Prosím o preventivku
Napsal: 12 čer 2015 20:32
Dobrý večer, mám podezření z nějaké chyby, strašně pomalý prohlížeč, občas zamrzá a na cokoliv kliknu, tak vyskáče miliarda reklam a automaticky mi to otevírá reklamy, ADblock nepomáhá, spíš to ještě zhoršuje. Děkuji za pochopení.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Win7 at 2015-06-12 21:26:45
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 159 GB (33%) free of 477 GB
Total RAM: 6142 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:26:53, on 12.6.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10.exe
C:\Program Files (x86)\Cool getWeather\cool_getweather_helper_service.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Win7.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GalaxyClient] C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GalaxyClientService - GOG.com - C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9834 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
taskeng.exe {7D29AE97-C35A-4E20-AC1E-B6261B2E45D4}
taskeng.exe {41A59FF3-B568-43D6-BBED-E57F6676A619}
"C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10.exe" /rawdata=eEnyDGZpyx/yyAOlo/+Kf8CNUeaTqIgXxYpTb0rE2zn29AD2luDqSCItOwOnBT6gF2Zj4TyoTKHXWS9AT9qFm03SSq8MSQQo0DDINMOebydOaZr9JNTD1VndPBGuwer5AXEOKE/X6l1fbbECI7H6ZqL3Y2pBkqlIMSLeON7VABdyOcwQ55uLr1fUoVpyvq+rsD1lQYM61Ps+teLZ/CHAzE+wsDvfEX2d+Xv+KfrQVn6dp5A9b9jwXeVvinhGVdeTeb546B8ug21Ar3PLbXYf3eYVWeG7vwq7UUXM+IJdV1hYNbYhb2RPOKEWmg+tIwL5DAiS68B9SBFp67gWPfuFaki/unkvn/nPub6FqwbZlQVdQ/eA68/MG6wbVrme7RzfruGiR+gDbI9U3kSKjfiJ3LKKdjURzi+1S0O/ukacgCN4RcPnvUorU61XkLmXG+crZ2seLrJw9rkIDk5sR+4MiZWjIkjx9Bch2nlfcax/FzML6Pn3qYQhMHkxzMwNH26ZqtaHSyopyptjy5PwOjNwNQLj2BxLVI+wIFVgqR4NdC3ibitq+Rw1sYRfvy7AGxgaEgvoO0uUtTHubXVMI0tzhDHZDwEhWRtqB55Q0e8G/+r4erJ61jVs7d04D3ko6S1zDxazyArKz8UIySli3RBr68V1BnFctAexZLcACzHmBbN3kkGmAdlIdnvD2+xgM2ynda4EVXA0fMtByuWL93EQ2ymt2X2VMiumzNDNqOCvxWuhqbhXHAcB5f1kExaodoTuMjzuNG7WEsi0unnYQ3MWpzRSiPq6fx5kdubtCi5BS4GgqtvGlG+SrFl7RslVyd6D6EOAkMUuBTCmw06/p8k03A==
"C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.exe" /rawdata=JQ4Zgg2iNy+QL1ZEj+NQU6x8a3wRlJM1HnH7aZvi9nAR0lR0s88Oy2nYovQeE0byS6g8hnHLxdEPlOecZ9XOFDZ8nG6tgpCu5SP5JUzeEFBDQqGBX1XthGR5XUrwC9fmHC1YsjkNqHeFjeunHE99SsTCeApSipvROuQKogMzDR23uZz86XKAx3DVehq3/Hizd5EzTEr2AX9y23I3zu6dN4EAhMQ7ADis7GCkaq/j4QtT2Lq5Qz0jOujndhQihMdWhYPc9z87C+e0Vw9c7dthwWEP7pLOCB/E4C0pi5uFQx3LUDvIig8PlOPzTdMSO9zhqEqyLTWXLIZx//C9N5A/OcX+XIsSIUXXmZiyedF6xncL0i2PKslDMz/VZtP6yxZcwOkAwRO8M6B5y3RPPaD2VlnOFWYL79iOtURSpOwT5mVCw/btQqsv3y8lNq3UoPGbXKyr4hT2AcODBeWKDn3qyvCAScDzjiAVKGmi9r+ad0KSJ2xVDUHjO9ywAj+zAEovtE2JmokCaEUYTKKkKYbxATIcKNJfu6swwnMtMBrkVyt9cx9jC4mG+y70iTdg/DjFKn/BtShgx4o+eixInGdUcHLW0SgdzJcmDvRO69pWPcNZs8R59aXnAxIcCaXLU8OVUDIXgs58NbcxzAkWKq85/yGCL1mhr2URd5IDppq3md61twGbZeYzei+nQrRWGyurh59YAhUtGz5zpWCh5SyjBP+wSdohZrkOXYUYY39bG35ANNlzfNLPG82DACAM8aje00hlOP3wtyDkDTUW/EFZswW9izQ9cVSI5m1MjPM0blhoIdC+FJL8WOQStQXqWBF7R/XI2z7wkg8vgmWno4hV/q8HAgu95eFnmdoEHf3FSwnsEG4XyWALqdAX5Qww7cgfmSpjX5OwL0myriNfrDuxj8q6wdspXJFx0tQBRX6hl6xfbHATS6PzoSQHjwPJuWEWmje/SZppnWBlKWHkSCYBnHt1oSgefyYXsZdKdx8g6XiyghqjP5GlxLz9PMZ5YQ0/hBVAmSwTpfB9OEEUzmemXK8PxzmMCFnT9eM+LASAcjC77Q76wzWPTBCk6IPYDRVhwVOG3+goYBA9asxUNEZXpJ+1ZPF+TuPi1jMZs/DX8CK/hy9I9xRv+4pEQWfNiTvHv0PVssQjNHOvsth5benFgZNtX1IhwxkjKUi2b7Vzpg8aRaHUN627aV3TLqNQ7NssMoiT5+E5687kgJzySYMtQc+YJ9YbQN71VyhJ1VTNZAV16JqABFpqwJsQsnSX9A1JW6kH7+7q9DfUpBS9iaExoDLiwKTTWSgI+TdGxXbkyjA/C+2j/4M9TvGPztpOWjxv4jhvIamJLVeNosSNk3p50l8pe5gngNuW1ue+3155aDawyzgwWTkpxcpADwiaoomGYQw433VU8XaB6zSJqK+zBteh+WewCrMqYvbOU39N3zR3D6PGGjvMjb3MG2RU99HcNv1VRyBF1w5OARTbNphVPYcxZ0N/sx0l4zlJ5AmdXq39hYWPE8M4SulqY/CvzKqSlt1YwhJPII+pqh5+Xc7C+UN9MfrItFc1fy+N/xdeWiBU1LeGZP/SLWMw4G2BekS9+1oX6/WU2el8tclMt1ELke/H/y9YNUnOcQa+Pqp9q25jhcoXDnGW484+W+UtSPt4MRQtoJl+eMTaQyYukMSMqqE7sxU13r0RgE+m/gbwqo/AVHR+zBkXy60/r326hb0+VPZKbuHeucCKjfNPtLl+a20nnf4Mwp3Zq01fp4yV0dNhI8toCWm9vAwLP0F+z3u7TFv3QDscaqXZzjpKJPiUQrISgzagSGKwYRxzAX0uSEOa02eu19IkfGgIQ7yix4/bNeLwNXPbR40+9iGTGaxehcIrFThWvG55WRP+5wpsBQDOpxouKp8+oco31oX78cY89yK5oESLugPlNoetFx+jjj5kH23n9IhmK090fDBt5wHKFrHz2/Q/NRnH1imfHzEKap0cThGQFib9h5GALa8WA/H7suJEeg77fjEBD3K6h/+xEVHsbf26YuHBuCNk83+wwLJpyYc7aGo7SvqXB+dEOCpkyKj3vJ16+1514rjYA8DPbIP+ybBh9fzzUicdfJDqHQOXni/5Nmx5D+PtwfUbKumaPgXLDmkGJly16LHdXDhqtRq0lrrrnj1i6IbX5IE44OFbYMAWCznb8AiezmAXCem89neWGIMW3Rv+lt4c7dZc5Uv3ycJEgkqBjsDI0NxS2SWGXc0YMROtBbVx0db8/iDSsuyYPT6OT7DlpeRC4eE6XsCyyoA/V7EwigcB1ujlF0m3HUQchkY7vB42ytUcUaBG3NcgFAXylqnjvi7BP52rYNXaqpeAGRHe8XTLkzA1yyZNbI+WkfupB5kvMsfNAF4CM8nq6tuCbZHhfp1AlPdOYpY1TuqxAYEyq6hOdbMoXqUp+rTbm4aUkl+MTtr9636LTcMwpaFPOiLbBe09SOnln5eq3eZGpgrmda+g9XuEgmnanS4C3ndxs26TCAkl9c+UhONjSCp6/QEOtFCmuL3JpSOkBPHWg8BVNOC5R/o2an6BcHWNFksReWnbrBCDX0VqGJxYWTZhGfHNmmdua1aJiMpyqn4cImuxMjgEt/BnD4Y00yO8yQI9cAeF2dNdA7gWXXx/mBijE/HutILvrwtQOmWmn2ia3uRUSmPfUKyr7EJE2g9rTWVx04AU7pyeoBkPMFoPLBYG07S6Xq+7zGY=
"C:\Program Files (x86)\Cool getWeather\cool_getweather_helper_service.exe" /installationtime=1432845467 /AppName="Cool getWeather"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.exe" /rawdata=x7wnFaqbUNLBN/NWjPPFP8r93psoY1V2CiritPomCN/fl6QFU3OKwLY/+/gzaOQXQKl3DREfcxE8H5RS7qS0pc051134/b8hCwoWx8kwJezolq8/20YRBxmSJV2jJdKW+5dxNIROZhS0QlbQwZuFYh1lxLffPlBNSKDoc2zWpqBPLvPnzJUs68SeqxQ9d8/XZu6LH5JXO07PAnHSMwBwZSs2DIfEART/G+D2lipyBB9j1DRaTLf0w75lQOu0F3KoVmEUEFsRDiFEPVher2ImVemxct8rxiUgr6LKjijONhURVaZvrTqv9MdrytBA3bpOZTkKlnwJXL02asKAWDZ27jmQZ0vPcf3d7vP4GzGL6vYfQqcs7AqHf8qq4/b50nqnhEOExp/vDU9lGd8ePNFGhXKO/txbIfFzklVG5s+K9QmxtSQWS8K4CdQ7Mfl8+tI0Flssj3e7vNYQlPKMYwwhVTm6z+F3VQKT2lndJ8+vzPr49NSpKxoTQdRz6UgPyKSJP9YzKXAS54vhpksY4cSHHbSEAYsWTs28zFj+pZ+S6KqOpQ/4sEvnnQVJwd/dWW7HeH80DW76xOHYUeAfydA3cQ8i885nKsMfT7A6YAWPCop2BbV4jTMJJG+ToEbgE4OFmi36qVGPGOGhgsAe6k/MWSmd5OfvPcKjSLVTYuFvdUJZfbd1Xm6FIvje9FoE6jrRmxGzIzIH8yZQlYaivStLqvL9FGuSa7wUA0+vTwJm5X9aExsSK4gBZ7Q7ddeh05M1nFwjg/W+rCw/Xg9+9JpCNm6gvjUArRnr4T89cOt0SANJM+RGWvBwgTmJCy/10tN5GH3uPHcVHa8eFRFqxuO19x6trjfn58J3TICNS/DuFek/x7egh2EupxJSr2dLC+tAa8X0eL4PHPWVVPrYsiElzFf8/xng0YNsURNZl9zcYsL8XCYYjlaRSeWApc7omNRF2dLn/ZYWlHsvdmXG6dp1IDPm8KjmZvqXUuhX92MEKJOyKU/PfRsYIuisIdgeEeoYsDucJ1SxUWEVvdFNkrYue9eVjUbSm2Zw3fbuLUs3S40pzOoaWk2P/owqYsjBSF7cszDnHTTvaBqx/4fchc3VM323xUvowNXc1VDkfvbGaWYeacRNNu2JgRZK8Z7tKFzjY9tkWrUWc6pUUwD+iN/TMk+pQhs7lEBTaEsXlKnTxkuFAZlM/Fd5Nmfwdqpb14eRTx5wbNURZ8gudm4Agi5A4njBQi3ZZI9J4Gr7J1krrQRhNmrJp6U078DubpTdgWd/F79Pu3EJT9nlztgDIUcqhYiOTRRxNOTwyBxJ/1ma6hd+6q8Iko/VgzwFCduRlZe/ewgpAMgCeqV1YjMSnxfMtA==
C:\Windows\SysWOW64\nethtsrv.exe
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\netupdsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
WLIDSvcM.exe 2556
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 80dd8e43-28e3-4e22-990c-27722e4adf3a 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "32466480390710283-14830595171893181930-9323799025058866441693780691236051132
\??\C:\Windows\system32\conhost.exe "351896112453643461761679494121692368121078664225430809401183080820-1160178182
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2576
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-af2b9927-4fcd-418e-bb7a-e0782c4e796f -SystemEventPortName:HostProcess-7c909b45-7bf1-41c8-9e90-d5dd11142ee2 -IoCancelEventPortName:HostProcess-ecec0ee2-6135-4684-a8e7-2e0d2b2db8d1 -NonStateChangingEventPortName:HostProcess-b145662d-8fef-4147-920b-d555bb7b09b6 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:ba048e66-9e50-435e-a8cf-1e6d8c05abc0 -DeviceGroupId:WpdFsGroup
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe"
"C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe" /runWithoutUpdating
"C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe" --type=renderer --disable-gpu --no-sandbox --lang=en-US --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --lang=en-US --log-file="C:\ProgramData\GOG.com\Galaxy\logs\cef.log" --log-severity=disable --disable-pepper-3d --disable-accelerated-compositing --enable-software-compositing --disable-gpu-compositing --disable-pepper-3d --channel="5400.0.888542765\1113084842" /prefetch:673131151
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6764.0.2000958030\725851384" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,21,44,53 --gpu-vendor-id=0x10de --gpu-device-id=0x1381 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.5306 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/BackgroundRendererProcesses/AllowBelowNormalFromBrowser/BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.1.796309753\1182981360" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.2.1176007820\1891621460" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.3.821523351\857249505" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.4.201190441\631558441" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.5.1383761024\1499026149" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.6.34131251\824469281" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6764.11.637046143\623566442" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.36.1682189280\1277211382" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.41.445601612\2093576700" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.47.915791387\718764406" /prefetch:673131151
"C:\Users\Win7\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\AmiUpdXp.job - C:\Users\Win7\AppData\Local\32400\Updater.exe
C:\Windows\tasks\BYAIAMUF.job - C:\Users\Win7\AppData\Roaming\BYAIAMUF.exe /infocmdline=Mu8SFIwa33mfWamrE8z0/TxVs+lgU+4RcSDW0+AqYKCTr9MK4n2O/KOxod5roes4Xp+4OOM0MuuLc5n5+KmFL59gzSCZgsm0bwPmP/EdbXrcS9XFJHfy+a0hRs7MJACab2dyx51UYNxnTfKo/cpuYVZ7JzJMJUh3JIBAYR0UQrm3IYaQjEIii4qvgze/OpsFdxkWv9lbCe9+SUjCT5HuPvYmn8a93Fp6aL2gqFWrRUG51q0xnq02HvV14WWonniLtisoeLGMI+S65zGJMEOEhJkb3zxiYqTeKKVN1B6unNZyouz5SFTWFhS3ZGhM37KeqzpYkXS7ZNqOAbqPRBFf8KnDIAUemw2jScGMIFapC4OK5RUFHrggfChqixtrcIkZFpD+rq7hYPZC4HZOb0TGtYCY81Bk1XL/5LDSVzH7HqDBIcsBVGlP7StfFcxMET5ow+qC7OuldWgXJzhiRDLiLcQUtFrQr+MbtKEn96GypnKYhMGt13pWRp1o5QfjHRRgsZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\Windows\tasks\cool_getweather_helper_service.job - C:\Program Files (x86)\Cool getWeather\cool_getweather_helper_service.exe /installationtime=1432845467 /AppName="Cool getWeather"
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.exe /rawdata=x7wnFaqbUNLBN/NWjPPFP8r93psoY1V2CiritPomCN/fl6QFU3OKwLY/+/gzaOQXQKl3DREfcxE8H5RS7qS0pc051134/b8hCwoWx8kwJezolq8/20YRBxmSJV2jJdKW+5dxNIROZhS0QlbQwZuFYh1lxLffPlBNSKDoc2zWpqBPLvPnzJUs68SeqxQ9d8/XZu6LH5JXO07PAnHSMwBwZSs2DIfEART/G+D2lipyBB9j1DRaTLf0w75lQOu0F3KoVmEUEFsRDiFEPVher2ImVemxct8rxiUgr6LKjijONhURVaZvrTqv9MdrytBA3bpOZTkKlnwJXL02asKAWDZ27jmQZ0vPcf3d7vP4GzGL6vYfQqcs7AqHf8qq4/b50nqnhEOExp/vDU9lGd8ePNFGhXKO/txbIfFzklVG5s+K9QmxtSQWS8K4CdQ7Mfl8+tI0Flssj3e7vNYQlPKMYwwhVTm6z+F3VQKT2lndJ8+vzPr49NSpKxoTQdRz6UgPyKSJP9YzKXAS54vhpksY4cSHHbSEAYsWTs28zFj+pZ+S6KqOpQ/4sEvnnQVJwd/dWW7HeH80DW76xOHYUeAfydA3cQ8i885nKsMfT7A6YAWPCop2BbV4jTMJJG+ToEbgE4OFmi36qVGPGOGhgsAe6k/MWSmd5OfvPcKjSLVTYuFvdUJZfbd1Xm6FIvje9FoE6jrRmxGzIzIH8yZQlYaivStLqvL9FGuSa7wUA0+vTwJm5X9aExsSK4gBZ7Q7ddeh05M1nFwjg/W+rCw/Xg9+9JpCNm6gvjUArRnr4T89cOt0SANJM+RGWvBwgTmJCy/10tN5GH3uPHcVHa8eFRFqxuO19x6trjfn58J3TICNS/DuFek/x7egh2EupxJSr2dLC+tAa8X0eL4PHPWVVPrYsiElzFf8/xng0YNsURNZl9zcYsL8XCYYjlaRSeWApc7omNRF2dLn/ZYWlHsvdmXG6dp1IDPm8KjmZvqXUuhX92MEKJOyKU/PfRsYIuisIdgeEeoYsDucJ1SxUWEVvdFNkrYue9eVjUbSm2Zw3fbuLUs3S40pzOoaWk2P/owqYsjBSF7cszDnHTTvaBqx/4fchc3VM323xUvowNXc1VDkfvbGaWYeacRNNu2JgRZK8Z7tKFzjY9tkWrUWc6pUUwD+iN/TMk+pQhs7lEBTaEsXlKnTxkuFAZlM/Fd5Nmfwdqpb14eRTx5wbNURZ8gudm4Agi5A4njBQi3ZZI9J4Gr7J1krrQRhNmrJp6U078DubpTdgWd/F79Pu3EJT9nlztgDIUcqhYiOTRRxNOTwyBxJ/1ma6hd+6q8Iko/VgzwFCduRlZe/ewgpAMgCeqV1YjMSnxfMtA==
