Prosim o kontrolu logu, pocitac je v hroznem stavu
Napsal: 24 úno 2015 15:45
Logfile of random's system information tool 1.10 (written by random/random)
Run by jointsmouka at 2015-02-24 15:38:13
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 36 GB (23%) free of 154 GB
Total RAM: 4094 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:39:36, on 24.2.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Users\jointsmouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winupdt32f.exe
C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe
C:\Windows\SysWOW64\WScript.exe
C:\Windows\SysWOW64\WScript.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\inf\mnccdgjd\mnccdgjd.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\jointsmouka.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\jointsmouka\AppData\Roaming\Microsoft\Network\inet32f.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.242.254.156 www.google-analytics.com.
O1 - Hosts: 94.242.254.156 google-analytics.com.
O1 - Hosts: 94.242.254.156 connect.facebook.net.
O1 - Hosts: 85.25.107.101 www.google-analytics.com.
O1 - Hosts: 85.25.107.101 google-analytics.com.
O1 - Hosts: 85.25.107.101 connect.facebook.net.
O1 - Hosts: 85.25.79.99 www.google-analytics.com.
O1 - Hosts: 85.25.79.99 google-analytics.com.
O1 - Hosts: 85.25.79.99 connect.facebook.net.
O2 - BHO: shoppia - {70ba1ce1-4478-4bf6-8028-a91b017bd1c2} - C:\ProgramData\shoppia\8KCVB5cQdItgNM.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [MSStp] C:\Windows\system32\msstp.vbe
O4 - HKLM\..\Run: [mnccdgjdSrv] C:\Windows\inf\mnccdgjd.vbe
O4 - HKLM\..\Run: [msphtovSrv] "C:\Windows\system32\msphtov.vbe" mskpko msstnj
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Ciidifamo] C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" -bootmode
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [CloudSystemBooster] "D:\INSTALL\CSB\Cloud System Booster\CloudSystemBooster.exe" /hide /autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Ujgbmedia] C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe
O4 - HKCU\..\Run: [Ciidifamo] C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
O4 - HKCU\..\Run: [Ezevlefehov] "C:\Users\jointsmouka\AppData\Roaming\Utadxou\vuyqb.exe"
O4 - HKCU\..\Run: [Hiwunimyy] "C:\Users\jointsmouka\AppData\Roaming\Uzqece\yhebl.exe"
O4 - HKCU\..\Run: [Oglinabuqunorie] "C:\Users\jointsmouka\AppData\Roaming\Etnapaw\uxarpie.exe"
O4 - HKCU\..\Run: [Laekes] "C:\Users\jointsmouka\AppData\Roaming\Ixvait\haleehr.exe"
O4 - HKCU\..\Run: [Welayfavneas] "C:\Users\jointsmouka\AppData\Roaming\Myagudi\aduseso.exe"
O4 - HKCU\..\Run: [Zolaazcawe] "C:\Users\jointsmouka\AppData\Roaming\Hoodid\ukneas.exe"
O4 - HKCU\..\Run: [Ityxxiemhiylom] "C:\Users\jointsmouka\AppData\Roaming\Awithim\ibqeyz.exe"
O4 - HKCU\..\Run: [Vesisoby] "C:\Users\jointsmouka\AppData\Roaming\Itohqi\vovaoqa.exe"
O4 - HKCU\..\Run: [Wuuzviakuvha] "C:\Users\jointsmouka\AppData\Roaming\Ampony\nyepcue.exe"
O4 - HKCU\..\Run: [Zigyrahe] "C:\Users\jointsmouka\AppData\Roaming\Dasaquut\ipodsa.exe"
O4 - HKCU\..\Run: [Cycyohnazuex] "C:\Users\jointsmouka\AppData\Roaming\Qoafesk\yxdaw.exe"
O4 - HKCU\..\Run: [Coivr] "C:\Users\jointsmouka\AppData\Roaming\Otyzxoa\ygcyygv.exe"
O4 - HKCU\..\Run: [Oxxavoacufy] "C:\Users\jointsmouka\AppData\Roaming\Yhiwaked\etryib.exe"
O4 - HKCU\..\Run: [Yfcuoqdyysewyx] "C:\Users\jointsmouka\AppData\Roaming\Lumiut\zuyza.exe"
O4 - HKCU\..\Run: [Ashaulgoe] "C:\Users\jointsmouka\AppData\Roaming\Awaskem\evovdie.exe"
O4 - HKCU\..\Run: [Anpworks] C:\Windows\SysWOW64\regsvr32.exe C:\Users\jointsmouka\AppData\Local\Ujgbmedia\loader_u.dll
O4 - HKCU\..\Run: [Omkics] regsvr32.exe C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll
O4 - HKCU\..\RunOnce: [Application Restart #4] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --extensions-on-chrome-urls --test-type --load-extension="c:\Program Files\Google\Chrome\Application\Extensions\chrome\app\37.1329.6.12" --flag-switches-begin --flag-switches-end --restore-last-session
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = jointsmouka\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: winupdt32f.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{878EC04A-E66B-447C-BB01-A651764F78C1}: NameServer = 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Anvi Cloud System Booster Speed Service (AnviCsbSvc) - Anvisoft - D:/INSTALL/CSB/Cloud System Booster/CSBSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Reimage Real Time Protector (ReimageRealTimeProtector) - Reimage® - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Security Center Server - 3595630534 (SecurityCenterServer3595630534) - Eraem Corniratu - C:\Windows\SysWOW64\ebmunem.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14980 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {B903E62D-F41B-4433-87D3-6698D0045ECF}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe"
"C:\Windows\SysWOW64\regsvr32.exe" C:\Users\jointsmouka\AppData\Local\Ujgbmedia\loader_u.dll
"C:\Windows\System32\regsvr32.exe" C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll
"C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll
"D:/INSTALL/CSB/Cloud System Booster/CSBSvc.exe"
"C:\Users\jointsmouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winupdt32f.exe"
szndesktop.exe default start
"C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "6655416801293719889-1987998681873703496-11269568075079076021761443178725308502
"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe
"C:\Windows\System32\WScript.exe" "C:\Windows\inf\mnccdgjd.vbe"
"C:\Windows\System32\WScript.exe" "C:\Windows\System32\msphtov.vbe" mskpko msstnj
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
\??\C:\Windows\system32\conhost.exe "-1690417169956602342-686170679282840477536870901420692325-129274885896599006
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe"
"C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe"
"C:\Windows\SysWOW64\ebmunem.exe" -service "C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 9656890a-0eb1-4d54-95d8-c4d281de9889 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "985405736-741527832-489258371162775702882568365-1472529436-319105090-238108218
\??\C:\Windows\system32\conhost.exe "-191035990-16951130469553021535383193401208321580-20953757651355730397-1208120681
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3120.2.1053930475\66035445" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.4.642899631\1283083011" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.5.2119136035\950334484" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.6.1118669217\1418832866" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.7.1925626281\1535354225" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3120.11.1572476254\998548877" --use-gl=swiftshader --supports-dual-gpus=false --swiftshader-path="C:\Users\jointsmouka\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159" --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --gpu-driver-version --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\inf\mnccdgjd\mnccdgjd.exe"
\??\C:\Windows\system32\conhost.exe "-149043812129052210717374592701944022597-10960272581986920602164412974-1050209803
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding -noframemerging -private
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:7032 CREDAT:275457 /prefetch:2
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"c:\program files (x86)\teamviewer\TeamViewer_Desktop.exe" --IPCport 5939
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/PrerenderFromOmnibox/OmniboxPrerenderEnabled/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.20.764035676\262652888" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3120.22.672063886\242874361" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\jointsmouka\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding -noframemerging -private
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6032 CREDAT:275457 /prefetch:2
"C:\Users\jointsmouka\AppData\Roaming\Microsoft\Network\inet32f.exe" -u 47VDBRxaNbE5EEDuWjJuWeUtjYb31NPMQTpA3Nt9Dn1YWS12JARgtGyL2wBYSv8pxiGS58nSbUNXCU9q7j7unTGf7Mrhu2u -p x -o stratum+tcp://mine.moneropool.com:3333
======Scheduled tasks folder======
C:\Windows\tasks\Ad-Aware Update (Daily).job - C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe update all silent
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-883375831-3728679416-1811525376-1001Core.job - C:\Users\jointsmouka\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-883375831-3728679416-1811525376-1001UA.job - C:\Users\jointsmouka\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Security Center Update - 3595630534.job - C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70ba1ce1-4478-4bf6-8028-a91b017bd1c2}]
shoppia - C:\ProgramData\shoppia\8KCVB5cQdItgNM.x64.dll [2015-01-09 701952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70ba1ce1-4478-4bf6-8028-a91b017bd1c2}]
shoppia - C:\ProgramData\shoppia\8KCVB5cQdItgNM.dll [2015-01-09 566272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2012-11-29 57928]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2462536]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-10-04 2800296]
"AutoKMS"=C:\Windows\AutoKMS.exe [2015-01-06 615936]
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Logitech Vid"=C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [2011-01-13 6129496]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2015-02-19 2874048]
"cz.seznam.software.autoupdate"=C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"CloudSystemBooster"=D:\INSTALL\CSB\Cloud System Booster\CloudSystemBooster.exe [2014-05-29 527544]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-01-23 31087200]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Ujgbmedia"=C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe [2014-12-21 139332]
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
"Ezevlefehov"=C:\Users\jointsmouka\AppData\Roaming\Utadxou\vuyqb.exe []
"Hiwunimyy"=C:\Users\jointsmouka\AppData\Roaming\Uzqece\yhebl.exe []
"Oglinabuqunorie"=C:\Users\jointsmouka\AppData\Roaming\Etnapaw\uxarpie.exe []
"Laekes"=C:\Users\jointsmouka\AppData\Roaming\Ixvait\haleehr.exe []
"Welayfavneas"=C:\Users\jointsmouka\AppData\Roaming\Myagudi\aduseso.exe []
"Zolaazcawe"=C:\Users\jointsmouka\AppData\Roaming\Hoodid\ukneas.exe []
"Ityxxiemhiylom"=C:\Users\jointsmouka\AppData\Roaming\Awithim\ibqeyz.exe []
"Vesisoby"=C:\Users\jointsmouka\AppData\Roaming\Itohqi\vovaoqa.exe []
"Wuuzviakuvha"=C:\Users\jointsmouka\AppData\Roaming\Ampony\nyepcue.exe []
"Zigyrahe"=C:\Users\jointsmouka\AppData\Roaming\Dasaquut\ipodsa.exe []
"Cycyohnazuex"=C:\Users\jointsmouka\AppData\Roaming\Qoafesk\yxdaw.exe []
"Coivr"=C:\Users\jointsmouka\AppData\Roaming\Otyzxoa\ygcyygv.exe []
"Oxxavoacufy"=C:\Users\jointsmouka\AppData\Roaming\Yhiwaked\etryib.exe []
"Yfcuoqdyysewyx"=C:\Users\jointsmouka\AppData\Roaming\Lumiut\zuyza.exe []
"Ashaulgoe"=C:\Users\jointsmouka\AppData\Roaming\Awaskem\evovdie.exe []
"Anpworks"=C:\Windows\SysWOW64\regsvr32.exe [2009-07-14 14848]
"Omkics"=regsvr32.exe C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Application Restart #4"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-12-06 856904]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LWS"=C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [2011-11-11 205336]
"MSStp"=C:\Windows\system32\msstp.vbe []
"mnccdgjdSrv"=C:\Windows\inf\mnccdgjd.vbe [2014-01-13 1338]
"msphtovSrv"=C:\Windows\system32\msphtov.vbe mskpko msstnj []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"Ad-Watch"=C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe [2009-01-18 506712]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
[HKEY_CURRENT_USER\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Hiwunimyy"=C:\Users\jointsmouka\AppData\Roaming\Uzqece\yhebl.exe []
"Oglinabuqunorie"=C:\Users\jointsmouka\AppData\Roaming\Etnapaw\uxarpie.exe []
"Laekes"=C:\Users\jointsmouka\AppData\Roaming\Ixvait\haleehr.exe []
"Ezevlefehov"=C:\Users\jointsmouka\AppData\Roaming\Utadxou\vuyqb.exe []
"Yfcuoqdyysewyx"=C:\Users\jointsmouka\AppData\Roaming\Lumiut\zuyza.exe []
"Welayfavneas"=C:\Users\jointsmouka\AppData\Roaming\Myagudi\aduseso.exe []
"Oxxavoacufy"=C:\Users\jointsmouka\AppData\Roaming\Yhiwaked\etryib.exe []
"Zigyrahe"=C:\Users\jointsmouka\AppData\Roaming\Dasaquut\ipodsa.exe []
"Cycyohnazuex"=C:\Users\jointsmouka\AppData\Roaming\Qoafesk\yxdaw.exe []
"Zolaazcawe"=C:\Users\jointsmouka\AppData\Roaming\Hoodid\ukneas.exe []
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
"Vesisoby"=C:\Users\jointsmouka\AppData\Roaming\Itohqi\vovaoqa.exe []
"Wuuzviakuvha"=C:\Users\jointsmouka\AppData\Roaming\Ampony\nyepcue.exe []
"Ashaulgoe"=C:\Users\jointsmouka\AppData\Roaming\Awaskem\evovdie.exe []
"Coivr"=C:\Users\jointsmouka\AppData\Roaming\Otyzxoa\ygcyygv.exe []
"Ityxxiemhiylom"=C:\Users\jointsmouka\AppData\Roaming\Awithim\ibqeyz.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Users\jointsmouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\jointsmouka\AppData\Roaming\Dropbox\bin\Dropbox.exe
winupdt32f.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~3\NETWOR~1\NETWOR~2.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-18 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-18 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcod64.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-02-24 15:38:13 ----D---- C:\Program Files\trend micro
