Asi virus prosím o pomoc
Napsal: 11 dub 2017 11:01
Zdravím vás, mám určitě zavirováno. Únos prohlížeče, popup okna, jiný vyhledávač a jiné nestandartní chování notebooku. Posílám log RSIT:
Logfile of random's system information tool 1.16 (written by random/random)
Run by Pepa at 2017-04-11 11:48:01
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 10 GB (4%) free of 226 GB
Total RAM: 3003 MB (53% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:52:07, on 11.4.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18618)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Windows\PLFSetI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files\trend micro\Pepa_RSITx64.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.ourluckysites.com/search/?ty ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ourluckysites.com/search/?ty ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.200.3:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Canon LBP2900 Status Window.lnk = C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD - Unknown owner - C:\Users\Pepa\AppData\Local\AMD\amd.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Update Service(FirefoxU) (FirefoxU) - Unknown owner - C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spy Emergency Health Check (SpyEmrgHealth) - Unknown owner - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11984 bytes
====== Enumerating Processes ======
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k localservice
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k networkservice
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Users\Pepa\AppData\Local\AMD\amd.exe -s
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
c:\windows\system32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe"
C:\Windows\system32\taskhost.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
C:\Windows\system32\CNAB4RPD.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files (x86)\Acer\Registration\GregHSRW.exe"
"C:\Windows\PLFSetI.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe"
"C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe"
c:\windows\system32\svchost.exe -k snarer
c:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
C:\Windows\SysWOW64\svchost.exe -k WinSAPSvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe"
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
C:\Program Files (x86)\CCleaner\CCleaner64.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
"C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe"
C:\Windows\SysWOW64\svchost.exe -k MVCService
C:\Windows\SysWOW64\rundll32.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\igfxsrvc.exe -Embedding
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --original-process-start-time=13136376734388911 --fast-start
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=watcher --main-thread-id=6028 --on-initialized-event-handle=328 --parent-handle=340 /prefetch:6
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=E9302A7FFE6C71B3D8ED9287CE602E90 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=E9302A7FFE6C71B3D8ED9287CE602E90 --renderer-client-id=5 --mojo-platform-channel-handle=1776 /prefetch:1
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=D19BDB4FC9AAD6DAC0B82D663D9C2C83 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-gpu-compositing --service-request-channel-token=D19BDB4FC9AAD6DAC0B82D663D9C2C83 --renderer-client-id=3 --mojo-platform-channel-handle=2144 /prefetch:1
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=409628F110F14FCDEB60AA4173CA5DCA --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-gpu-compositing --service-request-channel-token=409628F110F14FCDEB60AA4173CA5DCA --renderer-client-id=4 --mojo-platform-channel-handle=2284 /prefetch:1
"C:\Users\Pepa\Desktop\RSITx64.exe"
C:\Windows\system32\taskeng.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\msiexec.exe /V
====== Scheduled tasks folder ======
C:\Windows\tasks\{011B8E39-CE88-41E0-B0D4-311E33EC992A}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{17533D0E-A9DE-49DD-93CD-ADE62A97FD62}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{1A89CBC3-1771-4C0D-8B7E-E785109150BA}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{25381E09-4350-4CEB-8375-8F9B5FC882B8}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{2C34D498-06D7-4808-AD10-2C290AFC7C68}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{3E70DE31-F555-4BF7-ACCE-E9AF4AEE522B}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{42441CAB-D394-4ED2-B527-BF8586500CBF}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{6B0B2E13-DD0E-4974-82C3-7F7BCAB85C41}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{9355D9FC-1AAB-4933-A742-7E47402C6D12}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{A9827EA4-461C-4E96-BBCE-3BD151F2CAA6}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{B08D7569-C085-4F1D-A2F4-D594EEAE262A}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{C91DE031-215F-4A00-AADF-39A56BA2C4DA}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Atafogh Helper - "C:\Program Files (x86)\Prervoly\anerserly.exe" 7f10ac44-c09a-4c46-92a9-247afe0ea6f6
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\avastBCLRestartS-1-5-21-2349173935-1687467584-554729351-1000 - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files (x86)\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\GarminUpdaterTask - C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Milimili - "C:\Program Files (x86)\MIO\MIO.exe" -bindurl http://api.suibianmaimaicom.com/toshiba ... bs1kns.dat cmd=
C:\Windows\system32\tasks\Puhasy - "msiexec" /i HtTp://d2buh1bf1g584w.cloudfront.net/ms ... v=20170324 /q
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1458737292 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\Windows-PG - C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Update\psgo\psgo.ps1
C:\Windows\system32\tasks\{20E2C8C3-5DB4-408A-89D1-4C38BD54A02E} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\2\SSM_Uninstall.exe
C:\Windows\system32\tasks\{2AC11547-3FF8-4A4D-912B-D9B2947164FC} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\AppData\Local\Temp\Data\MapSource\MapSource_6163.exe -d C:\Users\Pepa\AppData\Local\Temp\
C:\Windows\system32\tasks\{36A219C0-6B08-4296-802B-D29B8D49A9F3} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\Desktop\irfanviewcestina.exe -d C:\Users\Pepa\Desktop
C:\Windows\system32\tasks\{53F16E9A-9782-4582-8922-367414AEFD68} - D:\AOESETUP.EXE
C:\Windows\system32\tasks\{5A65194E-DB10-41AA-9266-5D0C4D4E2908} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\1\SS_Uninstall.exe
C:\Windows\system32\tasks\{7C64D715-407E-45A2-98B1-E29A1D4DE4B6} - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\system32\tasks\{88FB3DD7-0BE2-4D38-BFD8-1AD9D8AC2FF4} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\3\SSCDUninstall.exe
C:\Windows\system32\tasks\{B8A9D966-BF69-41CF-9882-B525641CD7F7} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\AppData\Local\Temp\jre-8u45-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1
C:\Windows\system32\tasks\{DD770AF6-E648-43B5-9840-2FCE3E8082BA} - C:\Windows\system32\pcalua.exe -a "C:\Users\Pepa\Documents\Ze starého počítače\Prográmky\aoe2pack_v3.01_saj.exe" -d "C:\Users\Pepa\Documents\Ze starého počítače\Prográmky"
C:\Windows\system32\tasks\{E33F0E26-0D8E-4EE7-9ACD-034474810FB3} - C:\Windows\system32\pcalua.exe -a D:\aoesetup.exe -d D:\ -c /autorun
C:\Windows\system32\tasks\{E58CCF12-DBFD-4155-A9A2-B9BCAAED3D6F} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\5\SSSDUninstall.exe
C:\Windows\system32\tasks\{EC838D8B-8D3E-42B4-B99C-E856EBC4DBE6} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\Desktop\frd.exe -d C:\Users\Pepa\Desktop
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-2349173935-1687467584-554729351-1000 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup - %systemroot%\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor - %systemroot%\system32\sdclt.exe /CHECKSKIPPED
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Lpksetup - C:\Windows\System32\lpksetup.exe -v
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\Windows\System32\mcbuilder.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