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-7.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-7.exe /rawdata=gHDwrUzuNjqMyrD+XrvYSVaVOZN7dhpfY0NNwy3RjAVssJfowOEsC0HMknIFo25kw87VOOXCqUT+LRKXInevR8SihvuKO75FopIY94v9jeJieHQ1IWijD1PeXArFFNmbwJQFDBI2GwRjZFsQ59jtmRGcgEdMD6J2FAacEdj8t5VwBjfICkDwrIlbvL6PI0CJOHJMViQf8kINR1UsyjYNMGqoYzAPl+1z+ycoPwjLLu6bIB3m9Fg19LnmCXSWDCDpxQyZvXSShZBmi2eVPwq+FXiiqIKo2oLcR/xxMA6ItlHlNDP8YyPAW4vDdeVqEeRLqFkzLgorA69UUFjzGVksiBwEbjdR/4N0YxrY24//Rc7vnV9QOKZg8rm/BzBQaSCHzpklfulBFkdTZESQTVFxMcp0VL+NF8lSOyhyq3lFpuj0xnLoQOLxtT23zZfOLlXVyhnSlKmwg4aRxYjos0WhhtYI2kMwGOKu+JTIF5eRGl+1FBEc4qf+ZcWI4Ya9hK0VGa4PUZxuweISQ8KodN87kXmbq2S5b+iHPTaYXi7Dl+db1krd9yitx6yLPYaj1aL4EqBSBXSLL136Xxk7PAXbnd1Ezqze+uKUJX4Wp5ZMJ5HBPKgSSu0zgVZpwlVKrNp5uhs7emmSvMGmHmNFyLAtnd1YJZjXZyCWKE0OYP2FKGpW+TcqJRJWDHUImsLQ7Bphnv9SzskBjIzM5qKh2pSS/qc/4//s3yw+Onr8IR5kEAeqryzyItCFPW8dw6+wxmrzUp3QMRh1o+TgZJnTTsbhylv87r4rnF4ND593eMoNZIkcQzzIgDiPWWL1Ws7s+o0mej/0hO2ipwy7k2aGddWzlEHYyVtWTcPtKvlM7gtmWzSlNaDeL0jRjfhFp7GAM9+22BvHUCHfrrsmfLxYdMXx6bPqgJ+6yLngD4891KV5aSJFBr8lPaW1v3IR1tVbmUcfTSQPF5UYfLKdpRdKtxyJO0yQgiAo7cN+33nm+efBgSoQwRiyo0+ytYxyMTR3FhgXXf85IHjB0co0hFxOkELAsxB/bxWpX5qRVYZzoboo19FYQaQu0zqwJdmDs/3Q27OHxKfvM6xneYv+zi1iMDgMTcbLTJDwVXnKsmM9+qLrPp9FH/Ufx3sYTKjNEP1CyiT8bRC4xMgiPCjsic7OyWm++yOKzL4CQV2b8quie3WRL3WXTH7NdJfCcyZ2XhLYI2hIkSQGdWI4TVRR8KDTJhpWANF7t1BWcAfDbCM1Gk3ZGEl7OZ7WxZgen2y1U1PyMk8iW6l9DEnoKQ+R998keEeGvPX+IivBJIdtA0fmfhIjvvBUbmwU6qP7H1i6JMiGdbS04DGJlqPPTVQyoRex6VaYPC0Zue/zVmndPW/BtIlhWdLAftD9qO37rkUnYX3+PP1V9+QFj8H8NV4V2Rq4hwJdundwgSbkX4G5FOLFKClTbCv1vFTpiKCXtfFBsd8DX3A+rzRB7PkiKQhPf4nzFTXNxCL0w8Cd8s/n7qyzZGcHLSDThZvwi7pMGBLLwQ5+0GDU
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10_user.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10.exe /rawdata=eEnyDGZpyx/yyAOlo/+Kf8CNUeaTqIgXxYpTb0rE2zn29AD2luDqSCItOwOnBT6gF2Zj4TyoTKHXWS9AT9qFm03SSq8MSQQo0DDINMOebydOaZr9JNTD1VndPBGuwer5AXEOKE/X6l1fbbECI7H6ZqL3Y2pBkqlIMSLeON7VABdyOcwQ55uLr1fUoVpyvq+rsD1lQYM61Ps+teLZ/CHAzE+wsDvfEX2d+Xv+KfrQVn6dp5A9b9jwXeVvinhGVdeTeb546B8ug21Ar3PLbXYf3eYVWeG7vwq7UUXM+IJdV1hYNbYhb2RPOKEWmg+tIwL5DAiS68B9SBFp67gWPfuFaki/unkvn/nPub6FqwbZlQVdQ/eA68/MG6wbVrme7RzfruGiR+gDbI9U3kSKjfiJ3LKKdjURzi+1S0O/ukacgCN4RcPnvUorU61XkLmXG+crZ2seLrJw9rkIDk5sR+4MiZWjIkjx9Bch2nlfcax/FzML6Pn3qYQhMHkxzMwNH26ZqtaHSyopyptjy5PwOjNwNQLj2BxLVI+wIFVgqR4NdC3ibitq+Rw1sYRfvy7AGxgaEgvoO0uUtTHubXVMI0tzhDHZDwEhWRtqB55Q0e8G/+r4erJ61jVs7d04D3ko6S1zDxazyArKz8UIySli3RBr68V1BnFctAexZLcACzHmBbN3kkGmAdlIdnvD2+xgM2ynda4EVXA0fMtByuWL93EQ2ymt2X2VMiumzNDNqOCvxWuhqbhXHAcB5f1kExaodoTuMjzuNG7WEsi0unnYQ3MWpzRSiPq6fx5kdubtCi5BS4GgqtvGlG+SrFl7RslVyd6D6EOAkMUuBTCmw06/p8k03A==
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-3.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-3.exe /rawdata=eMbYeuVSliNax57Luq95IskpqGmrlxHRFxl+ZOsvTzjPG0PjNElf961jaIPe0s5qMasYkPrII2lXyyCQP70e46rA20M4HAgQlOYu7fE3S68u7XeT8lsqQYVxc7p+Jjbz+IpHB1G8yZ+hej8zj56ENmAbR53XyXuZWM7Jx+/1MA04si3bqLbmHpsxEuxYZBhYszKpGly749M4fKmaeTBwV9CDgpP85fLrIEkipZzBgdtrdAK7erGmMouZ3/Roc9fKrv3rBpOqMWKQMWiImLcdl3TyLSQtheYvJNwUny4IbuFSMgQdCd0bQy/HIsrSXuTQBoQc64No15JzlEx5p/1iZitH0DIejKVEsuYUFrUDAJ5cSaFU44jE0spYnF0TaBGb59eN+HO6Xf6YgVQgN0+lxwmt6WheQq6aftfJ3GuPj3WJlAaa+HO8rFnCF00xBEm4rn2sJXcbrhDWQzhF5VPROOMtIZt2W5S7+3zWxqVYg6BJcxlOnM43T4DzE12jnXkUqrkDmBF8MlG1vOUtg5+00OfrBtK5kFCQpv1Xh//x/RRylSuQKWNtlmrI95EEan53gKe8hFpRLwtOPeBG1SLS9SaoKbGgiCGXcXaFKnZGXzPXxooMyCHrtNAna70vCXaDC9VsYbr+/nCt2gnRsaPFjHY61Mw3/zb2jsImBk/s5EOxdKJHI7Cliot5OClFZKhCgyjyjs2LpD6BeIIM8OxzgFcJVhD8PNP6KEjGavZ2XFw0wfRbCkHbi4BkyNDsIZJS/b9ES9F0RiCZ/ZnMlaYxqHmfzu/3vhVcfO3MggouBWmvq5HB14VMFip/wJiMAEDm3Dmc9nDzE5gPd2XlTGgjW5oLd+pZjbDGyI55c3Ukg2NHqEhqk8AVujy8G6SE6CZKLOvu+n+MBuIEOkVjvKWog1BafYuxEn+CGEr0HMDe6ZOkvGzncwVUVfe6GZmcjOe7T3BVTqT/5YQT6qBR2ECEm0oYREQ+3Rp3Gh5UNjRdr6zkPf8RlwLB/lPR50a/Qw4rvIVm7uZwqomoxB0KcIC37L3yeSZtwhhiQqWAHaS2c0ha3wFy2EUGw0UGJFZBMQhHvvMEInS11qo37A2kF28ihDIxH6Em8rCy0sAD1lylkZwaI6QsOsIKjRIXuH3oQWwh/AvTx90omVqoKWafOeUyFTzbN1AnixHIGL+sTYD7rC8uf43z8dHrr7xjwbcYHNjD71OpugjMA8ndPQ1kzfXq3kf/AjwrRMlXE87la19POJIvwmKfTyncfR+tW5s8HY3ow43CRb0owF7pfcILYc0J4TxL3S06yIJ/2AoF+nyaWuuUTygV3TipWvP3OJJ9oL7bs8zvJk7hPaGLd5cBLhOWlptj018yC/pPp0QBb7c+fWA5mxpWvuVa+q+hg835nXH9zk5Z0owU1uFXX9nmRXLSXxKZ7lmQa6SZ/QHtpKg2nKQr207MsZERbwTArdu1OhaXYuG51FGBGhLpdIqLZGSowPsEqLADgu9d/6vkZ/lb/DP9JM7KnOrujQ67fGBcfBlDcQfnoCUx/FcX5pZMNw50/jM6f8V4Ysu+7X7s6H0Z2bPhbjviIfcJluxKNe6CIQfcgI0YDG56my080C+thDsoj2v3B5HrtKm/0ynO4GtsRQfwMC4n40Iz7rIJST7snaOm3U19DZZ+OkPE9Kjb66n4QbPgxOgczxahABwae90+fAaWyO39awwDwjfvIcBZ3xcF4zyQ+eLm/2ttU3z3S0KBNYS3jyihI68EUwQF/nRlI/nSK0N0WsqmYEuwkZlBVaivWOVqdecnd3L+vCJGjY/QR027/XWo5kW7MJB7j8sRuxuHOaD622NhtdGUThdY2TvsK2E0G6Tba2G8+Ec2HkW3Z5cSLvMcXjZdVqup9oU9hxJgEs6pNxFNuzlyNsMQrD11Sjd+Xp7a9qoiO+v7/XoaJAkxWrGReVc0o5hRfCtyI/m3DO6wIuvzfQPPSOr/3soaxGgebOiBAdcYe+v595easdoqa49ugPwvf0cR7HEjchhC/o9wBq9ceZjm2ltFgPiP
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.exe /rawdata=WP1sPNwr7pWSrlXSgT7JbQxTXV477Xo72sFuw4XQKFL8q39aVKrWcBnomPoAL22/ngYMmqxO+nsjPkda/lTh3FOdU/WmHIVM85L6SyvxPyzUNYmgEfS5tYg25XNAiVpTXD0dauPpkRxTpqwAITbc4YuktUIbA/a4GUuRWth2O8pdWo3ksGTYaUeum5i7vZoQ5Xwa9HVqcL2nLk9YcFnbKvoKdiDNmehxzqjWdwrUeaCX2UWMJnqHwdDoYJREJHRoq80eTYAuxXznhPzFTLhT6R5UC3H3Thx9oLERSAkJwQAEI3/+PKq+R4ZF0PEZs/V92+p1cptn3qpsfwsX36suta5Q++nlmVef5rs4chuNqenvamuOmuA2t9qajc73J1grAdd812CTIx8foMgPZWiYoCjySF+1GnLF8p8QcvLW8je0qAx+CnFlpY9CfvMHcla/qLmHcYIKEkVXNilZfgC2g0lpOXMwaCU+HyRSON5HSzPNWnCoifOy3tStVug0P4itp6hAb2RIu+Hk/MQfmBXBOKtejiUjVSEoF/0U0hWP6dyu+DIe8yGtbwHL2Z4SkOBGP405Fe8gaye3XjgtIJ0N/cCpi/NNlBxHC9nKd16C0QY3/gb/ZzKyZBf19+TGW6aXcwQBlwBnkA/5aWDUmLD5id0CrZGZNJPSMgbNQjGBQBs2jwpJBOvJjAJ7iCVe6dBx+hy2fnFItgt1G1D3HQxiTBSPMCh9o/UpZz7k5IzbTjUaHRrkZZqR2TQ0W/EX534ph5Dc+ifjM/DQCt2MQbcJ4lgP4XxACcd41QaSOgUBK7FtasgqjUpNvALBm03jZdMpVJ1YiYe7MZcVUgdtMpYHI4YOLhotLFamYaFgdYxyrJM5xfGm8ZjL9hZikpMmGXSaNrQk6ykeQsAeVlurnA0bLtMbo0jEl02q0q/YqGRxYWFN39Ydy/OO/Zn7i0gMfjdYnB3rn3hNrKUhXhmH48dTxnUaNsSGPSBxSovo3RJxwGLOs4nB9kWWcvu8Y8+T8UVl
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5_user.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.exe /rawdata=WP1sPNwr7pWSrlXSgT7JbQxTXV477Xo72sFuw4XQKFL8q39aVKrWcBnomPoAL22/ngYMmqxO+nsjPkda/lTh3FOdU/WmHIVM85L6SyvxPyzUNYmgEfS5tYg25XNAiVpTXD0dauPpkRxTpqwAITbc4YuktUIbA/a4GUuRWth2O8pdWo3ksGTYaUeum5i7vZoQ5Xwa9HVqcL2nLk9YcFnbKvoKdiDNmehxzqjWdwrUeaCX2UWMJnqHwdDoYJREJHRoq80eTYAuxXznhPzFTLhT6R5UC3H3Thx9oLERSAkJwQAEI3/+PKq+R4ZF0PEZs/V92+p1cptn3qpsfwsX36suta5Q++nlmVef5rs4chuNqenvamuOmuA2t9qajc73J1grAdd812CTIx8foMgPZWiYoCjySF+1GnLF8p8QcvLW8je0qAx+CnFlpY9CfvMHcla/qLmHcYIKEkVXNilZfgC2g0lpOXMwaCU+HyRSON5HSzPNWnCoifOy3tStVug0P4itp6hAb2RIu+Hk/MQfmBXBOKtejiUjVSEoF/0U0hWP6dyu+DIe8yGtbwHL2Z4SkOBGP405Fe8gaye3XjgtIJ0N/cCpi/NNlBxHC9nKd16C0QY3/gb/ZzKyZBf19+TGW6aXcwQBlwBnkA/5aWDUmLD5id0CrZGZNJPSMgbNQjGBQBs2jwpJBOvJjAJ7iCVe6dBx+hy2fnFItgt1G1D3HQxiTBSPMCh9o/UpZz7k5IzbTjUaHRrkZZqR2TQ0W/EX534ph5Dc+ifjM/DQCt2MQbcJ4lgP4XxACcd41QaSOgUBK7FtasgqjUpNvALBm03jZdMpVJ1YiYe7MZcVUgdtMpYHI2llXHlv0V2pCyMixRyjyv0TaosvEu1MD3gsnsuON3OhfDxEzKPoYq5Me9+EuABbaNODolEq0QOrmLObpb9jTe8aV7MnvagmCv2R9YDDbWfhrBXQDnJuuQl7KdcSpCPoSGQEbXq0rDWt00evchhDak/8NHI8ez8lof65fTDnc56s
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.exe /rawdata=JQ4Zgg2iNy+QL1ZEj+NQU6x8a3wRlJM1HnH7aZvi9nAR0lR0s88Oy2nYovQeE0byS6g8hnHLxdEPlOecZ9XOFDZ8nG6tgpCu5SP5JUzeEFBDQqGBX1XthGR5XUrwC9fmHC1YsjkNqHeFjeunHE99SsTCeApSipvROuQKogMzDR23uZz86XKAx3DVehq3/Hizd5EzTEr2AX9y23I3zu6dN4EAhMQ7ADis7GCkaq/j4QtT2Lq5Qz0jOujndhQihMdWhYPc9z87C+e0Vw9c7dthwWEP7pLOCB/E4C0pi5uFQx3LUDvIig8PlOPzTdMSO9zhqEqyLTWXLIZx//C9N5A/OcX+XIsSIUXXmZiyedF6xncL0i2PKslDMz/VZtP6yxZcwOkAwRO8M6B5y3RPPaD2VlnOFWYL79iOtURSpOwT5mVCw/btQqsv3y8lNq3UoPGbXKyr4hT2AcODBeWKDn3qyvCAScDzjiAVKGmi9r+ad0KSJ2xVDUHjO9ywAj+zAEovtE2JmokCaEUYTKKkKYbxATIcKNJfu6swwnMtMBrkVyt9cx9jC4mG+y70iTdg/DjFKn/BtShgx4o+eixInGdUcHLW0SgdzJcmDvRO69pWPcNZs8R59aXnAxIcCaXLU8OVUDIXgs58NbcxzAkWKq85/yGCL1mhr2URd5IDppq3md61twGbZeYzei+nQrRWGyurh59YAhUtGz5zpWCh5SyjBP+wSdohZrkOXYUYY39bG35ANNlzfNLPG82DACAM8aje00hlOP3wtyDkDTUW/EFZswW9izQ9cVSI5m1MjPM0blhoIdC+FJL8WOQStQXqWBF7R/XI2z7wkg8vgmWno4hV/q8HAgu95eFnmdoEHf3FSwnsEG4XyWALqdAX5Qww7cgfmSpjX5OwL0myriNfrDuxj8q6wdspXJFx0tQBRX6hl6xfbHATS6PzoSQHjwPJuWEWmje/SZppnWBlKWHkSCYBnHt1oSgefyYXsZdKdx8g6XiyghqjP5GlxLz9PMZ5YQ0/hBVAmSwTpfB9OEEUzmemXK8PxzmMCFnT9eM+LASAcjC77Q76wzWPTBCk6IPYDRVhwVOG3+goYBA9asxUNEZXpJ+1ZPF+TuPi1jMZs/DX8CK/hy9I9xRv+4pEQWfNiTvHv0PVssQjNHOvsth5benFgZNtX1IhwxkjKUi2b7Vzpg8aRaHUN627aV3TLqNQ7NssMoiT5+E5687kgJzySYMtQc+YJ9YbQN71VyhJ1VTNZAV16JqABFpqwJsQsnSX9A1JW6kH7+7q9DfUpBS9iaExoDLiwKTTWSgI+TdGxXbkyjA/C+2j/4M9TvGPztpOWjxv4jhvIamJLVeNosSNk3p50l8pe5gngNuW1ue+3155aDawyzgwWTkpxcpADwiaoomGYQw433VU8XaB6zSJqK+zBteh+WewCrMqYvbOU39N3zR3D6PGGjvMjb3MG2RU99HcNv1VRyBF1w5OARTbNphVPYcxZ0N/sx0l4zlJ5AmdXq39hYWPE8M4SulqY/CvzKqSlt1YwhJPII+pqh5+Xc7C+UN9MfrItFc1fy+N/xdeWiBU1LeGZP/SLWMw4G2BekS9+1oX6/WU2el8tclMt1ELke/H/y9YNUnOcQa+Pqp9q25jhcoXDnGW484+W+UtSPt4MRQtoJl+eMTaQyYukMSMqqE7sxU13r0RgE+m/gbwqo/AVHR+zBkXy60/r326hb0+VPZKbuHeucCKjfNPtLl+a20nnf4Mwp3Zq01fp4yV0dNhI8toCWm9vAwLP0F+z3u7TFv3QDscaqXZzjpKJPiUQrISgzagSGKwYRxzAX0uSEOa02eu19IkfGgIQ7yix4/bNeLwNXPbR40+9iGTGaxehcIrFThWvG55WRP+5wpsBQDOpxouKp8+oco31oX78cY89yK5oESLugPlNoetFx+jjj5kH23n9IhmK090fDBt5wHKFrHz2/Q/NRnH1imfHzEKap0cThGQFib9h5GALa8WA/H7suJEeg77fjEBD3K6h/+xEVHsbf26YuHBuCNk83+wwLJpyYc7aGo7SvqXB+dEOCpkyKj3vJ16+1514rjYA8DPbIP+ybBh9fzzUicdfJDqHQOXni/5Nmx5D+PtwfUbKumaPgXLDmkGJly16LHdXDhqtRq0lrrrnj1i6IbX5IE44OFbYMAWCznb8AiezmAXCem89neWGIMW3Rv+lt4c7dZc5Uv3ycJEgkqBjsDI0NxS2SWGXc0YMROtBbVx0db8/iDSsuyYPT6OT7DlpeRC4eE6XsCyyoA/V7EwigcB1ujlF0m3HUQchkY7vB42ytUcUaBG3NcgFAXylqnjvi7BP52rYNXaqpeAGRHe8XTLkzA1yyZNbI+WkfupB5kvMsfNAF4CM8nq6tuCbZHhfp1AlPdOYpY1TuqxAYEyq6hOdbMoXqUp+rTbm4aUkl+MTtr9636LTcMwpaFPOiLbBe09SOnln5eq3eZGpgrmda+g9XuEgmnanS4C3ndxs26TCAkl9c+UhONjSCp6/QEOtFCmuL3JpSOkBPHWg8BVNOC5R/o2an6BcHWNFksReWnbrBCDX0VqGJxYWTZhGfHNmmdua1aJiMpyqn4cImuxMjgEt/BnD4Y00yO8yQI9cAeF2dNdA7gWXXx/mBijE/HutILvrwtQOmWmn2ia3uRUSmPfUKyr7EJE2g9rTWVx04AU7pyeoBkPMFoPLBYG07S6Xq+7zGY=
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-7.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-7.exe /rawdata=xxPIgFYZH9v71P974Qkf0hgMD6tf4MTx8VNWZG09m9p0R1K3Mpq4rsbosnd12Bvi2jYuiAQE6Mv7itz0dkSQS7bYWnoohNNTLWiFU7HlnlBKGAOanFQjbTaOdr9lVktXFDh6aJwXyBgaBmyl0TAqgOaoFmTutNxGVhlh2K5XWtYYf6Cgzahu5oQtPJk+5TsopeWiKCy8fXp9vdx6eORbqtzSCXeRQhjR7Gh1Y4zXfTrJOQsgmJs4blLxaYkpzn4jbGHTts3EJZdJ2ZFODbOuWGuKNEFKZPMBX+mAoGCIJJKEmWs75S+H/TguymbvUK/NMtx52ZaCTtMHo4CeIhbRuFcYrR1vy1ocGW3EO6rLIhiKnuF3bAfIeYq0IAMtUIYr7VbcDWXe22CDYyJ++4LqhP7PW9m50ikdtlrgyfSLkgP1CsKq3am0leIRggfv90d8g8Jwi8IRipwJO3NKRhRRG7wae4liKsXcIG1MKUGPE1TY9q9L/rHMU9EFVPhYEBV4GDb6VFGLvmLH3ZLRxIk6iaUEr8P0zNol08N/YkgFtK80rSDDOVJRRUkNgfRIXdshMvNKzKhz8AV011+8ODBuew1CuJy1+Bna1Up4c2FEpDvSqcGWZ2TIbFAUWJZstqbz5EJh6LhXpzm8OpF11rSi3oGFKNDBFbucJegeTBblx29EjGefpHtTVM9g+s28WY3/V6WMtPzzDx2rCvMwP4UocnKanNRAn1AcNj1ETOSVCjvQAckxVqXAgY52GnBwoS5D7dKC/KTUOCkG6FlUYVlSj32QIlKKQ4u2t83g0Te1cOF7qrtKDzuuKgYDpl1fY3z7/KxIfItJ5b44nBECE+f/qrJAbDuShOIiwPRDW4GsTfxe6y0LH+8Dvf2PJLIFkF2QwJu/6ObOBAGj2pHCgpHJ+bvMMgzcHohGQzVK2J/nCV1dbXmZFp0NyC6TptowKyxFhrEurikJ5KSv7M16lhWNRsLDjygAQbazZ1E9a0iCLOWp3zDL71CFynZEvCBNX6y1sSx2bIahNI6iEFgWO8PEMcz4zvr5iD7Xn3jfJqReNrePkb5aAT352E502cchKPQT2KfshO4HNEf7fQPTsB8dfBN058PIK9z+Zq9LJkHOoK/9DLVsgpA0arHfQKbZnbe7tk5PIW+SjkaOeRsBtaBlyd99bCp/P5fjk2dQj9EmxS8k2BMBzb1PwKsOSVMNU4wAy3OJeEyEGmuqffLKpc8ZxQ0F/DMRWrExc7DOZiQvVc6yvIikTw75QJbC8i0o8CDikcC/bjt5UU6qO3f/vaA58BebzgZWEBp1ydsNkv8uZStclA65DFVugUaQotAHJPQz/XnQs/ubfi2A1xwBzsx4/Jj2jj2bgIKlL9u9xktLEuKuuqJP73cOkbUeETmswDKEb9gkx3wvAetUu2tCk+FTowonhhsbjzLUXBMrIP8oqHgcYiMsw3OYIZEmok2DSUYq/wAHJ9FZQYuxj8NBTW/42cHRhcDLloxb5l7DzSzwIHV2fgXafO/79913ckyPyfE/ST/vMApXWP8PAStLoDLT4HOuXHBMB7+RSsnVBCHxOKtPFPoQFBiLWZ1oHxCKTam1Yv7eoRmjK5rHW1GWuSjLnYIzOgJ1rOVQ/g82OLC5koo7gxcaI18rqFKDzqOosYhLDrPliGaT+GFE2Z8hEWk1Wch9o+KDnWT67G3COjhLUsgjZI+sy8xMQ+aa6obfhYYIQ1pPb7sYKog82QX7yU4SkzkP+wR+ufD3CfVZJR/M7UR9DcfYFr6YNw2oB2g+CxwumCQTdk2+8UVBVtJAY1NUGqDykaiVpUsNA0zUAiPBlG9HFDXI/ZKWF1hLu3T6kBxxwkJwS9F+jXGSFY0sKud3S4HWjZX7aSVYYctnUGDk6LqT3DloxSp4qjOiLXavBZVmooyfkIzLXI5phAMlATq3Yjzy56M9+T8YSyU0KcvQJOKtrub34h2ToA6RUoS136XbvyqISc4OyHJw5effS9OzqUg6V8lMMdM9V3Qfz79JXqueXlEWyPbrcgXhc3Eta6SRUIrNyqatXNjmQd1/CM/jMXDxHyfkDPVw+VH/4v0aMRynf2AlIHvwc8fqA6vmNZr6VefUPfiuSbOTL7xjlLtB+ctGcYIJ0T5zKngudSlSlVHhx7yXUqIJrN/AhJc+nCtaMZ5ZHQ9jotc4gboE9GJF+k/q5tZvyjeV9Ap5Raf7/5EflfyH/5ankn1r5wrnQCHafgWqxQ6lTPtFdE1ZyVOA1Oq+uAD4CM0+TlQN54z3IjBqJkeAiOv4IQQr6nUxX5F34B4jRMImXmJKIDnLz+9CE6lfSofsgIob+vEcvJqSIiV2jwep+WyHl/DnqzuOCTF1dKEDQ8zjQ+TAZIF29fGGOiwaYCfnPtIP43hKuriZc37JrTIX60jmoi/7eU1X4ytutCCyteg4zg46mgDdLAAoBY/qmzCpEECoGWv6SbFg6/1f0y+snIu3vZfHNc/CNDdFSMRPLa2iDILv4IRssqzkSsLuZPWF6OzuByXtqsnSKYMOo4XHWrWTCQfvkkfruHM/
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01 2133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-05-23 2754704]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2015-04-30 1337000]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-05-23 1571696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-04-07 169768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2015-06-04 2892992]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-06-02 28787840]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-04-23 8204056]
"GalaxyClient"=C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [2015-05-28 7457336]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2015-05-21 4471536]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.FPS1"=frapsv64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-06-12 12:54:55 ----A---- C:\awh8046.tmp
2015-06-12 12:49:17 ----D---- C:\Windows\Minidump
2015-06-12 10:46:08 ----A---- C:\awh59A3.tmp
2015-06-11 10:22:43 ----A---- C:\awhE7FD.tmp
2015-06-10 11:28:08 ----A---- C:\awhCCA1.tmp
2015-06-09 21:58:07 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-06-09 21:58:07 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-06-09 21:58:06 ----A---- C:\Windows\system32\iernonce.dll
2015-06-09 21:58:06 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-06-09 21:58:06 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-06-09 21:58:06 ----A---- C:\Windows\system32\ie4uinit.exe
2015-06-09 21:58:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-06-09 21:58:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-06-09 21:58:05 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-06-09 21:58:05 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-09 21:58:04 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-06-09 21:58:04 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-06-09 21:58:04 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-06-09 21:58:04 ----A---- C:\Windows\system32\urlmon.dll
2015-06-09 21:58:04 ----A---- C:\Windows\system32\iedkcs32.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-06-09 21:58:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-09 21:58:03 ----A---- C:\Windows\system32\msfeeds.dll
2015-06-09 21:58:03 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-06-09 21:58:03 ----A---- C:\Windows\system32\dxtrans.dll
2015-06-09 21:58:02 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-06-09 21:58:02 ----A---- C:\Windows\system32\iesetup.dll
2015-06-09 21:58:02 ----A---- C:\Windows\system32\ieapfltr.dll
2015-06-09 21:58:01 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-06-09 21:58:01 ----A---- C:\Windows\system32\vbscript.dll
2015-06-09 21:58:01 ----A---- C:\Windows\system32\iertutil.dll
2015-06-09 21:58:00 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-06-09 21:58:00 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-06-09 21:58:00 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-06-09 21:58:00 ----A---- C:\Windows\system32\jsproxy.dll
2015-06-09 21:58:00 ----A---- C:\Windows\system32\ieUnatt.exe
2015-06-09 21:57:59 ----A---- C:\Windows\system32\ieui.dll
2015-06-09 21:57:59 ----A---- C:\Windows\system32\ieframe.dll
2015-06-09 21:57:59 ----A---- C:\Windows\system32\dxtmsft.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\mshtmled.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\jscript9diag.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\jscript9.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\jscript.dll
2015-06-09 21:57:57 ----A---- C:\Windows\system32\wininet.dll
2015-06-09 21:57:57 ----A---- C:\Windows\system32\msrating.dll
2015-06-09 21:57:57 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-06-09 21:57:56 ----A---- C:\Windows\system32\mshtml.dll
2015-06-09 21:57:38 ----A---- C:\Windows\system32\wmp.dll
2015-06-09 21:57:37 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-06-09 21:57:36 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-06-09 21:57:36 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-06-09 21:57:36 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-06-09 21:57:36 ----A---- C:\Windows\system32\wmploc.DLL
2015-06-09 21:57:36 ----A---- C:\Windows\system32\spwmp.dll
2015-06-09 21:57:36 ----A---- C:\Windows\system32\dxmasf.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\invagent.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\generaltel.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\devinv.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\appraiser.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\aepic.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\aepdu.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\aeinv.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\acmigration.dll
2015-06-09 21:57:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-06-09 21:57:29 ----A---- C:\Windows\system32\KernelBase.dll
2015-06-09 21:57:29 ----A---- C:\Windows\system32\kerberos.dll
2015-06-09 21:57:29 ----A---- C:\Windows\system32\diagtrack.dll
2015-06-09 21:57:28 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-06-09 21:57:28 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-06-09 21:57:28 ----A---- C:\Windows\system32\lsasrv.dll
2015-06-09 21:57:28 ----A---- C:\Windows\system32\kernel32.dll
2015-06-09 21:57:28 ----A---- C:\Windows\system32\advapi32.dll
2015-06-09 21:57:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-06-09 21:57:27 ----A---- C:\Windows\system32\ntdll.dll
2015-06-09 21:57:27 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\wow64.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\winsrv.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\tracerpt.exe
2015-06-09 21:57:26 ----A---- C:\Windows\system32\srcore.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\schannel.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\rstrui.exe
2015-06-09 21:57:26 ----A---- C:\Windows\system32\msv1_0.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-06-09 21:57:26 ----A---- C:\Windows\system32\conhost.exe
2015-06-09 21:57:25 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-06-09 21:57:25 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-06-09 21:57:25 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-06-09 21:57:25 ----A---- C:\Windows\system32\wdigest.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\TSpkg.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\tdh.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\sspicli.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\sechost.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\ncrypt.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\logman.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\typeperf.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\smss.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\relog.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\lsass.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\auditpol.exe
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\sspisrv.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\srclient.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\secur32.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\ntvdm64.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\diskperf.exe
2015-06-09 21:57:23 ----A---- C:\Windows\system32\csrsrv.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\credssp.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-06-09 21:57:22 ----A---- C:\Windows\system32\wow64win.dll
2015-06-09 21:57:22 ----A---- C:\Windows\system32\wow64cpu.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\user.exe
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-06-09 21:57:21 ----A---- C:\Windows\system32\apisetschema.dll
2015-06-09 21:57:21 ----A---- C:\Windows\system32\adtschema.dll
2015-06-09 21:57:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-06-09 21:57:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-06-09 21:57:20 ----A---- C:\Windows\system32\UtcResources.dll
2015-06-09 21:57:20 ----A---- C:\Windows\system32\msobjs.dll
2015-06-09 21:57:20 ----A---- C:\Windows\system32\msaudite.dll
2015-06-09 21:56:48 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-06-09 21:56:48 ----A---- C:\Windows\system32\comctl32.dll
2015-06-09 21:56:46 ----A---- C:\Windows\system32\win32k.sys
2015-06-09 21:56:37 ----A---- C:\Windows\system32\drivers\stream.sys
2015-06-09 21:47:12 ----A---- C:\awh27CA.tmp
2015-06-08 11:03:04 ----A---- C:\awhA8BC.tmp
2015-06-07 01:07:45 ----A---- C:\awh4623.tmp
2015-06-06 10:56:13 ----A---- C:\awhB99E.tmp
2015-06-05 10:28:47 ----A---- C:\awh426C.tmp
2015-06-04 11:51:39 ----A---- C:\awhB17.tmp
2015-06-03 15:27:11 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2015-06-02 22:04:20 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvopencl.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvoglv64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvinitx.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\NvIFR64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\NvFBC64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvdispgenco6435306.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvdispco6435306.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvcuvid.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvcuda.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvcompiler.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-06-02 21:45:11 ----D---- C:\ProgramData\boost_interprocess
2015-06-02 21:45:06 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2015-06-02 21:45:06 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2015-06-01 22:47:03 ----D---- C:\rsit
2015-06-01 22:47:03 ----D---- C:\Program Files\trend micro
2015-05-28 22:37:46 ----D---- C:\Program Files (x86)\Cool getWeather
2015-05-28 22:32:04 ----D---- C:\Program Files (x86)\69dc8177-a574-4dff-8461-b3267b078dcf
2015-05-28 22:32:01 ----A---- C:\Users\Win7\AppData\Roaming\BYAIAMUF.exe
2015-05-28 22:31:59 ----D---- C:\Program Files (x86)\globalUpdate
2015-05-28 22:31:49 ----D---- C:\Program Files (x86)\CinemaP-1.9cV16.03
2015-05-28 22:31:38 ----D---- C:\Program Files (x86)\Seznam.cz
2015-05-28 22:31:25 ----D---- C:\Users\Win7\AppData\Roaming\Seznam.cz
2015-05-28 22:22:34 ----D---- C:\Program Files (x86)\Ubisoft
2015-05-28 22:17:01 ----D---- C:\Users\Win7\AppData\Roaming\DAEMON Tools Lite
2015-05-28 22:17:01 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2015-05-28 22:16:52 ----D---- C:\Program Files\DAEMON Tools Lite
2015-05-24 20:15:10 ----D---- C:\Users\Win7\AppData\Roaming\LolClient
2015-05-24 20:15:09 ----D---- C:\Users\Win7\AppData\Roaming\Macromedia
2015-05-24 18:04:56 ----D---- C:\ProgramData\Riot Games
2015-05-24 18:03:27 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2015-05-24 18:03:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2015-05-24 18:03:25 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2015-05-24 18:01:50 ----D---- C:\Program Files (x86)\Lol
2015-05-24 18:01:24 ----D---- C:\Users\Win7\AppData\Roaming\Riot Games
2015-05-24 02:10:26 ----D---- C:\Program Files (x86)\Life Is Strange
2015-05-23 23:55:02 ----D---- C:\Program Files (x86)\2K Games
2015-05-20 12:47:04 ----A---- C:\Windows\system32\drivers\nethfdrv.sys
2015-05-20 12:45:46 ----A---- C:\Windows\SYSWOW64\netupdsrv.exe
2015-05-20 12:45:24 ----A---- C:\Windows\SYSWOW64\installd.exe
2015-05-20 12:45:02 ----A---- C:\Windows\SYSWOW64\nethtsrv.exe
2015-05-20 12:44:26 ----A---- C:\Windows\SYSWOW64\hfnapi.dll
2015-05-20 12:43:54 ----A---- C:\Windows\SYSWOW64\hfpapi.dll
2015-05-20 11:52:52 ----D---- C:\Users\Win7\AppData\Roaming\NVIDIA
2015-05-20 11:47:01 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\nvhdap64.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\nvdispgenco6435286.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\nvdispco6435286.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2015-05-20 11:19:43 ----D---- C:\ProgramData\GOG.com
2015-05-20 11:19:43 ----D---- C:\Program Files (x86)\GalaxyClient
2015-05-20 10:34:11 ----D---- C:\GOG Games
2015-05-17 16:33:00 ----D---- C:\Users\Win7\AppData\Roaming\Apple Computer
2015-05-17 16:32:52 ----DC---- C:\Windows\system32\DRVSTORE
2015-05-17 16:32:52 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-05-17 16:32:13 ----D---- C:\Program Files\iPod
2015-05-17 16:32:13 ----D---- C:\Program Files (x86)\iTunes
2015-05-17 16:32:12 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-05-17 16:32:12 ----D---- C:\ProgramData\Apple Computer
2015-05-17 16:32:12 ----D---- C:\Program Files\iTunes
2015-05-17 16:31:00 ----D---- C:\Program Files (x86)\Apple Software Update
2015-05-17 16:30:11 ----D---- C:\Program Files\Common Files\Apple
2015-05-17 16:29:55 ----D---- C:\ProgramData\Apple
2015-05-16 22:38:58 ----D---- C:\Program Files\CCleaner
2015-05-16 18:13:19 ----D---- C:\Program Files (x86)\Total War Shogun 2
2015-05-14 21:26:46 ----D---- C:\ProgramData\Package Cache
2015-05-14 00:46:36 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 00:46:36 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 13:15:46 ----D---- C:\Users\Win7\AppData\Roaming\dvdcss
2015-05-13 08:11:45 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 08:11:45 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 08:06:37 ----A---- C:\Windows\system32\services.exe
2015-05-13 08:05:54 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 08:05:54 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 08:05:54 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 08:05:49 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 08:05:49 ----A---- C:\Windows\system32\jnwmon.dll
2015-05-13 08:05:49 ----A---- C:\Windows\system32\InkEd.dll
2015-05-13 08:05:47 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-13 08:05:47 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-13 08:05:44 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-13 08:05:43 ----A---- C:\Windows\system32\poqexec.exe
2015-05-13 08:05:39 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-13 08:05:39 ----A---- C:\Windows\system32\apphelp.dll
2015-05-13 08:05:39 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-13 08:05:38 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-13 08:05:38 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-13 08:05:38 ----A---- C:\Windows\system32\shimeng.dll
2015-05-13 08:05:38 ----A---- C:\Windows\system32\sdbinst.exe
======List of files/folders modified in the last 1 month======
2015-06-12 21:26:50 ----D---- C:\Windows\Temp
2015-06-12 17:06:11 ----D---- C:\Users\Win7\AppData\Roaming\vlc
2015-06-12 14:46:36 ----D---- C:\Program Files (x86)\Rockstar Games
2015-06-12 14:46:27 ----D---- C:\Program Files\Rockstar Games
2015-06-12 12:53:10 ----D---- C:\Users\Win7\AppData\Roaming\Skype
2015-06-12 12:53:09 ----D---- C:\Program Files (x86)\Steam
2015-06-12 12:51:24 ----D---- C:\Windows\Prefetch
2015-06-12 12:49:19 ----D---- C:\ProgramData\NVIDIA
2015-06-12 12:49:17 ----D---- C:\Windows
2015-06-12 10:44:50 ----D---- C:\Windows\system32\config
2015-06-11 15:09:03 ----D---- C:\Users\Win7\AppData\Roaming\TS3Client
2015-06-11 10:39:31 ----SD---- C:\Users\Win7\AppData\Roaming\Microsoft
2015-06-10 18:08:45 ----SHD---- C:\Windows\Installer
2015-06-10 18:08:25 ----D---- C:\ProgramData\Skype
2015-06-10 11:29:22 ----D---- C:\Windows\System32
2015-06-10 11:29:22 ----D---- C:\Windows\inf
2015-06-10 11:29:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-10 11:23:22 ----D---- C:\Windows\winsxs
2015-06-10 11:20:43 ----D---- C:\Program Files (x86)\Windows Media Player
2015-06-10 11:20:42 ----SD---- C:\Windows\system32\CompatTel
2015-06-10 11:20:42 ----D---- C:\Windows\SysWOW64
2015-06-10 11:20:42 ----D---- C:\Windows\system32\appraiser
2015-06-10 11:20:42 ----D---- C:\Windows\AppPatch
2015-06-10 11:20:42 ----D---- C:\Program Files\Windows Media Player
2015-06-10 11:20:41 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-06-10 11:20:40 ----D---- C:\Windows\system32\cs-CZ
2015-06-10 11:20:39 ----D---- C:\Windows\system32\drivers
2015-06-10 11:20:35 ----D---- C:\Program Files\Internet Explorer
2015-06-10 11:20:34 ----D---- C:\Windows\SYSWOW64\en-US
2015-06-10 11:20:34 ----D---- C:\Windows\PolicyDefinitions
2015-06-10 11:20:33 ----D---- C:\Windows\system32\en-US
2015-06-10 11:20:32 ----D---- C:\Program Files (x86)\Internet Explorer
2015-06-10 01:21:24 ----D---- C:\Windows\system32\MRT
2015-06-10 01:17:54 ----D---- C:\Windows\debug
2015-06-10 01:17:46 ----A---- C:\Windows\system32\MRT.exe
2015-06-10 01:16:30 ----SHD---- C:\System Volume Information
2015-06-09 21:52:56 ----D---- C:\Windows\system32\catroot2
2015-06-04 11:45:35 ----D---- C:\Windows\Microsoft.NET
2015-06-04 11:41:17 ----D---- C:\Program Files (x86)\Common Files
2015-06-03 15:27:15 ----RSD---- C:\Windows\assembly
2015-06-03 15:27:11 ----RD---- C:\Program Files (x86)
2015-06-02 22:04:48 ----D---- C:\ProgramData\NVIDIA Corporation
2015-06-02 22:04:13 ----D---- C:\Windows\system32\DriverStore
2015-06-02 21:45:11 ----HD---- C:\ProgramData
2015-06-01 22:47:03 ----RD---- C:\Program Files
2015-05-29 00:12:13 ----D---- C:\Windows\Tasks
2015-05-29 00:06:06 ----D---- C:\Program Files (x86)\Google
2015-05-29 00:06:02 ----D---- C:\Windows\system32\Tasks
2015-05-28 23:03:17 ----D---- C:\Users\Win7\AppData\Roaming\BitTorrent
2015-05-28 22:22:35 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-05-28 22:15:38 ----D---- C:\ProgramData\DAEMON Tools Lite
2015-05-28 22:07:21 ----D---- C:\Windows\system32\catroot
2015-05-28 22:06:23 ----D---- C:\Users\Win7\AppData\Roaming\DAEMON Tools Pro
2015-05-28 11:13:55 ----D---- C:\Windows\Logs
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\OpenCL.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvapi64.dll
2015-05-28 06:15:30 ----A---- C:\Windows\system32\nvvsvc.exe
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvcr.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvc64.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvshext.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvmctray.dll
2015-05-28 06:15:28 ----A---- C:\Windows\system32\nvcpl.dll
2015-05-25 12:01:01 ----RD---- C:\Program Files (x86)\Skype
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspcap64.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspbridge64.dll
2015-05-20 15:08:54 ----SD---- C:\Windows\SYSWOW64\GWX
2015-05-20 15:08:54 ----SD---- C:\Windows\system32\GWX
2015-05-20 11:48:31 ----D---- C:\Program Files\NVIDIA Corporation
2015-05-18 17:03:53 ----D---- C:\Windows\system32\drivers\UMDF
2015-05-17 16:30:11 ----D---- C:\Program Files\Common Files
2015-05-16 22:41:32 ----D---- C:\Windows\Panther
2015-05-16 18:34:02 ----D---- C:\Users\Win7\AppData\Roaming\The Creative Assembly
2015-05-16 10:44:42 ----D---- C:\Windows\rescache
2015-05-15 22:40:20 ----D---- C:\Users\Win7\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2015-05-14 13:36:09 ----D---- C:\ProgramData\Adobe
2015-05-14 13:35:25 ----D---- C:\Users\Win7\AppData\Roaming\Adobe
2015-05-14 10:36:29 ----D---- C:\Program Files\Windows Journal
2015-05-14 10:36:28 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-14 00:52:36 ----D---- C:\Program Files\Microsoft Security Client
2015-05-14 00:52:36 ----D---- C:\Program Files (x86)\Microsoft Security Client
2015-05-13 08:52:35 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 280376]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys [2015-05-20 46160]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 124568]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2015-05-28 30264]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-05-13 195912]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-05-23 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2015-04-03 38032]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2014-09-09 14112]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-05-01 81088]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-19 77128]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-05-23 1152656]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 23816]
R2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe [2015-05-20 338944]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-05-23 1893008]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-05-23 23006864]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-05-28 937288]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2015-05-04 76888]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2015-05-20 190464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-28 410768]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2014-10-17 2589496]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-05-21 1272560]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-04-07 643880]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 366544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-05-28 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-29 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 GalaxyClientService;GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [2015-05-28 1751096]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2015-06-03 6666808]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-05-28 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-29 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-05-22 114688]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-06-04 837312]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-04-20 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Win7 at 2015-06-12 21:26:45
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 159 GB (33%) free of 477 GB
Total RAM: 6142 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:26:53, on 12.6.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10.exe
C:\Program Files (x86)\Cool getWeather\cool_getweather_helper_service.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Win7.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GalaxyClient] C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GalaxyClientService - GOG.com - C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9834 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
taskeng.exe {7D29AE97-C35A-4E20-AC1E-B6261B2E45D4}
taskeng.exe {41A59FF3-B568-43D6-BBED-E57F6676A619}
"C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10.exe" /rawdata=eEnyDGZpyx/yyAOlo/+Kf8CNUeaTqIgXxYpTb0rE2zn29AD2luDqSCItOwOnBT6gF2Zj4TyoTKHXWS9AT9qFm03SSq8MSQQo0DDINMOebydOaZr9JNTD1VndPBGuwer5AXEOKE/X6l1fbbECI7H6ZqL3Y2pBkqlIMSLeON7VABdyOcwQ55uLr1fUoVpyvq+rsD1lQYM61Ps+teLZ/CHAzE+wsDvfEX2d+Xv+KfrQVn6dp5A9b9jwXeVvinhGVdeTeb546B8ug21Ar3PLbXYf3eYVWeG7vwq7UUXM+IJdV1hYNbYhb2RPOKEWmg+tIwL5DAiS68B9SBFp67gWPfuFaki/unkvn/nPub6FqwbZlQVdQ/eA68/MG6wbVrme7RzfruGiR+gDbI9U3kSKjfiJ3LKKdjURzi+1S0O/ukacgCN4RcPnvUorU61XkLmXG+crZ2seLrJw9rkIDk5sR+4MiZWjIkjx9Bch2nlfcax/FzML6Pn3qYQhMHkxzMwNH26ZqtaHSyopyptjy5PwOjNwNQLj2BxLVI+wIFVgqR4NdC3ibitq+Rw1sYRfvy7AGxgaEgvoO0uUtTHubXVMI0tzhDHZDwEhWRtqB55Q0e8G/+r4erJ61jVs7d04D3ko6S1zDxazyArKz8UIySli3RBr68V1BnFctAexZLcACzHmBbN3kkGmAdlIdnvD2+xgM2ynda4EVXA0fMtByuWL93EQ2ymt2X2VMiumzNDNqOCvxWuhqbhXHAcB5f1kExaodoTuMjzuNG7WEsi0unnYQ3MWpzRSiPq6fx5kdubtCi5BS4GgqtvGlG+SrFl7RslVyd6D6EOAkMUuBTCmw06/p8k03A==
"C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.exe" /rawdata=JQ4Zgg2iNy+QL1ZEj+NQU6x8a3wRlJM1HnH7aZvi9nAR0lR0s88Oy2nYovQeE0byS6g8hnHLxdEPlOecZ9XOFDZ8nG6tgpCu5SP5JUzeEFBDQqGBX1XthGR5XUrwC9fmHC1YsjkNqHeFjeunHE99SsTCeApSipvROuQKogMzDR23uZz86XKAx3DVehq3/Hizd5EzTEr2AX9y23I3zu6dN4EAhMQ7ADis7GCkaq/j4QtT2Lq5Qz0jOujndhQihMdWhYPc9z87C+e0Vw9c7dthwWEP7pLOCB/E4C0pi5uFQx3LUDvIig8PlOPzTdMSO9zhqEqyLTWXLIZx//C9N5A/OcX+XIsSIUXXmZiyedF6xncL0i2PKslDMz/VZtP6yxZcwOkAwRO8M6B5y3RPPaD2VlnOFWYL79iOtURSpOwT5mVCw/btQqsv3y8lNq3UoPGbXKyr4hT2AcODBeWKDn3qyvCAScDzjiAVKGmi9r+ad0KSJ2xVDUHjO9ywAj+zAEovtE2JmokCaEUYTKKkKYbxATIcKNJfu6swwnMtMBrkVyt9cx9jC4mG+y70iTdg/DjFKn/BtShgx4o+eixInGdUcHLW0SgdzJcmDvRO69pWPcNZs8R59aXnAxIcCaXLU8OVUDIXgs58NbcxzAkWKq85/yGCL1mhr2URd5IDppq3md61twGbZeYzei+nQrRWGyurh59YAhUtGz5zpWCh5SyjBP+wSdohZrkOXYUYY39bG35ANNlzfNLPG82DACAM8aje00hlOP3wtyDkDTUW/EFZswW9izQ9cVSI5m1MjPM0blhoIdC+FJL8WOQStQXqWBF7R/XI2z7wkg8vgmWno4hV/q8HAgu95eFnmdoEHf3FSwnsEG4XyWALqdAX5Qww7cgfmSpjX5OwL0myriNfrDuxj8q6wdspXJFx0tQBRX6hl6xfbHATS6PzoSQHjwPJuWEWmje/SZppnWBlKWHkSCYBnHt1oSgefyYXsZdKdx8g6XiyghqjP5GlxLz9PMZ5YQ0/hBVAmSwTpfB9OEEUzmemXK8PxzmMCFnT9eM+LASAcjC77Q76wzWPTBCk6IPYDRVhwVOG3+goYBA9asxUNEZXpJ+1ZPF+TuPi1jMZs/DX8CK/hy9I9xRv+4pEQWfNiTvHv0PVssQjNHOvsth5benFgZNtX1IhwxkjKUi2b7Vzpg8aRaHUN627aV3TLqNQ7NssMoiT5+E5687kgJzySYMtQc+YJ9YbQN71VyhJ1VTNZAV16JqABFpqwJsQsnSX9A1JW6kH7+7q9DfUpBS9iaExoDLiwKTTWSgI+TdGxXbkyjA/C+2j/4M9TvGPztpOWjxv4jhvIamJLVeNosSNk3p50l8pe5gngNuW1ue+3155aDawyzgwWTkpxcpADwiaoomGYQw433VU8XaB6zSJqK+zBteh+WewCrMqYvbOU39N3zR3D6PGGjvMjb3MG2RU99HcNv1VRyBF1w5OARTbNphVPYcxZ0N/sx0l4zlJ5AmdXq39hYWPE8M4SulqY/CvzKqSlt1YwhJPII+pqh5+Xc7C+UN9MfrItFc1fy+N/xdeWiBU1LeGZP/SLWMw4G2BekS9+1oX6/WU2el8tclMt1ELke/H/y9YNUnOcQa+Pqp9q25jhcoXDnGW484+W+UtSPt4MRQtoJl+eMTaQyYukMSMqqE7sxU13r0RgE+m/gbwqo/AVHR+zBkXy60/r326hb0+VPZKbuHeucCKjfNPtLl+a20nnf4Mwp3Zq01fp4yV0dNhI8toCWm9vAwLP0F+z3u7TFv3QDscaqXZzjpKJPiUQrISgzagSGKwYRxzAX0uSEOa02eu19IkfGgIQ7yix4/bNeLwNXPbR40+9iGTGaxehcIrFThWvG55WRP+5wpsBQDOpxouKp8+oco31oX78cY89yK5oESLugPlNoetFx+jjj5kH23n9IhmK090fDBt5wHKFrHz2/Q/NRnH1imfHzEKap0cThGQFib9h5GALa8WA/H7suJEeg77fjEBD3K6h/+xEVHsbf26YuHBuCNk83+wwLJpyYc7aGo7SvqXB+dEOCpkyKj3vJ16+1514rjYA8DPbIP+ybBh9fzzUicdfJDqHQOXni/5Nmx5D+PtwfUbKumaPgXLDmkGJly16LHdXDhqtRq0lrrrnj1i6IbX5IE44OFbYMAWCznb8AiezmAXCem89neWGIMW3Rv+lt4c7dZc5Uv3ycJEgkqBjsDI0NxS2SWGXc0YMROtBbVx0db8/iDSsuyYPT6OT7DlpeRC4eE6XsCyyoA/V7EwigcB1ujlF0m3HUQchkY7vB42ytUcUaBG3NcgFAXylqnjvi7BP52rYNXaqpeAGRHe8XTLkzA1yyZNbI+WkfupB5kvMsfNAF4CM8nq6tuCbZHhfp1AlPdOYpY1TuqxAYEyq6hOdbMoXqUp+rTbm4aUkl+MTtr9636LTcMwpaFPOiLbBe09SOnln5eq3eZGpgrmda+g9XuEgmnanS4C3ndxs26TCAkl9c+UhONjSCp6/QEOtFCmuL3JpSOkBPHWg8BVNOC5R/o2an6BcHWNFksReWnbrBCDX0VqGJxYWTZhGfHNmmdua1aJiMpyqn4cImuxMjgEt/BnD4Y00yO8yQI9cAeF2dNdA7gWXXx/mBijE/HutILvrwtQOmWmn2ia3uRUSmPfUKyr7EJE2g9rTWVx04AU7pyeoBkPMFoPLBYG07S6Xq+7zGY=
"C:\Program Files (x86)\Cool getWeather\cool_getweather_helper_service.exe" /installationtime=1432845467 /AppName="Cool getWeather"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.exe" /rawdata=x7wnFaqbUNLBN/NWjPPFP8r93psoY1V2CiritPomCN/fl6QFU3OKwLY/+/gzaOQXQKl3DREfcxE8H5RS7qS0pc051134/b8hCwoWx8kwJezolq8/20YRBxmSJV2jJdKW+5dxNIROZhS0QlbQwZuFYh1lxLffPlBNSKDoc2zWpqBPLvPnzJUs68SeqxQ9d8/XZu6LH5JXO07PAnHSMwBwZSs2DIfEART/G+D2lipyBB9j1DRaTLf0w75lQOu0F3KoVmEUEFsRDiFEPVher2ImVemxct8rxiUgr6LKjijONhURVaZvrTqv9MdrytBA3bpOZTkKlnwJXL02asKAWDZ27jmQZ0vPcf3d7vP4GzGL6vYfQqcs7AqHf8qq4/b50nqnhEOExp/vDU9lGd8ePNFGhXKO/txbIfFzklVG5s+K9QmxtSQWS8K4CdQ7Mfl8+tI0Flssj3e7vNYQlPKMYwwhVTm6z+F3VQKT2lndJ8+vzPr49NSpKxoTQdRz6UgPyKSJP9YzKXAS54vhpksY4cSHHbSEAYsWTs28zFj+pZ+S6KqOpQ/4sEvnnQVJwd/dWW7HeH80DW76xOHYUeAfydA3cQ8i885nKsMfT7A6YAWPCop2BbV4jTMJJG+ToEbgE4OFmi36qVGPGOGhgsAe6k/MWSmd5OfvPcKjSLVTYuFvdUJZfbd1Xm6FIvje9FoE6jrRmxGzIzIH8yZQlYaivStLqvL9FGuSa7wUA0+vTwJm5X9aExsSK4gBZ7Q7ddeh05M1nFwjg/W+rCw/Xg9+9JpCNm6gvjUArRnr4T89cOt0SANJM+RGWvBwgTmJCy/10tN5GH3uPHcVHa8eFRFqxuO19x6trjfn58J3TICNS/DuFek/x7egh2EupxJSr2dLC+tAa8X0eL4PHPWVVPrYsiElzFf8/xng0YNsURNZl9zcYsL8XCYYjlaRSeWApc7omNRF2dLn/ZYWlHsvdmXG6dp1IDPm8KjmZvqXUuhX92MEKJOyKU/PfRsYIuisIdgeEeoYsDucJ1SxUWEVvdFNkrYue9eVjUbSm2Zw3fbuLUs3S40pzOoaWk2P/owqYsjBSF7cszDnHTTvaBqx/4fchc3VM323xUvowNXc1VDkfvbGaWYeacRNNu2JgRZK8Z7tKFzjY9tkWrUWc6pUUwD+iN/TMk+pQhs7lEBTaEsXlKnTxkuFAZlM/Fd5Nmfwdqpb14eRTx5wbNURZ8gudm4Agi5A4njBQi3ZZI9J4Gr7J1krrQRhNmrJp6U078DubpTdgWd/F79Pu3EJT9nlztgDIUcqhYiOTRRxNOTwyBxJ/1ma6hd+6q8Iko/VgzwFCduRlZe/ewgpAMgCeqV1YjMSnxfMtA==
C:\Windows\SysWOW64\nethtsrv.exe
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\netupdsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
WLIDSvcM.exe 2556
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 80dd8e43-28e3-4e22-990c-27722e4adf3a 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "32466480390710283-14830595171893181930-9323799025058866441693780691236051132
\??\C:\Windows\system32\conhost.exe "351896112453643461761679494121692368121078664225430809401183080820-1160178182
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2576
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-af2b9927-4fcd-418e-bb7a-e0782c4e796f -SystemEventPortName:HostProcess-7c909b45-7bf1-41c8-9e90-d5dd11142ee2 -IoCancelEventPortName:HostProcess-ecec0ee2-6135-4684-a8e7-2e0d2b2db8d1 -NonStateChangingEventPortName:HostProcess-b145662d-8fef-4147-920b-d555bb7b09b6 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:ba048e66-9e50-435e-a8cf-1e6d8c05abc0 -DeviceGroupId:WpdFsGroup
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe"
"C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe" /runWithoutUpdating
"C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe" --type=renderer --disable-gpu --no-sandbox --lang=en-US --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --lang=en-US --log-file="C:\ProgramData\GOG.com\Galaxy\logs\cef.log" --log-severity=disable --disable-pepper-3d --disable-accelerated-compositing --enable-software-compositing --disable-gpu-compositing --disable-pepper-3d --channel="5400.0.888542765\1113084842" /prefetch:673131151
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6764.0.2000958030\725851384" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,21,44,53 --gpu-vendor-id=0x10de --gpu-device-id=0x1381 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.5306 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/BackgroundRendererProcesses/AllowBelowNormalFromBrowser/BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.1.796309753\1182981360" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.2.1176007820\1891621460" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.3.821523351\857249505" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.4.201190441\631558441" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.5.1383761024\1499026149" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.6.34131251\824469281" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6764.11.637046143\623566442" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.36.1682189280\1277211382" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.41.445601612\2093576700" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowBelowNormalFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ChromeSuggestions/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Stable_EthersuggestPrefix_A4/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/Default/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/default/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/*WebRTC-IPv6Default/Disabled/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --font-cache-shared-mem-suffix=6764 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=2 --use-image-texture-target=3553 --channel="6764.47.915791387\718764406" /prefetch:673131151
"C:\Users\Win7\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\AmiUpdXp.job - C:\Users\Win7\AppData\Local\32400\Updater.exe
C:\Windows\tasks\BYAIAMUF.job - C:\Users\Win7\AppData\Roaming\BYAIAMUF.exe /infocmdline=Mu8SFIwa33mfWamrE8z0/TxVs+lgU+4RcSDW0+AqYKCTr9MK4n2O/KOxod5roes4Xp+4OOM0MuuLc5n5+KmFL59gzSCZgsm0bwPmP/EdbXrcS9XFJHfy+a0hRs7MJACab2dyx51UYNxnTfKo/cpuYVZ7JzJMJUh3JIBAYR0UQrm3IYaQjEIii4qvgze/OpsFdxkWv9lbCe9+SUjCT5HuPvYmn8a93Fp6aL2gqFWrRUG51q0xnq02HvV14WWonniLtisoeLGMI+S65zGJMEOEhJkb3zxiYqTeKKVN1B6unNZyouz5SFTWFhS3ZGhM37KeqzpYkXS7ZNqOAbqPRBFf8KnDIAUemw2jScGMIFapC4OK5RUFHrggfChqixtrcIkZFpD+rq7hYPZC4HZOb0TGtYCY81Bk1XL/5LDSVzH7HqDBIcsBVGlP7StfFcxMET5ow+qC7OuldWgXJzhiRDLiLcQUtFrQr+MbtKEn96GypnKYhMGt13pWRp1o5QfjHRRgsZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\Windows\tasks\cool_getweather_helper_service.job - C:\Program Files (x86)\Cool getWeather\cool_getweather_helper_service.exe /installationtime=1432845467 /AppName="Cool getWeather"
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-6.exe /rawdata=x7wnFaqbUNLBN/NWjPPFP8r93psoY1V2CiritPomCN/fl6QFU3OKwLY/+/gzaOQXQKl3DREfcxE8H5RS7qS0pc051134/b8hCwoWx8kwJezolq8/20YRBxmSJV2jJdKW+5dxNIROZhS0QlbQwZuFYh1lxLffPlBNSKDoc2zWpqBPLvPnzJUs68SeqxQ9d8/XZu6LH5JXO07PAnHSMwBwZSs2DIfEART/G+D2lipyBB9j1DRaTLf0w75lQOu0F3KoVmEUEFsRDiFEPVher2ImVemxct8rxiUgr6LKjijONhURVaZvrTqv9MdrytBA3bpOZTkKlnwJXL02asKAWDZ27jmQZ0vPcf3d7vP4GzGL6vYfQqcs7AqHf8qq4/b50nqnhEOExp/vDU9lGd8ePNFGhXKO/txbIfFzklVG5s+K9QmxtSQWS8K4CdQ7Mfl8+tI0Flssj3e7vNYQlPKMYwwhVTm6z+F3VQKT2lndJ8+vzPr49NSpKxoTQdRz6UgPyKSJP9YzKXAS54vhpksY4cSHHbSEAYsWTs28zFj+pZ+S6KqOpQ/4sEvnnQVJwd/dWW7HeH80DW76xOHYUeAfydA3cQ8i885nKsMfT7A6YAWPCop2BbV4jTMJJG+ToEbgE4OFmi36qVGPGOGhgsAe6k/MWSmd5OfvPcKjSLVTYuFvdUJZfbd1Xm6FIvje9FoE6jrRmxGzIzIH8yZQlYaivStLqvL9FGuSa7wUA0+vTwJm5X9aExsSK4gBZ7Q7ddeh05M1nFwjg/W+rCw/Xg9+9JpCNm6gvjUArRnr4T89cOt0SANJM+RGWvBwgTmJCy/10tN5GH3uPHcVHa8eFRFqxuO19x6trjfn58J3TICNS/DuFek/x7egh2EupxJSr2dLC+tAa8X0eL4PHPWVVPrYsiElzFf8/xng0YNsURNZl9zcYsL8XCYYjlaRSeWApc7omNRF2dLn/ZYWlHsvdmXG6dp1IDPm8KjmZvqXUuhX92MEKJOyKU/PfRsYIuisIdgeEeoYsDucJ1SxUWEVvdFNkrYue9eVjUbSm2Zw3fbuLUs3S40pzOoaWk2P/owqYsjBSF7cszDnHTTvaBqx/4fchc3VM323xUvowNXc1VDkfvbGaWYeacRNNu2JgRZK8Z7tKFzjY9tkWrUWc6pUUwD+iN/TMk+pQhs7lEBTaEsXlKnTxkuFAZlM/Fd5Nmfwdqpb14eRTx5wbNURZ8gudm4Agi5A4njBQi3ZZI9J4Gr7J1krrQRhNmrJp6U078DubpTdgWd/F79Pu3EJT9nlztgDIUcqhYiOTRRxNOTwyBxJ/1ma6hd+6q8Iko/VgzwFCduRlZe/ewgpAMgCeqV1YjMSnxfMtA==
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-7.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-1-7.exe /rawdata=gHDwrUzuNjqMyrD+XrvYSVaVOZN7dhpfY0NNwy3RjAVssJfowOEsC0HMknIFo25kw87VOOXCqUT+LRKXInevR8SihvuKO75FopIY94v9jeJieHQ1IWijD1PeXArFFNmbwJQFDBI2GwRjZFsQ59jtmRGcgEdMD6J2FAacEdj8t5VwBjfICkDwrIlbvL6PI0CJOHJMViQf8kINR1UsyjYNMGqoYzAPl+1z+ycoPwjLLu6bIB3m9Fg19LnmCXSWDCDpxQyZvXSShZBmi2eVPwq+FXiiqIKo2oLcR/xxMA6ItlHlNDP8YyPAW4vDdeVqEeRLqFkzLgorA69UUFjzGVksiBwEbjdR/4N0YxrY24//Rc7vnV9QOKZg8rm/BzBQaSCHzpklfulBFkdTZESQTVFxMcp0VL+NF8lSOyhyq3lFpuj0xnLoQOLxtT23zZfOLlXVyhnSlKmwg4aRxYjos0WhhtYI2kMwGOKu+JTIF5eRGl+1FBEc4qf+ZcWI4Ya9hK0VGa4PUZxuweISQ8KodN87kXmbq2S5b+iHPTaYXi7Dl+db1krd9yitx6yLPYaj1aL4EqBSBXSLL136Xxk7PAXbnd1Ezqze+uKUJX4Wp5ZMJ5HBPKgSSu0zgVZpwlVKrNp5uhs7emmSvMGmHmNFyLAtnd1YJZjXZyCWKE0OYP2FKGpW+TcqJRJWDHUImsLQ7Bphnv9SzskBjIzM5qKh2pSS/qc/4//s3yw+Onr8IR5kEAeqryzyItCFPW8dw6+wxmrzUp3QMRh1o+TgZJnTTsbhylv87r4rnF4ND593eMoNZIkcQzzIgDiPWWL1Ws7s+o0mej/0hO2ipwy7k2aGddWzlEHYyVtWTcPtKvlM7gtmWzSlNaDeL0jRjfhFp7GAM9+22BvHUCHfrrsmfLxYdMXx6bPqgJ+6yLngD4891KV5aSJFBr8lPaW1v3IR1tVbmUcfTSQPF5UYfLKdpRdKtxyJO0yQgiAo7cN+33nm+efBgSoQwRiyo0+ytYxyMTR3FhgXXf85IHjB0co0hFxOkELAsxB/bxWpX5qRVYZzoboo19FYQaQu0zqwJdmDs/3Q27OHxKfvM6xneYv+zi1iMDgMTcbLTJDwVXnKsmM9+qLrPp9FH/Ufx3sYTKjNEP1CyiT8bRC4xMgiPCjsic7OyWm++yOKzL4CQV2b8quie3WRL3WXTH7NdJfCcyZ2XhLYI2hIkSQGdWI4TVRR8KDTJhpWANF7t1BWcAfDbCM1Gk3ZGEl7OZ7WxZgen2y1U1PyMk8iW6l9DEnoKQ+R998keEeGvPX+IivBJIdtA0fmfhIjvvBUbmwU6qP7H1i6JMiGdbS04DGJlqPPTVQyoRex6VaYPC0Zue/zVmndPW/BtIlhWdLAftD9qO37rkUnYX3+PP1V9+QFj8H8NV4V2Rq4hwJdundwgSbkX4G5FOLFKClTbCv1vFTpiKCXtfFBsd8DX3A+rzRB7PkiKQhPf4nzFTXNxCL0w8Cd8s/n7qyzZGcHLSDThZvwi7pMGBLLwQ5+0GDU
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10_user.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-10.exe /rawdata=eEnyDGZpyx/yyAOlo/+Kf8CNUeaTqIgXxYpTb0rE2zn29AD2luDqSCItOwOnBT6gF2Zj4TyoTKHXWS9AT9qFm03SSq8MSQQo0DDINMOebydOaZr9JNTD1VndPBGuwer5AXEOKE/X6l1fbbECI7H6ZqL3Y2pBkqlIMSLeON7VABdyOcwQ55uLr1fUoVpyvq+rsD1lQYM61Ps+teLZ/CHAzE+wsDvfEX2d+Xv+KfrQVn6dp5A9b9jwXeVvinhGVdeTeb546B8ug21Ar3PLbXYf3eYVWeG7vwq7UUXM+IJdV1hYNbYhb2RPOKEWmg+tIwL5DAiS68B9SBFp67gWPfuFaki/unkvn/nPub6FqwbZlQVdQ/eA68/MG6wbVrme7RzfruGiR+gDbI9U3kSKjfiJ3LKKdjURzi+1S0O/ukacgCN4RcPnvUorU61XkLmXG+crZ2seLrJw9rkIDk5sR+4MiZWjIkjx9Bch2nlfcax/FzML6Pn3qYQhMHkxzMwNH26ZqtaHSyopyptjy5PwOjNwNQLj2BxLVI+wIFVgqR4NdC3ibitq+Rw1sYRfvy7AGxgaEgvoO0uUtTHubXVMI0tzhDHZDwEhWRtqB55Q0e8G/+r4erJ61jVs7d04D3ko6S1zDxazyArKz8UIySli3RBr68V1BnFctAexZLcACzHmBbN3kkGmAdlIdnvD2+xgM2ynda4EVXA0fMtByuWL93EQ2ymt2X2VMiumzNDNqOCvxWuhqbhXHAcB5f1kExaodoTuMjzuNG7WEsi0unnYQ3MWpzRSiPq6fx5kdubtCi5BS4GgqtvGlG+SrFl7RslVyd6D6EOAkMUuBTCmw06/p8k03A==
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-3.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-3.exe /rawdata=eMbYeuVSliNax57Luq95IskpqGmrlxHRFxl+ZOsvTzjPG0PjNElf961jaIPe0s5qMasYkPrII2lXyyCQP70e46rA20M4HAgQlOYu7fE3S68u7XeT8lsqQYVxc7p+Jjbz+IpHB1G8yZ+hej8zj56ENmAbR53XyXuZWM7Jx+/1MA04si3bqLbmHpsxEuxYZBhYszKpGly749M4fKmaeTBwV9CDgpP85fLrIEkipZzBgdtrdAK7erGmMouZ3/Roc9fKrv3rBpOqMWKQMWiImLcdl3TyLSQtheYvJNwUny4IbuFSMgQdCd0bQy/HIsrSXuTQBoQc64No15JzlEx5p/1iZitH0DIejKVEsuYUFrUDAJ5cSaFU44jE0spYnF0TaBGb59eN+HO6Xf6YgVQgN0+lxwmt6WheQq6aftfJ3GuPj3WJlAaa+HO8rFnCF00xBEm4rn2sJXcbrhDWQzhF5VPROOMtIZt2W5S7+3zWxqVYg6BJcxlOnM43T4DzE12jnXkUqrkDmBF8MlG1vOUtg5+00OfrBtK5kFCQpv1Xh//x/RRylSuQKWNtlmrI95EEan53gKe8hFpRLwtOPeBG1SLS9SaoKbGgiCGXcXaFKnZGXzPXxooMyCHrtNAna70vCXaDC9VsYbr+/nCt2gnRsaPFjHY61Mw3/zb2jsImBk/s5EOxdKJHI7Cliot5OClFZKhCgyjyjs2LpD6BeIIM8OxzgFcJVhD8PNP6KEjGavZ2XFw0wfRbCkHbi4BkyNDsIZJS/b9ES9F0RiCZ/ZnMlaYxqHmfzu/3vhVcfO3MggouBWmvq5HB14VMFip/wJiMAEDm3Dmc9nDzE5gPd2XlTGgjW5oLd+pZjbDGyI55c3Ukg2NHqEhqk8AVujy8G6SE6CZKLOvu+n+MBuIEOkVjvKWog1BafYuxEn+CGEr0HMDe6ZOkvGzncwVUVfe6GZmcjOe7T3BVTqT/5YQT6qBR2ECEm0oYREQ+3Rp3Gh5UNjRdr6zkPf8RlwLB/lPR50a/Qw4rvIVm7uZwqomoxB0KcIC37L3yeSZtwhhiQqWAHaS2c0ha3wFy2EUGw0UGJFZBMQhHvvMEInS11qo37A2kF28ihDIxH6Em8rCy0sAD1lylkZwaI6QsOsIKjRIXuH3oQWwh/AvTx90omVqoKWafOeUyFTzbN1AnixHIGL+sTYD7rC8uf43z8dHrr7xjwbcYHNjD71OpugjMA8ndPQ1kzfXq3kf/AjwrRMlXE87la19POJIvwmKfTyncfR+tW5s8HY3ow43CRb0owF7pfcILYc0J4TxL3S06yIJ/2AoF+nyaWuuUTygV3TipWvP3OJJ9oL7bs8zvJk7hPaGLd5cBLhOWlptj018yC/pPp0QBb7c+fWA5mxpWvuVa+q+hg835nXH9zk5Z0owU1uFXX9nmRXLSXxKZ7lmQa6SZ/QHtpKg2nKQr207MsZERbwTArdu1OhaXYuG51FGBGhLpdIqLZGSowPsEqLADgu9d/6vkZ/lb/DP9JM7KnOrujQ67fGBcfBlDcQfnoCUx/FcX5pZMNw50/jM6f8V4Ysu+7X7s6H0Z2bPhbjviIfcJluxKNe6CIQfcgI0YDG56my080C+thDsoj2v3B5HrtKm/0ynO4GtsRQfwMC4n40Iz7rIJST7snaOm3U19DZZ+OkPE9Kjb66n4QbPgxOgczxahABwae90+fAaWyO39awwDwjfvIcBZ3xcF4zyQ+eLm/2ttU3z3S0KBNYS3jyihI68EUwQF/nRlI/nSK0N0WsqmYEuwkZlBVaivWOVqdecnd3L+vCJGjY/QR027/XWo5kW7MJB7j8sRuxuHOaD622NhtdGUThdY2TvsK2E0G6Tba2G8+Ec2HkW3Z5cSLvMcXjZdVqup9oU9hxJgEs6pNxFNuzlyNsMQrD11Sjd+Xp7a9qoiO+v7/XoaJAkxWrGReVc0o5hRfCtyI/m3DO6wIuvzfQPPSOr/3soaxGgebOiBAdcYe+v595easdoqa49ugPwvf0cR7HEjchhC/o9wBq9ceZjm2ltFgPiP
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.exe /rawdata=WP1sPNwr7pWSrlXSgT7JbQxTXV477Xo72sFuw4XQKFL8q39aVKrWcBnomPoAL22/ngYMmqxO+nsjPkda/lTh3FOdU/WmHIVM85L6SyvxPyzUNYmgEfS5tYg25XNAiVpTXD0dauPpkRxTpqwAITbc4YuktUIbA/a4GUuRWth2O8pdWo3ksGTYaUeum5i7vZoQ5Xwa9HVqcL2nLk9YcFnbKvoKdiDNmehxzqjWdwrUeaCX2UWMJnqHwdDoYJREJHRoq80eTYAuxXznhPzFTLhT6R5UC3H3Thx9oLERSAkJwQAEI3/+PKq+R4ZF0PEZs/V92+p1cptn3qpsfwsX36suta5Q++nlmVef5rs4chuNqenvamuOmuA2t9qajc73J1grAdd812CTIx8foMgPZWiYoCjySF+1GnLF8p8QcvLW8je0qAx+CnFlpY9CfvMHcla/qLmHcYIKEkVXNilZfgC2g0lpOXMwaCU+HyRSON5HSzPNWnCoifOy3tStVug0P4itp6hAb2RIu+Hk/MQfmBXBOKtejiUjVSEoF/0U0hWP6dyu+DIe8yGtbwHL2Z4SkOBGP405Fe8gaye3XjgtIJ0N/cCpi/NNlBxHC9nKd16C0QY3/gb/ZzKyZBf19+TGW6aXcwQBlwBnkA/5aWDUmLD5id0CrZGZNJPSMgbNQjGBQBs2jwpJBOvJjAJ7iCVe6dBx+hy2fnFItgt1G1D3HQxiTBSPMCh9o/UpZz7k5IzbTjUaHRrkZZqR2TQ0W/EX534ph5Dc+ifjM/DQCt2MQbcJ4lgP4XxACcd41QaSOgUBK7FtasgqjUpNvALBm03jZdMpVJ1YiYe7MZcVUgdtMpYHI4YOLhotLFamYaFgdYxyrJM5xfGm8ZjL9hZikpMmGXSaNrQk6ykeQsAeVlurnA0bLtMbo0jEl02q0q/YqGRxYWFN39Ydy/OO/Zn7i0gMfjdYnB3rn3hNrKUhXhmH48dTxnUaNsSGPSBxSovo3RJxwGLOs4nB9kWWcvu8Y8+T8UVl
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5_user.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-5.exe /rawdata=WP1sPNwr7pWSrlXSgT7JbQxTXV477Xo72sFuw4XQKFL8q39aVKrWcBnomPoAL22/ngYMmqxO+nsjPkda/lTh3FOdU/WmHIVM85L6SyvxPyzUNYmgEfS5tYg25XNAiVpTXD0dauPpkRxTpqwAITbc4YuktUIbA/a4GUuRWth2O8pdWo3ksGTYaUeum5i7vZoQ5Xwa9HVqcL2nLk9YcFnbKvoKdiDNmehxzqjWdwrUeaCX2UWMJnqHwdDoYJREJHRoq80eTYAuxXznhPzFTLhT6R5UC3H3Thx9oLERSAkJwQAEI3/+PKq+R4ZF0PEZs/V92+p1cptn3qpsfwsX36suta5Q++nlmVef5rs4chuNqenvamuOmuA2t9qajc73J1grAdd812CTIx8foMgPZWiYoCjySF+1GnLF8p8QcvLW8je0qAx+CnFlpY9CfvMHcla/qLmHcYIKEkVXNilZfgC2g0lpOXMwaCU+HyRSON5HSzPNWnCoifOy3tStVug0P4itp6hAb2RIu+Hk/MQfmBXBOKtejiUjVSEoF/0U0hWP6dyu+DIe8yGtbwHL2Z4SkOBGP405Fe8gaye3XjgtIJ0N/cCpi/NNlBxHC9nKd16C0QY3/gb/ZzKyZBf19+TGW6aXcwQBlwBnkA/5aWDUmLD5id0CrZGZNJPSMgbNQjGBQBs2jwpJBOvJjAJ7iCVe6dBx+hy2fnFItgt1G1D3HQxiTBSPMCh9o/UpZz7k5IzbTjUaHRrkZZqR2TQ0W/EX534ph5Dc+ifjM/DQCt2MQbcJ4lgP4XxACcd41QaSOgUBK7FtasgqjUpNvALBm03jZdMpVJ1YiYe7MZcVUgdtMpYHI2llXHlv0V2pCyMixRyjyv0TaosvEu1MD3gsnsuON3OhfDxEzKPoYq5Me9+EuABbaNODolEq0QOrmLObpb9jTe8aV7MnvagmCv2R9YDDbWfhrBXQDnJuuQl7KdcSpCPoSGQEbXq0rDWt00evchhDak/8NHI8ez8lof65fTDnc56s
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-6.exe /rawdata=JQ4Zgg2iNy+QL1ZEj+NQU6x8a3wRlJM1HnH7aZvi9nAR0lR0s88Oy2nYovQeE0byS6g8hnHLxdEPlOecZ9XOFDZ8nG6tgpCu5SP5JUzeEFBDQqGBX1XthGR5XUrwC9fmHC1YsjkNqHeFjeunHE99SsTCeApSipvROuQKogMzDR23uZz86XKAx3DVehq3/Hizd5EzTEr2AX9y23I3zu6dN4EAhMQ7ADis7GCkaq/j4QtT2Lq5Qz0jOujndhQihMdWhYPc9z87C+e0Vw9c7dthwWEP7pLOCB/E4C0pi5uFQx3LUDvIig8PlOPzTdMSO9zhqEqyLTWXLIZx//C9N5A/OcX+XIsSIUXXmZiyedF6xncL0i2PKslDMz/VZtP6yxZcwOkAwRO8M6B5y3RPPaD2VlnOFWYL79iOtURSpOwT5mVCw/btQqsv3y8lNq3UoPGbXKyr4hT2AcODBeWKDn3qyvCAScDzjiAVKGmi9r+ad0KSJ2xVDUHjO9ywAj+zAEovtE2JmokCaEUYTKKkKYbxATIcKNJfu6swwnMtMBrkVyt9cx9jC4mG+y70iTdg/DjFKn/BtShgx4o+eixInGdUcHLW0SgdzJcmDvRO69pWPcNZs8R59aXnAxIcCaXLU8OVUDIXgs58NbcxzAkWKq85/yGCL1mhr2URd5IDppq3md61twGbZeYzei+nQrRWGyurh59YAhUtGz5zpWCh5SyjBP+wSdohZrkOXYUYY39bG35ANNlzfNLPG82DACAM8aje00hlOP3wtyDkDTUW/EFZswW9izQ9cVSI5m1MjPM0blhoIdC+FJL8WOQStQXqWBF7R/XI2z7wkg8vgmWno4hV/q8HAgu95eFnmdoEHf3FSwnsEG4XyWALqdAX5Qww7cgfmSpjX5OwL0myriNfrDuxj8q6wdspXJFx0tQBRX6hl6xfbHATS6PzoSQHjwPJuWEWmje/SZppnWBlKWHkSCYBnHt1oSgefyYXsZdKdx8g6XiyghqjP5GlxLz9PMZ5YQ0/hBVAmSwTpfB9OEEUzmemXK8PxzmMCFnT9eM+LASAcjC77Q76wzWPTBCk6IPYDRVhwVOG3+goYBA9asxUNEZXpJ+1ZPF+TuPi1jMZs/DX8CK/hy9I9xRv+4pEQWfNiTvHv0PVssQjNHOvsth5benFgZNtX1IhwxkjKUi2b7Vzpg8aRaHUN627aV3TLqNQ7NssMoiT5+E5687kgJzySYMtQc+YJ9YbQN71VyhJ1VTNZAV16JqABFpqwJsQsnSX9A1JW6kH7+7q9DfUpBS9iaExoDLiwKTTWSgI+TdGxXbkyjA/C+2j/4M9TvGPztpOWjxv4jhvIamJLVeNosSNk3p50l8pe5gngNuW1ue+3155aDawyzgwWTkpxcpADwiaoomGYQw433VU8XaB6zSJqK+zBteh+WewCrMqYvbOU39N3zR3D6PGGjvMjb3MG2RU99HcNv1VRyBF1w5OARTbNphVPYcxZ0N/sx0l4zlJ5AmdXq39hYWPE8M4SulqY/CvzKqSlt1YwhJPII+pqh5+Xc7C+UN9MfrItFc1fy+N/xdeWiBU1LeGZP/SLWMw4G2BekS9+1oX6/WU2el8tclMt1ELke/H/y9YNUnOcQa+Pqp9q25jhcoXDnGW484+W+UtSPt4MRQtoJl+eMTaQyYukMSMqqE7sxU13r0RgE+m/gbwqo/AVHR+zBkXy60/r326hb0+VPZKbuHeucCKjfNPtLl+a20nnf4Mwp3Zq01fp4yV0dNhI8toCWm9vAwLP0F+z3u7TFv3QDscaqXZzjpKJPiUQrISgzagSGKwYRxzAX0uSEOa02eu19IkfGgIQ7yix4/bNeLwNXPbR40+9iGTGaxehcIrFThWvG55WRP+5wpsBQDOpxouKp8+oco31oX78cY89yK5oESLugPlNoetFx+jjj5kH23n9IhmK090fDBt5wHKFrHz2/Q/NRnH1imfHzEKap0cThGQFib9h5GALa8WA/H7suJEeg77fjEBD3K6h/+xEVHsbf26YuHBuCNk83+wwLJpyYc7aGo7SvqXB+dEOCpkyKj3vJ16+1514rjYA8DPbIP+ybBh9fzzUicdfJDqHQOXni/5Nmx5D+PtwfUbKumaPgXLDmkGJly16LHdXDhqtRq0lrrrnj1i6IbX5IE44OFbYMAWCznb8AiezmAXCem89neWGIMW3Rv+lt4c7dZc5Uv3ycJEgkqBjsDI0NxS2SWGXc0YMROtBbVx0db8/iDSsuyYPT6OT7DlpeRC4eE6XsCyyoA/V7EwigcB1ujlF0m3HUQchkY7vB42ytUcUaBG3NcgFAXylqnjvi7BP52rYNXaqpeAGRHe8XTLkzA1yyZNbI+WkfupB5kvMsfNAF4CM8nq6tuCbZHhfp1AlPdOYpY1TuqxAYEyq6hOdbMoXqUp+rTbm4aUkl+MTtr9636LTcMwpaFPOiLbBe09SOnln5eq3eZGpgrmda+g9XuEgmnanS4C3ndxs26TCAkl9c+UhONjSCp6/QEOtFCmuL3JpSOkBPHWg8BVNOC5R/o2an6BcHWNFksReWnbrBCDX0VqGJxYWTZhGfHNmmdua1aJiMpyqn4cImuxMjgEt/BnD4Y00yO8yQI9cAeF2dNdA7gWXXx/mBijE/HutILvrwtQOmWmn2ia3uRUSmPfUKyr7EJE2g9rTWVx04AU7pyeoBkPMFoPLBYG07S6Xq+7zGY=
C:\Windows\tasks\e653cf25-f107-4cbe-b8d1-5dadaea354f2-7.job - C:\Program Files (x86)\CinemaP-1.9cV16.03\e653cf25-f107-4cbe-b8d1-5dadaea354f2-7.exe /rawdata=xxPIgFYZH9v71P974Qkf0hgMD6tf4MTx8VNWZG09m9p0R1K3Mpq4rsbosnd12Bvi2jYuiAQE6Mv7itz0dkSQS7bYWnoohNNTLWiFU7HlnlBKGAOanFQjbTaOdr9lVktXFDh6aJwXyBgaBmyl0TAqgOaoFmTutNxGVhlh2K5XWtYYf6Cgzahu5oQtPJk+5TsopeWiKCy8fXp9vdx6eORbqtzSCXeRQhjR7Gh1Y4zXfTrJOQsgmJs4blLxaYkpzn4jbGHTts3EJZdJ2ZFODbOuWGuKNEFKZPMBX+mAoGCIJJKEmWs75S+H/TguymbvUK/NMtx52ZaCTtMHo4CeIhbRuFcYrR1vy1ocGW3EO6rLIhiKnuF3bAfIeYq0IAMtUIYr7VbcDWXe22CDYyJ++4LqhP7PW9m50ikdtlrgyfSLkgP1CsKq3am0leIRggfv90d8g8Jwi8IRipwJO3NKRhRRG7wae4liKsXcIG1MKUGPE1TY9q9L/rHMU9EFVPhYEBV4GDb6VFGLvmLH3ZLRxIk6iaUEr8P0zNol08N/YkgFtK80rSDDOVJRRUkNgfRIXdshMvNKzKhz8AV011+8ODBuew1CuJy1+Bna1Up4c2FEpDvSqcGWZ2TIbFAUWJZstqbz5EJh6LhXpzm8OpF11rSi3oGFKNDBFbucJegeTBblx29EjGefpHtTVM9g+s28WY3/V6WMtPzzDx2rCvMwP4UocnKanNRAn1AcNj1ETOSVCjvQAckxVqXAgY52GnBwoS5D7dKC/KTUOCkG6FlUYVlSj32QIlKKQ4u2t83g0Te1cOF7qrtKDzuuKgYDpl1fY3z7/KxIfItJ5b44nBECE+f/qrJAbDuShOIiwPRDW4GsTfxe6y0LH+8Dvf2PJLIFkF2QwJu/6ObOBAGj2pHCgpHJ+bvMMgzcHohGQzVK2J/nCV1dbXmZFp0NyC6TptowKyxFhrEurikJ5KSv7M16lhWNRsLDjygAQbazZ1E9a0iCLOWp3zDL71CFynZEvCBNX6y1sSx2bIahNI6iEFgWO8PEMcz4zvr5iD7Xn3jfJqReNrePkb5aAT352E502cchKPQT2KfshO4HNEf7fQPTsB8dfBN058PIK9z+Zq9LJkHOoK/9DLVsgpA0arHfQKbZnbe7tk5PIW+SjkaOeRsBtaBlyd99bCp/P5fjk2dQj9EmxS8k2BMBzb1PwKsOSVMNU4wAy3OJeEyEGmuqffLKpc8ZxQ0F/DMRWrExc7DOZiQvVc6yvIikTw75QJbC8i0o8CDikcC/bjt5UU6qO3f/vaA58BebzgZWEBp1ydsNkv8uZStclA65DFVugUaQotAHJPQz/XnQs/ubfi2A1xwBzsx4/Jj2jj2bgIKlL9u9xktLEuKuuqJP73cOkbUeETmswDKEb9gkx3wvAetUu2tCk+FTowonhhsbjzLUXBMrIP8oqHgcYiMsw3OYIZEmok2DSUYq/wAHJ9FZQYuxj8NBTW/42cHRhcDLloxb5l7DzSzwIHV2fgXafO/79913ckyPyfE/ST/vMApXWP8PAStLoDLT4HOuXHBMB7+RSsnVBCHxOKtPFPoQFBiLWZ1oHxCKTam1Yv7eoRmjK5rHW1GWuSjLnYIzOgJ1rOVQ/g82OLC5koo7gxcaI18rqFKDzqOosYhLDrPliGaT+GFE2Z8hEWk1Wch9o+KDnWT67G3COjhLUsgjZI+sy8xMQ+aa6obfhYYIQ1pPb7sYKog82QX7yU4SkzkP+wR+ufD3CfVZJR/M7UR9DcfYFr6YNw2oB2g+CxwumCQTdk2+8UVBVtJAY1NUGqDykaiVpUsNA0zUAiPBlG9HFDXI/ZKWF1hLu3T6kBxxwkJwS9F+jXGSFY0sKud3S4HWjZX7aSVYYctnUGDk6LqT3DloxSp4qjOiLXavBZVmooyfkIzLXI5phAMlATq3Yjzy56M9+T8YSyU0KcvQJOKtrub34h2ToA6RUoS136XbvyqISc4OyHJw5effS9OzqUg6V8lMMdM9V3Qfz79JXqueXlEWyPbrcgXhc3Eta6SRUIrNyqatXNjmQd1/CM/jMXDxHyfkDPVw+VH/4v0aMRynf2AlIHvwc8fqA6vmNZr6VefUPfiuSbOTL7xjlLtB+ctGcYIJ0T5zKngudSlSlVHhx7yXUqIJrN/AhJc+nCtaMZ5ZHQ9jotc4gboE9GJF+k/q5tZvyjeV9Ap5Raf7/5EflfyH/5ankn1r5wrnQCHafgWqxQ6lTPtFdE1ZyVOA1Oq+uAD4CM0+TlQN54z3IjBqJkeAiOv4IQQr6nUxX5F34B4jRMImXmJKIDnLz+9CE6lfSofsgIob+vEcvJqSIiV2jwep+WyHl/DnqzuOCTF1dKEDQ8zjQ+TAZIF29fGGOiwaYCfnPtIP43hKuriZc37JrTIX60jmoi/7eU1X4ytutCCyteg4zg46mgDdLAAoBY/qmzCpEECoGWv6SbFg6/1f0y+snIu3vZfHNc/CNDdFSMRPLa2iDILv4IRssqzkSsLuZPWF6OzuByXtqsnSKYMOo4XHWrWTCQfvkkfruHM/
