Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Zoek.exe v5.0.0.1 Updated 31-December-2015
- Tool run by Petr on so 05.03.2016 at 22:47:16,07.
- Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
- Running in: Normal Mode Internet Access Detected
- Launched: C:\Users\Petr\Downloads\zoek.exe [Scan all users] [Script inserted]
- ==== Older Logs ======================
- C:\zoek-results2016-03-05-204349.log 67297 bytes
- ==== Chromium Look ======================
- Google Slides - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
- Google Docs - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
- Google Drive - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
- YouTube - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
- Google Search - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
- Google Sheets - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
- Google Docs Offline - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
- Until AM for Chrome - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjafmkicbmhcbapadecadciafbkecofl
- Chrome Web Store Payments - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
- Seznam Lištička - Rychlá volba - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
- Gmail - Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
- ==== Chromium Fix ======================
- C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak deleted successfully
- ==== Silent Runners ======================
- "Silent Runners.vbs", revision 69.2, http://www.silentrunners.org/
- Output limited to non-default values, except where indicated by "{++}"
- Startup items buried in registry:
- ---------------------------------
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
- NvBackend = "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [NVIDIA Corporation]
- ShadowPlay = "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart [MS]
- MSC = "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [MS]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
- {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
- -> {HKLM...CLSID} = Java(tm) Plug-In SSV Helper
- \InProcServer32\(Default) = [file not found]
- -> {HKLM...Wow...CLSID} = Java(tm) Plug-In SSV Helper
- \InProcServer32\(Default) = C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [Oracle Corporation]
- {DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
- -> {HKLM...CLSID} = Java(tm) Plug-In 2 SSV Helper
- \InProcServer32\(Default) = [file not found]
- -> {HKLM...Wow...CLSID} = Java(tm) Plug-In 2 SSV Helper
- \InProcServer32\(Default) = C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [Oracle Corporation]
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
- {B41DB860-64E4-11D2-9906-E49FADC173CA} = WinRAR shell extension
- -> {HKLM...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]
- {c5aec3ec-e812-4677-a9a7-4fee1f9aa000} = Icaros Thumbnail Provider
- -> {HKLM...CLSID} = Icaros Thumbnail Provider
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\64-bit\IcarosThumbnailProvider.dll [Tabibito Technology]
- {0C08E3BB-D10B-4CC9-B1B3-701F5BE9D6EC} = Icaros Property Handler
- -> {HKLM...CLSID} = Icaros Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\64-bit\IcarosPropertyHandler.dll [Tabibito Technology]
- {A70C977A-BF00-412C-90B7-034C51DA2439} = NvCpl DesktopContext Class
- -> {HKLM...CLSID} = DesktopContext Class
- \InProcServer32\(Default) = C:\Program Files\NVIDIA Corporation\Display\nvui.dll [NVIDIA Corporation]
- {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} = NVIDIA Play On My TV Context Menu Extension
- -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension
- \InProcServer32\(Default) = C:\Windows\system32\nvshext.dll [NVIDIA Corporation]
- {09A47860-11B0-4DA5-AFA5-26D86198A780} = EPP
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = c:\PROGRA~1\MICROS~3\shellext.dll [MS]
- {AE424E85-F6DF-4910-A6A9-438797986431} = OpenOffice Property Handler
- -> {HKLM...CLSID} = OpenOffice Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll [Apache Software Foundation]
- {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} = iTunes
- -> {HKLM...CLSID} = iTunes
- \InProcServer32\(Default) = C:\Program Files\iTunes\iTunesMiniPlayer.dll [Apple Inc.]
- {2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9} = Image Catalog
- -> {HKLM...CLSID} = Image Catalog
- \InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [DT Soft Ltd]
- {A929C4CE-FD36-4270-B4F5-34ECAC5BD63C} = NvAppShExt extension
- -> {HKLM...CLSID} = NvAppShExt Class
- \InProcServer32\(Default) = C:\Windows\system32\nv3dappshext.dll [NVIDIA Corporation]
- {E97DEC16-A50D-49bb-AE24-CF682282E08D} = OpenGLShExt extension
- -> {HKLM...CLSID} = OpenGLShExt Class
- \InProcServer32\(Default) = C:\Windows\system32\nv3dappshext.dll [NVIDIA Corporation]
- HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
- {c5aec3ec-e812-4677-a9a7-4fee1f9aa000} = Icaros Thumbnail Provider
- -> {HKLM...Wow...CLSID} = Icaros Thumbnail Provider
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\32-bit\IcarosThumbnailProvider.dll [Tabibito Technology]
- {0C08E3BB-D10B-4CC9-B1B3-701F5BE9D6EC} = Icaros Property Handler
- -> {HKLM...Wow...CLSID} = Icaros Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\32-bit\IcarosPropertyHandler.dll [Tabibito Technology]
- {AE424E85-F6DF-4910-A6A9-438797986431} = OpenOffice Property Handler
- -> {HKLM...Wow...CLSID} = OpenOffice Property Handler
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl.dll [Apache Software Foundation]
- {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} = OpenOffice Column Handler
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {087B3AE3-E237-4467-B8DB-5A38AB959AC9} = OpenOffice Infotip Handler
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {63542C48-9552-494A-84F7-73AA6A7C99C1} = OpenOffice Property Sheet Handler
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {3B092F0C-7696-40E3-A80F-68D74DA84210} = OpenOffice Thumbnail Viewer
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- {2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9} = Image Catalog
- -> {HKLM...Wow...CLSID} = Image Catalog
- \InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl32.dll [DT Soft Ltd]
- HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
- DaemonShellExtImage\(Default) = {40966797-8FFE-46C8-9EF8-7003F33CCF0F}
- -> {HKLM...CLSID} = DaemonShellExtImage Class
- \InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [DT Soft Ltd]
- -> {HKLM...Wow...CLSID} = DaemonShellExtImage Class
- \InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl32.dll [DT Soft Ltd]
- EPP\(Default) = {09A47860-11B0-4DA5-AFA5-26D86198A780}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = c:\PROGRA~1\MICROS~3\shellext.dll [MS]
- WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}
- -> {HKLM...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]
- WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- -> {HKLM...Wow...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]
- HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
- EPP\(Default) = {09A47860-11B0-4DA5-AFA5-26D86198A780}
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = c:\PROGRA~1\MICROS~3\shellext.dll [MS]
- HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\
- NvCplDesktopContext\(Default) = {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9}
- -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension
- \InProcServer32\(Default) = C:\Windows\system32\nvshext.dll [NVIDIA Corporation]
- HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
- {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = OpenOffice Column Handler
- -> {HKLM...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll [Apache Software Foundation]
- -> {HKLM...Wow...CLSID} = (no title provided)
- \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation]
- HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
- WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}
- -> {HKLM...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]
- WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- -> {HKLM...Wow...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]
- HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
- WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}
- -> {HKLM...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal]
- WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}
- -> {HKLM...Wow...CLSID} = WinRAR
- \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal]
- Group Policies {GPedit.msc branch and setting}:
- -----------------------------------------------
- Note: detected settings may not have any effect.
- HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\
- DisableOSUpgrade = (REG_DWORD) dword:0x00000001
- {unrecognized setting}
- Active Desktop and Wallpaper:
- -----------------------------
- Active Desktop may be disabled at this entry:
- HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
- Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
- HKCU\Control Panel\Desktop\
- Wallpaper = C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
- Windows Portable Device AutoPlay Handlers
- -----------------------------------------
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
- CDBurnerXP\
- Provider = CDBurnerXP
- InvokeProgID = CDBurnerXPOpen
- InvokeVerb = open
- HKLM\SOFTWARE\Classes\CDBurnerXPOpen\shell\open\command\(Default) = "C:\Program Files\CDBurnerXP\cdbxpp.exe" /od "%1" [null data]
- iTunesBurnCDOnArrival\
- Provider = iTunes
- InvokeProgID = iTunes.BurnCD
- InvokeVerb = burn
- HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /AutoPlayBurn "%L" [Apple Inc.]
- iTunesImportSongsOnArrival\
- Provider = iTunes
- InvokeProgID = iTunes.ImportSongsOnCD
- InvokeVerb = import
- HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /AutoPlayImportSongs "%L" [Apple Inc.]
- iTunesPlaySongsOnArrival\
- Provider = iTunes
- InvokeProgID = iTunes.PlaySongsOnCD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /playCD "%L" [Apple Inc.]
- iTunesShowSongsOnArrival\
- Provider = iTunes
- InvokeProgID = iTunes.ShowSongsOnCD
- InvokeVerb = showsongs
- HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /AutoPlayShowSongs "%L" [Apple Inc.]
- MPCPlayBluRayOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayBlurayMovie
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayBlurayMovie\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %L\BDMV\INDEX.BDMV [MPC-HC Team]
- MPCPlayCDAudioOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayCDAudio
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayCDAudio\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 /cd [MPC-HC Team]
- MPCPlayDVDMovieOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayDVDMovie
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayDVDMovie\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 /dvd [MPC-HC Team]
- MPCPlayMusicFilesOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayMusicFiles
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayMusicFiles\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 [MPC-HC Team]
- MPCPlayVideoFilesOnArrival\
- Provider = Media Player Classic
- InvokeProgID = MediaPlayerClassic.Autorun
- InvokeVerb = PlayVideoFiles
- HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayVideoFiles\command\(Default) = "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" %1 [MPC-HC Team]
- MSPlayCDAudioOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.AudioCD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L" [MS]
- MSPlayDVDMovieOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.DVD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L" [MS]
- MSPlaySuperVideoCDMovieOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.VCD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]
- MSPlayVideoCDMovieOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.VCD
- InvokeVerb = play
- HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]
- MSWMPBurnCDOnArrival\
- Provider = @wmploc.dll,-6502
- InvokeProgID = WMP.BurnCD
- InvokeVerb = Burn
- HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" [MS]
- Picasa2ImportPicturesOnArrival\
- Provider = Picasa
- InvokeProgID = picasa2.autoplay
- InvokeVerb = import
- HKLM\SOFTWARE\Classes\picasa2.autoplay\shell\import\command\(Default) = "C:\Program Files (x86)\Google\Picasa3\Picasa3.exe" "%1" [Google Inc.]
- Startup items in "Petr" & "All Users" startup folders:
- ------------------------------------------------------
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup {++}
- TP-LINK Wireless Configuration Utility -> shortcut to: C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe -nogui [null data]
- Non-disabled Scheduled Tasks: {++}
- -----------------------------
- C:\Windows\System32\Tasks
- Adobe Acrobat Update Task -> launches: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [Adobe Systems Incorporated]
- GoogleUpdateTaskMachineCore -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c [Google Inc.]
- GoogleUpdateTaskMachineUA -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler [Google Inc.]
- klcp_update -> launches: "C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe" /verysilent /update /freq=90 [null data]
- C:\Windows\System32\Tasks\Apple
- AppleSoftwareUpdate -> launches: C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -task [Apple Inc.]
- C:\Windows\System32\Tasks\Microsoft\Microsoft Antimalware
- Microsoft Antimalware Scheduled Scan -> launches: C:\Program Files\Microsoft Security Client\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client
- AD RMS Rights Policy Template Management (Manual) -> launches: {BF5CB148-7C77-4d8a-A53E-D81C70CF743C}
- -> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler
- \InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS]
- -> {HKLM...Wow...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler
- \InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience
- AitAgent -> launches: aitagent [MS]
- Microsoft Compatibility Appraiser -> launches: %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly [MS]
- ProgramDataUpdater -> launches: %windir%\system32\compattelrunner.exe -maintenance [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Autochk
- Proxy -> launches: %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth
- UninstallDeviceTask -> launches: BthUdTask.exe $(Arg0) [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient
- SystemTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060}
- -> {HKLM...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]
- -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]
- UserTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060}
- -> {HKLM...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]
- -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler
- \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
- Consolidator -> launches: %SystemRoot%\System32\wsqmcons.exe [MS]
- KernelCeipTask -> (HIDDEN!) launches: {e7ed314f-2816-4c26-aeb5-54a34d02404c}
- -> {HKLM...CLSID} = KernelCeipCustomHandler
- \InProcServer32\(Default) = C:\Windows\System32\kernelceip.dll [MS]
- UsbCeip -> (HIDDEN!) launches: {c27f6b1d-fe0b-45e4-9257-38799fa69bc8}
- -> {HKLM...CLSID} = UsbCeip
- \InProcServer32\(Default) = C:\Windows\System32\usbceip.dll [MS]
- -> {HKLM...Wow...CLSID} = UsbCeip
- \InProcServer32\(Default) = C:\Windows\System32\usbceip.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Defrag
- ScheduledDefrag -> launches: %windir%\system32\defrag.exe -c [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis
- Scheduled -> (HIDDEN!) launches: {c1f85ef8-bcc2-4606-bb39-70c523715eb3}
- -> {HKLM...CLSID} = ScheduledDiagnosticCustomHandler
- \InProcServer32\(Default) = C:\Windows\System32\sdiagschd.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Location
- Notifications -> launches: %windir%\System32\LocationNotifications.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance
- WinSAT -> launches: {A9A33436-678B-4C9C-A211-7CC38785E79D}
- -> {HKLM...CLSID} = WinSAT Task Manger Task
- \InProcServer32\(Default) = C:\Windows\system32\WinSATAPI.dll [MS]
- -> {HKLM...Wow...CLSID} = WinSAT Task Manger Task
- \InProcServer32\(Default) = C:\Windows\system32\WinSATAPI.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Media Center
- ActivateWindowsSearch -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch [MS]
- ConfigureInternetTimeService -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService [MS]
- DispatchRecoveryTasks -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) [MS]
- ehDRMInit -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DRMInit [MS]
- InstallPlayReady -> launches: %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) [MS]
- mcupdate -> launches: %SystemRoot%\ehome\mcupdate $(Arg0) [MS]
- MediaCenterRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask [MS]
- ObjectStoreRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask [MS]
- OCURActivate -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate [MS]
- OCURDiscovery -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) [MS]
- PBDADiscovery -> launches: %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery [MS]
- PBDADiscoveryW1 -> launches: %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery [MS]
- PBDADiscoveryW2 -> launches: %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery [MS]
- PvrRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask [MS]
- PvrScheduleTask -> launches: %SystemRoot%\ehome\mcupdate.exe -PvrSchedule [MS]
- RegisterSearch -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) [MS]
- ReindexSearchRoot -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot [MS]
- SqlLiteRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask [MS]
- UpdateRecordPath -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic
- CorruptionDetector -> (HIDDEN!) launches: {190BA3F6-0205-4f46-B589-95C6822899D2}
- -> {HKLM...CLSID} = MemoryDiagnosticCustomHandler
- \InProcServer32\(Default) = C:\Windows\System32\memdiag.dll [MS]
- DecompressionFailureDetector -> (HIDDEN!) launches: {190BA3F6-0205-4f46-B589-95C6822899D2}
