Zpomalený pc...
Napsal: 19 zář 2017 18:29
Ahoj, mám problém se zpomaleným pc... když jsem nechal AVG zkontrolovat počítač nalezlo to tam trojský koně a další různý "havěti" Ale bohužel abych to smazal bych si musel koupit nějakou extra verzi... tak se zeptám zde co s tím
Děkuji...
log
Logfile of random's system information tool 1.10 (written by random/random)
Run by Tom at 2017-09-19 19:06:01
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 252 GB (26%) free of 954 GB
Total RAM: 3326 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:08:00, on 19.9.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG Web TuneUp\vprot.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Gaming Keyboard\Monitor.EXE
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Gaming Keyboard\OSD.exe
C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Tom\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Tom.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Protector by IB Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Protector by IB\Extension32.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files\Funmoods\1.5.23.22\bh\escort.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files\Softonic\softonic\1.5.11.5\bh\softonic.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll (file missing)
O3 - Toolbar: Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\softonic\1.5.11.5\softonicTlbr.dll
O3 - Toolbar: Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files\Funmoods\1.5.23.22\escorTlbr.dll
O3 - Toolbar: HyperCam Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\HyperCam Toolbar\tbcore3.dll (file missing)
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Web TuneUp\vprot.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [Cm108Sound] RunDll32 cm108.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [Gaming Keyboard] "C:\Program Files\Gaming Keyboard\Monitor.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.5.7.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\3.5.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: ASGT - Unknown owner - C:\Windows\System32\ASGT.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SafetyNut Manager (SafetyNutManager) - Unknown owner - C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: vToolbarUpdater40.3.8 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.3.8\ToolbarUpdater.exe
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe
--
End of file - 11068 bytes
======Scheduled tasks folder======
C:\Windows\tasks\HQ-Video-Pro-1.4-chromeinstaller.job - C:\Program Files\HQ-Video-Pro-1.4\HQ-Video-Pro-1.4-chromeinstaller.exe /rawdata=Vg650YD4A2pPiIJlCHWhpgAnQPZP4TqJmLTnKgb+SGxzQNZ1F2jkgAJ/v/8hJcTMbR6fxk5q7/4s1nttGu0s7ZNl97XzT25MC7R9rqYegnVtuY1qM/GMvpdeQrwLZqesE2GdKIRMAh7ZreW5VBAh8aGazNLSulzT4T8A2hDiLbwUnMMewHluA1CvEDBPR70Hirp/9PIk7ujbH65SLsmzT1gBL0a4FS0umz+qI13c6pP478ZO6JrvIH649VuwsrXrclMzay1TeCq5bBqw6SR7QtNEkSUrQDmR1J/ZHRfKgbQgwDwlKm8R0Y2oPHWiuupJvv7juC17r7upRQoFdUmN+BGRcw2M+RcXWm6gdxPKwRec020LYcT7svsX23XRSnGckvIbwGz7xkM1i93xpajiusEgIYDCWmLsFrY6P8gXJKFtvWfM9+FyuBndWCQK63KoPU9tpfGd5BNYcZiY9JuEDYXfkcVdNjII80HNZnHmGYccxsU2nE14gIxbCj510c6BGdDz4c1+TVCTGTYeZEWn/lreXPx9w2rMdggp1rThb3EoV6BiUJWSBtKEjBY9MTlLieYbr7t0T1hvlqxPQmKxHviwgMrWtijLofpn8ZZ5pCBE9gsMKXeuYhjesVjNsOy7tcrQqkDi60yC4Of1K896F4KtGKDXAIRX+e2pqHvqRL5IKRTB1yXVJftTgm8CfMUW0XtWyGE/+GEsfkDLwJArq5WRKWzvt9F+VXt6OmMbSTnRu5Jbir3EnSFJxYaAdFIDTlRS3LvKagKuZirGMo1Lnnq8s7zZQQFW7d0E53+KDT9S34+wU55NrVdgZ2zVTkIWowUxlvhD8G2qDeOdZOr+p6VuumU9gFVfroCKGF1hrY3WIQd3yZFh3clYPLUWnhE09QyMXA+/ui23cfbWV/1xrzLDe1XVnWb+8l5gWISiZmr3i8tx/1HbKCpcGL1AgDAUNXDbtTMYEBPRhYSokvmXoFm2wWhp3a4q4NofsnTDjvRV8hsGuQ0U4gB9S6soll9kd9Z+FM4bYU3rddYBOqHqvomkauLSAIQOcBYuTUp8MAJLEqtmNz1yuCQnv12TzhqlNjVSZiUQ1t2uFljjx2deD/Bj4s0/QXUaeyuLsVTRiygWPIQMjhQY46xhWRvNlVKukTzEVMF6ZbPgsgGGhx5vQ0ZwMoIpMfgm7k1cUVf6erFWPvTeGRpQ8sCnapNFu+ZLOIAfCbFOEP+l/GXB8DanqquMksW4Cc/OQQNA6HZ2+W0W5KQdjmGoKncOOmeYxlwfuAayTJPw11qCbeqec7SvCMLpUMW059foqqf4Ue+h983Eucvks4DCW8ZvXN7BW9AZGeJGp+5as3AdPYZuBZSnwQ==
C:\Windows\tasks\HQ-Video-Pro-1.4-codedownloader.job - C:\Program Files\HQ-Video-Pro-1.4\HQ-Video-Pro-1.4-codedownloader.exe /reinstallapp /runfrom=task /agentregpath='HQ-Video-Pro-1.4' /appid=52920 /srcid='001186' /subid='0' /zdata='0' /bic=FD43D030B61B47DDBF6B9564CF2A95F2IE /verifier=f1bff96c59713a6f70a07cbeabb309cc /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1394267978 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /codedownloaddomain=http://app-static.crossrider.com /defbro=ch /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_code_ ... pdate.json' /runfrom='task' /externallog=''
C:\Windows\tasks\HQ-Video-Pro-1.4-firefoxinstaller.job - C:\Program Files\HQ-Video-Pro-1.4\HQ-Video-Pro-1.4-firefoxinstaller.exe /installxpi /agentregpath='HQ-Video-Pro-1.4' /extensionfilepath='C:\Program Files\HQ-Video-Pro-1.4\52920.xpi' /appid=52920 /srcid='001186' /subid='0' /zdata='0' /bic=FD43D030B61B47DDBF6B9564CF2A95F2IE /verifier=f1bff96c59713a6f70a07cbeabb309cc /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1394267978 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /waitforbrowser=300 /extensionid=f6b78e05-0819-4914-a9b1-53baf8fa3cd8@5f1a7616-ab87-4cb2-b56e-1218d848ce49.com /extensionversion=0.93 /prefsbranch=af6b78e0508194914a9b153baf8fa3cd85f1a7616ab874cb2b56e1218d848ce49com52920 /updateurl=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /52920.rdf /extensionname='HQ-Video-Pro-1.4' /extensiondesc='HQ Videos is an add-on for your Internet browser that enhances your online experience by displaying online videos in their highest quality format available.' /publishername='HQ-Video' /defbro=ch /allusers /allprofiles /checkfflist /autoupdateulr='http://update.srvstatsdata.com/ff_agent ... pdate.json' /runfrom='task' /externallog=''
C:\Windows\tasks\weDownload-chromeinstaller.job - C:\Program Files\weDownload\weDownload-chromeinstaller.exe /installcrx /agentregpath='weDownload' /extensionfilepath='C:\Program Files\weDownload\45820.crx' /appid=45820 /srcid='000656' /subid='verticals-' /zdata='0' /bic=452D3CB8A75E4A1BAB71FA31B38E777DIE /verifier=e7f5c25da7b6d646664c35193f7d215f /installerversion=1_31_153 /installerfullversion=1.31.153.0 /installationtime=1387787532 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /waitforbrowser=300 /extensionid=fhhamfkcejhlnpojdpnjbmcfkpnadlpn /extensionversion=1.25.17 /extensionpublickey=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzuFJQVMp+rlE0WeKkopiJ4TC1coIUYXJFjvl8o/Bss8RgmaXZ+w0Bk4/8/3af2KDSCG4nW+UCRmwO9IviRB+ovVE3xFdyGHRCIBqkCTvEZyBHV7HOov6ZPTNsj1lsAZ6b8uWodcvRo22vN0hlaaLHXK7vq0JbFic8fjfY65kKdQIDAQAB /allusers /allprofiles /externallog=''
C:\Windows\tasks\weDownload-updater.job - C:\Program Files\weDownload\weDownload-updater.exe /runupdater /agentregpath='weDownload' /appid=45820 /srcid='000656' /subid='verticals-' /zdata='0' /bic=452D3CB8A75E4A1BAB71FA31B38E777DIE /verifier=e7f5c25da7b6d646664c35193f7d215f /installerversion=1_31_153 /installationtime=1387787532 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /monetizationdomain=http://stats.syncstatsdata.com /geoserviceurl=http://ipgeoapi.com/ /updatejsondomain=http://update.srvstatsdata.com /updaterversion=2 /externallog=''
=========Mozilla firefox=========
ProfilePath - C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\32xoduj0.default
prefs.js - "browser.startup.homepage" - "http:/google"
prefs.js - "keyword.URL" - "http://dts.search.ask.com/sr?src=ffb&gc ... PN10640&q="
"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\AVG2012\Firefox4\
"{336D0C35-8A85-403a-B9D2-65C292C39087}"=C:\Program Files\Protector by IB\Firefox
"{F53C93F1-07D5-430c-86D4-C9531B27DFAF}"=C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.8\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.6.2]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\2.6.2\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.7.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\2.7.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.7.1]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\2.7.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App V2 Presence Detector Plugin
"Path"=C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\NitroPDF]
"Description"=NitroPDF Web Browser Plugin
"Path"=C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\32xoduj0.default\extensions\
089c3b22-a366-427a-be95-d9074d9a4088@gmail.com
f6b78e05-0819-4914-a9b1-53baf8fa3cd8@5f1a7616-ab87-4cb2-b56e-1218d848ce49.com
{75656794-AB59-4712-BFBC-5D816D56F3BC}
{9A7DF664-82DC-020F-C190-9A665AF83389}
C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\32xoduj0.default\searchplugins\
Ask.xml
avg-secure-search.xml
WebSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do Not Track - C:\Program Files\AVG\AVG2012\avgdtiex.dll [2015-05-19 938496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
Protector by IB - C:\Program Files\Protector by IB\Extension32.dll [2012-04-24 163328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2015-05-19 1418752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}]
Funmoods Helper Object - C:\Program Files\Funmoods\1.5.23.22\bh\escort.dll [2012-11-09 243664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2011-05-13 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09 4502400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}]
Softonic Helper Object - C:\Program Files\Softonic\softonic\1.5.11.5\bh\softonic.dll [2012-01-11 241872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
SMTTB2009 Class - C:\Program Files\HyperCam Toolbar\tbcore3.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5018CFD2-804D-4C99-9F81-25EAEA2769DE} - Softonic Toolbar - C:\Program Files\Softonic\softonic\1.5.11.5\softonicTlbr.dll [2012-01-11 250064]
{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - Funmoods Toolbar - C:\Program Files\Funmoods\1.5.23.22\escorTlbr.dll [2012-11-09 251856]
{338B4DFE-2E2C-4338-9E41-E176D497299E} - HyperCam Toolbar - C:\Program Files\HyperCam Toolbar\tbcore3.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"vProt"=C:\Program Files\AVG Web TuneUp\vprot.exe [2017-07-08 2184776]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe [2015-05-19 2598912]
"Cm108Sound"=RunDll32 cm108.cpl,CMICtrlWnd []
"AvgUi"=C:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"Gaming Keyboard"=C:\Program Files\Gaming Keyboard\Monitor.exe [2014-01-16 479232]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"HydraVisionDesktopManager"=C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe [2013-12-06 389120]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2017-02-14 27545056]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"VIDC.FPS1"=frapsvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.tscc"=C:\Windows\system32\tsccvid.dll
"vidc.tsc2"=C:\Windows\system32\tsc2_codec32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-09-19 19:06:01 ----D---- C:\rsit
2017-09-19 19:06:01 ----D---- C:\Program Files\trend micro
2017-09-19 17:53:21 ----D---- C:\Windows\system32\appraiser
2017-09-18 11:17:26 ----A---- C:\Windows\system32\tbs.dll
2017-09-18 11:17:26 ----A---- C:\Windows\system32\fveapibase.dll
2017-09-18 11:17:26 ----A---- C:\Windows\system32\fveapi.dll
2017-09-18 09:24:41 ----A---- C:\Windows\system32\nlasvc.dll
2017-09-18 07:45:25 ----A---- C:\Windows\system32\WMPhoto.dll
2017-09-18 01:27:54 ----A---- C:\Windows\system32\charmap.exe
2017-09-18 01:27:15 ----A---- C:\Windows\system32\mapistub.dll
2017-09-18 01:27:15 ----A---- C:\Windows\system32\mapi32.dll
2017-09-18 01:27:15 ----A---- C:\Windows\system32\fixmapi.exe
2017-09-18 01:23:36 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-09-18 01:23:29 ----A---- C:\Windows\system32\schannel.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-09-18 01:23:29 ----A---- C:\Windows\system32\ntdll.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\msv1_0.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\lsasrv.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\kerberos.dll
2017-09-18 01:23:28 ----A---- C:\Windows\system32\rpcrt4.dll
2017-09-18 01:23:28 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\wdigest.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\TSpkg.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\sspisrv.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\sspicli.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\srcore.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\srclient.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\smss.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\secur32.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\rstrui.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\ncrypt.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\msobjs.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\msaudite.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\lsass.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\cng.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\csrsrv.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\cryptbase.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\credssp.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\basesrv.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\auditpol.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\apisetschema.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\adtschema.dll
2017-09-18 01:18:23 ----A---- C:\Windows\system32\cewmdm.dll
2017-09-18 01:18:07 ----A---- C:\Windows\system32\devinv.dll
2017-09-18 01:18:07 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-09-18 01:18:07 ----A---- C:\Windows\system32\centel.dll
2017-09-18 01:18:07 ----A---- C:\Windows\system32\aitstatic.exe
2017-09-18 01:18:04 ----A---- C:\Windows\system32\generaltel.dll
2017-09-18 01:18:01 ----A---- C:\Windows\system32\invagent.dll
2017-09-18 01:18:01 ----A---- C:\Windows\system32\acmigration.dll
2017-09-18 01:17:42 ----A---- C:\Windows\system32\appraiser.dll
2017-09-18 01:17:42 ----A---- C:\Windows\system32\aepic.dll
2017-09-18 01:17:42 ----A---- C:\Windows\system32\aeinv.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\ws2_32.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\winhttp.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\netbtugc.exe
2017-09-18 01:17:27 ----A---- C:\Windows\system32\mswsock.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\drivers\netbt.sys
2017-09-18 01:14:46 ----A---- C:\Windows\system32\msmpeg2adec.dll
2017-09-18 01:14:38 ----A---- C:\Windows\system32\WMVDECOD.DLL
2017-09-18 01:14:19 ----A---- C:\Windows\system32\mf.dll
2017-09-18 01:14:00 ----A---- C:\Windows\system32\WMADMOD.DLL
2017-09-18 01:13:52 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2017-09-18 01:13:52 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2017-09-18 01:13:51 ----A---- C:\Windows\system32\WMVSDECD.DLL
2017-09-18 01:13:51 ----A---- C:\Windows\system32\WMADMOE.DLL
2017-09-18 01:13:51 ----A---- C:\Windows\system32\quartz.dll
2017-09-18 01:13:51 ----A---- C:\Windows\system32\evr.dll
2017-09-18 01:13:47 ----A---- C:\Windows\system32\COLORCNV.DLL
2017-09-18 01:13:43 ----A---- C:\Windows\system32\wmpmde.dll
2017-09-18 01:13:39 ----A---- C:\Windows\system32\WMVENCOD.DLL
2017-09-18 01:13:36 ----A---- C:\Windows\system32\WMVXENCD.DLL
2017-09-18 01:13:36 ----A---- C:\Windows\system32\mfplat.dll
2017-09-18 01:13:36 ----A---- C:\Windows\system32\mcmde.dll
2017-09-18 01:13:36 ----A---- C:\Windows\system32\devenum.dll
2017-09-18 01:13:35 ----A---- C:\Windows\system32\WMVSENCD.DLL
2017-09-18 01:13:35 ----A---- C:\Windows\system32\qdvd.dll
2017-09-18 01:13:35 ----A---- C:\Windows\system32\MPG4DECD.DLL
2017-09-18 01:13:35 ----A---- C:\Windows\system32\MP43DECD.DLL
2017-09-18 01:13:35 ----A---- C:\Windows\system32\MFWMAAEC.DLL
2017-09-18 01:13:32 ----A---- C:\Windows\system32\WMALFXGFXDSP.dll
2017-09-18 01:13:32 ----A---- C:\Windows\system32\qasf.dll
2017-09-18 01:13:32 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2017-09-18 01:13:28 ----A---- C:\Windows\system32\WMSPDMOE.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\VIDRESZR.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\SysFxUI.dll
2017-09-18 01:13:21 ----A---- C:\Windows\system32\rrinstaller.exe
2017-09-18 01:13:21 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\MP4SDECD.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\MP3DMOD.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\mfvdsp.dll
2017-09-18 01:13:21 ----A---- C:\Windows\system32\mfps.dll
2017-09-18 01:13:21 ----A---- C:\Windows\system32\mfpmp.exe
2017-09-18 01:13:21 ----A---- C:\Windows\system32\drivers\portcls.sys
2017-09-18 01:13:17 ----A---- C:\Windows\system32\drivers\drmk.sys
2017-09-18 01:12:47 ----A---- C:\Windows\system32\mferror.dll
2017-09-18 01:12:47 ----A---- C:\Windows\system32\ksuser.dll
2017-09-18 01:12:47 ----A---- C:\Windows\system32\drivers\drmkaud.sys
2017-09-18 01:11:48 ----A---- C:\Windows\system32\msxml6.dll
2017-09-18 01:11:48 ----A---- C:\Windows\system32\msxml3.dll
2017-09-18 01:11:26 ----A---- C:\Windows\system32\msxml3r.dll
2017-09-18 01:11:25 ----A---- C:\Windows\system32\msxml6r.dll
2017-09-18 01:10:55 ----A---- C:\Windows\system32\scesrv.dll
2017-09-18 01:10:28 ----A---- C:\Windows\system32\comctl32.dll
2017-09-17 23:56:53 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-09-17 21:11:19 ----A---- C:\Windows\system32\termsrv.dll
2017-09-17 09:38:07 ----SHD---- C:\found.003
2017-09-17 08:56:06 ----N---- C:\bootsqm.dat
2017-09-17 08:54:03 ----SHD---- C:\found.002
======List of files/folders modified in the last 1 month======
2017-09-19 19:06:01 ----RD---- C:\Program Files
2017-09-19 19:05:35 ----D---- C:\Windows\system32\drivers
2017-09-19 19:05:08 ----D---- C:\Windows\Microsoft.NET
2017-09-19 19:04:28 ----RSD---- C:\Windows\assembly
2017-09-19 18:52:25 ----D---- C:\Users\Tom\AppData\Roaming\Skype
2017-09-19 18:34:19 ----D---- C:\Windows\system32\config
2017-09-19 18:31:30 ----D---- C:\Windows\Temp
2017-09-19 18:11:26 ----D---- C:\Windows\System32
2017-09-19 18:11:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-09-19 18:11:25 ----D---- C:\Windows\inf
2017-09-19 18:11:15 ----D---- C:\Windows\winsxs
2017-09-19 18:07:26 ----D---- C:\Windows\Prefetch
2017-09-19 17:58:44 ----D---- C:\Windows\system32\wdi
2017-09-19 17:55:25 ----D---- C:\Windows\system32\wbem
2017-09-19 17:55:25 ----D---- C:\Windows\system32\drivers\cs-CZ
2017-09-19 17:55:25 ----D---- C:\Windows\Logs
2017-09-19 17:54:47 ----D---- C:\Windows\system32\cs-CZ
2017-09-19 17:53:33 ----SD---- C:\Windows\system32\CompatTel
2017-09-19 17:53:33 ----D---- C:\Windows\AppCompat
2017-09-19 17:53:20 ----SD---- C:\ProgramData\Microsoft
2017-09-19 17:53:20 ----D---- C:\Windows\AppPatch
2017-09-19 17:50:45 ----D---- C:\Windows\system32\DriverStore
2017-09-19 17:29:44 ----D---- C:\Windows\system32\MRT
2017-09-19 17:26:17 ----AC---- C:\Windows\system32\MRT.exe
2017-09-19 17:20:26 ----SHD---- C:\Windows\Installer
2017-09-19 17:20:16 ----SHD---- C:\Config.Msi
2017-09-19 16:30:33 ----D---- C:\ProgramData\Microsoft Help
2017-09-19 16:22:25 ----SHD---- C:\System Volume Information
2017-09-19 14:01:35 ----D---- C:\Windows\system32\drivers\AVG
2017-09-18 17:29:14 ----D---- C:\Users\Tom\AppData\Roaming\newnext.me
2017-09-18 12:10:22 ----D---- C:\Windows\system32\catroot2
2017-09-18 07:17:02 ----D---- C:\Program Files\Microsoft Silverlight
2017-09-17 16:38:12 ----D---- C:\Windows\Minidump
2017-09-17 16:37:58 ----D---- C:\Windows
2017-08-29 09:53:40 ----D---- C:\Program Files\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2015-05-19 25352]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2015-05-19 34184]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SI3132;SiI-3132 SATALink Controller; C:\Windows\system32\DRIVERS\SI3132.sys [2007-10-03 80424]
R0 SiFilter;SATALink driver accelerator; C:\Windows\system32\DRIVERS\SiWinAcc.sys [2007-10-03 19240]
R0 SiRemFil;SATALink External Device Filter; C:\Windows\system32\DRIVERS\SiRemFil.sys [2007-10-03 15400]
R1 AsIO;AsIO; C:\Windows\system32\drivers\AsIO.sys [2009-08-04 11296]
R1 AsUpIO;AsUpIO; C:\Windows\system32\drivers\AsUpIO.sys [2009-07-06 11448]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2015-05-19 250632]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2015-11-18 42760]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2015-05-19 302472]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-22 242240]
R1 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Movies Toolbar\SafetyNut\configmgrc1.cfg [2014-04-13 31104]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\Windows\system32\DRIVERS\AegisP.sys [2011-10-23 21035]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2010-11-20 117760]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 11527680]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-06 501248]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2013-09-24 77312]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2015-05-19 142600]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\avgidsfilterx.sys [2015-05-19 26504]
R3 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2015-05-19 19976]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2011-12-30 6504]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
R3 USBPNPA;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM108.sys [2013-02-01 3234816]
R4 IOMap;IOMap; \??\C:\Windows\system32\drivers\IOMap.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 100352]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 39272]
S3 h643331;h643331; C:\Windows\system32\drivers\h643331.sys []
S3 hid3331;hid3331; C:\Windows\system32\drivers\hid3331.sys [2008-05-19 41336]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2012-06-11 19072]
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\rtl8187.sys [2010-01-07 375808]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8187.sys [2010-01-07 375808]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SjyPkt;SjyPkt; \??\C:\Windows\System32\Drivers\SjyPkt.sys [2006-03-31 13532]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 28160]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-06 209408]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 276992]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ASGT;ASGT; C:\Windows\System32\ASGT.exe [2012-01-17 55296]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [2015-05-19 5176832]
R2 avgsvc;AVG Service; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [2016-12-06 935184]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2015-05-19 198616]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
R2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2; C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe [2011-06-21 196912]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2014-11-25 76152]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 9216]
R2 vToolbarUpdater40.3.8;vToolbarUpdater40.3.8; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.3.8\ToolbarUpdater.exe [2017-07-08 1354824]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R2 WtuSystemSupport;WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [2017-07-08 981576]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files\Origin\OriginWebHelperService.exe [2017-07-25 3149672]
S2 SafetyNutManager;SafetyNut Manager; C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2017-01-16 317400]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe [2013-11-09 227936]
S3 GamesAppService;GamesAppService; C:\Program Files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-09-19 108032]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2017-07-26 175560]
S3 Origin Client Service;Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2017-07-25 2169696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-12-14 836176]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-10-06 1343400]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
S4 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files\Spyware Terminator\st_rsser.exe [2012-09-07 587472]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------
log
Logfile of random's system information tool 1.10 (written by random/random)
Run by Tom at 2017-09-19 19:06:01
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 252 GB (26%) free of 954 GB
Total RAM: 3326 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:08:00, on 19.9.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG Web TuneUp\vprot.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Gaming Keyboard\Monitor.EXE
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Gaming Keyboard\OSD.exe
C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Tom\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Tom.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Protector by IB Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Protector by IB\Extension32.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files\Funmoods\1.5.23.22\bh\escort.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files\Softonic\softonic\1.5.11.5\bh\softonic.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll (file missing)
O3 - Toolbar: Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\softonic\1.5.11.5\softonicTlbr.dll
O3 - Toolbar: Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files\Funmoods\1.5.23.22\escorTlbr.dll
O3 - Toolbar: HyperCam Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\HyperCam Toolbar\tbcore3.dll (file missing)
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Web TuneUp\vprot.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [Cm108Sound] RunDll32 cm108.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files\AVG\Framework\Common\avguirnx.exe" /lps=fmw
O4 - HKLM\..\Run: [Gaming Keyboard] "C:\Program Files\Gaming Keyboard\Monitor.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.5.7.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\3.5.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: ASGT - Unknown owner - C:\Windows\System32\ASGT.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Framework\Common\avgsvcx.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SafetyNut Manager (SafetyNutManager) - Unknown owner - C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: vToolbarUpdater40.3.8 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.3.8\ToolbarUpdater.exe
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe
--
End of file - 11068 bytes
======Scheduled tasks folder======
C:\Windows\tasks\HQ-Video-Pro-1.4-chromeinstaller.job - C:\Program Files\HQ-Video-Pro-1.4\HQ-Video-Pro-1.4-chromeinstaller.exe /rawdata=Vg650YD4A2pPiIJlCHWhpgAnQPZP4TqJmLTnKgb+SGxzQNZ1F2jkgAJ/v/8hJcTMbR6fxk5q7/4s1nttGu0s7ZNl97XzT25MC7R9rqYegnVtuY1qM/GMvpdeQrwLZqesE2GdKIRMAh7ZreW5VBAh8aGazNLSulzT4T8A2hDiLbwUnMMewHluA1CvEDBPR70Hirp/9PIk7ujbH65SLsmzT1gBL0a4FS0umz+qI13c6pP478ZO6JrvIH649VuwsrXrclMzay1TeCq5bBqw6SR7QtNEkSUrQDmR1J/ZHRfKgbQgwDwlKm8R0Y2oPHWiuupJvv7juC17r7upRQoFdUmN+BGRcw2M+RcXWm6gdxPKwRec020LYcT7svsX23XRSnGckvIbwGz7xkM1i93xpajiusEgIYDCWmLsFrY6P8gXJKFtvWfM9+FyuBndWCQK63KoPU9tpfGd5BNYcZiY9JuEDYXfkcVdNjII80HNZnHmGYccxsU2nE14gIxbCj510c6BGdDz4c1+TVCTGTYeZEWn/lreXPx9w2rMdggp1rThb3EoV6BiUJWSBtKEjBY9MTlLieYbr7t0T1hvlqxPQmKxHviwgMrWtijLofpn8ZZ5pCBE9gsMKXeuYhjesVjNsOy7tcrQqkDi60yC4Of1K896F4KtGKDXAIRX+e2pqHvqRL5IKRTB1yXVJftTgm8CfMUW0XtWyGE/+GEsfkDLwJArq5WRKWzvt9F+VXt6OmMbSTnRu5Jbir3EnSFJxYaAdFIDTlRS3LvKagKuZirGMo1Lnnq8s7zZQQFW7d0E53+KDT9S34+wU55NrVdgZ2zVTkIWowUxlvhD8G2qDeOdZOr+p6VuumU9gFVfroCKGF1hrY3WIQd3yZFh3clYPLUWnhE09QyMXA+/ui23cfbWV/1xrzLDe1XVnWb+8l5gWISiZmr3i8tx/1HbKCpcGL1AgDAUNXDbtTMYEBPRhYSokvmXoFm2wWhp3a4q4NofsnTDjvRV8hsGuQ0U4gB9S6soll9kd9Z+FM4bYU3rddYBOqHqvomkauLSAIQOcBYuTUp8MAJLEqtmNz1yuCQnv12TzhqlNjVSZiUQ1t2uFljjx2deD/Bj4s0/QXUaeyuLsVTRiygWPIQMjhQY46xhWRvNlVKukTzEVMF6ZbPgsgGGhx5vQ0ZwMoIpMfgm7k1cUVf6erFWPvTeGRpQ8sCnapNFu+ZLOIAfCbFOEP+l/GXB8DanqquMksW4Cc/OQQNA6HZ2+W0W5KQdjmGoKncOOmeYxlwfuAayTJPw11qCbeqec7SvCMLpUMW059foqqf4Ue+h983Eucvks4DCW8ZvXN7BW9AZGeJGp+5as3AdPYZuBZSnwQ==
C:\Windows\tasks\HQ-Video-Pro-1.4-codedownloader.job - C:\Program Files\HQ-Video-Pro-1.4\HQ-Video-Pro-1.4-codedownloader.exe /reinstallapp /runfrom=task /agentregpath='HQ-Video-Pro-1.4' /appid=52920 /srcid='001186' /subid='0' /zdata='0' /bic=FD43D030B61B47DDBF6B9564CF2A95F2IE /verifier=f1bff96c59713a6f70a07cbeabb309cc /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1394267978 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /codedownloaddomain=http://app-static.crossrider.com /defbro=ch /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_code_ ... pdate.json' /runfrom='task' /externallog=''
C:\Windows\tasks\HQ-Video-Pro-1.4-firefoxinstaller.job - C:\Program Files\HQ-Video-Pro-1.4\HQ-Video-Pro-1.4-firefoxinstaller.exe /installxpi /agentregpath='HQ-Video-Pro-1.4' /extensionfilepath='C:\Program Files\HQ-Video-Pro-1.4\52920.xpi' /appid=52920 /srcid='001186' /subid='0' /zdata='0' /bic=FD43D030B61B47DDBF6B9564CF2A95F2IE /verifier=f1bff96c59713a6f70a07cbeabb309cc /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1394267978 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /waitforbrowser=300 /extensionid=f6b78e05-0819-4914-a9b1-53baf8fa3cd8@5f1a7616-ab87-4cb2-b56e-1218d848ce49.com /extensionversion=0.93 /prefsbranch=af6b78e0508194914a9b153baf8fa3cd85f1a7616ab874cb2b56e1218d848ce49com52920 /updateurl=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /52920.rdf /extensionname='HQ-Video-Pro-1.4' /extensiondesc='HQ Videos is an add-on for your Internet browser that enhances your online experience by displaying online videos in their highest quality format available.' /publishername='HQ-Video' /defbro=ch /allusers /allprofiles /checkfflist /autoupdateulr='http://update.srvstatsdata.com/ff_agent ... pdate.json' /runfrom='task' /externallog=''
C:\Windows\tasks\weDownload-chromeinstaller.job - C:\Program Files\weDownload\weDownload-chromeinstaller.exe /installcrx /agentregpath='weDownload' /extensionfilepath='C:\Program Files\weDownload\45820.crx' /appid=45820 /srcid='000656' /subid='verticals-' /zdata='0' /bic=452D3CB8A75E4A1BAB71FA31B38E777DIE /verifier=e7f5c25da7b6d646664c35193f7d215f /installerversion=1_31_153 /installerfullversion=1.31.153.0 /installationtime=1387787532 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /waitforbrowser=300 /extensionid=fhhamfkcejhlnpojdpnjbmcfkpnadlpn /extensionversion=1.25.17 /extensionpublickey=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzuFJQVMp+rlE0WeKkopiJ4TC1coIUYXJFjvl8o/Bss8RgmaXZ+w0Bk4/8/3af2KDSCG4nW+UCRmwO9IviRB+ovVE3xFdyGHRCIBqkCTvEZyBHV7HOov6ZPTNsj1lsAZ6b8uWodcvRo22vN0hlaaLHXK7vq0JbFic8fjfY65kKdQIDAQAB /allusers /allprofiles /externallog=''
C:\Windows\tasks\weDownload-updater.job - C:\Program Files\weDownload\weDownload-updater.exe /runupdater /agentregpath='weDownload' /appid=45820 /srcid='000656' /subid='verticals-' /zdata='0' /bic=452D3CB8A75E4A1BAB71FA31B38E777DIE /verifier=e7f5c25da7b6d646664c35193f7d215f /installerversion=1_31_153 /installationtime=1387787532 /statsdomain=http://stats.srvstatsdata.com /errorsdomain=http://errors.srvstatsdata.com /monetizationdomain=http://stats.syncstatsdata.com /geoserviceurl=http://ipgeoapi.com/ /updatejsondomain=http://update.srvstatsdata.com /updaterversion=2 /externallog=''
=========Mozilla firefox=========
ProfilePath - C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\32xoduj0.default
prefs.js - "browser.startup.homepage" - "http:/google"
prefs.js - "keyword.URL" - "http://dts.search.ask.com/sr?src=ffb&gc ... PN10640&q="
"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\AVG2012\Firefox4\
"{336D0C35-8A85-403a-B9D2-65C292C39087}"=C:\Program Files\Protector by IB\Firefox
"{F53C93F1-07D5-430c-86D4-C9531B27DFAF}"=C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.8\\npsitesafety.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.6.2]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\2.6.2\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.7.0]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\2.7.0\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.7.1]
"Description"=
"Path"=C:\Program Files\Battlelog Web Plugins\2.7.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0]
"Description"=WildTangent Games App V2 Presence Detector Plugin
"Path"=C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\NitroPDF]
"Description"=NitroPDF Web Browser Plugin
"Path"=C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\32xoduj0.default\extensions\
089c3b22-a366-427a-be95-d9074d9a4088@gmail.com
f6b78e05-0819-4914-a9b1-53baf8fa3cd8@5f1a7616-ab87-4cb2-b56e-1218d848ce49.com
{75656794-AB59-4712-BFBC-5D816D56F3BC}
{9A7DF664-82DC-020F-C190-9A665AF83389}
C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\32xoduj0.default\searchplugins\
Ask.xml
avg-secure-search.xml
WebSearch.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}]
AVG Do Not Track - C:\Program Files\AVG\AVG2012\avgdtiex.dll [2015-05-19 938496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
Protector by IB - C:\Program Files\Protector by IB\Extension32.dll [2012-04-24 163328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2015-05-19 1418752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}]
Funmoods Helper Object - C:\Program Files\Funmoods\1.5.23.22\bh\escort.dll [2012-11-09 243664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2011-05-13 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09 4502400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}]
Softonic Helper Object - C:\Program Files\Softonic\softonic\1.5.11.5\bh\softonic.dll [2012-01-11 241872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
SMTTB2009 Class - C:\Program Files\HyperCam Toolbar\tbcore3.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5018CFD2-804D-4C99-9F81-25EAEA2769DE} - Softonic Toolbar - C:\Program Files\Softonic\softonic\1.5.11.5\softonicTlbr.dll [2012-01-11 250064]
{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - Funmoods Toolbar - C:\Program Files\Funmoods\1.5.23.22\escorTlbr.dll [2012-11-09 251856]
{338B4DFE-2E2C-4338-9E41-E176D497299E} - HyperCam Toolbar - C:\Program Files\HyperCam Toolbar\tbcore3.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"vProt"=C:\Program Files\AVG Web TuneUp\vprot.exe [2017-07-08 2184776]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe [2015-05-19 2598912]
"Cm108Sound"=RunDll32 cm108.cpl,CMICtrlWnd []
"AvgUi"=C:\Program Files\AVG\Framework\Common\avguirnx.exe [2016-12-06 220944]
"Gaming Keyboard"=C:\Program Files\Gaming Keyboard\Monitor.exe [2014-01-16 479232]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]
"HydraVisionDesktopManager"=C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe [2013-12-06 389120]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2017-02-14 27545056]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"VIDC.FPS1"=frapsvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.tscc"=C:\Windows\system32\tsccvid.dll
"vidc.tsc2"=C:\Windows\system32\tsc2_codec32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2017-09-19 19:06:01 ----D---- C:\rsit
2017-09-19 19:06:01 ----D---- C:\Program Files\trend micro
2017-09-19 17:53:21 ----D---- C:\Windows\system32\appraiser
2017-09-18 11:17:26 ----A---- C:\Windows\system32\tbs.dll
2017-09-18 11:17:26 ----A---- C:\Windows\system32\fveapibase.dll
2017-09-18 11:17:26 ----A---- C:\Windows\system32\fveapi.dll
2017-09-18 09:24:41 ----A---- C:\Windows\system32\nlasvc.dll
2017-09-18 07:45:25 ----A---- C:\Windows\system32\WMPhoto.dll
2017-09-18 01:27:54 ----A---- C:\Windows\system32\charmap.exe
2017-09-18 01:27:15 ----A---- C:\Windows\system32\mapistub.dll
2017-09-18 01:27:15 ----A---- C:\Windows\system32\mapi32.dll
2017-09-18 01:27:15 ----A---- C:\Windows\system32\fixmapi.exe
2017-09-18 01:23:36 ----A---- C:\Windows\system32\ntkrnlpa.exe
2017-09-18 01:23:29 ----A---- C:\Windows\system32\schannel.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-09-18 01:23:29 ----A---- C:\Windows\system32\ntdll.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\msv1_0.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\lsasrv.dll
2017-09-18 01:23:29 ----A---- C:\Windows\system32\kerberos.dll
2017-09-18 01:23:28 ----A---- C:\Windows\system32\rpcrt4.dll
2017-09-18 01:23:28 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\wdigest.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\TSpkg.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\sspisrv.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\sspicli.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\srcore.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\srclient.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\smss.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\secur32.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\rstrui.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\ncrypt.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\msobjs.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\msaudite.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\lsass.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\drivers\cng.sys
2017-09-18 01:23:25 ----A---- C:\Windows\system32\csrsrv.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\cryptbase.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\credssp.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\basesrv.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\auditpol.exe
2017-09-18 01:23:25 ----A---- C:\Windows\system32\apisetschema.dll
2017-09-18 01:23:25 ----A---- C:\Windows\system32\adtschema.dll
2017-09-18 01:18:23 ----A---- C:\Windows\system32\cewmdm.dll
2017-09-18 01:18:07 ----A---- C:\Windows\system32\devinv.dll
2017-09-18 01:18:07 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-09-18 01:18:07 ----A---- C:\Windows\system32\centel.dll
2017-09-18 01:18:07 ----A---- C:\Windows\system32\aitstatic.exe
2017-09-18 01:18:04 ----A---- C:\Windows\system32\generaltel.dll
2017-09-18 01:18:01 ----A---- C:\Windows\system32\invagent.dll
2017-09-18 01:18:01 ----A---- C:\Windows\system32\acmigration.dll
2017-09-18 01:17:42 ----A---- C:\Windows\system32\appraiser.dll
2017-09-18 01:17:42 ----A---- C:\Windows\system32\aepic.dll
2017-09-18 01:17:42 ----A---- C:\Windows\system32\aeinv.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\ws2_32.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\winhttp.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\netbtugc.exe
2017-09-18 01:17:27 ----A---- C:\Windows\system32\mswsock.dll
2017-09-18 01:17:27 ----A---- C:\Windows\system32\drivers\netbt.sys
2017-09-18 01:14:46 ----A---- C:\Windows\system32\msmpeg2adec.dll
2017-09-18 01:14:38 ----A---- C:\Windows\system32\WMVDECOD.DLL
2017-09-18 01:14:19 ----A---- C:\Windows\system32\mf.dll
2017-09-18 01:14:00 ----A---- C:\Windows\system32\WMADMOD.DLL
2017-09-18 01:13:52 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2017-09-18 01:13:52 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2017-09-18 01:13:51 ----A---- C:\Windows\system32\WMVSDECD.DLL
2017-09-18 01:13:51 ----A---- C:\Windows\system32\WMADMOE.DLL
2017-09-18 01:13:51 ----A---- C:\Windows\system32\quartz.dll
2017-09-18 01:13:51 ----A---- C:\Windows\system32\evr.dll
2017-09-18 01:13:47 ----A---- C:\Windows\system32\COLORCNV.DLL
2017-09-18 01:13:43 ----A---- C:\Windows\system32\wmpmde.dll
2017-09-18 01:13:39 ----A---- C:\Windows\system32\WMVENCOD.DLL
2017-09-18 01:13:36 ----A---- C:\Windows\system32\WMVXENCD.DLL
2017-09-18 01:13:36 ----A---- C:\Windows\system32\mfplat.dll
2017-09-18 01:13:36 ----A---- C:\Windows\system32\mcmde.dll
2017-09-18 01:13:36 ----A---- C:\Windows\system32\devenum.dll
2017-09-18 01:13:35 ----A---- C:\Windows\system32\WMVSENCD.DLL
2017-09-18 01:13:35 ----A---- C:\Windows\system32\qdvd.dll
2017-09-18 01:13:35 ----A---- C:\Windows\system32\MPG4DECD.DLL
2017-09-18 01:13:35 ----A---- C:\Windows\system32\MP43DECD.DLL
2017-09-18 01:13:35 ----A---- C:\Windows\system32\MFWMAAEC.DLL
2017-09-18 01:13:32 ----A---- C:\Windows\system32\WMALFXGFXDSP.dll
2017-09-18 01:13:32 ----A---- C:\Windows\system32\qasf.dll
2017-09-18 01:13:32 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2017-09-18 01:13:28 ----A---- C:\Windows\system32\WMSPDMOE.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\VIDRESZR.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\SysFxUI.dll
2017-09-18 01:13:21 ----A---- C:\Windows\system32\rrinstaller.exe
2017-09-18 01:13:21 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\MP4SDECD.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\MP3DMOD.DLL
2017-09-18 01:13:21 ----A---- C:\Windows\system32\mfvdsp.dll
2017-09-18 01:13:21 ----A---- C:\Windows\system32\mfps.dll
2017-09-18 01:13:21 ----A---- C:\Windows\system32\mfpmp.exe
2017-09-18 01:13:21 ----A---- C:\Windows\system32\drivers\portcls.sys
2017-09-18 01:13:17 ----A---- C:\Windows\system32\drivers\drmk.sys
2017-09-18 01:12:47 ----A---- C:\Windows\system32\mferror.dll
2017-09-18 01:12:47 ----A---- C:\Windows\system32\ksuser.dll
2017-09-18 01:12:47 ----A---- C:\Windows\system32\drivers\drmkaud.sys
2017-09-18 01:11:48 ----A---- C:\Windows\system32\msxml6.dll
2017-09-18 01:11:48 ----A---- C:\Windows\system32\msxml3.dll
2017-09-18 01:11:26 ----A---- C:\Windows\system32\msxml3r.dll
2017-09-18 01:11:25 ----A---- C:\Windows\system32\msxml6r.dll
2017-09-18 01:10:55 ----A---- C:\Windows\system32\scesrv.dll
2017-09-18 01:10:28 ----A---- C:\Windows\system32\comctl32.dll
2017-09-17 23:56:53 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-09-17 21:11:19 ----A---- C:\Windows\system32\termsrv.dll
2017-09-17 09:38:07 ----SHD---- C:\found.003
2017-09-17 08:56:06 ----N---- C:\bootsqm.dat
2017-09-17 08:54:03 ----SHD---- C:\found.002
======List of files/folders modified in the last 1 month======
2017-09-19 19:06:01 ----RD---- C:\Program Files
2017-09-19 19:05:35 ----D---- C:\Windows\system32\drivers
2017-09-19 19:05:08 ----D---- C:\Windows\Microsoft.NET
2017-09-19 19:04:28 ----RSD---- C:\Windows\assembly
2017-09-19 18:52:25 ----D---- C:\Users\Tom\AppData\Roaming\Skype
2017-09-19 18:34:19 ----D---- C:\Windows\system32\config
2017-09-19 18:31:30 ----D---- C:\Windows\Temp
2017-09-19 18:11:26 ----D---- C:\Windows\System32
2017-09-19 18:11:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-09-19 18:11:25 ----D---- C:\Windows\inf
2017-09-19 18:11:15 ----D---- C:\Windows\winsxs