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01 2133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-05-23 2754704]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2015-04-30 1337000]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-05-23 1571696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-04-07 169768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2015-06-04 2892992]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-06-02 28787840]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-04-23 8204056]
"GalaxyClient"=C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [2015-05-28 7457336]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2015-05-21 4471536]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"VIDC.FPS1"=frapsv64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-06-12 12:54:55 ----A---- C:\awh8046.tmp
2015-06-12 12:49:17 ----D---- C:\Windows\Minidump
2015-06-12 10:46:08 ----A---- C:\awh59A3.tmp
2015-06-11 10:22:43 ----A---- C:\awhE7FD.tmp
2015-06-10 11:28:08 ----A---- C:\awhCCA1.tmp
2015-06-09 21:58:07 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-06-09 21:58:07 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-06-09 21:58:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-06-09 21:58:06 ----A---- C:\Windows\system32\iernonce.dll
2015-06-09 21:58:06 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-06-09 21:58:06 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-06-09 21:58:06 ----A---- C:\Windows\system32\ie4uinit.exe
2015-06-09 21:58:05 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-06-09 21:58:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-06-09 21:58:05 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-06-09 21:58:05 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-09 21:58:04 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-06-09 21:58:04 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-06-09 21:58:04 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-06-09 21:58:04 ----A---- C:\Windows\system32\urlmon.dll
2015-06-09 21:58:04 ----A---- C:\Windows\system32\iedkcs32.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-06-09 21:58:03 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-06-09 21:58:03 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-09 21:58:03 ----A---- C:\Windows\system32\msfeeds.dll
2015-06-09 21:58:03 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-06-09 21:58:03 ----A---- C:\Windows\system32\dxtrans.dll
2015-06-09 21:58:02 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-06-09 21:58:02 ----A---- C:\Windows\system32\iesetup.dll
2015-06-09 21:58:02 ----A---- C:\Windows\system32\ieapfltr.dll
2015-06-09 21:58:01 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-06-09 21:58:01 ----A---- C:\Windows\system32\vbscript.dll
2015-06-09 21:58:01 ----A---- C:\Windows\system32\iertutil.dll
2015-06-09 21:58:00 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-06-09 21:58:00 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-06-09 21:58:00 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-06-09 21:58:00 ----A---- C:\Windows\system32\jsproxy.dll
2015-06-09 21:58:00 ----A---- C:\Windows\system32\ieUnatt.exe
2015-06-09 21:57:59 ----A---- C:\Windows\system32\ieui.dll
2015-06-09 21:57:59 ----A---- C:\Windows\system32\ieframe.dll
2015-06-09 21:57:59 ----A---- C:\Windows\system32\dxtmsft.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\mshtmled.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\jscript9diag.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\jscript9.dll
2015-06-09 21:57:58 ----A---- C:\Windows\system32\jscript.dll
2015-06-09 21:57:57 ----A---- C:\Windows\system32\wininet.dll
2015-06-09 21:57:57 ----A---- C:\Windows\system32\msrating.dll
2015-06-09 21:57:57 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-06-09 21:57:56 ----A---- C:\Windows\system32\mshtml.dll
2015-06-09 21:57:38 ----A---- C:\Windows\system32\wmp.dll
2015-06-09 21:57:37 ----A---- C:\Windows\SYSWOW64\wmp.dll
2015-06-09 21:57:36 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2015-06-09 21:57:36 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2015-06-09 21:57:36 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2015-06-09 21:57:36 ----A---- C:\Windows\system32\wmploc.DLL
2015-06-09 21:57:36 ----A---- C:\Windows\system32\spwmp.dll
2015-06-09 21:57:36 ----A---- C:\Windows\system32\dxmasf.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\invagent.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\generaltel.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\devinv.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\appraiser.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\aepic.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\aepdu.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\aeinv.dll
2015-06-09 21:57:34 ----A---- C:\Windows\system32\acmigration.dll
2015-06-09 21:57:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-06-09 21:57:29 ----A---- C:\Windows\system32\KernelBase.dll
2015-06-09 21:57:29 ----A---- C:\Windows\system32\kerberos.dll
2015-06-09 21:57:29 ----A---- C:\Windows\system32\diagtrack.dll
2015-06-09 21:57:28 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-06-09 21:57:28 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-06-09 21:57:28 ----A---- C:\Windows\system32\lsasrv.dll
2015-06-09 21:57:28 ----A---- C:\Windows\system32\kernel32.dll
2015-06-09 21:57:28 ----A---- C:\Windows\system32\advapi32.dll
2015-06-09 21:57:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-06-09 21:57:27 ----A---- C:\Windows\system32\ntdll.dll
2015-06-09 21:57:27 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\tracerpt.exe
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-06-09 21:57:26 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\wow64.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\winsrv.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\tracerpt.exe
2015-06-09 21:57:26 ----A---- C:\Windows\system32\srcore.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\schannel.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\rstrui.exe
2015-06-09 21:57:26 ----A---- C:\Windows\system32\msv1_0.dll
2015-06-09 21:57:26 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-06-09 21:57:26 ----A---- C:\Windows\system32\conhost.exe
2015-06-09 21:57:25 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-06-09 21:57:25 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-06-09 21:57:25 ----A---- C:\Windows\SYSWOW64\logman.exe
2015-06-09 21:57:25 ----A---- C:\Windows\system32\wdigest.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\TSpkg.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\tdh.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\sspicli.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\sechost.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\ncrypt.dll
2015-06-09 21:57:25 ----A---- C:\Windows\system32\logman.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\typeperf.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\sechost.dll
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\relog.exe
2015-06-09 21:57:24 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\typeperf.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\smss.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\relog.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\lsass.exe
2015-06-09 21:57:24 ----A---- C:\Windows\system32\auditpol.exe
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\diskperf.exe
2015-06-09 21:57:23 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\sspisrv.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\srclient.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\secur32.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\ntvdm64.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\diskperf.exe
2015-06-09 21:57:23 ----A---- C:\Windows\system32\csrsrv.dll
2015-06-09 21:57:23 ----A---- C:\Windows\system32\credssp.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-09 21:57:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-06-09 21:57:22 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-06-09 21:57:22 ----A---- C:\Windows\system32\wow64win.dll
2015-06-09 21:57:22 ----A---- C:\Windows\system32\wow64cpu.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-09 21:57:21 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\user.exe
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-06-09 21:57:21 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-06-09 21:57:21 ----A---- C:\Windows\system32\apisetschema.dll
2015-06-09 21:57:21 ----A---- C:\Windows\system32\adtschema.dll
2015-06-09 21:57:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-06-09 21:57:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-06-09 21:57:20 ----A---- C:\Windows\system32\UtcResources.dll
2015-06-09 21:57:20 ----A---- C:\Windows\system32\msobjs.dll
2015-06-09 21:57:20 ----A---- C:\Windows\system32\msaudite.dll
2015-06-09 21:56:48 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-06-09 21:56:48 ----A---- C:\Windows\system32\comctl32.dll
2015-06-09 21:56:46 ----A---- C:\Windows\system32\win32k.sys
2015-06-09 21:56:37 ----A---- C:\Windows\system32\drivers\stream.sys
2015-06-09 21:47:12 ----A---- C:\awh27CA.tmp
2015-06-08 11:03:04 ----A---- C:\awhA8BC.tmp
2015-06-07 01:07:45 ----A---- C:\awh4623.tmp
2015-06-06 10:56:13 ----A---- C:\awhB99E.tmp
2015-06-05 10:28:47 ----A---- C:\awh426C.tmp
2015-06-04 11:51:39 ----A---- C:\awhB17.tmp
2015-06-03 15:27:11 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2015-06-02 22:04:20 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-06-02 22:00:46 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvopencl.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvoglv64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvinitx.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\NvIFR64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\NvFBC64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvdispgenco6435306.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvdispco6435306.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvcuvid.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvcuda.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\nvcompiler.dll
2015-06-02 22:00:46 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-06-02 21:45:11 ----D---- C:\ProgramData\boost_interprocess
2015-06-02 21:45:06 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2015-06-02 21:45:06 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2015-06-01 22:47:03 ----D---- C:\rsit
2015-06-01 22:47:03 ----D---- C:\Program Files\trend micro
2015-05-28 22:37:46 ----D---- C:\Program Files (x86)\Cool getWeather
2015-05-28 22:32:04 ----D---- C:\Program Files (x86)\69dc8177-a574-4dff-8461-b3267b078dcf
2015-05-28 22:32:01 ----A---- C:\Users\Win7\AppData\Roaming\BYAIAMUF.exe
2015-05-28 22:31:59 ----D---- C:\Program Files (x86)\globalUpdate