- -> {HKLM...CLSID} = MemoryDiagnosticCustomHandler
- \InProcServer32\(Default) = C:\Windows\System32\memdiag.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC
- HotStart -> launches: {06DA0625-9701-43da-BFD7-FBEEA2180A1E}
- -> {HKLM...CLSID} = HotStart User Agent
- \InProcServer32\(Default) = C:\Windows\System32\HotStartUserAgent.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\MUI
- LPRemove -> launches: %windir%\system32\lpremove.exe [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia
- SystemSoundsService -> launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543}
- -> {HKLM...CLSID} = Microsoft PlaySoundService Class
- \InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS]
- -> {HKLM...Wow...CLSID} = Microsoft PlaySoundService Class
- \InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace
- GatherNetworkInfo -> launches: %windir%\system32\gatherNetworkInfo.vbs [null data]
- C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics
- AnalyzeSystem -> launches: %SystemRoot%\System32\powercfg.exe -energy -auto [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\RAC
- RacTask -> (HIDDEN!) launches: {42060D27-CA53-41f5-96E4-B1E8169308A6}
- -> {HKLM...CLSID} = ReliabilityAnalysisCustomHandler
- \InProcServer32\(Default) = C:\Windows\system32\RacEngn.dll [MS]
- -> {HKLM...Wow...CLSID} = ReliabilityAnalysisCustomHandler
- \InProcServer32\(Default) = C:\Windows\system32\RacEngn.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Ras
- MobilityManager -> launches: {c463a0fc-794f-4fdf-9201-01938ceacafa}
- -> {HKLM...CLSID} = RasMobilityManager
- \InProcServer32\(Default) = C:\Windows\system32\rasmbmgr.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Registry
- RegIdleBackup -> (HIDDEN!) launches: {ca767aa8-9157-4604-b64b-40747123d5f2}
- -> {HKLM...CLSID} = RegistryIdleBackupHandler
- \InProcServer32\(Default) = C:\Windows\System32\regidle.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance
- RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx
- launchtrayprocess -> launches: %windir%\system32\GWX\GWX.exe /tasklaunch [MS]
- refreshgwxconfig -> launches: %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfig [MS]
- refreshgwxconfigandcontent -> launches: %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfigAndContent [MS]
- refreshgwxcontent -> launches: %windir%\system32\GWX\GWXConfigManager.exe /RefreshContent [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers
- Logon-5d -> launches: %windir%\system32\GWX\GWX.exe /event:7 [MS]
- MachineUnlock-5d -> launches: %windir%\system32\GWX\GWX.exe /event:8 [MS]
- OutOfIdle-5d -> launches: %windir%\system32\GWX\GWX.exe /event:6 [MS]
- OutOfSleep-5d -> launches: %windir%\system32\GWX\GWX.exe /event:9 [MS]
- refreshgwxconfig-B -> launches: %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfigAndContent [MS]
- Telemetry-4xd -> launches: %windir%\system32\GWX\GWX.exe /event:11 [MS]
- Time-5d -> launches: %windir%\system32\GWX\GWX.exe /event:10 [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\SideShow
- GadgetManager -> launches: {FF87090D-4A9A-4f47-879B-29A80C355D61}
- -> {HKLM...CLSID} = GadgetsManager Class
- \InProcServer32\(Default) = C:\Windows\System32\AuxiliaryDisplayServices.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore
- SR -> launches: %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager
- Interactive -> (HIDDEN!) launches: {855fec53-d2e4-4999-9e87-3414e9cf0ff4}
- -> {HKLM...CLSID} = RunTask
- \InProcServer32\(Default) = C:\Windows\system32\wdc.dll [MS]
- -> {HKLM...Wow...CLSID} = RunTask
- \InProcServer32\(Default) = C:\Windows\system32\wdc.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip
- IpAddressConflict1 -> launches: %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem [MS]
- IpAddressConflict2 -> launches: %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework
- MsCtfMonitor -> (HIDDEN!) launches: {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1}
- -> {HKLM...CLSID} = MsCtfMonitor task handler
- \InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS]
- -> {HKLM...Wow...CLSID} = MsCtfMonitor task handler
- \InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization
- SynchronizeTime -> launches: %windir%\system32\sc.exe start w32time task_started [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\UPnP
- UPnPHostConfig -> launches: sc.exe config upnphost start= auto [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\WDI
- ResolutionHost -> (HIDDEN!) launches: {900be39d-6be8-461a-bc4d-b0fa71f5ecb1}
- -> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler
- \InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS]
- -> {HKLM...Wow...CLSID} = DiagnosticInfrastructureCustomHandler
- \InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting
- QueueReporting -> launches: %windir%\system32\wermgr.exe -queuereporting [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform
- BfeOnServiceStartTypeChange -> (HIDDEN!) launches: %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Windows Media Sharing
- UpdateLibrary -> launches: "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\WindowsBackup
- ConfigNotification -> launches: %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION [MS]
- C:\Windows\System32\Tasks\Microsoft\Windows\Wininet
- CacheTask -> launches: {0358b920-0ac7-461f-98f4-58e32cd89148}
- -> {HKLM...CLSID} = Wininet Cache task object
- \InProcServer32\(Default) = C:\Windows\system32\wininet.dll [MS]
- -> {HKLM...Wow...CLSID} = Wininet Cache task object
- \InProcServer32\(Default) = C:\Windows\system32\wininet.dll [MS]
- C:\Windows\System32\Tasks\WPD
- SqmUpload_S-1-5-21-3631145020-3224763176-4093947856-1000 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS]
- Winsock2 Service Provider DLLs:
- -------------------------------
- Namespace Service Providers
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
- 000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS]
- 000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS]
- 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
- 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\ {++}
- 000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS]
- 000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS]
- 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]
- 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]
- 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]
- Transport Service Providers
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
- 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
- %SystemRoot%\system32\mswsock.dll [MS], 01 - 10
- HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries64\ {++}
- 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
- %SystemRoot%\system32\mswsock.dll [MS], 01 - 10
- Miscellaneous IE Hijack Points
- ------------------------------
- HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\
- <<H>> InPrivate = res://ieframe.dll/inprivate_win7.htm [MS]
- Running Services (Display Name, Service Name, Path {Service DLL}):
- ------------------------------------------------------------------
- Adobe Acrobat Update Service, AdobeARMservice, "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [Adobe Systems Incorporated]
- Apple Mobile Device Service, Apple Mobile Device Service, "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [Apple Inc.]
- Audio Service, STacSV, C:\Program Files\IDT\WDM\STacSV64.exe [IDT, Inc.]
- Intel(R) Management and Security Application Local Management Service, LMS, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [Intel Corporation]
- Intel(R) Management and Security Application User Notification Service, UNS, "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [Intel Corporation]
- Intel(R) Rapid Storage Technology, IAStorDataMgrSvc, "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" [null data]
- Kontrola sˇtŘ Microsoft, NisSrv, "C:\Program Files\Microsoft Security Client\NisSrv.exe" [MS]
- Microsoft Antimalware Service, MsMpSvc, "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [MS]
- NVIDIA Display Driver Service, NVSvc, "C:\Windows\system32\nvvsvc.exe" [NVIDIA Corporation]
- NVIDIA GeForce Experience Service, GfExperienceService, "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe" [NVIDIA Corporation]
- NVIDIA Network Service, NvNetworkService, "C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe" [NVIDIA Corporation]
- NVIDIA Stereoscopic 3D Driver Service, Stereo Service, "C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe" [NVIDIA Corporation]
- NVIDIA Streamer Network Service, NvStreamNetworkSvc, "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe" [NVIDIA Corporation]
- NVIDIA Streamer Service, NvStreamSvc, "C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe" [NVIDIA Corporation]
- PnkBstrA, PnkBstrA, C:\Windows\system32\PnkBstrA.exe [file not found]
- Safe Mode Drivers & Services (subkey name, subkey default value):
- -----------------------------------------------------------------
- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\
- <<!>> MsMpSvc, Service
- HKLM\System\CurrentControlSet\Control\SafeBoot\Network\
- <<!>> Hamachi2Svc, Service
- <<!>> MsMpSvc, Service
- <<H>>: Suspicious data at a browser hijack point.
- ==== C:\zoek_backup content ======================
- C:\zoek_backup (files=431 folders=67 48840670 bytes)
- ==== EOF on so 05.03.2016 at 22:48:59,81 ======================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement