Prosím o pomoc při odstranění malware a balastu.
Napsal: 21 čer 2016 15:25
Zdravím, opět se obracím na místní fórum.
Mou blbostí se mi podařilo natáhnout si do počítače malware ale už se mi jej nedaří tím samým nástrojem dostat zpátky. Pomůžete prosím?
Logfile of random's system information tool 1.10 (written by random/random)
Run by Schmako at 2016-06-21 16:14:57
Microsoft Windows 10 Pro
System drive C: has 31 GB (26%) free of 121 GB
Total RAM: 8135 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:16:23, on 21. 6. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Uncheckit\uncheckitBsn.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files\trend micro\Schmako.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://un-stop.info/wpad.dat?e2fb50ca00 ... 3211417336
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Google Update] "C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Schmako\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Schmako\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = C:\Users\Schmako\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O9 - Extra button: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: cktSvc - EVANGEL TECHNOLOGY (HK) LIMITED - C:\Program Files (x86)\Uncheckit\cktSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Protect Service(GunshipP) (GunshipP) - Unknown owner - C:\ProgramData\Gunship\Gunship.exe
O23 - Service: Update Service(GunshipU) (GunshipU) - Unknown owner - C:\Program Files (x86)\Gunship\Update\GunshipUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protect Service(NobeanP) (NobeanP) - Unknown owner - C:\ProgramData\Nobean\Nobean.exe
O23 - Service: Update Service(NobeanU) (NobeanU) - Unknown owner - C:\Program Files (x86)\Nobean\Update\NobeanUpdate.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: qkseeService - Qksee Pvt Ltd. - C:\Program Files (x86)\qksee\qkseeSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TDataSvr - TData.com - C:\Program Files (x86)\TData\TData.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: UncheckitSvc - EVANGEL TECHNOLOGY (HK) LIMITED - C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: WFini WdMan Service (WdMan) - WFini LIMITED - C:\ProgramData\BwinpB\WFini.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WinZiper service (winzipersvc) - Winziper Pvt Ltd. - C:\Program Files (x86)\WinZipper\winzipersvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10577 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
"dwm.exe"
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\WINDOWS\system32\nvvsvc.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
c:\windows\system32\svchost.exe -k localservice
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
c:\windows\system32\svchost.exe -k networkservice
"C:\Program Files (x86)\qksee\qkseeSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
dashost.exe {9e9437f3-1df7-47ea-a128ed128c065b1c}
c:\windows\system32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe"
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Explorer.EXE
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\Logitech Gaming Software\LCore.exe" /minimized
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
C:\ProgramData\BwinpB\WFini.exe -svr
"fontdrvhost.exe"
"C:\Program Files (x86)\WinZipper\winzipersvc.exe"
"C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe"
"C:\Program Files (x86)\Uncheckit\uncheckitBsn.exe" -start
"C:\Program Files (x86)\Uncheckit\cktSvc.exe" {92E162D7-70FD-48F7-A779-91154F8FD518}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\ProgramData\Gunship\Gunship.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
"C:\ProgramData\Nobean\Nobean.exe"
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files (x86)\Nobean\Application\chrome.exe"
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Schmako\AppData\Local\Nobean\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Nobean --annotation=ver=51.19.2704.63 --handshake-handle=0x1b0
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=gpu-process --channel="7164.0.149495764\1632494027" --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,13,25,54,69 --gpu-vendor-id=0x10de --gpu-device-id=0x1380 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.5382 --mojo-platform-channel-handle=1244 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=1478258C03313F3F3592ECC112700FA1 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.2.823827852\1116457867" --mojo-platform-channel-handle=2612 /prefetch:1
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=C1CB5FC397446B487C99D58953809A94 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.13.573634393\374892423" --mojo-platform-channel-handle=2860 /prefetch:1
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=D9D0E5EA98C3E588DCB0931F5CF47655 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.14.639533800\776466399" --mojo-platform-channel-handle=5044 /prefetch:1
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=ppapi --channel="7164.16.1663496470\1794147609" --ppapi-flash-args --lang=cs --device-scale-factor=1 --mojo-platform-channel-handle=5752 --ignored=" --type=renderer " /prefetch:3
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=10DA04E8CA0D52BDA8BDBD6F26BA8975 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.18.1019547899\1807269467" --mojo-platform-channel-handle=3328 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Users\Schmako\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001Core.job - C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001UA.job - C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001Core.job - C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001UA.job - C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-05-27 229064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-05-27 163536]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2016-05-17 1741096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2014-05-28 36352]
"Launch LCore"=C:\Program Files\Logitech Gaming Software\LCore.exe [2015-03-12 13318424]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-03-13 8843520]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-04-30 3077712]
"Google Update"=C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe [2015-04-25 107848]
"Dropbox Update"=C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13 134512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\Schmako\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
C:\Users\Schmako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Schmako\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-06-21 16:14:57 ----D---- C:\rsit
2016-06-21 16:14:57 ----D---- C:\Program Files\trend micro
2016-06-21 16:02:12 ----D---- C:\ProgramData\Nobean
2016-06-21 16:01:41 ----D---- C:\Program Files (x86)\Nobean
2016-06-21 15:58:17 ----D---- C:\WINDOWS\system32\log
2016-06-21 15:58:17 ----A---- C:\WINDOWS\system32\drivers\iSafeNetFilter.sys
2016-06-21 15:58:17 ----A---- C:\WINDOWS\system32\drivers\iSafeKrnlBoot.sys
2016-06-21 15:58:16 ----D---- C:\Users\Schmako\AppData\Roaming\Elex-tech
2016-06-21 15:58:16 ----D---- C:\Program Files (x86)\Elex-tech
2016-06-21 15:57:14 ----D---- C:\ProgramData\Uncheckit
2016-06-21 15:57:08 ----D---- C:\Program Files (x86)\Uncheckit
2016-06-21 15:56:47 ----D---- C:\ProgramData\uckt
2016-06-21 15:56:46 ----D---- C:\Users\Schmako\AppData\Roaming\Uncheckit
2016-06-21 15:56:26 ----D---- C:\ProgramData\BwinpB
2016-06-21 15:56:18 ----D---- C:\WINDOWS\SYSWOW64\_tWm
2016-06-20 23:37:24 ----SHD---- C:\Config.Msi
2016-06-20 23:27:22 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-06-20 23:27:22 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-06-20 23:27:22 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-06-20 23:27:22 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-06-20 23:27:21 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-06-20 23:27:21 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\system32\mos.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\tdlrecover.exe
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\moshost.dll
2016-06-20 23:27:11 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-06-20 23:27:10 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-06-20 23:27:10 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-06-20 23:27:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-06-20 23:27:09 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-06-20 23:27:09 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-06-20 23:27:07 ----A---- C:\WINDOWS\system32\twinui.dll
2016-06-20 23:27:07 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-06-20 23:27:07 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-06-20 23:27:05 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-06-20 23:27:04 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-06-20 23:27:04 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-06-20 23:27:03 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-06-20 23:27:03 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-06-20 23:27:03 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-06-20 23:27:02 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-06-20 23:27:02 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2016-06-20 23:27:00 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\system32\winhttp.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\system32\gpsvc.dll
2016-06-20 23:26:58 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-06-20 23:26:58 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-06-20 23:26:58 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\SYSWOW64\LocationFramework.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\system32\ole32.dll
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\drivers\dumpsdport.sys
2016-06-20 23:26:55 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\tileobjserver.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\AppContracts.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\invagent.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\dxgi.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\SYSWOW64\tdlrecover.exe
2016-06-20 23:26:53 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\system32\gpprefcl.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\system32\wscsvc.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\explorer.exe
2016-06-20 23:26:50 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\SYSWOW64\setupapi.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\system32\VEEventDispatcher.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-06-20 23:26:49 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\ws2_32.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\usocore.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\SRH.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\setupapi.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\rastls.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\ws2_32.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\gpprefcl.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\BrokerLib.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\drivers\netbt.sys
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\shell32.dll
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\RDXService.dll
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\omadmclient.exe
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2016-06-20 23:26:44 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\wininet.dll
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\vpnike.dll
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\SYSWOW64\ncryptsslp.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\SYSWOW64\mswsock.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\mswsock.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\hal.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-06-20 23:26:42 ----A---- C:\WINDOWS\system32\polstore.dll
2016-06-20 23:26:40 ----A---- C:\WINDOWS\system32\ncryptsslp.dll
2016-06-20 23:26:39 ----A---- C:\WINDOWS\system32\IPSECSVC.DLL
2016-06-20 23:26:38 ----A---- C:\WINDOWS\SYSWOW64\VEEventDispatcher.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\system32\gpapi.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2016-06-20 23:26:37 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\internetmail.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\cryptsvc.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\NetworkUXBroker.exe
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\GnssAdapter.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\drivers\ufx01000.sys
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\devinv.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\polstore.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\newdev.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\gpscript.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\newdev.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\gpscript.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\ngcpopkeysrv.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\dhcpcore.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\cdd.dll
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\drivers\Ndu.sys
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-06-20 23:26:32 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc6.dll
2016-06-20 23:26:32 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc.dll
2016-06-20 23:26:32 ----A---- C:\WINDOWS\system32\dhcpcsvc6.dll
2016-06-20 23:26:32 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\SYSWOW64\FwRemoteSvr.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\MusNotification.exe
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\httpprxp.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\httpprxm.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\FwRemoteSvr.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\adhsvc.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\SYSWOW64\mdmregistration.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\browserbroker.dll
2016-06-20 23:26:29 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\drivers\bthenum.sys
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-06-20 23:11:48 ----D---- C:\ProgramData\Gunship
2016-06-20 23:11:29 ----D---- C:\Program Files (x86)\Gunship
2016-06-20 23:08:07 ----AD---- C:\Program Files (x86)\qksee
2016-06-13 14:12:12 ----D---- C:\Program Files (x86)\WinZipper
2016-06-13 14:12:11 ----D---- C:\Users\Schmako\AppData\Roaming\WinZiper
2016-06-13 14:12:11 ----D---- C:\Users\Schmako\AppData\Roaming\eCyber
2016-06-13 14:12:08 ----D---- C:\Users\Schmako\AppData\Roaming\qksee
2016-06-13 14:12:03 ----D---- C:\ProgramData\vwinpv
2016-06-13 14:12:02 ----D---- C:\Program Files (x86)\TData
2016-06-13 14:12:01 ----D---- C:\Program Files (x86)\TXQQBrowser
2016-06-13 14:11:58 ----D---- C:\Program Files (x86)\mqv8gbnt
2016-06-12 10:05:08 ----D---- C:\Program Files (x86)\Qiqerylugase
2016-06-12 10:05:08 ----D---- C:\Program Files (x86)\Ckupak
2016-06-12 10:05:08 ----D---- C:\Program Files (x86)\Atatuch
======List of files/folders modified in the last 1 month======
2016-06-21 16:16:22 ----D---- C:\WINDOWS\system32\drivers\etc
2016-06-21 16:15:08 ----D---- C:\WINDOWS\Prefetch
2016-06-21 16:14:57 ----RD---- C:\Program Files
2016-06-21 16:14:09 ----D---- C:\WINDOWS\Temp
2016-06-21 16:09:16 ----D---- C:\WINDOWS\system32\Tasks
2016-06-21 16:09:11 ----RD---- C:\Program Files (x86)
2016-06-21 16:02:12 ----HD---- C:\ProgramData
2016-06-21 16:02:12 ----D---- C:\WINDOWS\SysWOW64
2016-06-21 16:00:42 ----D---- C:\WINDOWS\System32
2016-06-21 16:00:42 ----D---- C:\WINDOWS\INF
2016-06-21 16:00:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-21 15:58:17 ----D---- C:\WINDOWS\system32\drivers
2016-06-21 15:58:02 ----D---- C:\WINDOWS\system32\sru
2016-06-21 15:57:08 ----RSD---- C:\WINDOWS\Fonts
2016-06-21 00:07:28 ----D---- C:\WINDOWS\WinSxS
2016-06-21 00:07:28 ----D---- C:\WINDOWS\system32\config
2016-06-21 00:07:24 ----D---- C:\WINDOWS\system32\DriverStore
2016-06-21 00:06:46 ----SD---- C:\WINDOWS\system32\DiagSvcs
2016-06-21 00:06:46 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-06-21 00:06:46 ----D---- C:\WINDOWS\system32\wbem
2016-06-21 00:06:46 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-06-21 00:06:46 ----D---- C:\WINDOWS\system32\cs-CZ
2016-06-21 00:06:45 ----D---- C:\WINDOWS\system32\migration
2016-06-21 00:06:45 ----D---- C:\WINDOWS\bcastdvr
2016-06-21 00:06:45 ----D---- C:\WINDOWS\AppPatch
2016-06-21 00:06:45 ----D---- C:\Windows
2016-06-20 23:39:27 ----SHD---- C:\WINDOWS\Installer
2016-06-20 23:39:13 ----D---- C:\WINDOWS\CbsTemp
2016-06-20 23:38:43 ----D---- C:\ProgramData\Microsoft Help
2016-06-20 23:38:08 ----RSD---- C:\WINDOWS\assembly
2016-06-20 23:37:15 ----N---- C:\WINDOWS\win.ini
2016-06-20 23:34:28 ----D---- C:\WINDOWS\system32\MRT
2016-06-20 23:32:00 ----A---- C:\WINDOWS\system32\MRT.exe
2016-06-20 23:31:38 ----D---- C:\WINDOWS\Microsoft.NET
2016-06-20 23:30:30 ----D---- C:\WINDOWS\AppReadiness
2016-06-20 23:30:29 ----HD---- C:\Program Files\WindowsApps
2016-06-20 23:17:18 ----AD---- C:\Program Files (x86)\Opera
2016-06-20 23:14:00 ----D---- C:\WINDOWS\system32\catroot2
2016-06-15 22:40:57 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-06-14 20:33:01 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-06-13 14:13:57 ----SD---- C:\Users\Schmako\AppData\Roaming\Microsoft
2016-06-13 00:52:45 ----D---- C:\Users\Schmako\AppData\Roaming\vlc
2016-06-12 12:13:35 ----D---- C:\Users\Schmako\AppData\Roaming\Battle.net
2016-06-12 12:13:35 ----D---- C:\ProgramData\Battle.net
2016-06-12 12:13:26 ----D---- C:\Games
2016-06-12 10:14:14 ----D---- C:\WINDOWS\Tasks
2016-06-12 10:05:15 ----SD---- C:\ProgramData\Microsoft
2016-06-12 09:34:26 ----D---- C:\WINDOWS\LiveKernelReports