2015-05-28 22:31:49 ----D---- C:\Program Files (x86)\CinemaP-1.9cV16.03
2015-05-28 22:31:38 ----D---- C:\Program Files (x86)\Seznam.cz
2015-05-28 22:31:25 ----D---- C:\Users\Win7\AppData\Roaming\Seznam.cz
2015-05-28 22:22:34 ----D---- C:\Program Files (x86)\Ubisoft
2015-05-28 22:17:01 ----D---- C:\Users\Win7\AppData\Roaming\DAEMON Tools Lite
2015-05-28 22:17:01 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2015-05-28 22:16:52 ----D---- C:\Program Files\DAEMON Tools Lite
2015-05-24 20:15:10 ----D---- C:\Users\Win7\AppData\Roaming\LolClient
2015-05-24 20:15:09 ----D---- C:\Users\Win7\AppData\Roaming\Macromedia
2015-05-24 18:04:56 ----D---- C:\ProgramData\Riot Games
2015-05-24 18:03:27 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2015-05-24 18:03:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2015-05-24 18:03:25 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2015-05-24 18:01:50 ----D---- C:\Program Files (x86)\Lol
2015-05-24 18:01:24 ----D---- C:\Users\Win7\AppData\Roaming\Riot Games
2015-05-24 02:10:26 ----D---- C:\Program Files (x86)\Life Is Strange
2015-05-23 23:55:02 ----D---- C:\Program Files (x86)\2K Games
2015-05-20 12:47:04 ----A---- C:\Windows\system32\drivers\nethfdrv.sys
2015-05-20 12:45:46 ----A---- C:\Windows\SYSWOW64\netupdsrv.exe
2015-05-20 12:45:24 ----A---- C:\Windows\SYSWOW64\installd.exe
2015-05-20 12:45:02 ----A---- C:\Windows\SYSWOW64\nethtsrv.exe
2015-05-20 12:44:26 ----A---- C:\Windows\SYSWOW64\hfnapi.dll
2015-05-20 12:43:54 ----A---- C:\Windows\SYSWOW64\hfpapi.dll
2015-05-20 11:52:52 ----D---- C:\Users\Win7\AppData\Roaming\NVIDIA
2015-05-20 11:47:01 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\nvhdap64.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\nvdispgenco6435286.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\nvdispco6435286.dll
2015-05-20 11:47:01 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2015-05-20 11:19:43 ----D---- C:\ProgramData\GOG.com
2015-05-20 11:19:43 ----D---- C:\Program Files (x86)\GalaxyClient
2015-05-20 10:34:11 ----D---- C:\GOG Games
2015-05-17 16:33:00 ----D---- C:\Users\Win7\AppData\Roaming\Apple Computer
2015-05-17 16:32:52 ----DC---- C:\Windows\system32\DRVSTORE
2015-05-17 16:32:52 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2015-05-17 16:32:13 ----D---- C:\Program Files\iPod
2015-05-17 16:32:13 ----D---- C:\Program Files (x86)\iTunes
2015-05-17 16:32:12 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-05-17 16:32:12 ----D---- C:\ProgramData\Apple Computer
2015-05-17 16:32:12 ----D---- C:\Program Files\iTunes
2015-05-17 16:31:00 ----D---- C:\Program Files (x86)\Apple Software Update
2015-05-17 16:30:11 ----D---- C:\Program Files\Common Files\Apple
2015-05-17 16:29:55 ----D---- C:\ProgramData\Apple
2015-05-16 22:38:58 ----D---- C:\Program Files\CCleaner
2015-05-16 18:13:19 ----D---- C:\Program Files (x86)\Total War Shogun 2
2015-05-14 21:26:46 ----D---- C:\ProgramData\Package Cache
2015-05-14 00:46:36 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 00:46:36 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 13:15:46 ----D---- C:\Users\Win7\AppData\Roaming\dvdcss
2015-05-13 08:11:45 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-13 08:11:45 ----A---- C:\Windows\system32\certcli.dll
2015-05-13 08:06:37 ----A---- C:\Windows\system32\services.exe
2015-05-13 08:05:54 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-13 08:05:54 ----A---- C:\Windows\system32\FntCache.dll
2015-05-13 08:05:54 ----A---- C:\Windows\system32\DWrite.dll
2015-05-13 08:05:49 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-05-13 08:05:49 ----A---- C:\Windows\system32\jnwmon.dll
2015-05-13 08:05:49 ----A---- C:\Windows\system32\InkEd.dll
2015-05-13 08:05:47 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2015-05-13 08:05:47 ----A---- C:\Windows\system32\wpdshext.dll
2015-05-13 08:05:44 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2015-05-13 08:05:43 ----A---- C:\Windows\system32\poqexec.exe
2015-05-13 08:05:39 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-05-13 08:05:39 ----A---- C:\Windows\system32\apphelp.dll
2015-05-13 08:05:39 ----A---- C:\Windows\system32\aelupsvc.dll
2015-05-13 08:05:38 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-05-13 08:05:38 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-05-13 08:05:38 ----A---- C:\Windows\system32\shimeng.dll
2015-05-13 08:05:38 ----A---- C:\Windows\system32\sdbinst.exe
======List of files/folders modified in the last 1 month======
2015-06-12 21:26:50 ----D---- C:\Windows\Temp
2015-06-12 17:06:11 ----D---- C:\Users\Win7\AppData\Roaming\vlc
2015-06-12 14:46:36 ----D---- C:\Program Files (x86)\Rockstar Games
2015-06-12 14:46:27 ----D---- C:\Program Files\Rockstar Games
2015-06-12 12:53:10 ----D---- C:\Users\Win7\AppData\Roaming\Skype
2015-06-12 12:53:09 ----D---- C:\Program Files (x86)\Steam
2015-06-12 12:51:24 ----D---- C:\Windows\Prefetch
2015-06-12 12:49:19 ----D---- C:\ProgramData\NVIDIA
2015-06-12 12:49:17 ----D---- C:\Windows
2015-06-12 10:44:50 ----D---- C:\Windows\system32\config
2015-06-11 15:09:03 ----D---- C:\Users\Win7\AppData\Roaming\TS3Client
2015-06-11 10:39:31 ----SD---- C:\Users\Win7\AppData\Roaming\Microsoft
2015-06-10 18:08:45 ----SHD---- C:\Windows\Installer
2015-06-10 18:08:25 ----D---- C:\ProgramData\Skype
2015-06-10 11:29:22 ----D---- C:\Windows\System32
2015-06-10 11:29:22 ----D---- C:\Windows\inf
2015-06-10 11:29:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-10 11:23:22 ----D---- C:\Windows\winsxs
2015-06-10 11:20:43 ----D---- C:\Program Files (x86)\Windows Media Player
2015-06-10 11:20:42 ----SD---- C:\Windows\system32\CompatTel
2015-06-10 11:20:42 ----D---- C:\Windows\SysWOW64
2015-06-10 11:20:42 ----D---- C:\Windows\system32\appraiser
2015-06-10 11:20:42 ----D---- C:\Windows\AppPatch
2015-06-10 11:20:42 ----D---- C:\Program Files\Windows Media Player
2015-06-10 11:20:41 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-06-10 11:20:40 ----D---- C:\Windows\system32\cs-CZ
2015-06-10 11:20:39 ----D---- C:\Windows\system32\drivers
2015-06-10 11:20:35 ----D---- C:\Program Files\Internet Explorer
2015-06-10 11:20:34 ----D---- C:\Windows\SYSWOW64\en-US
2015-06-10 11:20:34 ----D---- C:\Windows\PolicyDefinitions
2015-06-10 11:20:33 ----D---- C:\Windows\system32\en-US
2015-06-10 11:20:32 ----D---- C:\Program Files (x86)\Internet Explorer
2015-06-10 01:21:24 ----D---- C:\Windows\system32\MRT
2015-06-10 01:17:54 ----D---- C:\Windows\debug
2015-06-10 01:17:46 ----A---- C:\Windows\system32\MRT.exe
2015-06-10 01:16:30 ----SHD---- C:\System Volume Information
2015-06-09 21:52:56 ----D---- C:\Windows\system32\catroot2
2015-06-04 11:45:35 ----D---- C:\Windows\Microsoft.NET
2015-06-04 11:41:17 ----D---- C:\Program Files (x86)\Common Files
2015-06-03 15:27:15 ----RSD---- C:\Windows\assembly
2015-06-03 15:27:11 ----RD---- C:\Program Files (x86)
2015-06-02 22:04:48 ----D---- C:\ProgramData\NVIDIA Corporation
2015-06-02 22:04:13 ----D---- C:\Windows\system32\DriverStore
2015-06-02 21:45:11 ----HD---- C:\ProgramData
2015-06-01 22:47:03 ----RD---- C:\Program Files
2015-05-29 00:12:13 ----D---- C:\Windows\Tasks
2015-05-29 00:06:06 ----D---- C:\Program Files (x86)\Google
2015-05-29 00:06:02 ----D---- C:\Windows\system32\Tasks
2015-05-28 23:03:17 ----D---- C:\Users\Win7\AppData\Roaming\BitTorrent
2015-05-28 22:22:35 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-05-28 22:15:38 ----D---- C:\ProgramData\DAEMON Tools Lite
2015-05-28 22:07:21 ----D---- C:\Windows\system32\catroot
2015-05-28 22:06:23 ----D---- C:\Users\Win7\AppData\Roaming\DAEMON Tools Pro
2015-05-28 11:13:55 ----D---- C:\Windows\Logs
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\OpenCL.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvapi64.dll
2015-05-28 06:15:30 ----A---- C:\Windows\system32\nvvsvc.exe
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvcr.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvc64.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvshext.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvmctray.dll
2015-05-28 06:15:28 ----A---- C:\Windows\system32\nvcpl.dll
2015-05-25 12:01:01 ----RD---- C:\Program Files (x86)\Skype
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspcap64.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspbridge64.dll
2015-05-20 15:08:54 ----SD---- C:\Windows\SYSWOW64\GWX
2015-05-20 15:08:54 ----SD---- C:\Windows\system32\GWX
2015-05-20 11:48:31 ----D---- C:\Program Files\NVIDIA Corporation
2015-05-18 17:03:53 ----D---- C:\Windows\system32\drivers\UMDF
2015-05-17 16:30:11 ----D---- C:\Program Files\Common Files
2015-05-16 22:41:32 ----D---- C:\Windows\Panther
2015-05-16 18:34:02 ----D---- C:\Users\Win7\AppData\Roaming\The Creative Assembly
2015-05-16 10:44:42 ----D---- C:\Windows\rescache
2015-05-15 22:40:20 ----D---- C:\Users\Win7\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2015-05-14 13:36:09 ----D---- C:\ProgramData\Adobe
2015-05-14 13:35:25 ----D---- C:\Users\Win7\AppData\Roaming\Adobe
2015-05-14 10:36:29 ----D---- C:\Program Files\Windows Journal
2015-05-14 10:36:28 ----D---- C:\Windows\system32\AdvancedInstallers
2015-05-14 00:52:36 ----D---- C:\Program Files\Microsoft Security Client
2015-05-14 00:52:36 ----D---- C:\Program Files (x86)\Microsoft Security Client
2015-05-13 08:52:35 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 280376]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys [2015-05-20 46160]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 124568]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2015-05-28 30264]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-05-13 195912]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-05-23 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2015-04-03 38032]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2014-09-09 14112]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-05-01 81088]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-01-19 77128]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-05-23 1152656]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 23816]
R2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe [2015-05-20 338944]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-05-23 1893008]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-05-23 23006864]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-05-28 937288]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2015-05-04 76888]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2015-05-20 190464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-28 410768]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2014-10-17 2589496]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-05-21 1272560]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-04-07 643880]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 366544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-05-28 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-29 107848]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 GalaxyClientService;GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [2015-05-28 1751096]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2015-06-03 6666808]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-05-28 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-29 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-05-22 114688]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-06-04 837312]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2015-04-20 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------