CloseProcesses: CreateRestorePoint: EmptyTemp: HKU\S-1-5-21-4035913945-105837743-3845800814-1000\...\Command Processor: @mode 20,5 & tasklist /FI "IMAGENAME eq SoundMixer.exe" 2>NUL | find /I /N "SoundMixer.exe">NUL && exit & if exist "C:\Users\Jakub\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" ( start /MIN "" "C:\Users\Jakub\AppData\Roaming\Microsoft\SoundMixer\SoundMixer.exe" & tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) else ( tasklist /FI "IMAGENAME eq explorer.exe" 2>NUL | find /I /N "explorer.exe">NUL && exit & explorer.exe & exit ) <==== ATTENTION Tcpip\..\Interfaces\{aed99572-c332-4ce7-a0cf-5a701f7186cd}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{ed6c97af-711f-424e-a2cf-075972a62edd}: [DhcpNameServer] 31.11.202.254 37.8.214.2 SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\S-1-5-21-4035913945-105837743-3845800814-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = HKU\S-1-5-21-4035913945-105837743-3845800814-1000\...\StartMenuInternet\ChromeHTML: -> C:\Program Files (x86)\Junemike\Application\chrome.exe <==== ATTENTION CustomCLSID: HKU\S-1-5-21-4035913945-105837743-3845800814-1000_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-63ADF8285E9D}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-4035913945-105837743-3845800814-1000_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Jakub\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-4035913945-105837743-3845800814-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Jakub\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-4035913945-105837743-3845800814-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Jakub\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Jakub\AppData\Local\MEGAsync\ShellExtX64.dll -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe AlternateDataStreams: C:\Users\Public\AppData:CSM [458] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [480] HKU\S-1-5-21-4035913945-105837743-3845800814-1000\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Resident Evil 7 Biohazard\Resident Evil 7 Biohazard.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Resident Evil 7 Biohazard\Uninstall Resident Evil 7 Biohazard.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlast 2\Outlast 2.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlast 2\Uninstall Game.lnk C:\Users\Jakub\Documents\Euro Truck Simulator 2\readme.rtf.lnk C:\Users\Jakub\Documents\Adobe\After Effects CC 2015\User Presets\(Adobe).lnk HOSTS: