskeng.exe {E46EDEE3-89A6-4134-8E5A-9790E5874ECA}
taskhostex.exe
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\WINDOWS\Explorer.EXE
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\02212015_133920.log
C:\Users\Olda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe"

"C:\Users\Olda\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\ASC7_SkipUac_Olda.job - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe /SkipUac

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-12-21 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-12-21 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-12-21 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-13 13774040]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-08-07 36352]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-12-13 2824504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2014-05-28 1563440]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
""= []
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
c:\program files (x86)\samsung\kies\kiestrayagent.exe [2014-05-28 310064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SamsungRapidApp]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
c:\program files (x86)\seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2013-03-12 134616]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-11-20 1021128]
"Cobian Backup 11"=C:\Program Files (x86)\Cobian Backup 11\Cobian.exe [2012-12-05 720896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"PreRun"=C:\Program Files (x86)\Gigabyte\AppCenter\PreRun.exe [2013-04-29 8192]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-12-21 624640]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"VIDC.FPS1"=frapsv64.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw64.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-02-21 13:39:20 ----D---- C:\_OTM
2015-02-21 12:36:58 ----D---- C:\AdwCleaner
2015-02-20 08:30:24 ----D---- C:\rsit
2015-02-20 08:30:24 ----D---- C:\Program Files\trend micro
2015-02-19 19:32:55 ----D---- C:\WINDOWS\system32\appmgmt
2015-02-19 19:18:53 ----D---- C:\Program Files (x86)\Enigma Software Group
2015-02-19 18:35:22 ----D---- C:\Users\Olda\AppData\Roaming\Malwarebytes
2015-02-19 18:35:12 ----D---- C:\ProgramData\Malwarebytes
2015-02-19 18:35:11 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-02-17 00:46:55 ----D---- C:\Users\Olda\AppData\Roaming\MiniGet
2015-02-14 21:22:42 ----A---- C:\WINDOWS\system32\drivers\IntcDAud.sys
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdagenco64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\drivers\nvhda64v.sys
2015-02-12 11:30:25 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-02-12 11:30:24 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-02-10 23:02:36 ----D---- C:\ProgramData\Package Cache
2015-02-10 20:19:27 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2015-02-10 20:19:27 ----A---- C:\WINDOWS\system32\scesrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\adtschema.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\system32\oleaut32.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\system32\schannel.dll
2015-02-10 20:19:01 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-02-10 20:19:00 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-02-10 20:18:59 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-02-10 20:18:58 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\wininet.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\setup16.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\instnm.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64cpu.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\user.exe
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\invagent.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\devinv.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-02-10 20:18:07 ----A---- C:\WINDOWS\system32\win32k.sys
2015-02-06 11:03:09 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-02-05 08:42:17 ----D---- C:\ProgramData\Block The Ads
2015-01-27 00:23:46 ----A---- C:\WINDOWS\system32\drivers\wdcsam64.sys

======List of files/folders modified in the last 1 month======

2015-02-21 13:41:22 ----D---- C:\WINDOWS\Temp
2015-02-21 13:41:03 ----D---- C:\ProgramData\NVIDIA
2015-02-21 13:39:20 ----D---- C:\WINDOWS\Tasks
2015-02-21 13:39:20 ----D---- C:\Windows
2015-02-21 13:00:00 ----D---- C:\WINDOWS\system32\sru
2015-02-21 12:59:31 ----D---- C:\WINDOWS\Microsoft.NET
2015-02-21 12:47:30 ----RD---- C:\WINDOWS\System32
2015-02-21 12:47:30 ----D---- C:\WINDOWS\Inf
2015-02-21 12:47:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-21 12:41:03 ----D---- C:\ProgramData\ProductData
2015-02-21 12:39:03 ----D---- C:\WINDOWS\system32\Tasks
2015-02-21 12:39:02 ----D---- C:\WINDOWS\system32\drivers
2015-02-21 12:39:01 ----RD---- C:\Program Files (x86)
2015-02-21 12:39:00 ----HD---- C:\ProgramData
2015-02-21 11:39:43 ----SHD---- C:\System Volume Information
2015-02-21 11:19:37 ----D---- C:\Users\Olda\AppData\Roaming\uTorrent
2015-02-21 00:28:14 ----D---- C:\WINDOWS\debug
2015-02-20 08:45:17 ----D---- C:\WINDOWS\registration
2015-02-20 08:30:24 ----RD---- C:\Program Files
2015-02-20 01:04:54 ----D---- C:\WINDOWS\system32\catroot2
2015-02-20 01:01:11 ----D---- C:\WINDOWS\system32\config
2015-02-20 01:01:10 ----D---- C:\WINDOWS\system32\wbem
2015-02-20 01:00:50 ----D---- C:\WINDOWS\SysWOW64
2015-02-20 01:00:50 ----D---- C:\WINDOWS\system32\drivers\etc
2015-02-20 01:00:44 ----HD---- C:\Program Files\WindowsApps
2015-02-20 01:00:29 ----SD---- C:\Users\Olda\AppData\Roaming\Microsoft
2015-02-20 00:47:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-02-20 00:45:13 ----D---- C:\WINDOWS\Prefetch
2015-02-19 19:34:08 ----HD---- C:\Config.Msi
2015-02-19 19:18:33 ----D---- C:\Program Files (x86)\Common Files
2015-02-19 18:53:34 ----D---- C:\WINDOWS\PCHEALTH
2015-02-18 20:06:53 ----D---- C:\WINDOWS\AppReadiness
2015-02-18 00:24:13 ----D---- C:\WINDOWS\rescache
2015-02-17 00:55:50 ----A---- C:\WINDOWS\win.ini
2015-02-17 00:48:34 ----SHD---- C:\WINDOWS\Installer
2015-02-16 00:09:04 ----D---- C:\ProgramData\DVD Shrink
2015-02-14 21:24:21 ----D---- C:\WINDOWS\system32\catroot
2015-02-14 21:22:54 ----D---- C:\WINDOWS\system32\DriverStore
2015-02-13 10:43:15 ----D---- C:\WINDOWS\CbsTemp
2015-02-13 10:43:10 ----D---- C:\WINDOWS\WinSxS
2015-02-11 00:35:36 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\system32\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\apppatch
2015-02-10 23:02:21 ----D---- C:\ProgramData\Microsoft Help
2015-02-10 23:02:04 ----D---- C:\WINDOWS\system32\MRT
2015-02-10 22:59:03 ----A---- C:\WINDOWS\system32\MRT.exe
2015-02-10 22:58:02 ----SD---- C:\WINDOWS\system32\CompatTel
2015-02-10 22:58:02 ----D---- C:\WINDOWS\system32\appraiser
2015-02-01 10:14:36 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2015-01-31 20:52:44 ----D---- C:\Program Files (x86)\MSI Afterburner
2015-01-30 00:55:16 ----D---- C:\Users\Olda\AppData\Roaming\DAEMON Tools Lite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-08-07 644968]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2013-12-24 21184]
R1 AppleCharger;AppleCharger; C:\WINDOWS\system32\DRIVERS\AppleCharger.sys [2013-02-19 21584]
R1 dtsoftbus01;@oem28.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-01-04 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [2014-09-19 27552]
R2 PfFilter;PfFilter; \??\C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys [2013-04-03 39504]
R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys [2015-02-21 25640]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-12-21 4216320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-01-13 4263128]
R3 IntcDAud;@oem107.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-02-14 455440]
R3 iwdbus;@oem14.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-15 27032]
R3 MEIx64;@oem101.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-12-22 118272]
R3 NVHDA;@oem55.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-02-14 195728]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-11-13 13213512]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;@oem104.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RTCore64;RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2014-05-19 13480]
R3 RTL8168;@oem12.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2015-01-13 874712]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2014-12-22 31472]
S1 UsbCharger;UsbCharger; C:\WINDOWS\system32\DRIVERS\UsbCharger.sys [2013-05-06 21584]
S3 dg_ssudbus;@oem61.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-04-11 110336]
S3 dot4;@oem15.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 151968]
S3 Dot4Print;@oem16.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 27040]
S3 dot4usb;@oem15.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 49056]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-09-10 25640]
S3 etocdrv;etocdrv; \??\C:\WINDOWS\syswow64\etocdrv.sys []
S3 intaud_WaveExtensible;@oem13.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-15 39320]
S3 MBAMSwissArmy;MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys []
S3 nmwcd;@oem77.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;@oem82.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;@oem78.inf,%ServiceDisplayName%;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;@oem83.inf,%ServiceDisplayName%;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 ssudmdm;@oem64.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-04-11 206080]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2013-08-22 33280]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-12-05 67584]
R2 gadjservice;GIGABYTE Adjust; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [2014-04-16 16384]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-11-12 934032]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
R2 Smart TimeLock;Smart TimeLock Service; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [2013-02-22 102400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-11-12 409800]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-08-07 15720]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-16 169432]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-16 390616]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440]
S3 AppleChargerSrv;AppleChargerSrv; C:\WINDOWS\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-12-21 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-27 194032]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]

-----------------EOF-----------------

Re: Omniboxes

Napsal: 21 úno 2015 15:59
od Rudy
Dvouklikem na soubor C:\Program Files\trend micro\Olda.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... 929489B&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... 929489B&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hppp&ts= ... EAD929489B
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: Omniboxes

Napsal: 21 úno 2015 18:59
od koltmen
Vyskytly se dvě chybičky. První je ta, že R0 s popisem omniboxes se v hijackthis neobjeví a druhý problém je vidět v přiloženém printscreenu.

http://2i.cz/79a194be6d

Děkuji za odpoved. :)

Re: Omniboxes

Napsal: 21 úno 2015 19:50
od Rudy
Všechno fixovat nejde. Jsou to ale jen nefunkční zbytky, které jen zabírají trochu místa. Podstatné je, zda nastala změna k lepšímu.

Omniboxes

Napsal: 22 úno 2015 14:00
od koltmen
Tak omniboxes zmizel, ještě zasílám poslední log z RSIT.
Děkuji moc za rady a pomoc :)

Logfile of random's system information tool 1.10 (written by random/random)
Run by Olda at 2015-02-22 13:52:56
Microsoft Windows 8.1 Pro
System drive C: has 55 GB (48%) free of 114 GB
Total RAM: 8071 MB (81% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:52:57, on 22. 2. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe
C:\Users\Olda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
C:\Program Files (x86)\Cobian Backup 11\Cobian.exe
C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\trend micro\Olda.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Cobian Backup 11] "C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
O4 - HKLM\..\RunOnce: [PreRun] C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [Zoner Photo Studio Service 16] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\WINDOWS\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GIGABYTE Adjust (gadjservice) - Unknown owner - C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Smart TimeLock Service (Smart TimeLock) - Gigabyte Technology CO., LTD. - C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 9148 bytes

======Listing Processes======






wininit.exe
winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe"
"C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe"
dashost.exe {6117723d-5aa4-4d4d-a1cfc21dfa20c1d7}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\WINDOWS\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\svchost.exe -k HPService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 4a98a798-1a3a-4644-ac2a-48b2c3fc0d03 1
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\wbem\wmiprvse.exe


taskeng.exe {887E48D1-043A-46D7-B375-7629DA1E45BC}
taskhostex.exe
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\WINDOWS\Explorer.EXE
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\GIGABYTE\AppCenter\ApCent.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Users\Olda\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Cobian Backup 11\Cobian.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe"

"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" -startup
C:\WINDOWS\system32\wbem\wmiprvse.exe
wmiadap.exe /F /T /R
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Olda\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\ASC7_SkipUac_Olda.job - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe /SkipUac

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b5bc1e1-a01e-49be-adf6-06cfc9e7d3a9}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b0887b-b4ac-4752-b7cd-d3dd1fbb7ad9}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-12-21 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-12-21 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-12-21 770520]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-01-13 13774040]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-08-07 36352]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-12-13 2824504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nektra OEAPI"= []
"OEXPRESS"= []
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"Zoner Photo Studio Service 16"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2014-05-28 1563440]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
""= []
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE [2014-06-16 833024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
c:\program files (x86)\samsung\kies\kiestrayagent.exe [2014-05-28 310064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SamsungRapidApp]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
c:\program files (x86)\seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2013-03-12 134616]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-11-20 1021128]
"Cobian Backup 11"=C:\Program Files (x86)\Cobian Backup 11\Cobian.exe [2012-12-05 720896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"PreRun"=C:\Program Files (x86)\GIGABYTE\AppCenter\PreRun.exe [2013-04-29 8192]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-12-21 624640]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"VIDC.FPS1"=frapsv64.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw64.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-02-22 13:52:56 ----D---- C:\rsit
2015-02-21 12:36:58 ----D---- C:\AdwCleaner
2015-02-20 08:30:24 ----D---- C:\Program Files\trend micro
2015-02-19 19:32:55 ----D---- C:\WINDOWS\system32\appmgmt
2015-02-19 19:18:53 ----D---- C:\Program Files (x86)\Enigma Software Group
2015-02-19 18:35:22 ----D---- C:\Users\Olda\AppData\Roaming\Malwarebytes
2015-02-19 18:35:12 ----D---- C:\ProgramData\Malwarebytes
2015-02-19 18:35:11 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-02-17 00:46:55 ----D---- C:\Users\Olda\AppData\Roaming\MiniGet
2015-02-14 21:22:42 ----A---- C:\WINDOWS\system32\drivers\IntcDAud.sys
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\nvhdagenco64.dll
2015-02-14 21:21:02 ----A---- C:\WINDOWS\system32\drivers\nvhda64v.sys
2015-02-12 11:30:25 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-02-12 11:30:24 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-02-10 23:02:36 ----D---- C:\ProgramData\Package Cache
2015-02-10 20:19:27 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2015-02-10 20:19:27 ----A---- C:\WINDOWS\system32\scesrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\msaudite.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\certcli.dll
2015-02-10 20:19:25 ----A---- C:\WINDOWS\system32\adtschema.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2015-02-10 20:19:04 ----A---- C:\WINDOWS\system32\oleaut32.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-02-10 20:19:03 ----A---- C:\WINDOWS\system32\schannel.dll
2015-02-10 20:19:01 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-02-10 20:19:00 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-02-10 20:18:59 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-02-10 20:18:58 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\wininet.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\jscript.dll
2015-02-10 20:18:57 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-02-10 20:18:56 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-02-10 20:18:55 ----A---- C:\WINDOWS\system32\actxprxy.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-02-10 20:18:54 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\setup16.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\SYSWOW64\instnm.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64cpu.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\wow64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-02-10 20:18:11 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\SYSWOW64\user.exe
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\sppobjs.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\invagent.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\devinv.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aepdu.dll
2015-02-10 20:18:10 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-02-10 20:18:07 ----A---- C:\WINDOWS\system32\win32k.sys
2015-02-06 11:03:09 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-02-05 08:42:17 ----D---- C:\ProgramData\Block The Ads
2015-01-27 00:23:46 ----A---- C:\WINDOWS\system32\drivers\wdcsam64.sys