2016-06-10 02:07:02 ----D---- C:\Users\Schmako\AppData\Roaming\AIMP3
2016-06-04 21:22:12 ----D---- C:\WINDOWS\system32\NDF
2016-06-04 20:09:54 ----D---- C:\Users\Schmako\AppData\Roaming\Dropbox
2016-05-28 07:55:39 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-05-22 21:49:24 ----D---- C:\Program Files (x86)\Steam
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2014-05-28 672104]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2016-05-23 262344]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2016-05-23 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2016-05-23 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\WINDOWS\system32\DRIVERS\iSafeNetFilter.sys [2016-05-19 52392]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2016-03-13 4781824]
R3 Ke2200;@oem13.inf,%BFTN.Service.DispName%;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\WINDOWS\System32\drivers\e22w8x64.sys [2014-03-27 130224]
R3 LGBusEnum;@oem1.inf,%LGBusEnum.SVCDESC%;Logitech GamePanel Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
R3 LGSHidFilt;@oem18.inf,%LGSHidFilt.SvcDesc%;Logitech Gaming KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LGSHidFilt.Sys [2013-05-30 64280]
R3 LGVirHid;@oem6.inf,%LGVirHid.SVCDESC%;Logitech Gamepanel Virtual HID Device Driver; C:\WINDOWS\system32\drivers\LGVirHid.sys [2009-11-24 16008]
R3 MBfilt;MBfilt; C:\WINDOWS\system32\drivers\MBfilt64.sys [2016-03-13 41096]
R3 MEIx64;@oem23.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-09-03 126976]
R3 NETwNb64;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\WINDOWS\System32\drivers\Netwbw02.sys [2015-10-30 3485696]
R3 NVHDA;@oem24.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-08-29 206152]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2015-08-29 11151488]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2016-05-23 110112]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BthA2DP;@wdma_bt.inf,%BthA2DP.SvcDesc%;Bluetooth stereo; C:\WINDOWS\system32\drivers\BthA2DP.sys [2015-10-30 165376]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2016-05-28 112640]
S3 BthHFAud;@wdma_bt.inf,%DISPLAY_NAME%;Bluetooth handsfree; C:\WINDOWS\system32\DRIVERS\BthHfAud.sys [2015-10-30 36864]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-03-29 245760]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-05-28 954368]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2016-05-28 84992]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-13 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 ibtusb;@oem27.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R); C:\WINDOWS\system32\DRIVERS\ibtusb.sys [2015-07-14 263952]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 iSafeKrnlBoot;YAC Boot Driver; C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys [2016-05-23 55056]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2016-03-29 181248]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2016-04-23 63488]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2016-05-28 258912]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-04-23 131424]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 cktSvc;cktSvc; C:\Program Files (x86)\Uncheckit\cktSvc.exe [2016-06-20 274688]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 GunshipP;Protect Service(GunshipP); C:\ProgramData\Gunship\Gunship.exe [2016-06-17 426880]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-05-28 16232]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2016-05-23 118048]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-09-03 154584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-09-03 405976]
R2 NobeanP;Protect Service(NobeanP); C:\ProgramData\Nobean\Nobean.exe [2016-06-21 428416]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2015-08-07 937592]
R2 OneSyncSvc_2c5dc;Hostitel synchronizace_2c5dc; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 qkseeService;qkseeService; C:\Program Files (x86)\qksee\qkseeSvc.exe [2016-06-20 752376]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [2015-05-21 743688]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 UncheckitSvc;UncheckitSvc; C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe [2016-06-20 247552]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 GunshipU;Update Service(GunshipU); C:\Program Files (x86)\Gunship\Update\GunshipUpdate.exe [2016-06-17 587648]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 NobeanU;Update Service(NobeanU); C:\Program Files (x86)\Nobean\Update\NobeanUpdate.exe [2016-06-21 588672]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_2dbcd;Hostitel synchronizace_2dbcd; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_fa639d2;Hostitel synchronizace_fa639d2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2013-12-11 1050904]
S2 TDataSvr;TDataSvr; C:\Program Files (x86)\TData\TData.exe [2016-06-12 135880]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-05-13 887256]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2c5dc;Služba zasílání zpráv_2c5dc; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2dbcd;Služba zasílání zpráv_2dbcd; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_fa639d2;Služba zasílání zpráv_fa639d2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2c5dc;Data kontaktů_2c5dc; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2dbcd;Data kontaktů_2dbcd; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_fa639d2;Data kontaktů_fa639d2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-04-30 835664]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2c5dc;Úložiště uživatelských dat_2c5dc; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2dbcd;Úložiště uživatelských dat_2dbcd; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_fa639d2;Úložiště uživatelských dat_fa639d2; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------
Mou blbostí se mi podařilo natáhnout si do počítače malware ale už se mi jej nedaří tím samým nástrojem dostat zpátky. Pomůžete prosím?
Logfile of random's system information tool 1.10 (written by random/random)
Run by Schmako at 2016-06-21 16:14:57
Microsoft Windows 10 Pro
System drive C: has 31 GB (26%) free of 121 GB
Total RAM: 8135 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:16:23, on 21. 6. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Uncheckit\uncheckitBsn.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files (x86)\Nobean\Application\chrome.exe
C:\Program Files\trend micro\Schmako.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nuesearch.com/?type=hp&ts=14 ... 19093A5BCF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://un-stop.info/wpad.dat?e2fb50ca00 ... 3211417336
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Google Update] "C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Schmako\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Schmako\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = C:\Users\Schmako\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O9 - Extra button: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: cktSvc - EVANGEL TECHNOLOGY (HK) LIMITED - C:\Program Files (x86)\Uncheckit\cktSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Protect Service(GunshipP) (GunshipP) - Unknown owner - C:\ProgramData\Gunship\Gunship.exe
O23 - Service: Update Service(GunshipU) (GunshipU) - Unknown owner - C:\Program Files (x86)\Gunship\Update\GunshipUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protect Service(NobeanP) (NobeanP) - Unknown owner - C:\ProgramData\Nobean\Nobean.exe
O23 - Service: Update Service(NobeanU) (NobeanU) - Unknown owner - C:\Program Files (x86)\Nobean\Update\NobeanUpdate.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: qkseeService - Qksee Pvt Ltd. - C:\Program Files (x86)\qksee\qkseeSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TDataSvr - TData.com - C:\Program Files (x86)\TData\TData.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: UncheckitSvc - EVANGEL TECHNOLOGY (HK) LIMITED - C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: WFini WdMan Service (WdMan) - WFini LIMITED - C:\ProgramData\BwinpB\WFini.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WinZiper service (winzipersvc) - Winziper Pvt Ltd. - C:\Program Files (x86)\WinZipper\winzipersvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10577 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
"dwm.exe"
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\WINDOWS\system32\nvvsvc.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
c:\windows\system32\svchost.exe -k localservice
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
c:\windows\system32\svchost.exe -k networkservice
"C:\Program Files (x86)\qksee\qkseeSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
dashost.exe {9e9437f3-1df7-47ea-a128ed128c065b1c}
c:\windows\system32\svchost.exe -k utcsvc
c:\windows\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe"
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Explorer.EXE
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\Logitech Gaming Software\LCore.exe" /minimized
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
C:\ProgramData\BwinpB\WFini.exe -svr
"fontdrvhost.exe"
"C:\Program Files (x86)\WinZipper\winzipersvc.exe"
"C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe"
"C:\Program Files (x86)\Uncheckit\uncheckitBsn.exe" -start
"C:\Program Files (x86)\Uncheckit\cktSvc.exe" {92E162D7-70FD-48F7-A779-91154F8FD518}
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\ProgramData\Gunship\Gunship.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
"C:\ProgramData\Nobean\Nobean.exe"
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files (x86)\Nobean\Application\chrome.exe"
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Schmako\AppData\Local\Nobean\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Nobean --annotation=ver=51.19.2704.63 --handshake-handle=0x1b0
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=gpu-process --channel="7164.0.149495764\1632494027" --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,13,25,54,69 --gpu-vendor-id=0x10de --gpu-device-id=0x1380 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.5382 --mojo-platform-channel-handle=1244 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=1478258C03313F3F3592ECC112700FA1 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.2.823827852\1116457867" --mojo-platform-channel-handle=2612 /prefetch:1
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=C1CB5FC397446B487C99D58953809A94 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.13.573634393\374892423" --mojo-platform-channel-handle=2860 /prefetch:1
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=D9D0E5EA98C3E588DCB0931F5CF47655 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.14.639533800\776466399" --mojo-platform-channel-handle=5044 /prefetch:1
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=ppapi --channel="7164.16.1663496470\1794147609" --ppapi-flash-args --lang=cs --device-scale-factor=1 --mojo-platform-channel-handle=5752 --ignored=" --type=renderer " /prefetch:3
"C:\Program Files (x86)\Nobean\Application\chrome.exe" --type=renderer --primordial-pipe-token=10DA04E8CA0D52BDA8BDBD6F26BA8975 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7164.18.1019547899\1807269467" --mojo-platform-channel-handle=3328 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Users\Schmako\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001Core.job - C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001UA.job - C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001Core.job - C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4032979599-1777459474-1242859118-1001UA.job - C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-05-27 229064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-05-27 163536]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2016-05-17 1741096]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2014-05-28 36352]
"Launch LCore"=C:\Program Files\Logitech Gaming Software\LCore.exe [2015-03-12 13318424]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-03-13 8843520]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-04-30 3077712]
"Google Update"=C:\Users\Schmako\AppData\Local\Google\Update\GoogleUpdate.exe [2015-04-25 107848]