=========Mozilla firefox=========
ProfilePath - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.startup.homepage" - "http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.conduit.com/ResultsExt.as ... 2475029&q="
prefs.js - "browser.search.useDBForOrder" - true
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF48
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF48
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\
c1bwvxob.xml
luck.xml
ourluckysites.xml
startpageing123.xml
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\addons.json
Garmin Communicator - extension - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b}
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d}
Mozilla Firefox hotfix - extension - firefox-hotfix@mozilla.org
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions.json
Garmin Communicator - extension - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\firefox@getpocket.com.xpi
Firefox Hello - extension - loop@mozilla.org - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\loop@mozilla.org.xpi
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Site Deployment Checker - extension - deployment-checker@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Avast Online Security - webextension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF48
Avast SafePrice - webextension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\pluginreg.dat
Plugin - Shockwave Flash - 25.0.0.127 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll
=========Google Chrome=========
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
======Registry dump ======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL"=http://www.ourluckysites.com/search/?ty ... earchTerms}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL"=http://www.ourluckysites.com/search/?ty ... earchTerms}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}]
"URL"=http://www.google.com/search?sourceid=i ... lz=1I7ACAW
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
"URL"=http://search.conduit.com/ResultsExt.as ... =CT2475029
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-31 895528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-26 473152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-31 773920]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-26 186944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-09-17 1842472]
"Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [2009-10-03 496160]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-06 7940128]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-07-06 1833504]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-21 200704]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 161304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 386584]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 415256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-31 213824]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files (x86)\CCleaner\CCleaner64.exe [2017-03-03 9364696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19 1160408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray]
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-09-25 261888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boxoft Tools]
C:\ProgramData\Boxtools\Boxofttoolbox.exe [2010-12-15 514048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files (x86)\CCleaner\CCleaner64.exe [2017-03-03 9364696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [2015-10-29 1403304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]
C:\Program Files (x86)\Essentials Codec Pack\update.exe [2007-04-08 303104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeznamInstall-uninstall:62298f0e8f87a174e880190b05ada38f]
C:\Users\Pepa\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe -c C:\Users\Pepa\AppData\Roaming\Seznam.cz []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe /nosplash /minimized []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Pepa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\Pepa\AppData\Roaming\Dropbox\bin\Dropbox.exe [2014-03-19 32667896]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-11-01 1091152]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Canon LBP2900 Status Window.lnk - C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{D0668D3A-0EF4-11E7-B3CD-64006A5CFC35}"=C:\Users\Pepa\AppData\Roaming\Kulerty\Clifly.dll []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
====== File associations ======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
====== List of files/folders created in the last 1 month ======
2017-04-11 11:48:02 ----D---- C:\Program Files\trend micro
2017-04-11 11:48:01 ----D---- C:\rsit
2017-04-11 09:15:19 ----D---- C:\ProgramData\SWCUTemp
2017-04-10 23:02:13 ----D---- C:\Program Files (x86)\deskapp
2017-04-10 20:44:51 ----D---- C:\Update
2017-04-06 17:48:36 ----D---- C:\Users\Pepa\AppData\Roaming\SNARER
2017-04-05 10:39:54 ----D---- C:\Program Files (x86)\WINSNARE(4.4.6)
2017-04-01 20:58:39 ----A---- C:\Windows\system32\drivers\iSafeNetFilter.sys
2017-04-01 20:58:39 ----A---- C:\Windows\system32\drivers\iSafeKrnlBoot.sys
2017-04-01 20:58:36 ----D---- C:\Windows\system32\log
2017-04-01 20:58:11 ----D---- C:\Program Files (x86)\Elex-tech
2017-04-01 20:58:06 ----D---- C:\Users\Pepa\AppData\Roaming\Elex-tech
2017-04-01 20:57:48 ----D---- C:\Users\Pepa\AppData\Roaming\Firefox
2017-04-01 20:57:32 ----A---- C:\Windows\SYSWOW64\DB83.tmp
2017-04-01 20:56:57 ----AD---- C:\Program Files (x86)\Firefox
2017-04-01 20:56:38 ----D---- C:\Program Files (x86)\Eastone
2017-03-31 14:23:45 ----A---- C:\Windows\system32\aswBoot.exe
2017-03-31 11:50:05 ----D---- C:\Program Files\MK
2017-03-29 12:15:19 ----D---- C:\ProgramData\Pinnacle VideoSpin
2017-03-29 12:10:56 ----D---- C:\Users\Pepa\AppData\Roaming\Kyubey
2017-03-29 12:10:54 ----D---- C:\Program Files (x86)\MIO
2017-03-29 12:10:48 ----D---- C:\Users\Pepa\AppData\Roaming\WINSNARE
2017-03-29 12:10:47 ----D---- C:\Users\Pepa\AppData\Roaming\WinSAPSvc
2017-03-29 12:09:24 ----D---- C:\Program Files (x86)\MK
2017-03-29 12:07:56 ----D---- C:\Program Files\c1bwvxob
2017-03-27 21:36:55 ----HD---- C:\$AV_ASW
2017-03-26 22:29:02 ----D---- C:\Users\Pepa\AppData\Roaming\Sun
2017-03-26 20:37:55 ----D---- C:\Users\Pepa\AppData\Roaming\Netscape
2017-03-26 20:37:55 ----D---- C:\Program Files (x86)\Photodex Presenter
2017-03-26 20:37:38 ----D---- C:\Program Files (x86)\Photodex
2017-03-26 20:37:06 ----D---- C:\Users\Pepa\AppData\Roaming\Photodex
2017-03-24 16:19:51 ----D---- C:\ProgramData\Pinnacle Studio Ultimate Collection
2017-03-24 16:05:51 ----D---- C:\Program Files (x86)\Pinnacle
2017-03-24 16:03:37 ----A---- C:\ProgramData\__wdump.txt
2017-03-24 15:56:15 ----D---- C:\ProgramData\Pinnacle
2017-03-24 15:53:02 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2017-03-24 15:52:37 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2017-03-24 15:28:54 ----A---- C:\Windows\system32\drivers\dtultrausbbus.sys
2017-03-24 15:28:21 ----A---- C:\Windows\system32\drivers\dtultrascsibus.sys
2017-03-24 15:28:18 ----D---- C:\Users\Pepa\AppData\Roaming\DAEMON Tools Ultra
2017-03-24 15:26:20 ----D---- C:\ProgramData\DAEMON Tools Ultra
2017-03-24 15:04:25 ----D---- C:\Users\Pepa\AppData\Roaming\Kulerty
2017-03-24 15:03:29 ----D---- C:\Program Files (x86)\Atafogh Helper
2017-03-24 15:03:24 ----D---- C:\Users\Pepa\AppData\Roaming\Profiles
2017-03-24 15:03:24 ----D---- C:\Program Files (x86)\Prervoly
2017-03-24 15:01:25 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2017-03-24 15:00:16 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2017-03-16 22:12:27 ----A---- C:\Windows\system32\aepic.dll
2017-03-16 22:12:27 ----A---- C:\Windows\system32\aeinv.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\invagent.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\generaltel.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\devinv.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\centel.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\appraiser.dll
2017-03-16 22:12:25 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-03-16 22:12:25 ----A---- C:\Windows\system32\acmigration.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\inseng.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\iertutil.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\iernonce.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-03-15 16:48:24 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-03-15 16:48:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\occache.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\inseng.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\ie4uinit.exe
2017-03-15 16:48:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-03-15 16:48:22 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\urlmon.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\occache.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\iedkcs32.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\ieui.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-03-15 16:48:19 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-03-15 16:48:19 ----A---- C:\Windows\system32\msfeeds.dll
2017-03-15 16:48:19 ----A---- C:\Windows\system32\dxtrans.dll
2017-03-15 16:48:18 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-03-15 16:48:17 ----A---- C:\Windows\system32\iesetup.dll
2017-03-15 16:48:17 ----A---- C:\Windows\system32\ieapfltr.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-03-15 16:48:15 ----A---- C:\Windows\system32\vbscript.dll
2017-03-15 16:48:14 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-03-15 16:48:14 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2017-03-15 16:48:14 ----A---- C:\Windows\system32\jsproxy.dll
2017-03-15 16:48:14 ----A---- C:\Windows\system32\ieUnatt.exe
2017-03-15 16:48:13 ----A---- C:\Windows\system32\ieui.dll
2017-03-15 16:48:13 ----A---- C:\Windows\system32\dxtmsft.dll
2017-03-15 16:48:12 ----A---- C:\Windows\system32\ieframe.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\webcheck.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\mshtmled.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript9diag.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript9.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript.dll
2017-03-15 16:48:09 ----A---- C:\Windows\system32\wininet.dll
2017-03-15 16:48:08 ----A---- C:\Windows\system32\msrating.dll
2017-03-15 16:48:08 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-03-15 16:48:06 ----A---- C:\Windows\system32\mshtml.dll
2017-03-15 16:48:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-03-15 16:48:01 ----A---- C:\Windows\system32\win32k.sys
2017-03-15 16:48:00 ----A---- C:\Windows\system32\ntdll.dll
2017-03-15 16:47:59 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2017-03-15 16:47:59 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2017-03-15 16:47:59 ----A---- C:\Windows\system32\lsasrv.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\rpcrt4.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\msxml3.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\kerberos.dll
2017-03-15 16:47:57 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-03-15 16:47:57 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\schannel.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\KernelBase.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\DWrite.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\advapi32.dll
2017-03-15 16:47:56 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-03-15 16:47:56 ----A---- C:\Windows\system32\msv1_0.dll
2017-03-15 16:47:56 ----A---- C:\Windows\system32\kernel32.dll
2017-03-15 16:47:55 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2017-03-15 16:47:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\usp10.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\quartz.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\FntCache.dll
2017-03-15 16:47:55 ----A---- C:\Windows\HelpPane.exe
2017-03-15 16:47:54 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2017-03-15 16:47:54 ----A---- C:\Windows\system32\rpchttp.dll
2017-03-15 16:47:54 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\usp10.dll
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\ncrypt.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\gdi32.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\drivers\srv.sys
2017-03-15 16:47:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-03-15 16:47:53 ----A---- C:\Windows\system32\certcli.dll
2017-03-15 16:47:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\quartz.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\wow64win.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\inetcomm.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-03-15 16:47:51 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-03-15 16:47:51 ----A---- C:\Windows\system32\adtschema.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\wow64.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\winsrv.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\wdigest.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\TSpkg.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\srcore.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\appidsvc.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\certcli.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\mscms.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-03-15 16:47:49 ----A---- C:\Windows\system32\drivers\appid.sys
2017-03-15 16:47:49 ----A---- C:\Windows\system32\csrsrv.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\conhost.exe
2017-03-15 16:47:49 ----A---- C:\Windows\system32\bcrypt.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\appidapi.dll
2017-03-15 16:47:48 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-03-15 16:47:48 ----A---- C:\Windows\system32\icm32.dll
2017-03-15 16:47:48 ----A---- C:\Windows\system32\cryptbase.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\wow32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\WcsPlugInService.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\srclient.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\setup16.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\secur32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\mscms.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\instnm.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\icm32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\credssp.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\wow64cpu.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\WcsPlugInService.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\sspisrv.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\sspicli.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\srclient.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\smss.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\secur32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\rstrui.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\ntvdm64.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\msaudite.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\lsass.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\credssp.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\auditpol.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\apisetschema.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47:46 ----A---- C:\Windows\SYSWOW64\user.exe
2017-03-15 16:47:46 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2017-03-15 16:47:46 ----A---- C:\Windows\system32\INETRES.dll
2017-03-15 16:47:46 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-03-15 16:47:46 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-03-15 16:47:45 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2017-03-15 16:47:45 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2017-03-15 16:47:45 ----A---- C:\Windows\system32\msxml3r.dll
2017-03-15 16:47:45 ----A---- C:\Windows\system32\msobjs.dll
====== List of files/folders modified in the last 1 month ======
2017-04-11 11:51:22 ----D---- C:\Windows\Temp
2017-04-11 11:50:59 ----SHD---- C:\Windows\Installer
2017-04-11 11:50:59 ----SHD---- C:\Config.Msi
2017-04-11 11:48:02 ----D---- C:\Program Files
2017-04-11 11:46:02 ----RD---- C:\Program Files (x86)
2017-04-11 11:34:59 ----AD---- C:\Windows\system32\drivers
2017-04-11 09:30:18 ----D---- C:\Windows\system32\config
2017-04-11 09:15:19 ----HD---- C:\ProgramData
2017-04-10 22:48:31 ----SHD---- C:\System Volume Information
2017-04-10 20:44:58 ----D---- C:\Windows\system32\Tasks
2017-04-09 19:53:09 ----D---- C:\Windows
2017-04-09 10:43:08 ----D---- C:\Windows\Prefetch
2017-04-06 17:48:42 ----D---- C:\Windows\SysWOW64
2017-04-06 14:04:56 ----D---- C:\Users\Pepa\AppData\Roaming\vlc
2017-04-06 13:29:31 ----D---- C:\Windows\inf
2017-04-03 10:30:15 ----HD---- C:\Program Files (x86)\Temp
2017-04-02 17:13:23 ----D---- C:\Windows\System32
2017-04-02 17:13:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-01 20:57:11 ----D---- C:\ProgramData\Package Cache
2017-03-30 17:53:14 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-03-30 01:51:47 ----D---- C:\Windows\winsxs
2017-03-30 01:49:17 ----D---- C:\Users\Pepa\AppData\Roaming\DAEMON Tools Lite
2017-03-29 17:04:41 ----D---- C:\Program Files (x86)\Common Files
2017-03-29 15:57:19 ----D---- C:\Windows\system32\DriverStore
2017-03-29 15:50:13 ----RSD---- C:\Windows\Fonts
2017-03-26 22:27:21 ----N---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2017-03-26 22:26:47 ----D---- C:\Program Files (x86)\Java
2017-03-26 22:25:13 ----N---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-03-26 22:25:02 ----D---- C:\Windows\system32\Macromed
2017-03-26 22:24:56 ----D---- C:\Windows\SYSWOW64\Macromed
2017-03-26 20:37:55 ----D---- C:\Users\Pepa\AppData\Roaming\Mozilla
2017-03-24 16:37:04 ----D---- C:\Users\Pepa\AppData\Roaming\uTorrent
2017-03-24 16:35:57 ----D---- C:\Windows\debug
2017-03-24 14:59:45 ----D---- C:\ProgramData\DAEMON Tools Lite
2017-03-20 19:14:21 ----D---- C:\Users\Pepa\AppData\Roaming\dvdcss
2017-03-17 13:10:37 ----D---- C:\Windows\rescache
2017-03-17 08:13:36 ----SD---- C:\Windows\system32\CompatTel
2017-03-17 08:13:34 ----D---- C:\Windows\system32\appraiser
2017-03-17 08:13:33 ----D---- C:\Windows\AppPatch
2017-03-16 21:42:15 ----D---- C:\Program Files (x86)\Internet Explorer
2017-03-16 21:42:14 ----D---- C:\Program Files\Internet Explorer
2017-03-16 21:42:12 ----D---- C:\Windows\SYSWOW64\migration
2017-03-16 21:42:12 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-03-16 21:42:12 ----D---- C:\Program Files\DVD Maker
2017-03-16 21:42:10 ----D---- C:\Windows\SYSWOW64\en-US
2017-03-16 21:42:02 ----D---- C:\Windows\system32\migration
2017-03-16 21:42:02 ----D---- C:\Windows\system32\cs-CZ
2017-03-16 21:42:00 ----D---- C:\Windows\system32\en-US
2017-03-16 21:41:45 ----D---- C:\Windows\system32\Boot
2017-03-16 00:08:09 ----D---- C:\Windows\system32\MRT
2017-03-16 00:02:47 ----AC---- C:\Windows\system32\MRT.exe
2017-03-15 23:57:05 ----D---- C:\Program Files\Microsoft Silverlight
2017-03-15 23:57:05 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2017-03-15 16:32:42 ----D---- C:\Windows\system32\catroot2
File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed
====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-03-30 189768]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-03-30 334088]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-03-30 48528]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-03-31 75704]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-03-31 339696]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 408600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-03-18 834544]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-03-30 307736]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-03-31 32600]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-03-31 101152]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-03-31 1005048]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-03-31 556784]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2017-03-24 254528]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2016-05-23 262344]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2016-05-23 110112]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2016-05-23 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2016-05-23 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys [2016-05-19 52392]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-03-31 127112]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-03-31 164064]
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); SysWOW64\Drivers\DKbFltr.sys []
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-08-25 10611552]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-06 1824672]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2009-07-10 139264]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-07-27 58880]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-09-17 292912]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 16896]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-10-19 507392]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-03-31 38296]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2009-07-01 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
S3 dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2017-03-24 30264]
S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2017-03-24 47672]
S3 dtultrascsibus;DAEMON Tools Ultra Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtultrascsibus.sys [2017-03-24 30264]
S3 dtultrausbbus;DAEMON Tools Ultra Virtual USB Bus; C:\Windows\system32\DRIVERS\dtultrausbbus.sys [2017-03-24 47672]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 iSafeKrnlBoot;YAC Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys [2016-05-23 55056]
S3 LgBttPort;LGE Bluetooth TransPort; C:\Windows\system32\DRIVERS\lgbtpt64.sys []
S3 lgbusenum;LG Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\lgbtbs64.sys []
S3 lgmdbus;LG Mobile driver (WDM); C:\Windows\system32\DRIVERS\lgmdbus.sys [2008-07-08 115200]
S3 lgmdmdfl;LG Mobile USB WMC Modem Filter; C:\Windows\system32\DRIVERS\lgmdmdfl.sys [2008-07-08 18944]
S3 lgmdmdm;LG Mobile USB WMC Modem Driver; C:\Windows\system32\DRIVERS\lgmdmdm.sys [2008-07-08 158720]
S3 lgmdmgmt;LG Mobile USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\lgmdmgmt.sys [2008-07-08 137216]
S3 lgmdobex;LG Mobile USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\lgmdobex.sys [2008-07-08 136704]
S3 LGVMODEM;LGE Virtual Modem; C:\Windows\system32\DRIVERS\lgvmdm64.sys []
S3 massfilter;Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-08-22 5435904]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-05-08 215552]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
R2 AMD;AMD; C:\Users\Pepa\AppData\Local\AMD\amd.exe [2017-03-31 112128]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-31 261712]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-18 864032]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-08-24 107016]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-10-03 786976]
R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2016-12-02 131024]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-09-25 62720]
R2 RS_Service;Raw Socket Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe [2017-03-26 181312]
R2 SNARER;SNARER; C:\Windows\System32\svchost.exe -k SNARER;"ServiceDll" = C:\Users\Pepa\AppData\Local\SNARER\Snarer.dll
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-30 7398336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-11-29 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-11-29 125112]
S2 FirefoxU;Update Service(FirefoxU); C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [2017-04-01 132272]
S2 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [2015-10-29 777744]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S2 MVCSrv;VC IDE Base Service; %SystemRoot%\System32\svchost.exe -k MVCService;"ServiceDll" = C:\ProgramData\Package Cache\{2A002F88-FD5D-379B-A350-A25D84AF128B}v14.0.25420\packages\VisualC_D14\VC_IDE.Base\VC_IDE_Base.dll
S2 SpyEmrgHealth;Spy Emergency Health Check; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-03-26 271960]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-03-04 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-29 146888]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-11-29 51384]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 Kyubey;Kyubey; C:\Users\Pepa\AppData\Roaming\Kyubey\Kyubey.exe [2017-03-29 240128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
-----------------EOF-----------------
Logfile of random's system information tool 1.16 (written by random/random)
Run by Pepa at 2017-04-11 11:48:01
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 10 GB (4%) free of 226 GB
Total RAM: 3003 MB (53% free)
X64
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:52:07, on 11.4.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18618)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Windows\PLFSetI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files\trend micro\Pepa_RSITx64.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.ourluckysites.com/search/?ty ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ourluckysites.com/search/?ty ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.200.3:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Canon LBP2900 Status Window.lnk = C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD - Unknown owner - C:\Users\Pepa\AppData\Local\AMD\amd.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Update Service(FirefoxU) (FirefoxU) - Unknown owner - C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spy Emergency Health Check (SpyEmrgHealth) - Unknown owner - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11984 bytes
====== Enumerating Processes ======
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k localservice
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k networkservice
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Users\Pepa\AppData\Local\AMD\amd.exe -s
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
c:\windows\system32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe"
C:\Windows\system32\taskhost.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
C:\Windows\system32\CNAB4RPD.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files (x86)\Acer\Registration\GregHSRW.exe"
"C:\Windows\PLFSetI.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe"
"C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe"
c:\windows\system32\svchost.exe -k snarer
c:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
C:\Windows\SysWOW64\svchost.exe -k WinSAPSvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe"
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
C:\Program Files (x86)\CCleaner\CCleaner64.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
"C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe"
C:\Windows\SysWOW64\svchost.exe -k MVCService
C:\Windows\SysWOW64\rundll32.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\igfxsrvc.exe -Embedding
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --original-process-start-time=13136376734388911 --fast-start
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=watcher --main-thread-id=6028 --on-initialized-event-handle=328 --parent-handle=340 /prefetch:6
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=E9302A7FFE6C71B3D8ED9287CE602E90 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=E9302A7FFE6C71B3D8ED9287CE602E90 --renderer-client-id=5 --mojo-platform-channel-handle=1776 /prefetch:1
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=D19BDB4FC9AAD6DAC0B82D663D9C2C83 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-gpu-compositing --service-request-channel-token=D19BDB4FC9AAD6DAC0B82D663D9C2C83 --renderer-client-id=3 --mojo-platform-channel-handle=2144 /prefetch:1
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=409628F110F14FCDEB60AA4173CA5DCA --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-gpu-compositing --service-request-channel-token=409628F110F14FCDEB60AA4173CA5DCA --renderer-client-id=4 --mojo-platform-channel-handle=2284 /prefetch:1
"C:\Users\Pepa\Desktop\RSITx64.exe"
C:\Windows\system32\taskeng.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\msiexec.exe /V
====== Scheduled tasks folder ======
C:\Windows\tasks\{011B8E39-CE88-41E0-B0D4-311E33EC992A}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{17533D0E-A9DE-49DD-93CD-ADE62A97FD62}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{1A89CBC3-1771-4C0D-8B7E-E785109150BA}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{25381E09-4350-4CEB-8375-8F9B5FC882B8}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{2C34D498-06D7-4808-AD10-2C290AFC7C68}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{3E70DE31-F555-4BF7-ACCE-E9AF4AEE522B}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{42441CAB-D394-4ED2-B527-BF8586500CBF}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{6B0B2E13-DD0E-4974-82C3-7F7BCAB85C41}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{9355D9FC-1AAB-4933-A742-7E47402C6D12}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{A9827EA4-461C-4E96-BBCE-3BD151F2CAA6}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{B08D7569-C085-4F1D-A2F4-D594EEAE262A}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{C91DE031-215F-4A00-AADF-39A56BA2C4DA}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Atafogh Helper - "C:\Program Files (x86)\Prervoly\anerserly.exe" 7f10ac44-c09a-4c46-92a9-247afe0ea6f6
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\avastBCLRestartS-1-5-21-2349173935-1687467584-554729351-1000 - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files (x86)\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\GarminUpdaterTask - C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Milimili - "C:\Program Files (x86)\MIO\MIO.exe" -bindurl http://api.suibianmaimaicom.com/toshiba ... bs1kns.dat cmd=
C:\Windows\system32\tasks\Puhasy - "msiexec" /i HtTp://d2buh1bf1g584w.cloudfront.net/ms ... v=20170324 /q
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1458737292 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\Windows-PG - C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Update\psgo\psgo.ps1
C:\Windows\system32\tasks\{20E2C8C3-5DB4-408A-89D1-4C38BD54A02E} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\2\SSM_Uninstall.exe
C:\Windows\system32\tasks\{2AC11547-3FF8-4A4D-912B-D9B2947164FC} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\AppData\Local\Temp\Data\MapSource\MapSource_6163.exe -d C:\Users\Pepa\AppData\Local\Temp\
C:\Windows\system32\tasks\{36A219C0-6B08-4296-802B-D29B8D49A9F3} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\Desktop\irfanviewcestina.exe -d C:\Users\Pepa\Desktop
C:\Windows\system32\tasks\{53F16E9A-9782-4582-8922-367414AEFD68} - D:\AOESETUP.EXE
C:\Windows\system32\tasks\{5A65194E-DB10-41AA-9266-5D0C4D4E2908} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\1\SS_Uninstall.exe
C:\Windows\system32\tasks\{7C64D715-407E-45A2-98B1-E29A1D4DE4B6} - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\system32\tasks\{88FB3DD7-0BE2-4D38-BFD8-1AD9D8AC2FF4} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\3\SSCDUninstall.exe
C:\Windows\system32\tasks\{B8A9D966-BF69-41CF-9882-B525641CD7F7} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\AppData\Local\Temp\jre-8u45-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1
C:\Windows\system32\tasks\{DD770AF6-E648-43B5-9840-2FCE3E8082BA} - C:\Windows\system32\pcalua.exe -a "C:\Users\Pepa\Documents\Ze starého počítače\Prográmky\aoe2pack_v3.01_saj.exe" -d "C:\Users\Pepa\Documents\Ze starého počítače\Prográmky"
C:\Windows\system32\tasks\{E33F0E26-0D8E-4EE7-9ACD-034474810FB3} - C:\Windows\system32\pcalua.exe -a D:\aoesetup.exe -d D:\ -c /autorun
C:\Windows\system32\tasks\{E58CCF12-DBFD-4155-A9A2-B9BCAAED3D6F} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\5\SSSDUninstall.exe
C:\Windows\system32\tasks\{EC838D8B-8D3E-42B4-B99C-E856EBC4DBE6} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\Desktop\frd.exe -d C:\Users\Pepa\Desktop
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-2349173935-1687467584-554729351-1000 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup - %systemroot%\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor - %systemroot%\system32\sdclt.exe /CHECKSKIPPED
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Lpksetup - C:\Windows\System32\lpksetup.exe -v
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\Windows\System32\mcbuilder.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
=========Mozilla firefox=========
ProfilePath - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.startup.homepage" - "http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.conduit.com/ResultsExt.as ... 2475029&q="
prefs.js - "browser.search.useDBForOrder" - true
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF48
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF48
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\
c1bwvxob.xml
luck.xml
ourluckysites.xml
startpageing123.xml
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\addons.json
Garmin Communicator - extension - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b}
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d}
Mozilla Firefox hotfix - extension - firefox-hotfix@mozilla.org
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions.json
Garmin Communicator - extension - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\firefox@getpocket.com.xpi
Firefox Hello - extension - loop@mozilla.org - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\loop@mozilla.org.xpi
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Site Deployment Checker - extension - deployment-checker@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Avast Online Security - webextension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF48
Avast SafePrice - webextension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\pluginreg.dat
Plugin - Shockwave Flash - 25.0.0.127 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll
=========Google Chrome=========
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
======Registry dump ======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL"=http://www.ourluckysites.com/search/?ty ... earchTerms}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL"=http://www.ourluckysites.com/search/?ty ... earchTerms}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}]
"URL"=http://www.google.com/search?sourceid=i ... lz=1I7ACAW
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
"URL"=http://search.conduit.com/ResultsExt.as ... =CT2475029
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-31 895528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-26 473152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-31 773920]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-26 186944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-09-17 1842472]
"Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [2009-10-03 496160]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-06 7940128]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-07-06 1833504]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-21 200704]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 161304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 386584]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 415256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-31 213824]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files (x86)\CCleaner\CCleaner64.exe [2017-03-03 9364696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19 1160408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray]
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-09-25 261888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boxoft Tools]
C:\ProgramData\Boxtools\Boxofttoolbox.exe [2010-12-15 514048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files (x86)\CCleaner\CCleaner64.exe [2017-03-03 9364696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [2015-10-29 1403304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]
C:\Program Files (x86)\Essentials Codec Pack\update.exe [2007-04-08 303104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeznamInstall-uninstall:62298f0e8f87a174e880190b05ada38f]
C:\Users\Pepa\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe -c C:\Users\Pepa\AppData\Roaming\Seznam.cz []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe /nosplash /minimized []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Pepa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\Pepa\AppData\Roaming\Dropbox\bin\Dropbox.exe [2014-03-19 32667896]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-11-01 1091152]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Canon LBP2900 Status Window.lnk - C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{D0668D3A-0EF4-11E7-B3CD-64006A5CFC35}"=C:\Users\Pepa\AppData\Roaming\Kulerty\Clifly.dll []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
====== File associations ======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
====== List of files/folders created in the last 1 month ======
2017-04-11 11:48:02 ----D---- C:\Program Files\trend micro
2017-04-11 11:48:01 ----D---- C:\rsit
2017-04-11 09:15:19 ----D---- C:\ProgramData\SWCUTemp
2017-04-10 23:02:13 ----D---- C:\Program Files (x86)\deskapp
2017-04-10 20:44:51 ----D---- C:\Update
2017-04-06 17:48:36 ----D---- C:\Users\Pepa\AppData\Roaming\SNARER
2017-04-05 10:39:54 ----D---- C:\Program Files (x86)\WINSNARE(4.4.6)
2017-04-01 20:58:39 ----A---- C:\Windows\system32\drivers\iSafeNetFilter.sys
2017-04-01 20:58:39 ----A---- C:\Windows\system32\drivers\iSafeKrnlBoot.sys
2017-04-01 20:58:36 ----D---- C:\Windows\system32\log
2017-04-01 20:58:11 ----D---- C:\Program Files (x86)\Elex-tech
2017-04-01 20:58:06 ----D---- C:\Users\Pepa\AppData\Roaming\Elex-tech
2017-04-01 20:57:48 ----D---- C:\Users\Pepa\AppData\Roaming\Firefox
2017-04-01 20:57:32 ----A---- C:\Windows\SYSWOW64\DB83.tmp
2017-04-01 20:56:57 ----AD---- C:\Program Files (x86)\Firefox
2017-04-01 20:56:38 ----D---- C:\Program Files (x86)\Eastone
2017-03-31 14:23:45 ----A---- C:\Windows\system32\aswBoot.exe
2017-03-31 11:50:05 ----D---- C:\Program Files\MK
2017-03-29 12:15:19 ----D---- C:\ProgramData\Pinnacle VideoSpin
2017-03-29 12:10:56 ----D---- C:\Users\Pepa\AppData\Roaming\Kyubey
2017-03-29 12:10:54 ----D---- C:\Program Files (x86)\MIO
2017-03-29 12:10:48 ----D---- C:\Users\Pepa\AppData\Roaming\WINSNARE
2017-03-29 12:10:47 ----D---- C:\Users\Pepa\AppData\Roaming\WinSAPSvc
2017-03-29 12:09:24 ----D---- C:\Program Files (x86)\MK
2017-03-29 12:07:56 ----D---- C:\Program Files\c1bwvxob
2017-03-27 21:36:55 ----HD---- C:\$AV_ASW
2017-03-26 22:29:02 ----D---- C:\Users\Pepa\AppData\Roaming\Sun
2017-03-26 20:37:55 ----D---- C:\Users\Pepa\AppData\Roaming\Netscape
2017-03-26 20:37:55 ----D---- C:\Program Files (x86)\Photodex Presenter
2017-03-26 20:37:38 ----D---- C:\Program Files (x86)\Photodex
2017-03-26 20:37:06 ----D---- C:\Users\Pepa\AppData\Roaming\Photodex
2017-03-24 16:19:51 ----D---- C:\ProgramData\Pinnacle Studio Ultimate Collection
2017-03-24 16:05:51 ----D---- C:\Program Files (x86)\Pinnacle
2017-03-24 16:03:37 ----A---- C:\ProgramData\__wdump.txt
2017-03-24 15:56:15 ----D---- C:\ProgramData\Pinnacle
2017-03-24 15:53:02 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2017-03-24 15:52:37 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2017-03-24 15:28:54 ----A---- C:\Windows\system32\drivers\dtultrausbbus.sys
2017-03-24 15:28:21 ----A---- C:\Windows\system32\drivers\dtultrascsibus.sys
2017-03-24 15:28:18 ----D---- C:\Users\Pepa\AppData\Roaming\DAEMON Tools Ultra
2017-03-24 15:26:20 ----D---- C:\ProgramData\DAEMON Tools Ultra
2017-03-24 15:04:25 ----D---- C:\Users\Pepa\AppData\Roaming\Kulerty
2017-03-24 15:03:29 ----D---- C:\Program Files (x86)\Atafogh Helper
2017-03-24 15:03:24 ----D---- C:\Users\Pepa\AppData\Roaming\Profiles
2017-03-24 15:03:24 ----D---- C:\Program Files (x86)\Prervoly
2017-03-24 15:01:25 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2017-03-24 15:00:16 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2017-03-16 22:12:27 ----A---- C:\Windows\system32\aepic.dll
2017-03-16 22:12:27 ----A---- C:\Windows\system32\aeinv.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\invagent.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\generaltel.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\devinv.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\centel.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\appraiser.dll