2017-09-19 18:07:26 ----D---- C:\Windows\Prefetch
2017-09-19 17:58:44 ----D---- C:\Windows\system32\wdi
2017-09-19 17:55:25 ----D---- C:\Windows\system32\wbem
2017-09-19 17:55:25 ----D---- C:\Windows\system32\drivers\cs-CZ
2017-09-19 17:55:25 ----D---- C:\Windows\Logs
2017-09-19 17:54:47 ----D---- C:\Windows\system32\cs-CZ
2017-09-19 17:53:33 ----SD---- C:\Windows\system32\CompatTel
2017-09-19 17:53:33 ----D---- C:\Windows\AppCompat
2017-09-19 17:53:20 ----SD---- C:\ProgramData\Microsoft
2017-09-19 17:53:20 ----D---- C:\Windows\AppPatch
2017-09-19 17:50:45 ----D---- C:\Windows\system32\DriverStore
2017-09-19 17:29:44 ----D---- C:\Windows\system32\MRT
2017-09-19 17:26:17 ----AC---- C:\Windows\system32\MRT.exe
2017-09-19 17:20:26 ----SHD---- C:\Windows\Installer
2017-09-19 17:20:16 ----SHD---- C:\Config.Msi
2017-09-19 16:30:33 ----D---- C:\ProgramData\Microsoft Help
2017-09-19 16:22:25 ----SHD---- C:\System Volume Information
2017-09-19 14:01:35 ----D---- C:\Windows\system32\drivers\AVG
2017-09-18 17:29:14 ----D---- C:\Users\Tom\AppData\Roaming\newnext.me
2017-09-18 12:10:22 ----D---- C:\Windows\system32\catroot2
2017-09-18 07:17:02 ----D---- C:\Program Files\Microsoft Silverlight
2017-09-17 16:38:12 ----D---- C:\Windows\Minidump
2017-09-17 16:37:58 ----D---- C:\Windows
2017-08-29 09:53:40 ----D---- C:\Program Files\Google
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2015-05-19 25352]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2015-05-19 34184]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SI3132;SiI-3132 SATALink Controller; C:\Windows\system32\DRIVERS\SI3132.sys [2007-10-03 80424]
R0 SiFilter;SATALink driver accelerator; C:\Windows\system32\DRIVERS\SiWinAcc.sys [2007-10-03 19240]
R0 SiRemFil;SATALink External Device Filter; C:\Windows\system32\DRIVERS\SiRemFil.sys [2007-10-03 15400]
R1 AsIO;AsIO; C:\Windows\system32\drivers\AsIO.sys [2009-08-04 11296]
R1 AsUpIO;AsUpIO; C:\Windows\system32\drivers\AsUpIO.sys [2009-07-06 11448]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2015-05-19 250632]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2015-11-18 42760]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2015-05-19 302472]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-22 242240]
R1 F06DEFF2-5B9C-490D-910F-35D3A91196222;F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Movies Toolbar\SafetyNut\configmgrc1.cfg [2014-04-13 31104]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\Windows\system32\DRIVERS\AegisP.sys [2011-10-23 21035]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2010-11-20 117760]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 11527680]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-06 501248]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2013-09-24 77312]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2015-05-19 142600]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\avgidsfilterx.sys [2015-05-19 26504]
R3 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2015-05-19 19976]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2011-12-30 6504]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
R3 USBPNPA;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM108.sys [2013-02-01 3234816]
R4 IOMap;IOMap; \??\C:\Windows\system32\drivers\IOMap.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 100352]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 39272]
S3 h643331;h643331; C:\Windows\system32\drivers\h643331.sys []
S3 hid3331;hid3331; C:\Windows\system32\drivers\hid3331.sys [2008-05-19 41336]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2012-06-11 19072]
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\rtl8187.sys [2010-01-07 375808]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8187.sys [2010-01-07 375808]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 SjyPkt;SjyPkt; \??\C:\Windows\System32\Drivers\SjyPkt.sys [2006-03-31 13532]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 28160]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-06 209408]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-06 276992]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 ASGT;ASGT; C:\Windows\System32\ASGT.exe [2012-01-17 55296]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [2015-05-19 5176832]
R2 avgsvc;AVG Service; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [2016-12-06 935184]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2015-05-19 198616]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
R2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2; C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe [2011-06-21 196912]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2014-11-25 76152]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 9216]
R2 vToolbarUpdater40.3.8;vToolbarUpdater40.3.8; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\40.3.8\ToolbarUpdater.exe [2017-07-08 1354824]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R2 WtuSystemSupport;WtuSystemSupport; C:\Program Files\AVG Web TuneUp\WtuSystemSupport.exe [2017-07-08 981576]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files\Origin\OriginWebHelperService.exe [2017-07-25 3149672]
S2 SafetyNutManager;SafetyNut Manager; C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2017-01-16 317400]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe [2013-11-09 227936]
S3 GamesAppService;GamesAppService; C:\Program Files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-09-19 108032]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2017-07-26 175560]
S3 Origin Client Service;Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2017-07-25 2169696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-12-14 836176]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-10-06 1343400]
S4 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136]
S4 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files\Spyware Terminator\st_rsser.exe [2012-09-07 587472]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------