"Dropbox Update"=C:\Users\Schmako\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-13 134512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\Schmako\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"=C:\WINDOWS\system32\cmd.exe [2015-10-30 233984]
C:\Users\Schmako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Schmako\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-06-21 16:14:57 ----D---- C:\rsit
2016-06-21 16:14:57 ----D---- C:\Program Files\trend micro
2016-06-21 16:02:12 ----D---- C:\ProgramData\Nobean
2016-06-21 16:01:41 ----D---- C:\Program Files (x86)\Nobean
2016-06-21 15:58:17 ----D---- C:\WINDOWS\system32\log
2016-06-21 15:58:17 ----A---- C:\WINDOWS\system32\drivers\iSafeNetFilter.sys
2016-06-21 15:58:17 ----A---- C:\WINDOWS\system32\drivers\iSafeKrnlBoot.sys
2016-06-21 15:58:16 ----D---- C:\Users\Schmako\AppData\Roaming\Elex-tech
2016-06-21 15:58:16 ----D---- C:\Program Files (x86)\Elex-tech
2016-06-21 15:57:14 ----D---- C:\ProgramData\Uncheckit
2016-06-21 15:57:08 ----D---- C:\Program Files (x86)\Uncheckit
2016-06-21 15:56:47 ----D---- C:\ProgramData\uckt
2016-06-21 15:56:46 ----D---- C:\Users\Schmako\AppData\Roaming\Uncheckit
2016-06-21 15:56:26 ----D---- C:\ProgramData\BwinpB
2016-06-21 15:56:18 ----D---- C:\WINDOWS\SYSWOW64\_tWm
2016-06-20 23:37:24 ----SHD---- C:\Config.Msi
2016-06-20 23:27:22 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-06-20 23:27:22 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-06-20 23:27:22 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-06-20 23:27:22 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-06-20 23:27:21 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-06-20 23:27:21 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-06-20 23:27:20 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-06-20 23:27:19 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\system32\mos.dll
2016-06-20 23:27:18 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-06-20 23:27:17 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-06-20 23:27:14 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\tdlrecover.exe
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-06-20 23:27:13 ----A---- C:\WINDOWS\system32\moshost.dll
2016-06-20 23:27:11 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-06-20 23:27:10 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-06-20 23:27:10 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-06-20 23:27:10 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-06-20 23:27:09 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-06-20 23:27:09 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-06-20 23:27:09 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-06-20 23:27:07 ----A---- C:\WINDOWS\system32\twinui.dll
2016-06-20 23:27:07 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-06-20 23:27:07 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-06-20 23:27:05 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-06-20 23:27:04 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-06-20 23:27:04 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-06-20 23:27:03 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-06-20 23:27:03 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-06-20 23:27:03 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-06-20 23:27:02 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-06-20 23:27:02 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-06-20 23:27:01 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2016-06-20 23:27:00 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\system32\winhttp.dll
2016-06-20 23:26:59 ----A---- C:\WINDOWS\system32\gpsvc.dll
2016-06-20 23:26:58 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-06-20 23:26:58 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-06-20 23:26:58 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\SYSWOW64\LocationFramework.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-06-20 23:26:57 ----A---- C:\WINDOWS\system32\ole32.dll
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-06-20 23:26:56 ----A---- C:\WINDOWS\system32\drivers\dumpsdport.sys
2016-06-20 23:26:55 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\tileobjserver.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2016-06-20 23:26:55 ----A---- C:\WINDOWS\system32\AppContracts.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\invagent.dll
2016-06-20 23:26:54 ----A---- C:\WINDOWS\system32\dxgi.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\SYSWOW64\tdlrecover.exe
2016-06-20 23:26:53 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\system32\gpprefcl.dll
2016-06-20 23:26:53 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2016-06-20 23:26:52 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\system32\wscsvc.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-06-20 23:26:51 ----A---- C:\WINDOWS\explorer.exe
2016-06-20 23:26:50 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\SYSWOW64\setupapi.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\system32\VEEventDispatcher.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2016-06-20 23:26:50 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-06-20 23:26:49 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\ws2_32.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-06-20 23:26:49 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\usocore.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\SRH.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\setupapi.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\rastls.dll
2016-06-20 23:26:48 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\ws2_32.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\gpprefcl.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2016-06-20 23:26:47 ----A---- C:\WINDOWS\system32\BrokerLib.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\SYSWOW64\LockAppHost.exe
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\drivers\netbt.sys
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-06-20 23:26:46 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\shell32.dll
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\RDXService.dll
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\omadmclient.exe
2016-06-20 23:26:45 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2016-06-20 23:26:44 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\wininet.dll