2015-02-24 15:16:17 ----D---- C:\Users\jointsmouka\AppData\Roaming\TeamViewer
2015-02-12 14:10:08 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-02-12 14:10:08 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-02-12 14:10:08 ----A---- C:\Windows\system32\jscript9diag.dll
2015-02-12 14:10:08 ----A---- C:\Windows\system32\jscript9.dll
2015-02-11 14:35:30 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-02-11 14:35:29 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-02-11 14:35:26 ----A---- C:\Windows\system32\lsasrv.dll
2015-02-11 14:35:26 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-11 14:35:26 ----A---- C:\Windows\system32\adtschema.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\sspisrv.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\sspicli.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\secur32.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\msobjs.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\msaudite.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\lsass.exe
2015-02-11 14:35:25 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-11 14:35:25 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-02-11 14:35:25 ----A---- C:\Windows\system32\auditpol.exe
2015-02-11 14:35:19 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-02-11 14:35:19 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-02-11 14:35:19 ----A---- C:\Windows\system32\mstscax.dll
2015-02-11 14:34:58 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-11 14:34:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-02-11 14:34:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-02-11 14:34:53 ----A---- C:\Windows\system32\srcore.dll
2015-02-11 14:34:53 ----A---- C:\Windows\system32\rstrui.exe
2015-02-11 14:34:52 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-02-11 14:34:52 ----A---- C:\Windows\system32\srclient.dll
2015-02-11 14:34:34 ----A---- C:\Windows\system32\generaltel.dll
2015-02-11 14:34:34 ----A---- C:\Windows\system32\appraiser.dll
2015-02-11 14:34:34 ----A---- C:\Windows\system32\aeinv.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\invagent.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\devinv.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\aitstatic.exe
2015-02-11 14:34:33 ----A---- C:\Windows\system32\aepic.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\aepdu.dll
2015-02-11 14:34:27 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-02-11 14:34:27 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-02-11 14:34:27 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\wdigest.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\schannel.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\msv1_0.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\kerberos.dll
2015-02-11 14:34:26 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-02-11 14:34:26 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-02-11 14:34:26 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-02-11 14:34:26 ----A---- C:\Windows\system32\TSpkg.dll
2015-02-11 14:34:26 ----A---- C:\Windows\system32\ncrypt.dll
2015-02-11 14:34:25 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-02-11 14:34:25 ----A---- C:\Windows\system32\credssp.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-02-11 14:34:13 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-02-11 14:34:13 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\iernonce.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-11 14:34:10 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-02-11 14:34:10 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-02-11 14:34:10 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-02-11 14:34:10 ----A---- C:\Windows\system32\urlmon.dll
2015-02-11 14:34:10 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 14:34:10 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-02-11 14:34:09 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 14:34:09 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-11 14:34:09 ----A---- C:\Windows\system32\dxtrans.dll
2015-02-11 14:34:08 ----A---- C:\Windows\system32\iesetup.dll
2015-02-11 14:34:08 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-11 14:34:06 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-02-11 14:34:06 ----A---- C:\Windows\system32\iertutil.dll
2015-02-11 14:34:05 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-02-11 14:34:05 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-02-11 14:34:05 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-02-11 14:34:05 ----A---- C:\Windows\system32\jsproxy.dll
2015-02-11 14:34:05 ----A---- C:\Windows\system32\ieUnatt.exe
2015-02-11 14:34:04 ----A---- C:\Windows\system32\ieui.dll
2015-02-11 14:34:04 ----A---- C:\Windows\system32\ieframe.dll
2015-02-11 14:34:04 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-11 14:34:03 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-02-11 14:34:03 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-11 14:34:02 ----A---- C:\Windows\system32\wininet.dll
2015-02-11 14:34:02 ----A---- C:\Windows\system32\vbscript.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\msrating.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-11 14:34:00 ----A---- C:\Windows\system32\mshtml.dll
2015-02-11 14:30:23 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-02-11 14:30:23 ----A---- C:\Windows\system32\crypt32.dll
2015-02-11 14:29:34 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-02-11 14:29:34 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-11 14:28:59 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-02-11 14:28:59 ----A---- C:\Windows\system32\scesrv.dll
2015-02-11 14:28:04 ----A---- C:\Windows\system32\win32k.sys
2015-02-05 00:39:01 ----D---- C:\ProgramData\BlockIt Ad remover
2015-02-05 00:36:16 ----D---- C:\ProgramData\8022386465577498893UL
======List of files/folders modified in the last 1 month======
2015-02-24 15:39:17 ----D---- C:\Windows\Prefetch
2015-02-24 15:38:46 ----D---- C:\Windows\Temp
2015-02-24 15:38:13 ----RD---- C:\Program Files
2015-02-24 15:34:41 ----D---- C:\Program Files (x86)\Steam
2015-02-24 15:33:55 ----D---- C:\Users\jointsmouka\AppData\Roaming\Skype
2015-02-24 15:16:49 ----D---- C:\Program Files (x86)\TeamViewer
2015-02-24 15:16:47 ----D---- C:\Windows\system32\Tasks
2015-02-24 15:16:18 ----RSD---- C:\Windows\Fonts
2015-02-24 15:15:45 ----D---- C:\Windows\system32\config
2015-02-24 15:01:51 ----D---- C:\Users\jointsmouka\AppData\Roaming\Seznam.cz
2015-02-24 15:00:44 ----D---- C:\Users\jointsmouka\AppData\Roaming\Dropbox
2015-02-24 15:00:27 ----D---- C:\Windows
2015-02-24 14:57:58 ----D---- C:\Windows\System32
2015-02-24 14:56:03 ----D---- C:\ProgramData\NVIDIA
2015-02-24 10:27:43 ----D---- C:\Windows\Minidump
2015-02-24 10:08:49 ----D---- C:\Windows\inf
2015-02-24 10:08:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-24 09:06:20 ----SHD---- C:\Windows\Installer
2015-02-24 09:06:19 ----D---- C:\ProgramData\Skype
2015-02-24 09:05:00 ----RD---- C:\Program Files (x86)\Skype
2015-02-24 09:02:24 ----D---- C:\ProgramData\LogMeIn
2015-02-23 04:03:44 ----SHD---- C:\System Volume Information
2015-02-23 02:48:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-02-23 02:48:19 ----D---- C:\Windows\SysWOW64
2015-02-23 02:41:45 ----D---- C:\Windows\system32\en-US
2015-02-23 02:39:37 ----D---- C:\Windows\Tasks
2015-02-23 02:39:37 ----D---- C:\Windows\system32\wfp
2015-02-23 02:39:37 ----D---- C:\Windows\system32\wbem
2015-02-23 02:39:37 ----D---- C:\Windows\system32\DriverStore
2015-02-23 02:39:36 ----D---- C:\Windows\system32\drivers
2015-02-23 02:39:36 ----D---- C:\Windows\system32\CodeIntegrity
2015-02-23 02:39:35 ----D---- C:\Windows\system32\catroot2
2015-02-23 02:39:33 ----D---- C:\Users\jointsmouka\AppData\Roaming\vlc
2015-02-23 02:39:30 ----D---- C:\ProgramData\McAfee Security Scan
2015-02-23 02:39:26 ----D---- C:\Windows\registration
2015-02-23 02:39:15 ----SD---- C:\Users\jointsmouka\AppData\Roaming\Microsoft
2015-02-23 02:38:58 ----D---- C:\Program Files (x86)\LogMeIn
2015-02-22 18:54:58 ----HD---- C:\ProgramData
2015-02-16 17:59:02 ----D---- C:\Windows\system32\drivers\etc
2015-02-14 02:30:32 ----D---- C:\ProgramData\shoppia
2015-02-13 13:14:52 ----D---- C:\Windows\Microsoft.NET
2015-02-13 12:55:12 ----RSD---- C:\Windows\assembly
2015-02-13 08:09:17 ----D---- C:\Windows\rescache
2015-02-13 01:15:28 ----D---- C:\Windows\winsxs
2015-02-12 14:21:02 ----D---- C:\Windows\system32\MRT
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Yhiwaked
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Qoafesk
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Otyzxoa
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Myagudi
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Lumiut
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Itohqi
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Ikycwe
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Hoodid
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Dasaquut
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Awithim
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Awaskem
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Ampony
2015-02-12 04:18:09 ----SD---- C:\Windows\system32\CompatTel
2015-02-12 04:18:08 ----D---- C:\Windows\system32\appraiser
2015-02-12 04:18:08 ----D---- C:\Program Files\Internet Explorer
2015-02-12 04:18:06 ----D---- C:\Program Files (x86)\Internet Explorer
2015-02-12 04:18:00 ----D---- C:\Windows\PolicyDefinitions
2015-02-12 03:56:00 ----D---- C:\ProgramData\Microsoft Help
2015-02-12 03:45:08 ----A---- C:\Windows\win.ini
2015-02-12 03:10:00 ----A---- C:\Windows\system32\MRT.exe
2015-02-08 22:33:48 ----D---- C:\Users\jointsmouka\AppData\Roaming\BitTorrent
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 {01531192-f7ef-415f-a549-cfdb11836731}w64;{01531192-f7ef-415f-a549-cfdb11836731}w64; C:\Windows\system32\drivers\{01531192-f7ef-415f-a549-cfdb11836731}w64.sys [2014-04-24 61120]
R1 {3f538614-b636-4023-9ec2-564ada4b07b3}Gw64;{3f538614-b636-4023-9ec2-564ada4b07b3}Gw64; C:\Windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}Gw64.sys [2014-06-25 61112]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-11-17 283064]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2012-11-29 72216]
R3 CompFilter64;UVCCompositeFilter; C:\Windows\system32\DRIVERS\lvbflt64.sys [2012-01-18 25632]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2012-11-29 11552]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136]
R3 LVUVC64;Logitech HD Webcam C525(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-01-18 4865568]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 19272]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2013-06-02 16056]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-13 5020672]
S3 cpuz134;cpuz134; \??\C:\Users\JOINTS~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-22 40664]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AnviCsbSvc;Anvi Cloud System Booster Speed Service; D:/INSTALL/CSB/Cloud System Booster/CSBSvc.exe []
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1148744]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2015-01-16 377704]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1795912]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19439944]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-07-02 935368]
R2 ReimageRealTimeProtector;Reimage Real Time Protector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2015-01-14 7410024]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176]
R2 UMVPFSrv;UMVPFSrv; C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 2384af53;Network Acceleration; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-21 107912]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
S2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [2015-01-16 226152]
S2 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2012-11-29 407424]
S2 SecurityCenterServer3595630534;Security Center Server - 3595630534; C:\Windows\SysWOW64\ebmunem.exe [2014-03-08 504512]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-21 107912]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 114688]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-18 50942144]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-06-06 543656]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-26 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------
Run by jointsmouka at 2015-02-24 15:38:13
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 36 GB (23%) free of 154 GB
Total RAM: 4094 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:39:36, on 24.2.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Windows\SysWOW64\regsvr32.exe
C:\Users\jointsmouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winupdt32f.exe
C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe
C:\Windows\SysWOW64\WScript.exe
C:\Windows\SysWOW64\WScript.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\inf\mnccdgjd\mnccdgjd.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\jointsmouka.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\jointsmouka\AppData\Roaming\Microsoft\Network\inet32f.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.242.254.156 www.google-analytics.com.
O1 - Hosts: 94.242.254.156 google-analytics.com.
O1 - Hosts: 94.242.254.156 connect.facebook.net.
O1 - Hosts: 85.25.107.101 www.google-analytics.com.
O1 - Hosts: 85.25.107.101 google-analytics.com.
O1 - Hosts: 85.25.107.101 connect.facebook.net.
O1 - Hosts: 85.25.79.99 www.google-analytics.com.
O1 - Hosts: 85.25.79.99 google-analytics.com.
O1 - Hosts: 85.25.79.99 connect.facebook.net.
O2 - BHO: shoppia - {70ba1ce1-4478-4bf6-8028-a91b017bd1c2} - C:\ProgramData\shoppia\8KCVB5cQdItgNM.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [MSStp] C:\Windows\system32\msstp.vbe
O4 - HKLM\..\Run: [mnccdgjdSrv] C:\Windows\inf\mnccdgjd.vbe
O4 - HKLM\..\Run: [msphtovSrv] "C:\Windows\system32\msphtov.vbe" mskpko msstnj
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Ciidifamo] C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" -bootmode
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [CloudSystemBooster] "D:\INSTALL\CSB\Cloud System Booster\CloudSystemBooster.exe" /hide /autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Ujgbmedia] C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe
O4 - HKCU\..\Run: [Ciidifamo] C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
O4 - HKCU\..\Run: [Ezevlefehov] "C:\Users\jointsmouka\AppData\Roaming\Utadxou\vuyqb.exe"
O4 - HKCU\..\Run: [Hiwunimyy] "C:\Users\jointsmouka\AppData\Roaming\Uzqece\yhebl.exe"
O4 - HKCU\..\Run: [Oglinabuqunorie] "C:\Users\jointsmouka\AppData\Roaming\Etnapaw\uxarpie.exe"
O4 - HKCU\..\Run: [Laekes] "C:\Users\jointsmouka\AppData\Roaming\Ixvait\haleehr.exe"
O4 - HKCU\..\Run: [Welayfavneas] "C:\Users\jointsmouka\AppData\Roaming\Myagudi\aduseso.exe"
O4 - HKCU\..\Run: [Zolaazcawe] "C:\Users\jointsmouka\AppData\Roaming\Hoodid\ukneas.exe"
O4 - HKCU\..\Run: [Ityxxiemhiylom] "C:\Users\jointsmouka\AppData\Roaming\Awithim\ibqeyz.exe"
O4 - HKCU\..\Run: [Vesisoby] "C:\Users\jointsmouka\AppData\Roaming\Itohqi\vovaoqa.exe"
O4 - HKCU\..\Run: [Wuuzviakuvha] "C:\Users\jointsmouka\AppData\Roaming\Ampony\nyepcue.exe"
O4 - HKCU\..\Run: [Zigyrahe] "C:\Users\jointsmouka\AppData\Roaming\Dasaquut\ipodsa.exe"
O4 - HKCU\..\Run: [Cycyohnazuex] "C:\Users\jointsmouka\AppData\Roaming\Qoafesk\yxdaw.exe"
O4 - HKCU\..\Run: [Coivr] "C:\Users\jointsmouka\AppData\Roaming\Otyzxoa\ygcyygv.exe"
O4 - HKCU\..\Run: [Oxxavoacufy] "C:\Users\jointsmouka\AppData\Roaming\Yhiwaked\etryib.exe"
O4 - HKCU\..\Run: [Yfcuoqdyysewyx] "C:\Users\jointsmouka\AppData\Roaming\Lumiut\zuyza.exe"
O4 - HKCU\..\Run: [Ashaulgoe] "C:\Users\jointsmouka\AppData\Roaming\Awaskem\evovdie.exe"
O4 - HKCU\..\Run: [Anpworks] C:\Windows\SysWOW64\regsvr32.exe C:\Users\jointsmouka\AppData\Local\Ujgbmedia\loader_u.dll
O4 - HKCU\..\Run: [Omkics] regsvr32.exe C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll
O4 - HKCU\..\RunOnce: [Application Restart #4] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --extensions-on-chrome-urls --test-type --load-extension="c:\Program Files\Google\Chrome\Application\Extensions\chrome\app\37.1329.6.12" --flag-switches-begin --flag-switches-end --restore-last-session
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = jointsmouka\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: winupdt32f.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{878EC04A-E66B-447C-BB01-A651764F78C1}: NameServer = 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Anvi Cloud System Booster Speed Service (AnviCsbSvc) - Anvisoft - D:/INSTALL/CSB/Cloud System Booster/CSBSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Reimage Real Time Protector (ReimageRealTimeProtector) - Reimage® - C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Security Center Server - 3595630534 (SecurityCenterServer3595630534) - Eraem Corniratu - C:\Windows\SysWOW64\ebmunem.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14980 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {B903E62D-F41B-4433-87D3-6698D0045ECF}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe"
"C:\Windows\SysWOW64\regsvr32.exe" C:\Users\jointsmouka\AppData\Local\Ujgbmedia\loader_u.dll
"C:\Windows\System32\regsvr32.exe" C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll
"C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll
"D:/INSTALL/CSB/Cloud System Booster/CSBSvc.exe"
"C:\Users\jointsmouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winupdt32f.exe"
szndesktop.exe default start
"C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "6655416801293719889-1987998681873703496-11269568075079076021761443178725308502
"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe
"C:\Windows\System32\WScript.exe" "C:\Windows\inf\mnccdgjd.vbe"
"C:\Windows\System32\WScript.exe" "C:\Windows\System32\msphtov.vbe" mskpko msstnj
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
\??\C:\Windows\system32\conhost.exe "-1690417169956602342-686170679282840477536870901420692325-129274885896599006
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe"
"C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe"
"C:\Windows\SysWOW64\ebmunem.exe" -service "C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 9656890a-0eb1-4d54-95d8-c4d281de9889 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "985405736-741527832-489258371162775702882568365-1472529436-319105090-238108218
\??\C:\Windows\system32\conhost.exe "-191035990-16951130469553021535383193401208321580-20953757651355730397-1208120681
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3120.2.1053930475\66035445" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.4.642899631\1283083011" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.5.2119136035\950334484" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.6.1118669217\1418832866" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.7.1925626281\1535354225" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3120.11.1572476254\998548877" --use-gl=swiftshader --supports-dual-gpus=false --swiftshader-path="C:\Users\jointsmouka\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159" --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x0000 --gpu-device-id=0x0000 --gpu-driver-vendor --gpu-driver-version --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\inf\mnccdgjd\mnccdgjd.exe"
\??\C:\Windows\system32\conhost.exe "-149043812129052210717374592701944022597-10960272581986920602164412974-1050209803
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding -noframemerging -private
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:7032 CREDAT:275457 /prefetch:2
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"c:\program files (x86)\teamviewer\TeamViewer_Desktop.exe" --IPCport 5939
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/PasswordGeneration/Enabled/Prerender/MatchComplete/PrerenderFromOmnibox/OmniboxPrerenderEnabled/RememberCertificateErrorDecisions/OneDay/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --enable-gpu-rasterization --disable-gpu-compositing --channel="3120.20.764035676\262652888" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3120.22.672063886\242874361" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\jointsmouka\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Internet Explorer\iexplore.exe" -Embedding -noframemerging -private
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6032 CREDAT:275457 /prefetch:2
"C:\Users\jointsmouka\AppData\Roaming\Microsoft\Network\inet32f.exe" -u 47VDBRxaNbE5EEDuWjJuWeUtjYb31NPMQTpA3Nt9Dn1YWS12JARgtGyL2wBYSv8pxiGS58nSbUNXCU9q7j7unTGf7Mrhu2u -p x -o stratum+tcp://mine.moneropool.com:3333
======Scheduled tasks folder======
C:\Windows\tasks\Ad-Aware Update (Daily).job - C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe update all silent
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-883375831-3728679416-1811525376-1001Core.job - C:\Users\jointsmouka\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-883375831-3728679416-1811525376-1001UA.job - C:\Users\jointsmouka\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Security Center Update - 3595630534.job - C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70ba1ce1-4478-4bf6-8028-a91b017bd1c2}]
shoppia - C:\ProgramData\shoppia\8KCVB5cQdItgNM.x64.dll [2015-01-09 701952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70ba1ce1-4478-4bf6-8028-a91b017bd1c2}]
shoppia - C:\ProgramData\shoppia\8KCVB5cQdItgNM.dll [2015-01-09 566272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2012-11-29 57928]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-06-11 12503184]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2462536]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-10-04 2800296]
"AutoKMS"=C:\Windows\AutoKMS.exe [2015-01-06 615936]
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Logitech Vid"=C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [2011-01-13 6129496]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2015-02-19 2874048]
"cz.seznam.software.autoupdate"=C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\jointsmouka\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"CloudSystemBooster"=D:\INSTALL\CSB\Cloud System Booster\CloudSystemBooster.exe [2014-05-29 527544]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-01-23 31087200]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Ujgbmedia"=C:\Users\jointsmouka\AppData\Local\Ujgbmedia\tmp2889.exe [2014-12-21 139332]
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
"Ezevlefehov"=C:\Users\jointsmouka\AppData\Roaming\Utadxou\vuyqb.exe []
"Hiwunimyy"=C:\Users\jointsmouka\AppData\Roaming\Uzqece\yhebl.exe []
"Oglinabuqunorie"=C:\Users\jointsmouka\AppData\Roaming\Etnapaw\uxarpie.exe []
"Laekes"=C:\Users\jointsmouka\AppData\Roaming\Ixvait\haleehr.exe []
"Welayfavneas"=C:\Users\jointsmouka\AppData\Roaming\Myagudi\aduseso.exe []
"Zolaazcawe"=C:\Users\jointsmouka\AppData\Roaming\Hoodid\ukneas.exe []
"Ityxxiemhiylom"=C:\Users\jointsmouka\AppData\Roaming\Awithim\ibqeyz.exe []
"Vesisoby"=C:\Users\jointsmouka\AppData\Roaming\Itohqi\vovaoqa.exe []
"Wuuzviakuvha"=C:\Users\jointsmouka\AppData\Roaming\Ampony\nyepcue.exe []
"Zigyrahe"=C:\Users\jointsmouka\AppData\Roaming\Dasaquut\ipodsa.exe []
"Cycyohnazuex"=C:\Users\jointsmouka\AppData\Roaming\Qoafesk\yxdaw.exe []
"Coivr"=C:\Users\jointsmouka\AppData\Roaming\Otyzxoa\ygcyygv.exe []
"Oxxavoacufy"=C:\Users\jointsmouka\AppData\Roaming\Yhiwaked\etryib.exe []
"Yfcuoqdyysewyx"=C:\Users\jointsmouka\AppData\Roaming\Lumiut\zuyza.exe []
"Ashaulgoe"=C:\Users\jointsmouka\AppData\Roaming\Awaskem\evovdie.exe []
"Anpworks"=C:\Windows\SysWOW64\regsvr32.exe [2009-07-14 14848]
"Omkics"=regsvr32.exe C:\Users\jointsmouka\AppData\Local\Omkics\loader_u.dll []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Application Restart #4"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-12-06 856904]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LWS"=C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [2011-11-11 205336]
"MSStp"=C:\Windows\system32\msstp.vbe []
"mnccdgjdSrv"=C:\Windows\inf\mnccdgjd.vbe [2014-01-13 1338]
"msphtovSrv"=C:\Windows\system32\msphtov.vbe mskpko msstnj []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"Ad-Watch"=C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe [2009-01-18 506712]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
[HKEY_CURRENT_USER\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Hiwunimyy"=C:\Users\jointsmouka\AppData\Roaming\Uzqece\yhebl.exe []
"Oglinabuqunorie"=C:\Users\jointsmouka\AppData\Roaming\Etnapaw\uxarpie.exe []
"Laekes"=C:\Users\jointsmouka\AppData\Roaming\Ixvait\haleehr.exe []
"Ezevlefehov"=C:\Users\jointsmouka\AppData\Roaming\Utadxou\vuyqb.exe []
"Yfcuoqdyysewyx"=C:\Users\jointsmouka\AppData\Roaming\Lumiut\zuyza.exe []
"Welayfavneas"=C:\Users\jointsmouka\AppData\Roaming\Myagudi\aduseso.exe []
"Oxxavoacufy"=C:\Users\jointsmouka\AppData\Roaming\Yhiwaked\etryib.exe []
"Zigyrahe"=C:\Users\jointsmouka\AppData\Roaming\Dasaquut\ipodsa.exe []
"Cycyohnazuex"=C:\Users\jointsmouka\AppData\Roaming\Qoafesk\yxdaw.exe []
"Zolaazcawe"=C:\Users\jointsmouka\AppData\Roaming\Hoodid\ukneas.exe []
"Ciidifamo"=C:\Users\jointsmouka\AppData\Roaming\Exizumb\dyesfi.exe [2014-03-08 504512]
"Vesisoby"=C:\Users\jointsmouka\AppData\Roaming\Itohqi\vovaoqa.exe []
"Wuuzviakuvha"=C:\Users\jointsmouka\AppData\Roaming\Ampony\nyepcue.exe []
"Ashaulgoe"=C:\Users\jointsmouka\AppData\Roaming\Awaskem\evovdie.exe []
"Coivr"=C:\Users\jointsmouka\AppData\Roaming\Otyzxoa\ygcyygv.exe []
"Ityxxiemhiylom"=C:\Users\jointsmouka\AppData\Roaming\Awithim\ibqeyz.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Users\jointsmouka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\jointsmouka\AppData\Roaming\Dropbox\bin\Dropbox.exe
winupdt32f.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~3\NETWOR~1\NETWOR~2.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-18 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-18 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcod64.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-02-24 15:38:13 ----D---- C:\Program Files\trend micro
2015-02-24 15:16:17 ----D---- C:\Users\jointsmouka\AppData\Roaming\TeamViewer
2015-02-12 14:10:08 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-02-12 14:10:08 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-02-12 14:10:08 ----A---- C:\Windows\system32\jscript9diag.dll
2015-02-12 14:10:08 ----A---- C:\Windows\system32\jscript9.dll
2015-02-11 14:35:30 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-02-11 14:35:29 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-02-11 14:35:26 ----A---- C:\Windows\system32\lsasrv.dll
2015-02-11 14:35:26 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-11 14:35:26 ----A---- C:\Windows\system32\adtschema.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-02-11 14:35:25 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\sspisrv.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\sspicli.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\secur32.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\msobjs.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\msaudite.dll
2015-02-11 14:35:25 ----A---- C:\Windows\system32\lsass.exe
2015-02-11 14:35:25 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-11 14:35:25 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-02-11 14:35:25 ----A---- C:\Windows\system32\auditpol.exe
2015-02-11 14:35:19 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-02-11 14:35:19 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-02-11 14:35:19 ----A---- C:\Windows\system32\mstscax.dll
2015-02-11 14:34:58 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-11 14:34:57 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-02-11 14:34:57 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-02-11 14:34:53 ----A---- C:\Windows\system32\srcore.dll
2015-02-11 14:34:53 ----A---- C:\Windows\system32\rstrui.exe
2015-02-11 14:34:52 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-02-11 14:34:52 ----A---- C:\Windows\system32\srclient.dll
2015-02-11 14:34:34 ----A---- C:\Windows\system32\generaltel.dll
2015-02-11 14:34:34 ----A---- C:\Windows\system32\appraiser.dll
2015-02-11 14:34:34 ----A---- C:\Windows\system32\aeinv.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\invagent.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\devinv.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\aitstatic.exe
2015-02-11 14:34:33 ----A---- C:\Windows\system32\aepic.dll
2015-02-11 14:34:33 ----A---- C:\Windows\system32\aepdu.dll
2015-02-11 14:34:27 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-02-11 14:34:27 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-02-11 14:34:27 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\wdigest.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\schannel.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\msv1_0.dll
2015-02-11 14:34:27 ----A---- C:\Windows\system32\kerberos.dll
2015-02-11 14:34:26 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-02-11 14:34:26 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-02-11 14:34:26 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-02-11 14:34:26 ----A---- C:\Windows\system32\TSpkg.dll
2015-02-11 14:34:26 ----A---- C:\Windows\system32\ncrypt.dll
2015-02-11 14:34:25 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-02-11 14:34:25 ----A---- C:\Windows\system32\credssp.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-02-11 14:34:13 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-02-11 14:34:13 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-02-11 14:34:13 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-02-11 14:34:12 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\iernonce.dll
2015-02-11 14:34:12 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-11 14:34:10 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-02-11 14:34:10 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-02-11 14:34:10 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-02-11 14:34:10 ----A---- C:\Windows\system32\urlmon.dll
2015-02-11 14:34:10 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 14:34:10 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-02-11 14:34:09 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-02-11 14:34:09 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 14:34:09 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-11 14:34:09 ----A---- C:\Windows\system32\dxtrans.dll
2015-02-11 14:34:08 ----A---- C:\Windows\system32\iesetup.dll
2015-02-11 14:34:08 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-11 14:34:06 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-02-11 14:34:06 ----A---- C:\Windows\system32\iertutil.dll
2015-02-11 14:34:05 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-02-11 14:34:05 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-02-11 14:34:05 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-02-11 14:34:05 ----A---- C:\Windows\system32\jsproxy.dll
2015-02-11 14:34:05 ----A---- C:\Windows\system32\ieUnatt.exe
2015-02-11 14:34:04 ----A---- C:\Windows\system32\ieui.dll
2015-02-11 14:34:04 ----A---- C:\Windows\system32\ieframe.dll
2015-02-11 14:34:04 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-11 14:34:03 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-02-11 14:34:03 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-11 14:34:02 ----A---- C:\Windows\system32\wininet.dll
2015-02-11 14:34:02 ----A---- C:\Windows\system32\vbscript.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\msrating.dll
2015-02-11 14:34:01 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-11 14:34:00 ----A---- C:\Windows\system32\mshtml.dll
2015-02-11 14:30:23 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-02-11 14:30:23 ----A---- C:\Windows\system32\crypt32.dll
2015-02-11 14:29:34 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-02-11 14:29:34 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-11 14:28:59 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-02-11 14:28:59 ----A---- C:\Windows\system32\scesrv.dll
2015-02-11 14:28:04 ----A---- C:\Windows\system32\win32k.sys
2015-02-05 00:39:01 ----D---- C:\ProgramData\BlockIt Ad remover
2015-02-05 00:36:16 ----D---- C:\ProgramData\8022386465577498893UL
======List of files/folders modified in the last 1 month======
2015-02-24 15:39:17 ----D---- C:\Windows\Prefetch
2015-02-24 15:38:46 ----D---- C:\Windows\Temp
2015-02-24 15:38:13 ----RD---- C:\Program Files
2015-02-24 15:34:41 ----D---- C:\Program Files (x86)\Steam
