Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Logfile of random's system information tool 1.10 (written by random/random)
- Run by MrHack at 2014-10-14 00:19:11
- Microsoft Windows 7 Ultimate Service Pack 1
- System drive C: has 35 GB (12%) free of 305 GB
- Total RAM: 10239 MB (71% free)
- Logfile of Trend Micro HijackThis v2.0.4
- Scan saved at 00:19:20, on 14.10.2014
- Platform: Windows 7 SP1 (WinNT 6.00.3505)
- MSIE: Internet Explorer v8.00 (8.00.7601.18571)
- Boot mode: Normal
- Running processes:
- C:\Users\MrHack\AppData\Local\Temp\svchost.exe
- C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
- C:\Users\MrHack\AppData\Roaming\uTorrent\uTorrent.exe
- C:\Program Files (x86)\Skype\Phone\Skype.exe
- C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe
- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
- C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
- C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
- C:\Program Files (x86)\iTunes\iTunesHelper.exe
- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
- C:\Users\MrHack\AppData\Roaming\Dropbox\bin\Dropbox.exe
- C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
- C:\PROGRA~2\Raptr\raptr.exe
- C:\PROGRA~2\Raptr\raptr_im.exe
- C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
- C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
- C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe
- F:\Steam\Steam.exe
- F:\Steam\bin\steamwebhelper.exe
- F:\Steam\bin\steamwebhelper.exe
- C:\Users\MrHack\S-80-5849-4992-4820\winmgr.exe
- F:\Steam\bin\steamwebhelper.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- C:\UsbFix\UsbFix.exe
- C:\Program Files\trend micro\MrHack.exe
- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com/?gd=&ctid=CT3233496&octid=EB_ORIGINAL_CTID&ISID=bf6b7f00-88ff-4a7e-921e-b0e471d13a18&SearchSource=55&CUI=&UM=5&UP=SP73B05B96-B4CE-4F73-9E79-823BD6CFC15D&SSPV=
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
- R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
- R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
- R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
- R3 - URLSearchHook: BS Player ControlBar B Toolbar - {31264a33-a653-46c4-af49-1232c59a7da5} - C:\Users\MrHack\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll
- O2 - BHO: BS Player ControlBar B - {31264a33-a653-46c4-af49-1232c59a7da5} - C:\Users\MrHack\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll
- O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
- O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
- O2 - BHO: WinToFlash Suggestor - {FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD} - C:\Program Files (x86)\WinToFlash Suggestor\WinToFlashSuggestor.dll
- O3 - Toolbar: BS Player ControlBar B Toolbar - {31264a33-a653-46c4-af49-1232c59a7da5} - C:\Users\MrHack\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll
- O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
- O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
- O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
- O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
- O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
- O4 - HKCU\..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup
- O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
- O4 - HKCU\..\Run: [uTorrent] "C:\Users\MrHack\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
- O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
- O4 - HKCU\..\Run: [OscarX7Mouse5Mode] "C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe" Minimum
- O4 - HKCU\..\Run: [Microsoft Windows Manager] C:\Users\MrHack\S-80-5849-4992-4820\winmgr.exe
- O4 - Startup: Curse.lnk = MrHack\AppData\Roaming\Curse Client\Bin\Curse.exe
- O4 - Startup: Dropbox.lnk = MrHack\AppData\Roaming\Dropbox\bin\Dropbox.exe
- O4 - Global Startup: UltraMon.lnk = ?