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\vpnike.dll
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-06-20 23:26:44 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\SYSWOW64\ncryptsslp.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\SYSWOW64\mswsock.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\mswsock.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\hal.dll
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-06-20 23:26:43 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-06-20 23:26:42 ----A---- C:\WINDOWS\system32\polstore.dll
2016-06-20 23:26:40 ----A---- C:\WINDOWS\system32\ncryptsslp.dll
2016-06-20 23:26:39 ----A---- C:\WINDOWS\system32\IPSECSVC.DLL
2016-06-20 23:26:38 ----A---- C:\WINDOWS\SYSWOW64\VEEventDispatcher.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\system32\gpapi.dll
2016-06-20 23:26:38 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2016-06-20 23:26:37 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\internetmail.dll
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2016-06-20 23:26:37 ----A---- C:\WINDOWS\system32\cryptsvc.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\NetworkUXBroker.exe
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\GnssAdapter.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\drivers\ufx01000.sys
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\devinv.dll
2016-06-20 23:26:36 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\polstore.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\newdev.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\SYSWOW64\gpscript.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\newdev.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\gpscript.dll
2016-06-20 23:26:35 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\ngcpopkeysrv.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\dhcpcore.dll
2016-06-20 23:26:34 ----A---- C:\WINDOWS\system32\cdd.dll
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\drivers\Ndu.sys
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys
2016-06-20 23:26:33 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-06-20 23:26:32 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc6.dll
2016-06-20 23:26:32 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc.dll
2016-06-20 23:26:32 ----A---- C:\WINDOWS\system32\dhcpcsvc6.dll
2016-06-20 23:26:32 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\SYSWOW64\FwRemoteSvr.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\MusNotification.exe
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\httpprxp.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\httpprxm.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\FwRemoteSvr.dll
2016-06-20 23:26:31 ----A---- C:\WINDOWS\system32\adhsvc.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\SYSWOW64\mdmregistration.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-06-20 23:26:30 ----A---- C:\WINDOWS\system32\browserbroker.dll
2016-06-20 23:26:29 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\drivers\bthenum.sys
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-06-20 23:26:29 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-06-20 23:11:48 ----D---- C:\ProgramData\Gunship
2016-06-20 23:11:29 ----D---- C:\Program Files (x86)\Gunship
2016-06-20 23:08:07 ----AD---- C:\Program Files (x86)\qksee
2016-06-13 14:12:12 ----D---- C:\Program Files (x86)\WinZipper
2016-06-13 14:12:11 ----D---- C:\Users\Schmako\AppData\Roaming\WinZiper
2016-06-13 14:12:11 ----D---- C:\Users\Schmako\AppData\Roaming\eCyber
2016-06-13 14:12:08 ----D---- C:\Users\Schmako\AppData\Roaming\qksee
2016-06-13 14:12:03 ----D---- C:\ProgramData\vwinpv
2016-06-13 14:12:02 ----D---- C:\Program Files (x86)\TData
2016-06-13 14:12:01 ----D---- C:\Program Files (x86)\TXQQBrowser
2016-06-13 14:11:58 ----D---- C:\Program Files (x86)\mqv8gbnt
2016-06-12 10:05:08 ----D---- C:\Program Files (x86)\Qiqerylugase
2016-06-12 10:05:08 ----D---- C:\Program Files (x86)\Ckupak
2016-06-12 10:05:08 ----D---- C:\Program Files (x86)\Atatuch
======List of files/folders modified in the last 1 month======
2016-06-21 16:16:22 ----D---- C:\WINDOWS\system32\drivers\etc
2016-06-21 16:15:08 ----D---- C:\WINDOWS\Prefetch
2016-06-21 16:14:57 ----RD---- C:\Program Files
2016-06-21 16:14:09 ----D---- C:\WINDOWS\Temp
2016-06-21 16:09:16 ----D---- C:\WINDOWS\system32\Tasks
2016-06-21 16:09:11 ----RD---- C:\Program Files (x86)
2016-06-21 16:02:12 ----HD---- C:\ProgramData
2016-06-21 16:02:12 ----D---- C:\WINDOWS\SysWOW64
2016-06-21 16:00:42 ----D---- C:\WINDOWS\System32
2016-06-21 16:00:42 ----D---- C:\WINDOWS\INF
2016-06-21 16:00:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-21 15:58:17 ----D---- C:\WINDOWS\system32\drivers
2016-06-21 15:58:02 ----D---- C:\WINDOWS\system32\sru
2016-06-21 15:57:08 ----RSD---- C:\WINDOWS\Fonts
2016-06-21 00:07:28 ----D---- C:\WINDOWS\WinSxS
2016-06-21 00:07:28 ----D---- C:\WINDOWS\system32\config
2016-06-21 00:07:24 ----D---- C:\WINDOWS\system32\DriverStore
2016-06-21 00:06:46 ----SD---- C:\WINDOWS\system32\DiagSvcs
2016-06-21 00:06:46 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-06-21 00:06:46 ----D---- C:\WINDOWS\system32\wbem
2016-06-21 00:06:46 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-06-21 00:06:46 ----D---- C:\WINDOWS\system32\cs-CZ
2016-06-21 00:06:45 ----D---- C:\WINDOWS\system32\migration
2016-06-21 00:06:45 ----D---- C:\WINDOWS\bcastdvr
2016-06-21 00:06:45 ----D---- C:\WINDOWS\AppPatch
2016-06-21 00:06:45 ----D---- C:\Windows
2016-06-20 23:39:27 ----SHD---- C:\WINDOWS\Installer
2016-06-20 23:39:13 ----D---- C:\WINDOWS\CbsTemp
2016-06-20 23:38:43 ----D---- C:\ProgramData\Microsoft Help
2016-06-20 23:38:08 ----RSD---- C:\WINDOWS\assembly
2016-06-20 23:37:15 ----N---- C:\WINDOWS\win.ini
2016-06-20 23:34:28 ----D---- C:\WINDOWS\system32\MRT
2016-06-20 23:32:00 ----A---- C:\WINDOWS\system32\MRT.exe
2016-06-20 23:31:38 ----D---- C:\WINDOWS\Microsoft.NET
2016-06-20 23:30:30 ----D---- C:\WINDOWS\AppReadiness
2016-06-20 23:30:29 ----HD---- C:\Program Files\WindowsApps
2016-06-20 23:17:18 ----AD---- C:\Program Files (x86)\Opera
2016-06-20 23:14:00 ----D---- C:\WINDOWS\system32\catroot2
2016-06-15 22:40:57 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-06-14 20:33:01 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-06-13 14:13:57 ----SD---- C:\Users\Schmako\AppData\Roaming\Microsoft
2016-06-13 00:52:45 ----D---- C:\Users\Schmako\AppData\Roaming\vlc
2016-06-12 12:13:35 ----D---- C:\Users\Schmako\AppData\Roaming\Battle.net
2016-06-12 12:13:35 ----D---- C:\ProgramData\Battle.net
2016-06-12 12:13:26 ----D---- C:\Games
2016-06-12 10:14:14 ----D---- C:\WINDOWS\Tasks
2016-06-12 10:05:15 ----SD---- C:\ProgramData\Microsoft
2016-06-12 09:34:26 ----D---- C:\WINDOWS\LiveKernelReports
2016-06-10 02:07:02 ----D---- C:\Users\Schmako\AppData\Roaming\AIMP3
2016-06-04 21:22:12 ----D---- C:\WINDOWS\system32\NDF
2016-06-04 20:09:54 ----D---- C:\Users\Schmako\AppData\Roaming\Dropbox
2016-05-28 07:55:39 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-05-22 21:49:24 ----D---- C:\Program Files (x86)\Steam
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2014-05-28 672104]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2016-05-23 262344]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2016-05-23 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2016-05-23 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\WINDOWS\system32\DRIVERS\iSafeNetFilter.sys [2016-05-19 52392]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2016-03-13 4781824]
R3 Ke2200;@oem13.inf,%BFTN.Service.DispName%;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\WINDOWS\System32\drivers\e22w8x64.sys [2014-03-27 130224]
R3 LGBusEnum;@oem1.inf,%LGBusEnum.SVCDESC%;Logitech GamePanel Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
R3 LGSHidFilt;@oem18.inf,%LGSHidFilt.SvcDesc%;Logitech Gaming KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LGSHidFilt.Sys [2013-05-30 64280]
R3 LGVirHid;@oem6.inf,%LGVirHid.SVCDESC%;Logitech Gamepanel Virtual HID Device Driver; C:\WINDOWS\system32\drivers\LGVirHid.sys [2009-11-24 16008]
R3 MBfilt;MBfilt; C:\WINDOWS\system32\drivers\MBfilt64.sys [2016-03-13 41096]
R3 MEIx64;@oem23.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [2014-09-03 126976]
R3 NETwNb64;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\WINDOWS\System32\drivers\Netwbw02.sys [2015-10-30 3485696]
R3 NVHDA;@oem24.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2015-08-29 206152]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2015-08-29 11151488]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2016-05-23 110112]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BthA2DP;@wdma_bt.inf,%BthA2DP.SvcDesc%;Bluetooth stereo; C:\WINDOWS\system32\drivers\BthA2DP.sys [2015-10-30 165376]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2016-05-28 112640]
S3 BthHFAud;@wdma_bt.inf,%DISPLAY_NAME%;Bluetooth handsfree; C:\WINDOWS\system32\DRIVERS\BthHfAud.sys [2015-10-30 36864]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-03-29 245760]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-05-28 954368]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2016-05-28 84992]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-13 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 ibtusb;@oem27.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R); C:\WINDOWS\system32\DRIVERS\ibtusb.sys [2015-07-14 263952]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 iSafeKrnlBoot;YAC Boot Driver; C:\WINDOWS\system32\DRIVERS\iSafeKrnlBoot.sys [2016-05-23 55056]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2016-03-29 181248]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2016-04-23 63488]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2016-05-28 258912]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2016-04-23 131424]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 cktSvc;cktSvc; C:\Program Files (x86)\Uncheckit\cktSvc.exe [2016-06-20 274688]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 GunshipP;Protect Service(GunshipP); C:\ProgramData\Gunship\Gunship.exe [2016-06-17 426880]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2014-05-28 16232]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2016-05-23 118048]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-09-03 154584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-09-03 405976]
R2 NobeanP;Protect Service(NobeanP); C:\ProgramData\Nobean\Nobean.exe [2016-06-21 428416]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2015-08-07 937592]
R2 OneSyncSvc_2c5dc;Hostitel synchronizace_2c5dc; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 qkseeService;qkseeService; C:\Program Files (x86)\qksee\qkseeSvc.exe [2016-06-20 752376]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [2015-05-21 743688]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 UncheckitSvc;UncheckitSvc; C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe [2016-06-20 247552]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 GunshipU;Update Service(GunshipU); C:\Program Files (x86)\Gunship\Update\GunshipUpdate.exe [2016-06-17 587648]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 NobeanU;Update Service(NobeanU); C:\Program Files (x86)\Nobean\Update\NobeanUpdate.exe [2016-06-21 588672]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_2dbcd;Hostitel synchronizace_2dbcd; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_fa639d2;Hostitel synchronizace_fa639d2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2013-12-11 1050904]
S2 TDataSvr;TDataSvr; C:\Program Files (x86)\TData\TData.exe [2016-06-12 135880]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-05-13 887256]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2c5dc;Služba zasílání zpráv_2c5dc; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2dbcd;Služba zasílání zpráv_2dbcd; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_fa639d2;Služba zasílání zpráv_fa639d2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2c5dc;Data kontaktů_2c5dc; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2dbcd;Data kontaktů_2dbcd; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_fa639d2;Data kontaktů_fa639d2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-04-30 835664]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2c5dc;Úložiště uživatelských dat_2c5dc; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_2dbcd;Úložiště uživatelských dat_2dbcd; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_fa639d2;Úložiště uživatelských dat_fa639d2; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------