Prosím o kontrolu logu
Napsal: 18 zář 2016 10:59
Dobrý den, prosím o kontrolu RSIT logu, na některých stránkách mi to píše ''502 Bad gateway nginx /1.9.2''. Celkově je počítač nabržděný . Předem děkuji za pomoc.
___
Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2016-09-18 11:21:08
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 28 GB (23%) free of 122 GB
Total RAM: 8145 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:21:13, on 18.9.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18450)
Boot mode: Normal
Running processes:
C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Clownfish\Clownfish.exe
C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
D:\_Instal\volumouse\volumouse32.exe
C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\monhost.exe
C:\Users\Admin\AppData\Local\MEGAsync\MEGAsync.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
D:\_Instal\AtomTime Pro\AtomTime.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Local\Host Service\httpfilter.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\Admin\AppData\Roaming\ssn\SSN.exe
D:\_Dokumenty\Plocha\RSIT.exe
C:\Program Files (x86)\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pandasecurity.mystart.com/?pr=vm ... 575BFBDE7D
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=93018773_hao_pg
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\SysWOW64\userinit.exe,
O2 - BHO: QPMIEHelper - {50F4150A-48B2-417A-BE4C-C83F580FB904} - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Youtube AdBlock - {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} - C:\Program Files (x86)\Youtube AdBlock\IEEF\zC8s4PSbnr.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [AtomTime] "D:\_Instal\AtomTime Pro\AtomTime.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [app] C:\Program Files (x86)\sbqh\uc.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [$Volumouse$] "D:\_Instal\volumouse\volumouse.exe" /nodlg
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Voobly] "C:\Program Files (x86)\Voobly\voobly.exe" --startup
O4 - HKCU\..\Run: [Clownfish] "C:\Program Files (x86)\Clownfish\Clownfish.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [svchost0] "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe"\UUC0789.exe
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\sbqh\uc.exe
O4 - HKCU\..\Run: [produpd] C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
O4 - HKCU\..\Run: [ssn] C:\Users\Admin\AppData\Roaming\ssn\saveup.exe
O4 - HKCU\..\Run: [Host Service] wscript "C:\Users\Admin\AppData\Local\Host Service\launchall.js"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MEGAsync.lnk = Admin\AppData\Local\MEGAsync\MEGAsync.exe
O4 - Startup: produpd.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BaiduPinyin Updater (BaiduPinyinUpdater) - Unknown owner - C:\Program Files (x86)\Baidu\BaiduPinyinUpdate\bdupdate.exe (file missing)
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-Service.exe (file missing)
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (file missing)
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (file missing)
O23 - Service: CloudPrinter - Unknown owner - C:\ProgramData\\CloudPrinter\\CloudPrinter.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QQRepair2651 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: QQRepairc1b - Unknown owner - C:\Program.exe (file missing)
O23 - Service: QQRepairFixSVC - Unknown owner - C:\Program.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: winsaber - Unknown owner - C:\Program Files (x86)\WinSaber\WinSaber.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14694 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Update Service for Youtube AdBlock.job - C:\Program Files (x86)\Youtube AdBlock\p9B5Mzp.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmeqztvn.default
prefs.js - "browser.startup.homepage" - "http://pandasecurity.mystart.com/?pr=vm ... 575BFBDE7D"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.173 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_173.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@baidu.com/npxbdcntb]
"Description"=Baiducnff Plugin
"Path"=C:\Program Files (x86)\Baidu\BaiduPinyin\3.3.2.1028\npxbdcntb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=D:\_Instal\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=D:\_Instal\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmeqztvn.default\extensions\
{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}]
Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30 140344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2016-01-01 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}]
Youtube AdBlock - C:\Program Files (x86)\Youtube AdBlock\IEEF\zC8s4PSbnr.dll [2016-09-12 291792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13 1307928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-01 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13 1307928]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2015-06-15 296216]
"AtomTime"=D:\_Instal\AtomTime Pro\AtomTime.EXE [2015-10-19 396316]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-01-01 596528]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2016-08-18 1062472]
"app"=C:\Program Files (x86)\sbqh\uc.exe [2016-09-08 221246]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2016-09-14 5565960]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"$Volumouse$"=D:\_Instal\volumouse\volumouse.exe [2015-08-09 94816]
"uTorrent"=C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [2016-09-08 2139840]
"RGSC"=C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2008-11-14 305064]
"Voobly"=C:\Program Files (x86)\Voobly\voobly.exe [2016-06-19 159744]
"Clownfish"=C:\Program Files (x86)\Clownfish\Clownfish.exe [2016-08-18 1329408]
"cz.seznam.software.autoupdate"=C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe [2016-08-18 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2016-08-18 103080]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-08-28 2857248]
"svchost0"=C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe\UUC0789.exe []
"apphide"=C:\Program Files (x86)\sbqh\uc.exe [2016-09-08 221246]
"produpd"=C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe [2016-09-08 521216]
"ssn"=C:\Users\Admin\AppData\Roaming\ssn\saveup.exe [2016-09-08 29184]
"Host Service"=wscript C:\Users\Admin\AppData\Local\Host Service\launchall.js []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-09-17 8912088]
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Admin\AppData\Local\MEGAsync\MEGAsync.exe
produpd.lnk - C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux9"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-09-18 11:21:08 ----D---- C:\rsit
2016-09-18 11:21:08 ----D---- C:\Program Files (x86)\trend micro
2016-09-17 19:04:12 ----D---- C:\%LOCALAPPDATA%
2016-09-17 16:11:08 ----D---- C:\Program Files (x86)\Google
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\vbscript.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\urlmon.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\occache.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\inseng.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\iernonce.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\mshtml.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\iesetup.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\iertutil.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jscript.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\ieui.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\ieframe.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\webcheck.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\msrating.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\jscript9.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuwebv.dll
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wudriver.dll
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuapp.exe
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuapi.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wups.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wow32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wintrust.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\srclient.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\schannel.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\setup16.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\olepro32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntdll.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\msiexec.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\msi.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\KernelBase.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\kernel32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\instnm.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\cryptsvc.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\cryptnet.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\crypt32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\certcli.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\asycfilt.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\appidapi.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\advapi32.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\wdigest.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\user.exe
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\sspicli.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\secur32.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\rpchttp.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\rpcrt4.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msobjs.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msimsg.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msihnd.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msaudite.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\kerberos.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\cryptbase.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\credssp.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\authui.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\auditpol.exe
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\apisetschema.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\adtschema.dll
2016-09-15 15:29:48 ----A---- C:\Windows\SysWOW64\user32.dll
2016-09-15 15:29:47 ----A---- C:\Windows\SysWOW64\inetcomm.dll
2016-09-15 15:29:46 ----A---- C:\Windows\SysWOW64\INETRES.dll
2016-09-15 15:29:38 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2016-09-14 17:26:29 ----D---- C:\Program Files (x86)\{5B3162EB-D13D-41BA-9F10-0091DA316387}
2016-09-14 17:26:27 ----D---- C:\Program Files (x86)\e1ry2bpi
2016-09-14 13:27:56 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2016-09-13 14:37:41 ----D---- C:\Program Files (x86)\WinSaber
2016-09-13 14:36:36 ----D---- C:\Program Files (x86)\{9EC321B2-3D20-4C7A-95B8-047A55B2827F}
2016-09-13 14:36:34 ----D---- C:\Program Files (x86)\eqt7zw22
2016-09-12 11:43:06 ----D---- C:\Program Files (x86)\Youtube AdBlock
2016-09-12 11:42:24 ----D---- C:\Users\Admin\AppData\Roaming\GameLauncher
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v4
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v3
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v2
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v1
2016-09-09 15:00:32 ----D---- C:\ProgramData\AVAST Software
2016-09-08 13:36:39 ----A---- C:\Windows\SysWOW64\kz.exe
2016-09-08 07:05:27 ----D---- C:\Users\Admin\AppData\Roaming\ssn
2016-09-08 07:05:16 ----D---- C:\Users\Admin\AppData\Roaming\VDI
2016-09-08 07:03:01 ----D---- C:\Users\Admin\AppData\Roaming\Softlink
2016-09-08 07:03:01 ----D---- C:\Users\Admin\AppData\Roaming\KuaiZip
2016-09-08 07:02:33 ----D---- C:\Program Files (x86)\UCBrowser
2016-09-08 07:00:37 ----D---- C:\Program Files (x86)\sbqh
2016-09-08 07:00:28 ----HD---- C:\Program Files (x86)\a2d5DB9
2016-09-08 07:00:21 ----D---- C:\Users\Admin\AppData\Roaming\Profiles
2016-09-08 07:00:20 ----D---- C:\Program Files (x86)\Rerwadomeboch
2016-09-08 07:00:09 ----D---- C:\Program Files (x86)\ContentPush
2016-09-08 07:00:05 ----D---- C:\Program Files (x86)\WeatherChickn
2016-09-02 15:50:57 ----D---- C:\Users\Admin\AppData\Roaming\Windows Live Writer
2016-08-28 19:21:12 ----D---- C:\Program Files (x86)\Steam
======List of files/folders modified in the last 1 month======
2016-09-18 11:21:12 ----D---- C:\Windows\Temp
2016-09-18 11:21:12 ----D---- C:\Users\Admin\AppData\Roaming\uTorrent
2016-09-18 11:21:08 ----RD---- C:\Program Files (x86)
2016-09-18 10:03:46 ----D---- C:\Windows\inf
2016-09-18 09:33:33 ----SHD---- C:\Windows\Installer
2016-09-18 09:33:29 ----D---- C:\Windows\SysWOW64
2016-09-18 09:27:03 ----D---- C:\Windows\System32
2016-09-18 09:26:11 ----D---- C:\Users\Admin\AppData\Roaming\Seznam.cz
2016-09-18 09:21:08 ----D---- C:\Windows
2016-09-17 21:21:00 ----D---- C:\ProgramData\BlueStacksSetup
2016-09-17 21:20:56 ----D---- C:\Windows\Minidump
2016-09-17 21:20:56 ----D---- C:\Windows\Logs
2016-09-17 21:19:45 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-09-17 21:19:36 ----RD---- C:\Program Files
2016-09-17 20:05:51 ----D---- C:\Users\Admin\AppData\Roaming\.minecraft
2016-09-17 16:11:11 ----D---- C:\Windows\Tasks
2016-09-17 15:38:52 ----D---- C:\Users\Admin\AppData\Roaming\Skype
2016-09-16 16:00:15 ----D---- C:\Windows\rescache
2016-09-16 13:59:08 ----D---- C:\Windows\winsxs
2016-09-16 13:56:59 ----D---- C:\Windows\SysWOW64\en-US
2016-09-16 13:56:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2016-09-16 13:56:58 ----D---- C:\Windows\AppPatch
2016-09-16 13:56:58 ----D---- C:\Program Files (x86)\Internet Explorer
2016-09-15 20:10:07 ----D---- C:\ProgramData\Microsoft Help
2016-09-15 20:08:29 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-09-15 20:08:08 ----SHD---- C:\System Volume Information
2016-09-15 16:37:47 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-09-15 16:37:43 ----D---- C:\Windows\SysWOW64\Macromed
2016-09-12 11:43:00 ----HD---- C:\ProgramData
2016-09-08 13:35:14 ----D---- C:\Program Files (x86)\Common Files\Steam
2016-09-08 07:07:12 ----D---- C:\ProgramData\panda_url_filtering
2016-09-08 07:00:04 ----SD---- C:\Users\Admin\AppData\Roaming\Microsoft
2016-09-01 11:33:02 ----D---- C:\Program Files (x86)\Cheat Engine 6.4
2016-08-23 20:16:03 ----D---- C:\Program Files (x86)\Voobly
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys []
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys []
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys []
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-12-08 75248]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys []
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys []
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 ScreamBAudioSvc;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
S1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys []
S1 softaal;softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys []
S1 SRepairDrv;SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\SRepairDrv []
S2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys []
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2016-05-21 26192]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys []
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TSSKX64;TSSKX64; C:\Windows\System32\drivers\tsskx64.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-11-21 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 CkerloyClient;CkerloyClient; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2016-06-13 5817200]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2016-09-14 2621448]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2015-06-23 18856]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [2016-09-14 419248]
R2 winsaber;winsaber; C:\Program Files (x86)\WinSaber\WinSaber.exe [2016-09-13 521496]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe [2016-06-17 240408]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-28 1465120]
S2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe [2016-06-17 193816]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android []
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe []
S2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe []
S2 CloudPrinter;CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe shuz -f C:\ProgramData\\CloudPrinter\\CloudPrinter.dat -l -a []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-05-17 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-05-17 125112]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-17 153752]
S2 QQRepair2651;QQRepair2651; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair2651 []
S2 QQRepairc1b;QQRepairc1b; C:\Program Files (x86)\Tencent\QQPCMGR\QQRepairc1b []
S2 QQRepairFixSVC;QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\QQRepairFixSVC []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-05-23 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-15 270528]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BaiduPinyinUpdater;BaiduPinyin Updater; C:\Program Files (x86)\Baidu\BaiduPinyinUpdate\bdupdate.exe []
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2016-06-13 2271928]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-17 153752]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2015-06-03 217888]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-06-10 1289968]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-05-17 51376]
S4 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-12-08 83240]
S4 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-12-07 75048]
S4 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [2011-12-07 292136]
S4 EasyTuneEngineService;EasyTune Engine; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [2015-08-05 138240]
S4 gadjservice;GIGABYTE Adjust; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [2015-06-25 17920]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 OcButtonService;OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [2015-08-05 117760]
-----------------EOF-----------------
___
Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2016-09-18 11:21:08
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 28 GB (23%) free of 122 GB
Total RAM: 8145 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:21:13, on 18.9.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18450)
Boot mode: Normal
Running processes:
C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Clownfish\Clownfish.exe
C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
D:\_Instal\volumouse\volumouse32.exe
C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\monhost.exe
C:\Users\Admin\AppData\Local\MEGAsync\MEGAsync.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
D:\_Instal\AtomTime Pro\AtomTime.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Local\Host Service\httpfilter.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\Admin\AppData\Roaming\ssn\SSN.exe
D:\_Dokumenty\Plocha\RSIT.exe
C:\Program Files (x86)\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pandasecurity.mystart.com/?pr=vm ... 575BFBDE7D
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=93018773_hao_pg
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\SysWOW64\userinit.exe,
O2 - BHO: QPMIEHelper - {50F4150A-48B2-417A-BE4C-C83F580FB904} - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Youtube AdBlock - {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} - C:\Program Files (x86)\Youtube AdBlock\IEEF\zC8s4PSbnr.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [AtomTime] "D:\_Instal\AtomTime Pro\AtomTime.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [app] C:\Program Files (x86)\sbqh\uc.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [$Volumouse$] "D:\_Instal\volumouse\volumouse.exe" /nodlg
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Voobly] "C:\Program Files (x86)\Voobly\voobly.exe" --startup
O4 - HKCU\..\Run: [Clownfish] "C:\Program Files (x86)\Clownfish\Clownfish.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [svchost0] "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe"\UUC0789.exe
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\sbqh\uc.exe
O4 - HKCU\..\Run: [produpd] C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
O4 - HKCU\..\Run: [ssn] C:\Users\Admin\AppData\Roaming\ssn\saveup.exe
O4 - HKCU\..\Run: [Host Service] wscript "C:\Users\Admin\AppData\Local\Host Service\launchall.js"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MEGAsync.lnk = Admin\AppData\Local\MEGAsync\MEGAsync.exe
O4 - Startup: produpd.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BaiduPinyin Updater (BaiduPinyinUpdater) - Unknown owner - C:\Program Files (x86)\Baidu\BaiduPinyinUpdate\bdupdate.exe (file missing)
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-Service.exe (file missing)
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (file missing)
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (file missing)
O23 - Service: CloudPrinter - Unknown owner - C:\ProgramData\\CloudPrinter\\CloudPrinter.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QQRepair2651 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: QQRepairc1b - Unknown owner - C:\Program.exe (file missing)
O23 - Service: QQRepairFixSVC - Unknown owner - C:\Program.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: winsaber - Unknown owner - C:\Program Files (x86)\WinSaber\WinSaber.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14694 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Update Service for Youtube AdBlock.job - C:\Program Files (x86)\Youtube AdBlock\p9B5Mzp.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmeqztvn.default
prefs.js - "browser.startup.homepage" - "http://pandasecurity.mystart.com/?pr=vm ... 575BFBDE7D"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.173 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_173.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@baidu.com/npxbdcntb]
"Description"=Baiducnff Plugin
"Path"=C:\Program Files (x86)\Baidu\BaiduPinyin\3.3.2.1028\npxbdcntb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=D:\_Instal\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=D:\_Instal\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmeqztvn.default\extensions\
{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
{ea614400-e918-4741-9a97-7a972ff7c30b}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}]
Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30 140344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2016-01-01 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}]
Youtube AdBlock - C:\Program Files (x86)\Youtube AdBlock\IEEF\zC8s4PSbnr.dll [2016-09-12 291792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13 1307928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-01 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13 1307928]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2015-06-15 296216]
"AtomTime"=D:\_Instal\AtomTime Pro\AtomTime.EXE [2015-10-19 396316]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-01-01 596528]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2016-08-18 1062472]
"app"=C:\Program Files (x86)\sbqh\uc.exe [2016-09-08 221246]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2016-09-14 5565960]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"$Volumouse$"=D:\_Instal\volumouse\volumouse.exe [2015-08-09 94816]
"uTorrent"=C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [2016-09-08 2139840]
"RGSC"=C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2008-11-14 305064]
"Voobly"=C:\Program Files (x86)\Voobly\voobly.exe [2016-06-19 159744]
"Clownfish"=C:\Program Files (x86)\Clownfish\Clownfish.exe [2016-08-18 1329408]
"cz.seznam.software.autoupdate"=C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe [2016-08-18 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2016-08-18 103080]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-08-28 2857248]
"svchost0"=C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe\UUC0789.exe []
"apphide"=C:\Program Files (x86)\sbqh\uc.exe [2016-09-08 221246]
"produpd"=C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe [2016-09-08 521216]
"ssn"=C:\Users\Admin\AppData\Roaming\ssn\saveup.exe [2016-09-08 29184]
"Host Service"=wscript C:\Users\Admin\AppData\Local\Host Service\launchall.js []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-09-17 8912088]
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Admin\AppData\Local\MEGAsync\MEGAsync.exe
produpd.lnk - C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux9"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-09-18 11:21:08 ----D---- C:\rsit
2016-09-18 11:21:08 ----D---- C:\Program Files (x86)\trend micro
2016-09-17 19:04:12 ----D---- C:\%LOCALAPPDATA%
2016-09-17 16:11:08 ----D---- C:\Program Files (x86)\Google
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\vbscript.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\urlmon.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\occache.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\inseng.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\iernonce.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\mshtml.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\iesetup.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\iertutil.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jscript.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\ieui.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\ieframe.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\webcheck.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\msrating.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\jscript9.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuwebv.dll
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wudriver.dll
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuapp.exe
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuapi.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wups.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wow32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wintrust.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\srclient.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\schannel.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\setup16.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\olepro32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntdll.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\msiexec.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\msi.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\KernelBase.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\kernel32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\instnm.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\cryptsvc.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\cryptnet.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\crypt32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\certcli.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\asycfilt.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\appidapi.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\advapi32.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\wdigest.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\user.exe
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\sspicli.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\secur32.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\rpchttp.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\rpcrt4.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msobjs.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msimsg.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msihnd.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msaudite.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\kerberos.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\cryptbase.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\credssp.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\authui.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\auditpol.exe
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\apisetschema.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\adtschema.dll
2016-09-15 15:29:48 ----A---- C:\Windows\SysWOW64\user32.dll
2016-09-15 15:29:47 ----A---- C:\Windows\SysWOW64\inetcomm.dll
2016-09-15 15:29:46 ----A---- C:\Windows\SysWOW64\INETRES.dll
2016-09-15 15:29:38 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2016-09-14 17:26:29 ----D---- C:\Program Files (x86)\{5B3162EB-D13D-41BA-9F10-0091DA316387}
2016-09-14 17:26:27 ----D---- C:\Program Files (x86)\e1ry2bpi
2016-09-14 13:27:56 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2016-09-13 14:37:41 ----D---- C:\Program Files (x86)\WinSaber
2016-09-13 14:36:36 ----D---- C:\Program Files (x86)\{9EC321B2-3D20-4C7A-95B8-047A55B2827F}
2016-09-13 14:36:34 ----D---- C:\Program Files (x86)\eqt7zw22
2016-09-12 11:43:06 ----D---- C:\Program Files (x86)\Youtube AdBlock
2016-09-12 11:42:24 ----D---- C:\Users\Admin\AppData\Roaming\GameLauncher
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v4
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v3
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v2
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v1
2016-09-09 15:00:32 ----D---- C:\ProgramData\AVAST Software
2016-09-08 13:36:39 ----A---- C:\Windows\SysWOW64\kz.exe
2016-09-08 07:05:27 ----D---- C:\Users\Admin\AppData\Roaming\ssn
2016-09-08 07:05:16 ----D---- C:\Users\Admin\AppData\Roaming\VDI
2016-09-08 07:03:01 ----D---- C:\Users\Admin\AppData\Roaming\Softlink
2016-09-08 07:03:01 ----D---- C:\Users\Admin\AppData\Roaming\KuaiZip
2016-09-08 07:02:33 ----D---- C:\Program Files (x86)\UCBrowser
2016-09-08 07:00:37 ----D---- C:\Program Files (x86)\sbqh
2016-09-08 07:00:28 ----HD---- C:\Program Files (x86)\a2d5DB9
2016-09-08 07:00:21 ----D---- C:\Users\Admin\AppData\Roaming\Profiles
2016-09-08 07:00:20 ----D---- C:\Program Files (x86)\Rerwadomeboch
2016-09-08 07:00:09 ----D---- C:\Program Files (x86)\ContentPush
2016-09-08 07:00:05 ----D---- C:\Program Files (x86)\WeatherChickn
2016-09-02 15:50:57 ----D---- C:\Users\Admin\AppData\Roaming\Windows Live Writer
2016-08-28 19:21:12 ----D---- C:\Program Files (x86)\Steam
======List of files/folders modified in the last 1 month======
2016-09-18 11:21:12 ----D---- C:\Windows\Temp
2016-09-18 11:21:12 ----D---- C:\Users\Admin\AppData\Roaming\uTorrent
2016-09-18 11:21:08 ----RD---- C:\Program Files (x86)
2016-09-18 10:03:46 ----D---- C:\Windows\inf
2016-09-18 09:33:33 ----SHD---- C:\Windows\Installer
2016-09-18 09:33:29 ----D---- C:\Windows\SysWOW64
2016-09-18 09:27:03 ----D---- C:\Windows\System32
2016-09-18 09:26:11 ----D---- C:\Users\Admin\AppData\Roaming\Seznam.cz
2016-09-18 09:21:08 ----D---- C:\Windows
2016-09-17 21:21:00 ----D---- C:\ProgramData\BlueStacksSetup
2016-09-17 21:20:56 ----D---- C:\Windows\Minidump
2016-09-17 21:20:56 ----D---- C:\Windows\Logs
2016-09-17 21:19:45 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-09-17 21:19:36 ----RD---- C:\Program Files
2016-09-17 20:05:51 ----D---- C:\Users\Admin\AppData\Roaming\.minecraft
2016-09-17 16:11:11 ----D---- C:\Windows\Tasks
2016-09-17 15:38:52 ----D---- C:\Users\Admin\AppData\Roaming\Skype
2016-09-16 16:00:15 ----D---- C:\Windows\rescache
2016-09-16 13:59:08 ----D---- C:\Windows\winsxs
2016-09-16 13:56:59 ----D---- C:\Windows\SysWOW64\en-US
2016-09-16 13:56:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2016-09-16 13:56:58 ----D---- C:\Windows\AppPatch
2016-09-16 13:56:58 ----D---- C:\Program Files (x86)\Internet Explorer
2016-09-15 20:10:07 ----D---- C:\ProgramData\Microsoft Help
2016-09-15 20:08:29 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-09-15 20:08:08 ----SHD---- C:\System Volume Information
2016-09-15 16:37:47 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-09-15 16:37:43 ----D---- C:\Windows\SysWOW64\Macromed
2016-09-12 11:43:00 ----HD---- C:\ProgramData
2016-09-08 13:35:14 ----D---- C:\Program Files (x86)\Common Files\Steam
2016-09-08 07:07:12 ----D---- C:\ProgramData\panda_url_filtering
2016-09-08 07:00:04 ----SD---- C:\Users\Admin\AppData\Roaming\Microsoft
2016-09-01 11:33:02 ----D---- C:\Program Files (x86)\Cheat Engine 6.4
2016-08-23 20:16:03 ----D---- C:\Program Files (x86)\Voobly
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys []
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys []
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys []
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-12-08 75248]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys []
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys []
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 ScreamBAudioSvc;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
S1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys []
S1 softaal;softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys []
S1 SRepairDrv;SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\SRepairDrv []
S2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys []
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2016-05-21 26192]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys []
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TSSKX64;TSSKX64; C:\Windows\System32\drivers\tsskx64.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-11-21 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 CkerloyClient;CkerloyClient; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2016-06-13 5817200]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2016-09-14 2621448]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2015-06-23 18856]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [2016-09-14 419248]
R2 winsaber;winsaber; C:\Program Files (x86)\WinSaber\WinSaber.exe [2016-09-13 521496]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe [2016-06-17 240408]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-28 1465120]
S2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe [2016-06-17 193816]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android []
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe []
S2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe []
S2 CloudPrinter;CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe shuz -f C:\ProgramData\\CloudPrinter\\CloudPrinter.dat -l -a []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-05-17 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-05-17 125112]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-17 153752]
S2 QQRepair2651;QQRepair2651; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair2651 []
S2 QQRepairc1b;QQRepairc1b; C:\Program Files (x86)\Tencent\QQPCMGR\QQRepairc1b []
S2 QQRepairFixSVC;QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\QQRepairFixSVC []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-05-23 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-15 270528]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BaiduPinyinUpdater;BaiduPinyin Updater; C:\Program Files (x86)\Baidu\BaiduPinyinUpdate\bdupdate.exe []
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2016-06-13 2271928]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-17 153752]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2015-06-03 217888]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-06-10 1289968]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-05-17 51376]
S4 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-12-08 83240]
S4 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-12-07 75048]
S4 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [2011-12-07 292136]
S4 EasyTuneEngineService;EasyTune Engine; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [2015-08-05 138240]
S4 gadjservice;GIGABYTE Adjust; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [2015-06-25 17920]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 OcButtonService;OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [2015-08-05 117760]
-----------------EOF-----------------