- O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
- O9 - Extra button: WinToFlash Suggestor - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - C:\Program Files (x86)\WinToFlash Suggestor\WinToFlashSuggestor.dll
- O9 - Extra 'Tools' menuitem: WinToFlash Suggestor options - {A52C66B3-D4A9-4d10-A67D-2BEF0A85AB3F} - C:\Program Files (x86)\WinToFlash Suggestor\WinToFlashSuggestor.dll
- O15 - Trusted Zone: *.clonewarsadventures.com
- O15 - Trusted Zone: *.freerealms.com
- O15 - Trusted Zone: *.soe.com
- O15 - Trusted Zone: *.sony.com
- O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
- O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
- O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
- O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
- O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
- O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
- O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
- O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
- O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
- O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
- O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
- O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
- O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
- O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
- O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
- O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
- O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
- O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
- O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
- O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
- O23 - Service: NBService - Nero AG - F:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
- O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
- O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
- O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCDApp\StartHelp.exe
- O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
- O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
- O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
- O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
- O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
- O23 - Service: Toolbar Service (TBSrv) - ClientConnect Ltd. - C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe
- O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
- O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
- O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
- O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
- O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
- O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
- O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
- O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
- O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
- --
- End of file - 12781 bytes
- ======Listing Processes======
- \SystemRoot\System32\smss.exe
- %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
- %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
- wininit.exe
- winlogon.exe
- C:\Windows\system32\services.exe
- C:\Windows\system32\lsass.exe
- C:\Windows\system32\lsm.exe
- C:\Windows\system32\svchost.exe -k DcomLaunch
- "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
- C:\Windows\system32\svchost.exe -k RPCSS
- C:\Windows\system32\atiesrxx.exe
- C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
- C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
- C:\Windows\system32\svchost.exe -k netsvcs
- C:\Windows\system32\svchost.exe -k LocalService
- C:\Windows\system32\svchost.exe -k NetworkService
- atieclxx
- C:\Windows\System32\spoolsv.exe
- "taskhost.exe"
- C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
- "C:\Windows\system32\Dwm.exe"
- C:\Windows\Explorer.EXE
- "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
- "C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
- taskeng.exe {01D98F48-63AF-4F69-A52B-2B118EB3BA62}
- C:\Users\MrHack\AppData\Local\Temp\svchost.exe
- "C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe"
- "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
- "C:\Program Files\Bonjour\mDNSResponder.exe"
- "C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe"
- C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
- "C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe"
- "C:\Users\MrHack\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
- "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
- "C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe" Minimum
- "C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
- "C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe"
- adb fork-server server
- "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
- "C:\Program Files\UltraMon\UltraMon.exe" /auto
- "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
- "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
- "C:\Users\MrHack\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
- "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
- "C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
- C:\Windows\SysWOW64\PnkBstrA.exe
- C:\Windows\system32\cmd.exe /c ""C:\Program Files\PCDApp\cstart.bat" x14 6000"
- \??\C:\Windows\system32\conhost.exe "-215125396-6110197961930004780-17487566871380447395-2105801715643875592-1540874822
- "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
- "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"
- C:\Windows\system32\sppsvc.exe
- "C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
- C:\Windows\system32\svchost.exe -k imgsvc
- "C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe"
- "C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
- "C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"
- C:\Windows\system32\viakaraokesrv.exe
- C:\Windows\System32\svchost.exe -k secsvcs
- "C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe" -Embedding
- "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
- "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe"
- "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"
- "C:\Program Files\iPod\bin\iPodService.exe"
- C:\Windows\system32\SearchIndexer.exe /Embedding
- C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
- "C:\Program Files\Windows Media Player\wmpnetwk.exe"
- "C:\PROGRA~2\Raptr\raptr.exe" --log_to_file --from_stub --startup
- raptr_im.exe
- C:\Windows\System32\svchost.exe -k LocalServicePeerNet
- "C:\Program Files\UltraMon\UltraMonUiAcc.exe"
- "C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe" -Embedding
- "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /showtip "AutoSweeper_1|1515"
- "C:\Program Files (x86)\Raptr\raptr_ep64.exe"
- "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe" /widget_scan
- "taskhost.exe"
- "F:\Steam\Steam.exe"
- "F:\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "F:\Steam\config\htmlcache" -cookiepath "F:\Steam\config\cookies" -steampid 7848 --blacklist-accelerated-compositing --process-per-tab --enable-direct-write
- "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
- "F:\Steam\bin\steamwebhelper.exe" --type=renderer --disable-delegated-renderer --disable-gpu-compositing --disable-threaded-compositing --enable-pinch --enable-software-compositing --no-sandbox --enable-direct-write --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-accelerated-compositing --disable-gpu-compositing --channel="7736.0.477567540\1529257089" /prefetch:673131151
- "C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-45872514-aa31-41a1-a2ca-fd5485d33095 -SystemEventPortName:HostProcess-7a905ac3-c416-4ac4-a56d-2a1e3736cb3e -IoCancelEventPortName:HostProcess-74cdc251-157f-4abf-b8f3-1e5a403b697e -NonStateChangingEventPortName:HostProcess-cf779014-dc17-4243-b72b-bff2b825041a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:ed4d330d-1a81-4796-ad9c-686809cbae4d
- "C:\Users\MrHack\S-80-5849-4992-4820\winmgr.exe"
- "F:\Steam\bin\steamwebhelper.exe" --type=renderer --disable-delegated-renderer --disable-gpu-compositing --disable-threaded-compositing --enable-pinch --enable-software-compositing --no-sandbox --enable-direct-write --lang=en-US --lang=en-US --product-version="Valve Steam Client" --disable-accelerated-compositing --disable-gpu-compositing --channel="7736.3.1748652872\600154406" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="7824.0.1096451050\732864573" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --gpu-vendor-id=0x1002 --gpu-device-id=0x6818 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.301.1001.0 --ignored=" --type=renderer " /prefetch:822062411
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.1.1085051611\950932356" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.2.1691842674\566827957" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.3.1141698035\1099544555" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.4.80741948\1533485883" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.7.1419013230\100637175" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.8.1495361056\1857150673" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.10.104483586\439015249" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.11.750774205\1374800202" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.12.1081062335\1233829051" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.13.1094271613\747444854" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="7824.16.1053864747\844624415" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.20.1263701669\997860366" /prefetch:673131151
- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_33/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="7824.30.695593149\1707149082" /prefetch:673131151
- C:\Windows\system32\AUDIODG.EXE 0xc08
- C:\UsbFix\UsbFix.exe
- "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe34_ Global\UsGthrCtrlFltPipeMssGthrPipe34 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
- "C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
- "C:\Users\MrHack\Downloads\RSITx64.exe"
- C:\Windows\system32\wbem\wmiprvse.exe
- ======Scheduled tasks folder======
- C:\Windows\tasks\Acrobat Update.job - C:\Users\MrHack\AppData\Local\Temp\svchost.exe
- C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
- C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe /autoupdate /silent /autoclose /background
- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
- C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe /immunize /silent /autoclose
- C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe /scan /cleanclose
- ======Registry dump======
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
- SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14 81024]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
- Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-26 553896]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
- Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-26 211880]
- [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31264a33-a653-46c4-af49-1232c59a7da5}]
- BS Player ControlBar B Toolbar - C:\Users\MrHack\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll [2014-04-10 423744]
- [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
- SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14 69760]
- [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
- Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2014-02-20 669504]
- [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC36B0BD-27F0-4cdd-8AB1-50651EFC3EFD}]
- WinToFlash Suggestor - C:\Program Files (x86)\WinToFlash Suggestor\WinToFlashSuggestor.dll [2012-05-25 281424]
- [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
- {31264a33-a653-46c4-af49-1232c59a7da5} - BS Player ControlBar B Toolbar - C:\Users\MrHack\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll [2014-04-10 423744]
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- "Raptr"=C:\PROGRA~2\Raptr\raptrstub.exe [2014-08-20 55568]
- "DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [2014-02-24 3129560]
- "uTorrent"=C:\Users\MrHack\AppData\Roaming\uTorrent\uTorrent.exe [2014-04-30 1270352]
- "Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-08-27 22041192]
- "OscarX7Mouse5Mode"=C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe [2013-02-01 3571712]
- "Microsoft Windows Manager"=C:\Users\MrHack\S-80-5849-4992-4820\winmgr.exe [2013-03-12 659808]
- [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
- "NUSB3MON"=C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-01-22 106496]
- "HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-03-17 2371584]
- "iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-05-26 152392]
- "LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2014-09-04 3802448]
- "StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-09-15 767200]
- [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
- ""= []
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
- UltraMon.lnk - C:\Windows\Installer\{9069EE0A-7615-4D86-AD80-CA263E936DA6}\IcoUltraMon.ico
- C:\Users\MrHack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- Curse.lnk - C:\Users\MrHack\AppData\Roaming\Curse Client\Bin\Curse.exe
- Dropbox.lnk - C:\Users\MrHack\AppData\Roaming\Dropbox\bin\Dropbox.exe
- [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
- "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
- "SecurityProviders"=credssp.dll
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
- "ConsentPromptBehaviorAdmin"=5
- "ConsentPromptBehaviorUser"=3
- "EnableUIADesktopToggle"=0
- "dontdisplaylastusername"=0
- "legalnoticecaption"=
- "legalnoticetext"=
- "shutdownwithoutlogon"=1
- "undockwithoutlogon"=1
- "EnableLinkedConnections"=1
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
- "NoDrives"=0
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
- "NoDrives"=0
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
- "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
- "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
- "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
- "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
- "vidc.mrle"=msrle32.dll
- "vidc.msvc"=msvidc32.dll
- "msacm.imaadpcm"=imaadp32.acm
- "msacm.msg711"=msg711.acm
- "msacm.msgsm610"=msgsm32.acm
- "msacm.msadpcm"=msadp32.acm
- "midimapper"=midimap.dll
- "wavemapper"=msacm32.drv
- "VIDC.UYVY"=msyuv.dll
- "VIDC.YUY2"=msyuv.dll
- "VIDC.YVYU"=msyuv.dll
- "VIDC.IYUV"=iyuv_32.dll
- "VIDC.I420"=MSH263.DRV
- "VIDC.YVU9"=tsbyuv.dll
- "msacm.l3acm"=C:\Windows\System32\l3codeca.acm
- "MSVideo8"=VfWWDM32.dll
- "msacm.ac3filter"=ac3filter64.acm
- "VIDC.FPS1"=frapsv64.dll
- "VIDC.SP54"=SP5X_32.DLL
- "VIDC.SP55"=SP5X_32.DLL
- "VIDC.SP56"=SP5X_32.DLL
- "VIDC.SP57"=SP5X_32.DLL
- "VIDC.SP58"=SP5X_32.DLL
- "vidc.x264"=C:\PROGRA~1\X264VF~1\X264VF~1.DLL
- "wave"=wdmaud.drv
- "midi"=wdmaud.drv
- "mixer"=wdmaud.drv
- "aux"=wdmaud.drv
- "wave1"=wdmaud.drv
- "midi1"=wdmaud.drv
- "mixer1"=wdmaud.drv
- "aux1"=wdmaud.drv
- "wave3"=wdmaud.drv
- "midi3"=wdmaud.drv
- "mixer3"=wdmaud.drv
- "aux3"=wdmaud.drv
- "wave2"=wdmaud.drv
- "midi2"=wdmaud.drv
- "mixer2"=wdmaud.drv
- "aux2"=wdmaud.drv
- ======File associations======
- .js - edit - C:\Windows\System32\Notepad.exe %1
- ======List of files/folders created in the last 1 month======
- 2014-10-14 00:19:11 ----D---- C:\rsit
- 2014-10-14 00:19:11 ----D---- C:\Program Files\trend micro
- 2014-10-14 00:16:34 ----D---- C:\UsbFix
- 2014-10-13 20:22:15 ----A---- C:\Windows\system32\mss32.dll
- 2014-10-05 21:08:49 ----D---- C:\ProgramData\boost_interprocess
- 2014-10-05 20:56:20 ----A---- C:\Windows\Wiainst64.exe
- 2014-10-05 20:56:08 ----A---- C:\Windows\system32\SaMinDrv.dll
- 2014-10-05 20:56:08 ----A---- C:\Windows\system32\SaImgFlt.dll
- 2014-10-05 20:56:08 ----A---- C:\Windows\system32\SaErHdlr.dll
- 2014-10-05 19:33:10 ----D---- C:\Users\MrHack\AppData\Roaming\AMD
- 2014-10-01 17:20:18 ----D---- C:\ProgramData\ATI
- 2014-10-01 17:20:15 ----D---- C:\Program Files (x86)\AMD AVT
- 2014-09-22 00:01:17 ----RD---- C:\Program Files (x86)\Skype
- 2014-09-18 22:15:36 ----A---- C:\Windows\SYSWOW64\winver.exe
- 2014-09-18 22:15:36 ----A---- C:\Windows\SYSWOW64\user32.dll
- 2014-09-18 22:15:36 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
- 2014-09-18 22:15:36 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
- 2014-09-18 22:15:36 ----A---- C:\Windows\SYSWOW64\slmgr.vbs
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\wininet.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\url.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\mshtml.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\mshta.exe
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\ieui.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\wininet.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\url.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\mshtmled.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\mshtml.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\mshta.exe
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\msfeedssync.exe
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\msfeedsbs.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\msfeeds.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\ieUnatt.exe
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\ieui.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\iertutil.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\ieframe.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\dxtrans.dll
- 2014-09-18 21:38:53 ----A---- C:\Windows\system32\dxtmsft.dll
- 2014-09-18 21:38:52 ----A---- C:\Windows\SYSWOW64\urlmon.dll
- 2014-09-18 21:38:52 ----A---- C:\Windows\SYSWOW64\iertutil.dll
- 2014-09-18 21:38:52 ----A---- C:\Windows\system32\urlmon.dll
- 2014-09-18 21:38:52 ----A---- C:\Windows\system32\jsproxy.dll