======List of files/folders modified in the last 1 month======

2015-02-22 13:52:19 ----D---- C:\WINDOWS\Temp
2015-02-22 13:48:21 ----D---- C:\ProgramData\NVIDIA
2015-02-22 13:47:54 ----D---- C:\WINDOWS\system32\Tasks
2015-02-22 13:00:00 ----D---- C:\WINDOWS\system32\sru
2015-02-22 12:58:02 ----RD---- C:\WINDOWS\System32
2015-02-22 12:58:02 ----D---- C:\WINDOWS\Inf
2015-02-22 12:58:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-22 09:44:13 ----D---- C:\WINDOWS\Microsoft.NET
2015-02-22 09:36:00 ----D---- C:\WINDOWS\system32\catroot2
2015-02-21 20:50:41 ----D---- C:\Users\Olda\AppData\Roaming\uTorrent
2015-02-21 13:39:20 ----D---- C:\WINDOWS\Tasks
2015-02-21 13:39:20 ----D---- C:\Windows
2015-02-21 12:41:03 ----D---- C:\ProgramData\ProductData
2015-02-21 12:39:02 ----D---- C:\WINDOWS\system32\drivers
2015-02-21 12:39:01 ----RD---- C:\Program Files (x86)
2015-02-21 12:39:00 ----HD---- C:\ProgramData
2015-02-21 11:39:43 ----SHD---- C:\System Volume Information
2015-02-21 00:28:14 ----D---- C:\WINDOWS\debug
2015-02-20 08:45:17 ----D---- C:\WINDOWS\registration
2015-02-20 08:30:24 ----RD---- C:\Program Files
2015-02-20 01:01:11 ----D---- C:\WINDOWS\system32\config
2015-02-20 01:01:10 ----D---- C:\WINDOWS\system32\wbem
2015-02-20 01:00:50 ----D---- C:\WINDOWS\SysWOW64
2015-02-20 01:00:50 ----D---- C:\WINDOWS\system32\drivers\etc
2015-02-20 01:00:44 ----HD---- C:\Program Files\WindowsApps
2015-02-20 01:00:29 ----SD---- C:\Users\Olda\AppData\Roaming\Microsoft
2015-02-20 00:47:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-02-20 00:45:13 ----D---- C:\WINDOWS\Prefetch
2015-02-19 19:34:08 ----HD---- C:\Config.Msi
2015-02-19 19:18:33 ----D---- C:\Program Files (x86)\Common Files
2015-02-19 18:53:34 ----D---- C:\WINDOWS\PCHEALTH
2015-02-18 20:06:53 ----D---- C:\WINDOWS\AppReadiness
2015-02-18 00:24:13 ----D---- C:\WINDOWS\rescache
2015-02-17 00:55:50 ----A---- C:\WINDOWS\win.ini
2015-02-17 00:48:34 ----SHD---- C:\WINDOWS\Installer
2015-02-16 00:09:04 ----D---- C:\ProgramData\DVD Shrink
2015-02-14 21:24:21 ----D---- C:\WINDOWS\system32\catroot
2015-02-14 21:22:54 ----D---- C:\WINDOWS\system32\DriverStore
2015-02-13 10:43:15 ----D---- C:\WINDOWS\CbsTemp
2015-02-13 10:43:10 ----D---- C:\WINDOWS\WinSxS
2015-02-11 00:35:36 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\system32\cs-CZ
2015-02-11 00:35:36 ----D---- C:\WINDOWS\apppatch
2015-02-10 23:02:21 ----D---- C:\ProgramData\Microsoft Help
2015-02-10 23:02:04 ----D---- C:\WINDOWS\system32\MRT
2015-02-10 22:59:03 ----A---- C:\WINDOWS\system32\MRT.exe
2015-02-10 22:58:02 ----SD---- C:\WINDOWS\system32\CompatTel
2015-02-10 22:58:02 ----D---- C:\WINDOWS\system32\appraiser
2015-02-01 10:14:36 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2015-01-31 20:52:44 ----D---- C:\Program Files (x86)\MSI Afterburner
2015-01-30 00:55:16 ----D---- C:\Users\Olda\AppData\Roaming\DAEMON Tools Lite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2013-08-07 644968]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2013-12-24 21184]
R1 AppleCharger;AppleCharger; C:\WINDOWS\system32\DRIVERS\AppleCharger.sys [2013-02-19 21584]
R1 dtsoftbus01;@oem28.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-01-04 283064]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [2014-09-19 27552]
R2 PfFilter;PfFilter; \??\C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys [2013-04-03 39504]
R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys [2015-02-22 25640]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-12-21 4216320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-01-13 4263128]
R3 IntcDAud;@oem107.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2015-02-14 455440]
R3 iwdbus;@oem14.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-15 27032]
R3 MEIx64;@oem101.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-12-22 118272]
R3 NVHDA;@oem55.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-02-14 195728]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-11-13 13213512]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;@oem104.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RTCore64;RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2014-05-19 13480]
R3 RTL8168;@oem12.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2015-01-13 874712]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2014-12-22 31472]
S1 UsbCharger;UsbCharger; C:\WINDOWS\system32\DRIVERS\UsbCharger.sys [2013-05-06 21584]
S3 dg_ssudbus;@oem61.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-04-11 110336]
S3 dot4;@oem15.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 151968]
S3 Dot4Print;@oem16.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 27040]
S3 dot4usb;@oem15.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 49056]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-09-10 25640]
S3 etocdrv;etocdrv; \??\C:\WINDOWS\syswow64\etocdrv.sys []
S3 intaud_WaveExtensible;@oem13.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-15 39320]
S3 MBAMSwissArmy;MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys []
S3 nmwcd;@oem77.inf,%MFG% %SVC%;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;@oem82.inf,%MFG% %SVC%;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;@oem78.inf,%ServiceDisplayName%;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;@oem83.inf,%ServiceDisplayName%;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 ssudmdm;@oem64.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-04-11 206080]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2013-08-22 33280]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-12-05 67584]
R2 gadjservice;GIGABYTE Adjust; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [2014-04-16 16384]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-08-07 15720]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-09-16 169432]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-09-16 390616]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-11-12 934032]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2013-08-22 37768]
R2 Smart TimeLock;Smart TimeLock Service; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [2013-02-22 102400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-11-12 409800]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2013-08-22 37768]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04 267440]
S3 AppleChargerSrv;AppleChargerSrv; C:\WINDOWS\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-12-21 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-27 116648]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-12-27 194032]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]

-----------------EOF-----------------

Re: Omniboxes

Napsal: 22 úno 2015 15:50
od Rudy
Log je OK. Jen se mi tam nelíbí AdvancedSystemCare. Důvod: http://forum.viry.cz/viewtopic.php?f=14 ... ilit=iobit .

Re: Omniboxes

Napsal: 30 lis 2015 20:46
od Lojenov
hxxp://nabzsoftware.com/types-of-threats/omniboxes stojí za vyzkoušení? :?:

EDIT: linkk znefunkcnil pavuk29