mozny virus (keylogger) - nezvycajne spravanie kalvesnice
Napsal: 05 čer 2015 22:29
Dobry den,
V poslednom case sa mi stava, ze ked chcem pouzit pismena na klavesnica tak ich funkcia je ina ako by mala byt. Uvediem priklad, mam Windwos 8.1, ked chcem napisat S tak sa mi napravo otvori okienko na vyhladavanie. Taketo spravanie nastava nahodne ale casto, riesenim je len restart pocitaca. Dalej mi nejde updatovat Malwarebyte's Antimalware.
Prikladam log z RSIT, dufam, ze mi bude niekto schopny poradit.
Vopred dakujem.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2015-06-05 23:21:25
Microsoft Windows 8.1 Pro
System drive C: has 38 GB (16%) free of 244 GB
Total RAM: 16245 MB (68% free)
HijackThis download failed
======Listing Processes======
wininit.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 9c52ec7f-1ebb-43cb-bdb9-d5ba818d35d1 1
\??\C:\Windows\system32\conhost.exe 0x4
dashost.exe {cbfa983a-ba6c-4129-92c517aace4d8dba}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Explorer.EXE
ClassicStartMenu.exe -startup
igfxEM.exe
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
taskhostex.exe
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"dwm.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
"C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp.exe" --normal
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe"
"C:\Program Files (x86)\Grand Theft Auto V\GTA5.exe"
C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="4208.1.1280755118\1346130566" "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4208 "\\.\pipe\gecko-crash-server-pipe.4208" plugin
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe" --proxy-stub-channel=Flash3000.68284398.5663 --host-broker-channel=Flash3000.68284398.7712 --host-pid=3000 --host-npapi-version=28 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_17_0_0_188.dll"
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe" --channel=4844.0090F57C.1354214380 --proxy-stub-channel=Flash3000.68284398.5663 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_17_0_0_188.dll" --host-npapi-version=28 --type=renderer
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568
"C:\Users\Martin\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\iko9om6z.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.188 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.188 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31 219296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20 683200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-01 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL [2015-04-14 1729752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-01 172968]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20 683200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-05-23 2754704]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-05-23 1571696]
"Classic Start Menu"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2014-04-20 161984]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-12-11 7666392]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-04-10 335232]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{D6E67DA7-8988-46FB-BF12-70635254B0CD}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-06-05 23:21:26 ----D---- C:\Program Files\trend micro
2015-06-05 23:21:25 ----D---- C:\rsit
2015-06-05 22:42:32 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-06-05 22:42:02 ----D---- C:\Windows\LastGood
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvopencl.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvoglv64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvmcumd.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvinitx.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\NvIFR64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\NvFBC64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvdispgenco6435306.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvdispco6435306.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvcuvid.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvcuda.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvcompiler.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvaudcaparm.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\drivers\nvvadarm.sys
2015-06-05 22:41:49 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuwebv.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wups.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wudriver.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wucltux.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuaueng.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuauclt.exe
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuapp.exe
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuapi.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-06-05 22:30:30 ----A---- C:\Windows\system32\UtcResources.dll
2015-06-05 22:30:30 ----A---- C:\Windows\system32\diagtrack.dll
2015-06-05 22:29:25 ----D---- C:\ProgramData\boost_interprocess
2015-06-05 22:29:23 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2015-06-05 22:29:23 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\mssph.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\tquery.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-05-23 13:57:54 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-05-23 13:57:54 ----A---- C:\Windows\system32\puiobj.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssvp.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssrch.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssphtb.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssph.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\localspl.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\compstui.dll
2015-05-23 13:57:53 ----AC---- C:\Windows\system32\drivers\USBXHCI.SYS
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\rgb9rast.dll
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\rastapi.dll
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\authz.dll
2015-05-23 13:57:53 ----A---- C:\Windows\system32\rastapi.dll
2015-05-23 13:57:53 ----A---- C:\Windows\system32\msftedit.dll
2015-05-23 13:57:53 ----A---- C:\Windows\system32\authz.dll
2015-05-23 13:27:56 ----A---- C:\Windows\system32\nvhdap64.dll
2015-05-23 13:27:56 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2015-05-23 13:27:55 ----A---- C:\Windows\system32\nvdispgenco6435286.dll
2015-05-23 13:27:55 ----A---- C:\Windows\system32\nvdispco6435286.dll
2015-05-22 21:40:57 ----D---- C:\Program Files\Crucial
2015-05-22 21:03:22 ----D---- C:\Windows\Migration
2015-05-22 20:49:28 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-22 20:49:28 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-16 20:40:31 ----D---- C:\Program Files\HHD Software
2015-05-16 20:29:34 ----D---- C:\Users\Martin\AppData\Roaming\Notepad++
2015-05-16 20:29:34 ----D---- C:\Program Files (x86)\Notepad++
2015-05-16 20:05:07 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-16 20:05:07 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-16 20:05:07 ----A---- C:\Windows\system32\win32k.sys
2015-05-16 20:05:07 ----A---- C:\Windows\system32\schannel.dll
2015-05-16 20:05:07 ----A---- C:\Windows\system32\services.exe
2015-05-16 20:05:07 ----A---- C:\Windows\system32\FntCache.dll
2015-05-16 20:05:07 ----A---- C:\Windows\system32\DWrite.dll
2015-05-16 20:04:49 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-16 20:04:49 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-16 20:04:49 ----A---- C:\Windows\system32\drivers\cng.sys
2015-05-16 20:04:49 ----A---- C:\Windows\system32\certcli.dll
2015-05-16 20:04:48 ----A---- C:\Windows\system32\mshtml.dll
2015-05-16 20:04:47 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-16 20:04:47 ----A---- C:\Windows\system32\jscript9.dll
2015-05-16 20:04:47 ----A---- C:\Windows\system32\ieframe.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\wininet.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\webcheck.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\vbscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\urlmon.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\jscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\inseng.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\inetcomm.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\ieui.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\iertutil.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\iepeers.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-16 20:04:46 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-09 18:37:33 ----D---- C:\ProgramData\Socialclub
2015-05-09 18:31:06 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-05-09 18:31:06 ----A---- C:\Windows\system32\dwmcore.dll
2015-05-09 13:19:12 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-05-09 13:14:51 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-05-09 13:14:36 ----D---- C:\ProgramData\Malwarebytes
2015-05-09 13:14:36 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-09 13:14:36 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-05-09 13:14:36 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-05-09 13:14:36 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-05-08 07:08:00 ----A---- C:\Recovery.txt
======List of files/folders modified in the last 1 month======
2015-06-05 23:21:26 ----RD---- C:\Program Files
2015-06-05 23:15:13 ----D---- C:\Users\Martin\AppData\Roaming\ClassicShell
2015-06-05 23:13:15 ----D---- C:\Windows\Prefetch
2015-06-05 22:59:07 ----D---- C:\Program Files\KMSpico
2015-06-05 22:55:20 ----D---- C:\Program Files (x86)\MSI Afterburner
2015-06-05 22:45:29 ----D---- C:\MSI
2015-06-05 22:45:17 ----D---- C:\Windows\system32\config
2015-06-05 22:45:12 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2015-06-05 22:45:11 ----D---- C:\Windows\Temp
2015-06-05 22:45:04 ----D---- C:\Windows\SYSWOW64\directx
2015-06-05 22:45:01 ----SHD---- C:\Windows\Installer
2015-06-05 22:45:01 ----HD---- C:\Windows\msdownld.tmp
2015-06-05 22:45:01 ----D---- C:\Windows\Logs
2015-06-05 22:42:57 ----D---- C:\ProgramData\NVIDIA Corporation
2015-06-05 22:42:54 ----D---- C:\temp
2015-06-05 22:42:42 ----D---- C:\Windows\Inf
2015-06-05 22:42:42 ----D---- C:\ProgramData\NVIDIA
2015-06-05 22:42:36 ----D---- C:\Windows\SysWOW64
2015-06-05 22:42:31 ----D---- C:\Windows\system32\DriverStore
2015-06-05 22:42:16 ----RD---- C:\Windows\System32
2015-06-05 22:42:13 ----D---- C:\Windows\system32\drivers
2015-06-05 22:42:02 ----D---- C:\Windows
2015-06-05 22:40:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-05 22:34:15 ----D---- C:\Windows\WinSxS
2015-06-05 22:33:48 ----D---- C:\Windows\system32\en-US
2015-06-05 22:33:48 ----D---- C:\Windows\PolicyDefinitions
2015-06-05 22:32:48 ----HD---- C:\Program Files\WindowsApps
2015-06-05 22:30:49 ----D---- C:\Windows\AppReadiness
2015-06-05 22:30:46 ----D---- C:\Windows\CbsTemp
2015-06-05 22:30:41 ----SHD---- C:\System Volume Information
2015-06-05 22:29:25 ----HD---- C:\ProgramData
2015-05-31 15:51:20 ----D---- C:\Users\Martin\AppData\Roaming\vlc
2015-05-30 14:22:46 ----D---- C:\Windows\Microsoft.NET
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvmcvadgenco64.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvapi64.dll
2015-05-28 06:15:30 ----A---- C:\Windows\system32\nvvsvc.exe
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvcr.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvc64.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvshext.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvmctray.dll
2015-05-28 06:15:28 ----A---- C:\Windows\system32\nvcpl.dll
2015-05-26 11:54:10 ----D---- C:\Program Files (x86)\Grand Theft Auto V
2015-05-25 10:13:44 ----D---- C:\Windows\rescache
2015-05-24 15:56:51 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-23 16:13:14 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-05-23 13:58:28 ----RD---- C:\Windows\ToastData
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspcap64.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspbridge64.dll
2015-05-22 21:34:28 ----RSD---- C:\Windows\assembly
2015-05-22 21:04:18 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-22 21:04:18 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-22 21:03:56 ----D---- C:\Program Files\Internet Explorer
2015-05-22 21:03:56 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-22 21:03:22 ----SD---- C:\Windows\SYSWOW64\GWX
2015-05-22 21:03:22 ----SD---- C:\Windows\system32\GWX
2015-05-22 20:50:31 ----D---- C:\ProgramData\Microsoft Help
2015-05-22 20:49:27 ----D---- C:\Windows\system32\MRT
2015-05-22 20:47:56 ----A---- C:\Windows\system32\MRT.exe
2015-05-22 20:44:25 ----D---- C:\Program Files\Windows Journal
2015-05-16 20:29:34 ----RD---- C:\Program Files (x86)
2015-05-16 19:39:28 ----D---- C:\Windows\system32\catroot2
2015-05-13 08:52:35 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2015-05-12 08:27:22 ----A---- C:\Windows\SYSWOW64\SET79AF.tmp
2015-05-12 08:27:22 ----A---- C:\Windows\system32\SET76B7.tmp
2015-05-12 08:27:22 ----A---- C:\Windows\system32\SET70ED.tmp
2015-05-12 08:27:22 ----A---- C:\Windows\system32\SET4288.tmp
2015-05-09 18:37:32 ----D---- C:\ProgramData\Steam
2015-05-09 13:00:13 ----D---- C:\Program Files\RogueKiller
2015-05-09 12:58:00 ----D---- C:\AdwCleaner
2015-05-07 21:08:43 ----A---- C:\Windows\ntbtlog.txt
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 BfLwf;@oem2.inf,%BfLwf_Desc%;Qualcomm Atheros Bandwidth Control; C:\Windows\system32\DRIVERS\bwcW8x64.sys [2014-10-16 98992]
R1 mbamchameleon;mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [2015-04-14 107736]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2014-12-24 231376]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-03-19 4888368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-03-04 30512]
R3 Ke2200;@oem1.inf,%BFTN.Service.DispName%;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\e22w8x64.sys [2014-03-27 130224]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-04-14 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-06-05 136408]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-04-14 64216]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2014-12-11 32344]
R3 MEIx64;@oem89.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 NVHDA;@oem96.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-05-13 195912]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2015-05-28 10995528]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-05-23 19600]
R3 nvvad_WaveExtensible;@oem98.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2015-04-03 38032]
R3 NVVADARM;@oem99.inf,%NVVADARM.SvcDesc%;NVIDIA Miracast Audio; C:\Windows\system32\drivers\nvvadarm.sys [2015-05-28 39056]
R3 RTCore64;RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2015-05-27 13536]
S3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-03-04 42288]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2007-07-24 229376]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 GamingApp_Service;GamingApp_Service; C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe [2014-03-13 20512]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-05-23 1152656]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-03-19 345864]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-03-20 154584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-03-20 398296]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-04-14 1080120]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-04-14 1871160]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-05-23 1893008]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-05-23 23006864]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-05-28 937288]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2014-10-17 387584]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-28 410768]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2014-06-29 997568]
S2 Synergy;Synergy; C:\Program Files\Synergy\synergyd.exe [2015-04-21 304832]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-17 268464]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-03-19 280840]
S3 HitmanPro37Crusader;HitmanPro 3.7 Crusader; C:\Program Files\HitmanPro\HitmanPro.exe [2014-10-29 11222744]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-01-31 887232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-23 148080]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
-----------------EOF-----------------
V poslednom case sa mi stava, ze ked chcem pouzit pismena na klavesnica tak ich funkcia je ina ako by mala byt. Uvediem priklad, mam Windwos 8.1, ked chcem napisat S tak sa mi napravo otvori okienko na vyhladavanie. Taketo spravanie nastava nahodne ale casto, riesenim je len restart pocitaca. Dalej mi nejde updatovat Malwarebyte's Antimalware.
Prikladam log z RSIT, dufam, ze mi bude niekto schopny poradit.
Vopred dakujem.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2015-06-05 23:21:25
Microsoft Windows 8.1 Pro
System drive C: has 38 GB (16%) free of 244 GB
Total RAM: 16245 MB (68% free)
HijackThis download failed
======Listing Processes======
wininit.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" 9c52ec7f-1ebb-43cb-bdb9-d5ba818d35d1 1
\??\C:\Windows\system32\conhost.exe 0x4
dashost.exe {cbfa983a-ba6c-4129-92c517aace4d8dba}
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Explorer.EXE
ClassicStartMenu.exe -startup
igfxEM.exe
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
taskhostex.exe
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"dwm.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
"C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp.exe" --normal
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe"
"C:\Program Files (x86)\Grand Theft Auto V\GTA5.exe"
C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="4208.1.1280755118\1346130566" "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4208 "\\.\pipe\gecko-crash-server-pipe.4208" plugin
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe" --proxy-stub-channel=Flash3000.68284398.5663 --host-broker-channel=Flash3000.68284398.7712 --host-pid=3000 --host-npapi-version=28 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_17_0_0_188.dll"
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe" --channel=4844.0090F57C.1354214380 --proxy-stub-channel=Flash3000.68284398.5663 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_17_0_0_188.dll" --host-npapi-version=28 --type=renderer
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 560 564 572 65536 568
"C:\Users\Martin\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\iko9om6z.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.188 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.188 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31 219296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20 683200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-01 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL [2015-04-14 1729752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-01 172968]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20 683200]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2015-05-23 2754704]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2015-05-23 1571696]
"Classic Start Menu"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2014-04-20 161984]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-12-11 7666392]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-04-10 335232]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{D6E67DA7-8988-46FB-BF12-70635254B0CD}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.RTV1"=rtvcvfw64.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-06-05 23:21:26 ----D---- C:\Program Files\trend micro
2015-06-05 23:21:25 ----D---- C:\rsit
2015-06-05 22:42:32 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2015-06-05 22:42:02 ----D---- C:\Windows\LastGood
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2015-06-05 22:41:49 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvumdshimx.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvopencl.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvoglv64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvoglshim64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvmcumd.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvinitx.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\NvIFR64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\NvFBC64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvdispgenco6435306.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvdispco6435306.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvd3dumx.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvcuvid.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvcuda.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvcompiler.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\nvaudcaparm.dll
2015-06-05 22:41:49 ----A---- C:\Windows\system32\drivers\nvvadarm.sys
2015-06-05 22:41:49 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-06-05 22:30:31 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuwebv.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\WUSettingsProvider.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wups.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wudriver.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wucltux.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuaueng.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuauclt.exe
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuapp.exe
2015-06-05 22:30:31 ----A---- C:\Windows\system32\wuapi.dll
2015-06-05 22:30:31 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-06-05 22:30:30 ----A---- C:\Windows\system32\UtcResources.dll
2015-06-05 22:30:30 ----A---- C:\Windows\system32\diagtrack.dll
2015-06-05 22:29:25 ----D---- C:\ProgramData\boost_interprocess
2015-06-05 22:29:23 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2015-06-05 22:29:23 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-05-23 13:57:54 ----A---- C:\Windows\SYSWOW64\mssph.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\tquery.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-05-23 13:57:54 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-05-23 13:57:54 ----A---- C:\Windows\system32\puiobj.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssvp.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssrch.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssphtb.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\mssph.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\localspl.dll
2015-05-23 13:57:54 ----A---- C:\Windows\system32\compstui.dll
2015-05-23 13:57:53 ----AC---- C:\Windows\system32\drivers\USBXHCI.SYS
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\rgb9rast.dll
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\rastapi.dll
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-05-23 13:57:53 ----A---- C:\Windows\SYSWOW64\authz.dll
2015-05-23 13:57:53 ----A---- C:\Windows\system32\rastapi.dll
2015-05-23 13:57:53 ----A---- C:\Windows\system32\msftedit.dll
2015-05-23 13:57:53 ----A---- C:\Windows\system32\authz.dll
2015-05-23 13:27:56 ----A---- C:\Windows\system32\nvhdap64.dll
2015-05-23 13:27:56 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2015-05-23 13:27:55 ----A---- C:\Windows\system32\nvdispgenco6435286.dll
2015-05-23 13:27:55 ----A---- C:\Windows\system32\nvdispco6435286.dll
2015-05-22 21:40:57 ----D---- C:\Program Files\Crucial
2015-05-22 21:03:22 ----D---- C:\Windows\Migration
2015-05-22 20:49:28 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-22 20:49:28 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-16 20:40:31 ----D---- C:\Program Files\HHD Software
2015-05-16 20:29:34 ----D---- C:\Users\Martin\AppData\Roaming\Notepad++
2015-05-16 20:29:34 ----D---- C:\Program Files (x86)\Notepad++
2015-05-16 20:05:07 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-05-16 20:05:07 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2015-05-16 20:05:07 ----A---- C:\Windows\system32\win32k.sys
2015-05-16 20:05:07 ----A---- C:\Windows\system32\schannel.dll
2015-05-16 20:05:07 ----A---- C:\Windows\system32\services.exe
2015-05-16 20:05:07 ----A---- C:\Windows\system32\FntCache.dll
2015-05-16 20:05:07 ----A---- C:\Windows\system32\DWrite.dll
2015-05-16 20:04:49 ----A---- C:\Windows\SYSWOW64\certcli.dll
2015-05-16 20:04:49 ----A---- C:\Windows\system32\lsasrv.dll
2015-05-16 20:04:49 ----A---- C:\Windows\system32\drivers\cng.sys
2015-05-16 20:04:49 ----A---- C:\Windows\system32\certcli.dll
2015-05-16 20:04:48 ----A---- C:\Windows\system32\mshtml.dll
2015-05-16 20:04:47 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-05-16 20:04:47 ----A---- C:\Windows\system32\jscript9.dll
2015-05-16 20:04:47 ----A---- C:\Windows\system32\ieframe.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-05-16 20:04:46 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\wininet.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\webcheck.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\vbscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\urlmon.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\mshtmled.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\msfeeds.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\jscript.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\inseng.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\inetcomm.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\ieui.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\iertutil.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\iepeers.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\iedkcs32.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\ieapfltr.dll
2015-05-16 20:04:46 ----A---- C:\Windows\system32\ie4uinit.exe
2015-05-16 20:04:46 ----A---- C:\Windows\system32\dxtrans.dll
2015-05-09 18:37:33 ----D---- C:\ProgramData\Socialclub
2015-05-09 18:31:06 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-05-09 18:31:06 ----A---- C:\Windows\system32\dwmcore.dll
2015-05-09 13:19:12 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-05-09 13:14:51 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-05-09 13:14:36 ----D---- C:\ProgramData\Malwarebytes
2015-05-09 13:14:36 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-09 13:14:36 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-05-09 13:14:36 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-05-09 13:14:36 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-05-08 07:08:00 ----A---- C:\Recovery.txt
======List of files/folders modified in the last 1 month======
2015-06-05 23:21:26 ----RD---- C:\Program Files
2015-06-05 23:15:13 ----D---- C:\Users\Martin\AppData\Roaming\ClassicShell
2015-06-05 23:13:15 ----D---- C:\Windows\Prefetch
2015-06-05 22:59:07 ----D---- C:\Program Files\KMSpico
2015-06-05 22:55:20 ----D---- C:\Program Files (x86)\MSI Afterburner
2015-06-05 22:45:29 ----D---- C:\MSI
2015-06-05 22:45:17 ----D---- C:\Windows\system32\config
2015-06-05 22:45:12 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2015-06-05 22:45:11 ----D---- C:\Windows\Temp
2015-06-05 22:45:04 ----D---- C:\Windows\SYSWOW64\directx
2015-06-05 22:45:01 ----SHD---- C:\Windows\Installer
2015-06-05 22:45:01 ----HD---- C:\Windows\msdownld.tmp
2015-06-05 22:45:01 ----D---- C:\Windows\Logs
2015-06-05 22:42:57 ----D---- C:\ProgramData\NVIDIA Corporation
2015-06-05 22:42:54 ----D---- C:\temp
2015-06-05 22:42:42 ----D---- C:\Windows\Inf
2015-06-05 22:42:42 ----D---- C:\ProgramData\NVIDIA
2015-06-05 22:42:36 ----D---- C:\Windows\SysWOW64
2015-06-05 22:42:31 ----D---- C:\Windows\system32\DriverStore
2015-06-05 22:42:16 ----RD---- C:\Windows\System32
2015-06-05 22:42:13 ----D---- C:\Windows\system32\drivers
2015-06-05 22:42:02 ----D---- C:\Windows
2015-06-05 22:40:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-05 22:34:15 ----D---- C:\Windows\WinSxS
2015-06-05 22:33:48 ----D---- C:\Windows\system32\en-US
2015-06-05 22:33:48 ----D---- C:\Windows\PolicyDefinitions
2015-06-05 22:32:48 ----HD---- C:\Program Files\WindowsApps
2015-06-05 22:30:49 ----D---- C:\Windows\AppReadiness
2015-06-05 22:30:46 ----D---- C:\Windows\CbsTemp
2015-06-05 22:30:41 ----SHD---- C:\System Volume Information
2015-06-05 22:29:25 ----HD---- C:\ProgramData
2015-05-31 15:51:20 ----D---- C:\Users\Martin\AppData\Roaming\vlc
2015-05-30 14:22:46 ----D---- C:\Windows\Microsoft.NET
2015-05-28 09:04:11 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvwgf2umx.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvmcvadgenco64.dll
2015-05-28 09:04:11 ----A---- C:\Windows\system32\nvapi64.dll
2015-05-28 06:15:30 ----A---- C:\Windows\system32\nvvsvc.exe
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvcr.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvsvc64.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvshext.dll
2015-05-28 06:15:29 ----A---- C:\Windows\system32\nvmctray.dll
2015-05-28 06:15:28 ----A---- C:\Windows\system32\nvcpl.dll
2015-05-26 11:54:10 ----D---- C:\Program Files (x86)\Grand Theft Auto V
2015-05-25 10:13:44 ----D---- C:\Windows\rescache
2015-05-24 15:56:51 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-23 16:13:14 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-05-23 13:58:28 ----RD---- C:\Windows\ToastData
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2015-05-23 03:47:15 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspcap64.dll
2015-05-23 03:47:06 ----A---- C:\Windows\system32\nvspbridge64.dll
2015-05-22 21:34:28 ----RSD---- C:\Windows\assembly
2015-05-22 21:04:18 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-22 21:04:18 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-22 21:03:56 ----D---- C:\Program Files\Internet Explorer
2015-05-22 21:03:56 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-22 21:03:22 ----SD---- C:\Windows\SYSWOW64\GWX
2015-05-22 21:03:22 ----SD---- C:\Windows\system32\GWX
2015-05-22 20:50:31 ----D---- C:\ProgramData\Microsoft Help
2015-05-22 20:49:27 ----D---- C:\Windows\system32\MRT
2015-05-22 20:47:56 ----A---- C:\Windows\system32\MRT.exe
2015-05-22 20:44:25 ----D---- C:\Program Files\Windows Journal
2015-05-16 20:29:34 ----RD---- C:\Program Files (x86)
2015-05-16 19:39:28 ----D---- C:\Windows\system32\catroot2
2015-05-13 08:52:35 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2015-05-12 08:27:22 ----A---- C:\Windows\SYSWOW64\SET79AF.tmp
2015-05-12 08:27:22 ----A---- C:\Windows\system32\SET76B7.tmp
2015-05-12 08:27:22 ----A---- C:\Windows\system32\SET70ED.tmp
2015-05-12 08:27:22 ----A---- C:\Windows\system32\SET4288.tmp
2015-05-09 18:37:32 ----D---- C:\ProgramData\Steam
2015-05-09 13:00:13 ----D---- C:\Program Files\RogueKiller
2015-05-09 12:58:00 ----D---- C:\AdwCleaner
2015-05-07 21:08:43 ----A---- C:\Windows\ntbtlog.txt
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 BfLwf;@oem2.inf,%BfLwf_Desc%;Qualcomm Atheros Bandwidth Control; C:\Windows\system32\DRIVERS\bwcW8x64.sys [2014-10-16 98992]
R1 mbamchameleon;mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [2015-04-14 107736]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2014-12-24 231376]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-03-19 4888368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-03-04 30512]
R3 Ke2200;@oem1.inf,%BFTN.Service.DispName%;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\e22w8x64.sys [2014-03-27 130224]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-04-14 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-06-05 136408]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-04-14 64216]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2014-12-11 32344]
R3 MEIx64;@oem89.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 NVHDA;@oem96.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-05-13 195912]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2015-05-28 10995528]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-05-23 19600]
R3 nvvad_WaveExtensible;@oem98.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2015-04-03 38032]
R3 NVVADARM;@oem99.inf,%NVVADARM.SvcDesc%;NVIDIA Miracast Audio; C:\Windows\system32\drivers\nvvadarm.sys [2015-05-28 39056]
R3 RTCore64;RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2015-05-27 13536]
S3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-03-04 42288]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2007-07-24 229376]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 GamingApp_Service;GamingApp_Service; C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe [2014-03-13 20512]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-05-23 1152656]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2015-03-19 345864]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-03-20 154584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-03-20 398296]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-04-14 1080120]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-04-14 1871160]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-05-23 1893008]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-05-23 23006864]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-05-28 937288]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2014-10-17 387584]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-28 410768]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2014-06-29 997568]
S2 Synergy;Synergy; C:\Program Files\Synergy\synergyd.exe [2015-04-21 304832]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-17 268464]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2015-03-19 280840]
S3 HitmanPro37Crusader;HitmanPro 3.7 Crusader; C:\Program Files\HitmanPro\HitmanPro.exe [2014-10-29 11222744]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-01-31 887232]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-23 148080]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
-----------------EOF-----------------