2015-02-24 15:33:55 ----D---- C:\Users\jointsmouka\AppData\Roaming\Skype
2015-02-24 15:16:49 ----D---- C:\Program Files (x86)\TeamViewer
2015-02-24 15:16:47 ----D---- C:\Windows\system32\Tasks
2015-02-24 15:16:18 ----RSD---- C:\Windows\Fonts
2015-02-24 15:15:45 ----D---- C:\Windows\system32\config
2015-02-24 15:01:51 ----D---- C:\Users\jointsmouka\AppData\Roaming\Seznam.cz
2015-02-24 15:00:44 ----D---- C:\Users\jointsmouka\AppData\Roaming\Dropbox
2015-02-24 15:00:27 ----D---- C:\Windows
2015-02-24 14:57:58 ----D---- C:\Windows\System32
2015-02-24 14:56:03 ----D---- C:\ProgramData\NVIDIA
2015-02-24 10:27:43 ----D---- C:\Windows\Minidump
2015-02-24 10:08:49 ----D---- C:\Windows\inf
2015-02-24 10:08:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-24 09:06:20 ----SHD---- C:\Windows\Installer
2015-02-24 09:06:19 ----D---- C:\ProgramData\Skype
2015-02-24 09:05:00 ----RD---- C:\Program Files (x86)\Skype
2015-02-24 09:02:24 ----D---- C:\ProgramData\LogMeIn
2015-02-23 04:03:44 ----SHD---- C:\System Volume Information
2015-02-23 02:48:19 ----D---- C:\Windows\SYSWOW64\en-US
2015-02-23 02:48:19 ----D---- C:\Windows\SysWOW64
2015-02-23 02:41:45 ----D---- C:\Windows\system32\en-US
2015-02-23 02:39:37 ----D---- C:\Windows\Tasks
2015-02-23 02:39:37 ----D---- C:\Windows\system32\wfp
2015-02-23 02:39:37 ----D---- C:\Windows\system32\wbem
2015-02-23 02:39:37 ----D---- C:\Windows\system32\DriverStore
2015-02-23 02:39:36 ----D---- C:\Windows\system32\drivers
2015-02-23 02:39:36 ----D---- C:\Windows\system32\CodeIntegrity
2015-02-23 02:39:35 ----D---- C:\Windows\system32\catroot2
2015-02-23 02:39:33 ----D---- C:\Users\jointsmouka\AppData\Roaming\vlc
2015-02-23 02:39:30 ----D---- C:\ProgramData\McAfee Security Scan
2015-02-23 02:39:26 ----D---- C:\Windows\registration
2015-02-23 02:39:15 ----SD---- C:\Users\jointsmouka\AppData\Roaming\Microsoft
2015-02-23 02:38:58 ----D---- C:\Program Files (x86)\LogMeIn
2015-02-22 18:54:58 ----HD---- C:\ProgramData
2015-02-16 17:59:02 ----D---- C:\Windows\system32\drivers\etc
2015-02-14 02:30:32 ----D---- C:\ProgramData\shoppia
2015-02-13 13:14:52 ----D---- C:\Windows\Microsoft.NET
2015-02-13 12:55:12 ----RSD---- C:\Windows\assembly
2015-02-13 08:09:17 ----D---- C:\Windows\rescache
2015-02-13 01:15:28 ----D---- C:\Windows\winsxs
2015-02-12 14:21:02 ----D---- C:\Windows\system32\MRT
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Yhiwaked
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Qoafesk
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Otyzxoa
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Myagudi
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Lumiut
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Itohqi
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Ikycwe
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Hoodid
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Dasaquut
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Awithim
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Awaskem
2015-02-12 04:21:41 ----D---- C:\Users\jointsmouka\AppData\Roaming\Ampony
2015-02-12 04:18:09 ----SD---- C:\Windows\system32\CompatTel
2015-02-12 04:18:08 ----D---- C:\Windows\system32\appraiser
2015-02-12 04:18:08 ----D---- C:\Program Files\Internet Explorer
2015-02-12 04:18:06 ----D---- C:\Program Files (x86)\Internet Explorer
2015-02-12 04:18:00 ----D---- C:\Windows\PolicyDefinitions
2015-02-12 03:56:00 ----D---- C:\ProgramData\Microsoft Help
2015-02-12 03:45:08 ----A---- C:\Windows\win.ini
2015-02-12 03:10:00 ----A---- C:\Windows\system32\MRT.exe
2015-02-08 22:33:48 ----D---- C:\Users\jointsmouka\AppData\Roaming\BitTorrent
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 {01531192-f7ef-415f-a549-cfdb11836731}w64;{01531192-f7ef-415f-a549-cfdb11836731}w64; C:\Windows\system32\drivers\{01531192-f7ef-415f-a549-cfdb11836731}w64.sys [2014-04-24 61120]
R1 {3f538614-b636-4023-9ec2-564ada4b07b3}Gw64;{3f538614-b636-4023-9ec2-564ada4b07b3}Gw64; C:\Windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}Gw64.sys [2014-06-25 61112]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-11-17 283064]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2012-11-29 72216]
R3 CompFilter64;UVCCompositeFilter; C:\Windows\system32\DRIVERS\lvbflt64.sys [2012-01-18 25632]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2012-11-29 11552]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136]
R3 LVUVC64;Logitech HD Webcam C525(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-01-18 4865568]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 19272]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2013-06-02 16056]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-13 5020672]
S3 cpuz134;cpuz134; \??\C:\Users\JOINTS~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-22 40664]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AnviCsbSvc;Anvi Cloud System Booster Speed Service; D:/INSTALL/CSB/Cloud System Booster/CSBSvc.exe []
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1148744]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2015-01-16 377704]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1795912]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19439944]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-07-02 935368]
R2 ReimageRealTimeProtector;Reimage Real Time Protector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2015-01-14 7410024]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-07-02 411936]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176]
R2 UMVPFSrv;UMVPFSrv; C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 2384af53;Network Acceleration; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-21 107912]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
S2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [2015-01-16 226152]
S2 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2012-11-29 407424]
S2 SecurityCenterServer3595630534;Security Center Server - 3595630534; C:\Windows\SysWOW64\ebmunem.exe [2014-03-08 504512]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-21 107912]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 114688]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 289256]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-18 50942144]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-06-06 543656]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-26 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
-----------------EOF-----------------