- 2014-09-18 21:36:54 ----A---- C:\Windows\SYSWOW64\sspicli.dll
- 2014-09-18 21:36:54 ----A---- C:\Windows\SYSWOW64\secur32.dll
- 2014-09-18 21:36:54 ----A---- C:\Windows\SYSWOW64\kerberos.dll
- 2014-09-18 21:36:54 ----A---- C:\Windows\system32\lsasrv.dll
- 2014-09-18 21:36:54 ----A---- C:\Windows\system32\kerberos.dll
- 2014-09-16 00:32:04 ----A---- C:\Windows\system32\amdhcp64.dll
- 2014-09-16 00:32:00 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
- 2014-09-16 00:32:00 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
- 2014-09-16 00:32:00 ----A---- C:\Windows\system32\atimpc64.dll
- 2014-09-16 00:32:00 ----A---- C:\Windows\system32\amdpcom64.dll
- 2014-09-16 00:31:48 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
- 2014-09-16 00:31:30 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
- 2014-09-16 00:29:04 ----A---- C:\Windows\system32\drivers\amdacpksd.sys
- 2014-09-16 00:26:58 ----A---- C:\Windows\system32\drivers\atikmdag.sys
- 2014-09-16 00:18:06 ----A---- C:\Windows\system32\clinfo.exe
- 2014-09-16 00:18:00 ----A---- C:\Windows\system32\OpenVideo64.dll
- 2014-09-16 00:17:58 ----A---- C:\Windows\SYSWOW64\OpenVideo.dll
- 2014-09-16 00:17:56 ----A---- C:\Windows\SYSWOW64\OVDecode.dll
- 2014-09-16 00:17:56 ----A---- C:\Windows\system32\OVDecode64.dll
- 2014-09-16 00:17:54 ----A---- C:\Windows\system32\amdocl64.dll
- 2014-09-16 00:17:04 ----A---- C:\Windows\SYSWOW64\amdocl.dll
- 2014-09-16 00:16:18 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
- 2014-09-16 00:16:18 ----A---- C:\Windows\system32\OpenCL.dll
- 2014-09-16 00:13:24 ----A---- C:\Windows\system32\atio6axx.dll
- 2014-09-16 00:09:38 ----A---- C:\Windows\system32\amdmmcl6.dll
- 2014-09-16 00:09:36 ----A---- C:\Windows\SYSWOW64\amdmmcl.dll
- 2014-09-16 00:09:10 ----A---- C:\Windows\system32\mantle64.dll
- 2014-09-16 00:09:04 ----A---- C:\Windows\SYSWOW64\mantle32.dll
- 2014-09-16 00:09:00 ----A---- C:\Windows\system32\amdmantle64.dll
- 2014-09-16 00:08:08 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
- 2014-09-16 00:07:48 ----A---- C:\Windows\system32\atiapfxx.exe
- 2014-09-16 00:07:46 ----A---- C:\Windows\system32\aticalrt64.dll
- 2014-09-16 00:07:44 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
- 2014-09-16 00:07:42 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
- 2014-09-16 00:07:42 ----A---- C:\Windows\system32\aticalcl64.dll
- 2014-09-16 00:07:36 ----A---- C:\Windows\system32\aticaldd64.dll
- 2014-09-16 00:06:46 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
- 2014-09-16 00:05:52 ----A---- C:\Windows\SYSWOW64\amdmantle32.dll
- 2014-09-16 00:03:28 ----A---- C:\Windows\system32\atidemgy.dll
- 2014-09-16 00:03:26 ----A---- C:\Windows\system32\atimuixx.dll
- 2014-09-16 00:03:24 ----A---- C:\Windows\system32\atieclxx.exe
- 2014-09-16 00:03:18 ----A---- C:\Windows\system32\atiesrxx.exe
- 2014-09-16 00:03:12 ----A---- C:\Windows\system32\mantleaxl64.dll
- 2014-09-16 00:03:08 ----A---- C:\Windows\SYSWOW64\mantleaxl32.dll
- 2014-09-16 00:03:04 ----A---- C:\Windows\system32\atitmm64.dll
- 2014-09-16 00:00:04 ----A---- C:\Windows\system32\amdave64.dll
- 2014-09-15 23:59:50 ----A---- C:\Windows\system32\atisamu64.dll
- 2014-09-15 23:59:46 ----A---- C:\Windows\SYSWOW64\atisamu32.dll
- 2014-09-15 23:59:40 ----A---- C:\Windows\system32\coinst_14.30.dll
- 2014-09-15 23:59:20 ----A---- C:\Windows\system32\atiadlxx.dll
- 2014-09-15 23:59:16 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
- 2014-09-15 23:59:14 ----A---- C:\Windows\system32\atig6pxx.dll
- 2014-09-15 23:59:12 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
- 2014-09-15 23:59:12 ----A---- C:\Windows\system32\atiglpxx.dll
- 2014-09-15 23:59:12 ----A---- C:\Windows\system32\atig6txx.dll
- 2014-09-15 23:59:08 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
- 2014-09-15 23:59:06 ----A---- C:\Windows\system32\drivers\atikmpag.sys
- 2014-09-15 23:58:54 ----A---- C:\Windows\system32\drivers\ati2erec.dll
- 2014-09-15 18:21:34 ----A---- C:\Windows\system32\kdbsdk64.dll
- 2014-09-15 18:19:58 ----A---- C:\Windows\SYSWOW64\kdbsdk32.dll
- ======List of files/folders modified in the last 1 month======
- 2014-10-14 00:19:20 ----D---- C:\Windows\Prefetch
- 2014-10-14 00:19:12 ----D---- C:\Windows\temp
- 2014-10-14 00:19:11 ----RD---- C:\Program Files
- 2014-10-14 00:14:43 ----D---- C:\Users\MrHack\AppData\Roaming\uTorrent
- 2014-10-14 00:12:23 ----D---- C:\Users\MrHack\AppData\Roaming\Skype
- 2014-10-13 23:01:41 ----D---- C:\Program Files (x86)\osu!
- 2014-10-13 22:28:32 ----D---- C:\Users\MrHack\AppData\Roaming\Raptr
- 2014-10-13 20:42:08 ----D---- C:\Windows\System32
- 2014-10-13 20:42:08 ----D---- C:\Windows\inf
- 2014-10-13 20:42:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
- 2014-10-13 20:38:31 ----D---- C:\Users\MrHack\AppData\Roaming\vlc
- 2014-10-13 19:46:02 ----SHD---- C:\System Volume Information
- 2014-10-13 19:05:22 ----D---- C:\Windows\system32\catroot2
- 2014-10-13 19:05:22 ----D---- C:\Windows\Logs
- 2014-10-13 19:05:22 ----D---- C:\Windows
- 2014-10-13 19:02:14 ----D---- C:\Windows\system32\config
- 2014-10-13 18:58:50 ----D---- C:\Boot
- 2014-10-13 18:51:18 ----RSD---- C:\Windows\assembly
- 2014-10-13 18:49:54 ----SHD---- C:\Windows\Installer
- 2014-10-13 18:49:54 ----D---- C:\Config.Msi
- 2014-10-13 14:36:57 ----D---- C:\Users\MrHack\AppData\Roaming\Dropbox
- 2014-10-13 14:24:38 ----D---- C:\ProgramData\ProductData
- 2014-10-13 14:23:18 ----D---- C:\Windows\system32\Tasks
- 2014-10-13 14:23:11 ----D---- C:\Windows\Tasks
- 2014-10-12 22:14:50 ----D---- C:\Windows\system32\catroot
- 2014-10-09 19:31:39 ----D---- C:\Users\MrHack\AppData\Roaming\SpaceEngineers
- 2014-10-09 19:17:51 ----D---- C:\Windows\SysWOW64
- 2014-10-09 19:17:30 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
- 2014-10-08 19:51:56 ----D---- C:\Program Files (x86)\Origin
- 2014-10-05 21:08:59 ----D---- C:\Users\MrHack\AppData\Roaming\Samsung
- 2014-10-05 21:08:49 ----D---- C:\ProgramData
- 2014-10-05 21:08:44 ----D---- C:\Windows\system32\drivers
- 2014-10-05 21:08:32 ----D---- C:\Program Files (x86)\Common Files
- 2014-10-05 21:08:30 ----D---- C:\Program Files (x86)\Samsung
- 2014-10-05 20:56:17 ----D---- C:\Windows\system32\DriverStore
- 2014-10-05 20:56:09 ----D---- C:\Windows\twain_32
- 2014-10-01 21:05:18 ----D---- C:\Users\MrHack\AppData\Roaming\TS3Client
- 2014-10-01 17:52:11 ----D---- C:\Windows\Microsoft.NET
- 2014-10-01 17:20:16 ----D---- C:\ProgramData\AMD
- 2014-10-01 17:20:15 ----RD---- C:\Program Files (x86)
- 2014-10-01 17:19:43 ----D---- C:\Program Files\ATI Technologies
- 2014-10-01 17:14:45 ----D---- C:\ProgramData\Package Cache
- 2014-10-01 17:10:39 ----D---- C:\AMD
- 2014-09-26 09:23:15 ----D---- C:\Users\MrHack\AppData\Roaming\Curse Client
- 2014-09-24 02:56:20 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
- 2014-09-24 00:42:29 ----D---- C:\Users\MrHack\AppData\Roaming\Audacity
- 2014-09-22 00:01:21 ----D---- C:\ProgramData\Skype
- 2014-09-21 23:53:00 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
- 2014-09-20 20:50:11 ----D---- C:\ProgramData\Origin
- 2014-09-18 22:20:32 ----D---- C:\Windows\winsxs
- 2014-09-18 22:16:15 ----D---- C:\Windows\SYSWOW64\migration
- 2014-09-18 22:16:15 ----D---- C:\Windows\system32\migration
- 2014-09-18 22:16:15 ----D---- C:\Program Files\Internet Explorer
- 2014-09-18 22:16:15 ----D---- C:\Program Files (x86)\Internet Explorer
- 2014-09-18 21:32:14 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
- 2014-09-17 23:38:57 ----D---- C:\Windows\system32\drivers\etc
- 2014-09-16 00:32:04 ----A---- C:\Windows\SYSWOW64\amdhcp32.dll
- 2014-09-16 00:31:50 ----A---- C:\Windows\system32\atiuxp64.dll
- 2014-09-16 00:31:46 ----A---- C:\Windows\system32\atiu9p64.dll
- 2014-09-16 00:31:44 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
- 2014-09-16 00:31:42 ----A---- C:\Windows\system32\aticfx64.dll
- 2014-09-16 00:31:40 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
- 2014-09-16 00:31:34 ----A---- C:\Windows\system32\atidxx64.dll
- 2014-09-16 00:31:22 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
- 2014-09-16 00:31:16 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
- 2014-09-16 00:31:06 ----A---- C:\Windows\system32\atiumd6a.dll
- 2014-09-16 00:31:02 ----A---- C:\Windows\system32\atiumd64.dll
- 2014-09-16 00:00:00 ----A---- C:\Windows\SYSWOW64\amdave32.dll
- 2014-09-15 16:19:16 ----D---- C:\Users\MrHack\AppData\Roaming\.minecraft
- ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
- R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
- R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
- R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
- R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2014-07-31 386680]
- R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
- R1 A2DDA;A2 Direct Disk Access Support Driver; \??\C:\EEK\RUN\a2ddax64.sys [2013-11-01 26176]
- R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
- R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
- R2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
- R2 mi2c;mi2c; \??\C:\Windows\system32\drivers\mi2c.sys [2014-04-18 20784]
- R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2013-04-10 11576]
- R2 UltraMonUtility;UltraMon Utility Driver; \??\C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2012-08-24 20512]
- R2 VBoxDrv;VBox Support Driver; \??\C:\Program Files (x86)\YouWave Android\vb\VBoxDrv.sys [2011-11-20 202592]
- R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-09-16 16750080]
- R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-09-15 576000]
- R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
- R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-07-31 283064]
- R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
- R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
- R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-01-22 77824]
- R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2014-05-08 181760]
- R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2014-05-08 901848]
- R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2014-02-16 60640]
- R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2014-05-08 689840]
- S2 Ca1528av;SPCA1528 Video Camera Service; C:\Windows\System32\Drivers\Ca1528av.sys [2008-12-17 533760]
- S3 AsrOcDrv;AsrOcDrv; C:\Windows\system32\drivers\AsrOcDrv.sys []
- S3 athr;Wireless PCI Adapter Driver Service; C:\Windows\system32\DRIVERS\athrx.sys [2012-11-06 2755584]
- S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
- S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
- S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
- S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-20 552448]
- S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 80384]
- S3 Bulk1528;SPCA1528 Still Camera Service; C:\Windows\System32\Drivers\Bulk1528.sys [2008-06-28 14848]
- S3 catchme;catchme; C:\Windows\system32\drivers\catchme.sys []
- S3 cleanhlp;cleanhlp; \??\C:\EEK\Run\cleanhlp64.sys [2013-11-01 57024]
- S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
- S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
- S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2013-10-17 36928]
- S3 HtcVCom32;HTC Diagnostic Port; C:\Windows\system32\DRIVERS\HtcVComV64.sys [2010-03-09 121800]
- S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
- S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 20992]
- S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
- S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
- S3 SMIGrabber3C;SMI Grabber Device Tuner Filter 3C; C:\Windows\System32\Drivers\SmiUsbGrabber3C.sys [2011-01-26 821888]
- S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
- S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
- S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
- S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
- S3 tsusbhub;tsusbhub; C:\Windows\system32\drivers\tsusbhub.sys []
- S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2013-03-18 54784]
- S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
- S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
- S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]
- ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
- R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
- R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2014-01-14 881952]
- R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-09-16 239616]
- R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-09-15 344064]
- R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-02-12 43336]
- R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
- R2 Capture Device Service;Capture Device Service; C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
- R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2014-09-04 2525008]
- R2 HTCMonitorService;HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [2013-11-18 87368]
- R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2014-08-08 377616]
- R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2013-10-17 166912]
- R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-08-09 76152]
- R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-04-25 1738200]
- R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-04-25 2081752]
- R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
- R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
- R2 TBSrv;Toolbar Service; C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe [2014-04-10 350528]
- R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-07-02 5037888]
- R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2006-09-28 49152]
- R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2014-05-08 27768]
- R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-05-26 641352]
- R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-10-09 833728]
- S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
- S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-09 123856]
- S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-25 116648]
- S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2014-05-04 2152736]
- S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
- S2 ProtectMonitor;Protect Monitor; C:\Program Files\PCDApp\StartHelp.exe [2014-05-09 97232]
- S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24 267440]
- S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-25 116648]
- S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
- S3 NBService;NBService; F:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
- S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
- S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
- S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
- S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
- S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-03-08 1255736]
- S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
- S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-09 51648]
- S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
- S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
- S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
- S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
- S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
- S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
- S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
- S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
- -----------------EOF-----------------
Advertisement
Add Comment
Please, Sign In to add comment