2017-03-16 22:12:25 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-03-16 22:12:25 ----A---- C:\Windows\system32\acmigration.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\inseng.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\iertutil.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\iernonce.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-03-15 16:48:24 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-03-15 16:48:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\occache.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\inseng.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\ie4uinit.exe
2017-03-15 16:48:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-03-15 16:48:22 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\urlmon.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\occache.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\iedkcs32.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\ieui.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-03-15 16:48:19 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-03-15 16:48:19 ----A---- C:\Windows\system32\msfeeds.dll
2017-03-15 16:48:19 ----A---- C:\Windows\system32\dxtrans.dll
2017-03-15 16:48:18 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-03-15 16:48:17 ----A---- C:\Windows\system32\iesetup.dll
2017-03-15 16:48:17 ----A---- C:\Windows\system32\ieapfltr.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-03-15 16:48:15 ----A---- C:\Windows\system32\vbscript.dll
2017-03-15 16:48:14 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-03-15 16:48:14 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2017-03-15 16:48:14 ----A---- C:\Windows\system32\jsproxy.dll
2017-03-15 16:48:14 ----A---- C:\Windows\system32\ieUnatt.exe
2017-03-15 16:48:13 ----A---- C:\Windows\system32\ieui.dll
2017-03-15 16:48:13 ----A---- C:\Windows\system32\dxtmsft.dll
2017-03-15 16:48:12 ----A---- C:\Windows\system32\ieframe.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\webcheck.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\mshtmled.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript9diag.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript9.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript.dll
2017-03-15 16:48:09 ----A---- C:\Windows\system32\wininet.dll
2017-03-15 16:48:08 ----A---- C:\Windows\system32\msrating.dll
2017-03-15 16:48:08 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-03-15 16:48:06 ----A---- C:\Windows\system32\mshtml.dll
2017-03-15 16:48:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-03-15 16:48:01 ----A---- C:\Windows\system32\win32k.sys
2017-03-15 16:48:00 ----A---- C:\Windows\system32\ntdll.dll
2017-03-15 16:47:59 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2017-03-15 16:47:59 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2017-03-15 16:47:59 ----A---- C:\Windows\system32\lsasrv.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\rpcrt4.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\msxml3.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\kerberos.dll
2017-03-15 16:47:57 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-03-15 16:47:57 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\schannel.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\KernelBase.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\DWrite.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\advapi32.dll
2017-03-15 16:47:56 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-03-15 16:47:56 ----A---- C:\Windows\system32\msv1_0.dll
2017-03-15 16:47:56 ----A---- C:\Windows\system32\kernel32.dll
2017-03-15 16:47:55 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2017-03-15 16:47:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\usp10.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\quartz.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\FntCache.dll
2017-03-15 16:47:55 ----A---- C:\Windows\HelpPane.exe
2017-03-15 16:47:54 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2017-03-15 16:47:54 ----A---- C:\Windows\system32\rpchttp.dll
2017-03-15 16:47:54 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\usp10.dll
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\ncrypt.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\gdi32.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\drivers\srv.sys
2017-03-15 16:47:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-03-15 16:47:53 ----A---- C:\Windows\system32\certcli.dll
2017-03-15 16:47:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\quartz.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\wow64win.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\inetcomm.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-03-15 16:47:51 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-03-15 16:47:51 ----A---- C:\Windows\system32\adtschema.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\wow64.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\winsrv.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\wdigest.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\TSpkg.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\srcore.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\appidsvc.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\certcli.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\mscms.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-03-15 16:47:49 ----A---- C:\Windows\system32\drivers\appid.sys
2017-03-15 16:47:49 ----A---- C:\Windows\system32\csrsrv.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\conhost.exe
2017-03-15 16:47:49 ----A---- C:\Windows\system32\bcrypt.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\appidapi.dll
2017-03-15 16:47:48 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-03-15 16:47:48 ----A---- C:\Windows\system32\icm32.dll
2017-03-15 16:47:48 ----A---- C:\Windows\system32\cryptbase.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\wow32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\WcsPlugInService.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\srclient.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\setup16.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\secur32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\mscms.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\instnm.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\icm32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\credssp.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\wow64cpu.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\WcsPlugInService.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\sspisrv.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\sspicli.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\srclient.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\smss.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\secur32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\rstrui.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\ntvdm64.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\msaudite.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\lsass.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\credssp.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\auditpol.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\apisetschema.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47:46 ----A---- C:\Windows\SYSWOW64\user.exe
2017-03-15 16:47:46 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2017-03-15 16:47:46 ----A---- C:\Windows\system32\INETRES.dll
2017-03-15 16:47:46 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-03-15 16:47:46 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-03-15 16:47:45 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2017-03-15 16:47:45 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2017-03-15 16:47:45 ----A---- C:\Windows\system32\msxml3r.dll
2017-03-15 16:47:45 ----A---- C:\Windows\system32\msobjs.dll
====== List of files/folders modified in the last 1 month ======
2017-04-11 11:51:22 ----D---- C:\Windows\Temp
2017-04-11 11:50:59 ----SHD---- C:\Windows\Installer
2017-04-11 11:50:59 ----SHD---- C:\Config.Msi
2017-04-11 11:48:02 ----D---- C:\Program Files
2017-04-11 11:46:02 ----RD---- C:\Program Files (x86)
2017-04-11 11:34:59 ----AD---- C:\Windows\system32\drivers
2017-04-11 09:30:18 ----D---- C:\Windows\system32\config
2017-04-11 09:15:19 ----HD---- C:\ProgramData
2017-04-10 22:48:31 ----SHD---- C:\System Volume Information
2017-04-10 20:44:58 ----D---- C:\Windows\system32\Tasks
2017-04-09 19:53:09 ----D---- C:\Windows
2017-04-09 10:43:08 ----D---- C:\Windows\Prefetch
2017-04-06 17:48:42 ----D---- C:\Windows\SysWOW64
2017-04-06 14:04:56 ----D---- C:\Users\Pepa\AppData\Roaming\vlc
2017-04-06 13:29:31 ----D---- C:\Windows\inf
2017-04-03 10:30:15 ----HD---- C:\Program Files (x86)\Temp
2017-04-02 17:13:23 ----D---- C:\Windows\System32
2017-04-02 17:13:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-01 20:57:11 ----D---- C:\ProgramData\Package Cache
2017-03-30 17:53:14 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-03-30 01:51:47 ----D---- C:\Windows\winsxs
2017-03-30 01:49:17 ----D---- C:\Users\Pepa\AppData\Roaming\DAEMON Tools Lite
2017-03-29 17:04:41 ----D---- C:\Program Files (x86)\Common Files
2017-03-29 15:57:19 ----D---- C:\Windows\system32\DriverStore
2017-03-29 15:50:13 ----RSD---- C:\Windows\Fonts
2017-03-26 22:27:21 ----N---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2017-03-26 22:26:47 ----D---- C:\Program Files (x86)\Java
2017-03-26 22:25:13 ----N---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-03-26 22:25:02 ----D---- C:\Windows\system32\Macromed
2017-03-26 22:24:56 ----D---- C:\Windows\SYSWOW64\Macromed
2017-03-26 20:37:55 ----D---- C:\Users\Pepa\AppData\Roaming\Mozilla
2017-03-24 16:37:04 ----D---- C:\Users\Pepa\AppData\Roaming\uTorrent
2017-03-24 16:35:57 ----D---- C:\Windows\debug
2017-03-24 14:59:45 ----D---- C:\ProgramData\DAEMON Tools Lite
2017-03-20 19:14:21 ----D---- C:\Users\Pepa\AppData\Roaming\dvdcss
2017-03-17 13:10:37 ----D---- C:\Windows\rescache
2017-03-17 08:13:36 ----SD---- C:\Windows\system32\CompatTel
2017-03-17 08:13:34 ----D---- C:\Windows\system32\appraiser
2017-03-17 08:13:33 ----D---- C:\Windows\AppPatch
2017-03-16 21:42:15 ----D---- C:\Program Files (x86)\Internet Explorer
2017-03-16 21:42:14 ----D---- C:\Program Files\Internet Explorer
2017-03-16 21:42:12 ----D---- C:\Windows\SYSWOW64\migration
2017-03-16 21:42:12 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-03-16 21:42:12 ----D---- C:\Program Files\DVD Maker
2017-03-16 21:42:10 ----D---- C:\Windows\SYSWOW64\en-US
2017-03-16 21:42:02 ----D---- C:\Windows\system32\migration
2017-03-16 21:42:02 ----D---- C:\Windows\system32\cs-CZ
2017-03-16 21:42:00 ----D---- C:\Windows\system32\en-US
2017-03-16 21:41:45 ----D---- C:\Windows\system32\Boot
2017-03-16 00:08:09 ----D---- C:\Windows\system32\MRT
2017-03-16 00:02:47 ----AC---- C:\Windows\system32\MRT.exe
2017-03-15 23:57:05 ----D---- C:\Program Files\Microsoft Silverlight
2017-03-15 23:57:05 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2017-03-15 16:32:42 ----D---- C:\Windows\system32\catroot2
File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed
====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-03-30 189768]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-03-30 334088]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-03-30 48528]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-03-31 75704]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-03-31 339696]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 408600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-03-18 834544]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-03-30 307736]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-03-31 32600]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-03-31 101152]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-03-31 1005048]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-03-31 556784]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2017-03-24 254528]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2016-05-23 262344]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2016-05-23 110112]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2016-05-23 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2016-05-23 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys [2016-05-19 52392]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-03-31 127112]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-03-31 164064]
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); SysWOW64\Drivers\DKbFltr.sys []
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-08-25 10611552]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-06 1824672]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2009-07-10 139264]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-07-27 58880]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-09-17 292912]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 16896]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-10-19 507392]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-03-31 38296]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2009-07-01 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
S3 dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2017-03-24 30264]
S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2017-03-24 47672]
S3 dtultrascsibus;DAEMON Tools Ultra Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtultrascsibus.sys [2017-03-24 30264]
S3 dtultrausbbus;DAEMON Tools Ultra Virtual USB Bus; C:\Windows\system32\DRIVERS\dtultrausbbus.sys [2017-03-24 47672]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 iSafeKrnlBoot;YAC Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys [2016-05-23 55056]
S3 LgBttPort;LGE Bluetooth TransPort; C:\Windows\system32\DRIVERS\lgbtpt64.sys []
S3 lgbusenum;LG Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\lgbtbs64.sys []
S3 lgmdbus;LG Mobile driver (WDM); C:\Windows\system32\DRIVERS\lgmdbus.sys [2008-07-08 115200]
S3 lgmdmdfl;LG Mobile USB WMC Modem Filter; C:\Windows\system32\DRIVERS\lgmdmdfl.sys [2008-07-08 18944]
S3 lgmdmdm;LG Mobile USB WMC Modem Driver; C:\Windows\system32\DRIVERS\lgmdmdm.sys [2008-07-08 158720]
S3 lgmdmgmt;LG Mobile USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\lgmdmgmt.sys [2008-07-08 137216]
S3 lgmdobex;LG Mobile USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\lgmdobex.sys [2008-07-08 136704]
S3 LGVMODEM;LGE Virtual Modem; C:\Windows\system32\DRIVERS\lgvmdm64.sys []
S3 massfilter;Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-08-22 5435904]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-05-08 215552]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []
====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
R2 AMD;AMD; C:\Users\Pepa\AppData\Local\AMD\amd.exe [2017-03-31 112128]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-31 261712]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-18 864032]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-08-24 107016]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-10-03 786976]
R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2016-12-02 131024]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-09-25 62720]
R2 RS_Service;Raw Socket Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe [2017-03-26 181312]
R2 SNARER;SNARER; C:\Windows\System32\svchost.exe -k SNARER;"ServiceDll" = C:\Users\Pepa\AppData\Local\SNARER\Snarer.dll
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-30 7398336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-11-29 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-11-29 125112]
S2 FirefoxU;Update Service(FirefoxU); C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [2017-04-01 132272]
S2 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [2015-10-29 777744]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S2 MVCSrv;VC IDE Base Service; %SystemRoot%\System32\svchost.exe -k MVCService;"ServiceDll" = C:\ProgramData\Package Cache\{2A002F88-FD5D-379B-A350-A25D84AF128B}v14.0.25420\packages\VisualC_D14\VC_IDE.Base\VC_IDE_Base.dll
S2 SpyEmrgHealth;Spy Emergency Health Check; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-03-26 271960]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-03-04 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-29 146888]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-11-29 51384]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 Kyubey;Kyubey; C:\Users\Pepa\AppData\Roaming\Kyubey\Kyubey.exe [2017-03-29 240128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
-----------------EOF-----------------