Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Out of the sky... 4 accounts... prosím o kontrolu

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zamčeno
Zpráva
Autor
korkis
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 157
Registrován: 16 zář 2007 14:37
Kontaktovat uživatele:

Out of the sky... 4 accounts... prosím o kontrolu

#1 Příspěvek od korkis »

Zdravíčko,

zničeho nic mi tam naskočili 4 accounty, tak bych rád poprosil o kontrolu ,jestli tam nemám náhoudou nějakou havet.
aaaaaaaaaaaaaaaa.jpg
aaaaaaaaaaaaaaaa.jpg (35.61 KiB) Zobrazeno 3083 x

Logfile of random's system information tool 1.16 (written by random/random)
Run by Korki$ at 2018-03-23 20:41:43
Microsoft Windows 8.1
System drive C: has 21 GB (9%) free of 231 GB
Total RAM: 8007 MB (63% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:41:45, on 23/03/2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18817)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe
C:\Program Files\trend micro\Korki$_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer13.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: True Key Helper - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O2 - BHO: (no name) - {13D67BB7-DB5F-48AA-884D-7A5D94168509} - (no file)
O3 - Toolbar: True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Discord] C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
O4 - HKUS\S-1-5-18\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'Default user')
O4 - Startup: Facebook Gameroom.lnk = Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
O4 - Startup: Send to OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: intu-help-qb8 - {CD17C364-2EC8-4929-91A9-C4839A20E909} - C:\Program Files (x86)\Intuit\QuickBooks 2015\HelpAsyncPluggableProtocol.dll
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: @oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: EZel Sensor Service (EzelSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Biometric and Context Agent Service (IntelBCAsvc) - Intel(R) Corporation - C:\Program Files\Intel\BCA\pabeSvc64.exe
O23 - Service: IQOptionUpdater - Unknown owner - C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MxService - Maxthon International ltd. - C:\Program Files (x86)\Maxthon5\Bin\MxService.exe
O23 - Service: Nero Update (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Sage SData Service - Sage (UK) Limited - C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: Intel Security True Key (TrueKey) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
O23 - Service: Intel Security True Key Scheduler (TrueKeyScheduler) - McAfee, Inc. - C:\Program Files\TrueKey\McTkSchedulerService.exe
O23 - Service: Intel Security True Key Helper Service (TrueKeyServiceHelper) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Xperia Companion Service (XperiaCompanionService) - Sony - C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe

--
End of file - 14617 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3772d482-1d63-4875-bb0c-650d14eb8035 -SystemEventPortName:HostProcess-a8bf411a-a797-4689-a525-d25451136dd7 -IoCancelEventPortName:HostProcess-8572a185-4fbe-4efb-ae6f-92ac7fb1c8bb -NonStateChangingEventPortName:HostProcess-0fa0e3d8-3f0a-4b34-baf0-7090ef3b544e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:94b8a1db-f104-4ec2-90f3-ab09a2232d3d -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\DbxSvc.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\dashost.exe
"C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Intel\BCA\pabeSvc64.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe"
"C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe"
"C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe"
"C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-fbf0953d-be40-48ba-9f64-dfb56872a050 -SystemEventPortName:HostProcess-1a273957-4a3a-49fb-847d-1f8aedfd2b9e -IoCancelEventPortName:HostProcess-51086184-c6a3-41cc-8d85-9a472fb1c24f -NonStateChangingEventPortName:HostProcess-75450e8a-eef5-4a79-a85e-5148e38e1590 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0bbc4320-4ef1-4d41-9c77-741ff9f6c381 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files\TrueKey\McTkSchedulerService.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
C:\WINDOWS\system32\taskhost.exe
C:\Program Files (x86)\IQ Option\IQOptionUpdater.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\dwm.exe
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
C:\WINDOWS\system32\taskhostex.exe
"C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe"
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\OEM\EzelSensorBehavior\EzelSensorBehavior.exe
C:\OEM\EzelSensorBehavior\EzelAudio.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
"C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMTray.exe"
"C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Elantech\ETDTouch.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --flag-switches-begin --flag-switches-end
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x128,0x12c,0x130,0x124,0x134,0x7ffe7d86f1e8,0x7ffe7d86f1f8,0x7ffe7d86f208
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=6488 --on-initialized-event-handle=348 --parent-handle=312 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --gpu-preferences=KAAAAAAAAAAABwAAAQAAAAAAAAAAAGAAAQAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --gpu-vendor-id=0x8086 --gpu-device-id=0x0166 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3958 --gpu-driver-date=9-30-2014 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x0fe4 --service-request-channel-token=B63B36436D0995B344425E13C9753F1E --mojo-platform-channel-handle=1360 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\Greenshot\Greenshot.exe"
"C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe" fbgames://windows_startup/
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=AB529C23906D7293EC5E1404C087E01C --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=AB529C23906D7293EC5E1404C087E01C --renderer-client-id=3 --mojo-platform-channel-handle=2876 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=8951E774F71756BD33CBD2FD6F90AD45 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=8951E774F71756BD33CBD2FD6F90AD45 --renderer-client-id=4 --mojo-platform-channel-handle=2336 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=6943A04DD3395130E39121966104F575 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=6943A04DD3395130E39121966104F575 --renderer-client-id=5 --mojo-platform-channel-handle=3156 /prefetch:1
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=366291FBDA03634AF55AF6B945DD789B --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=366291FBDA03634AF55AF6B945DD789B --renderer-client-id=6 --mojo-platform-channel-handle=3492 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=ACDB465C597A5F2B407CB040F44755A7 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=ACDB465C597A5F2B407CB040F44755A7 --renderer-client-id=7 --mojo-platform-channel-handle=3536 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=22EC0E746391EAEC31EB45404915652A --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=22EC0E746391EAEC31EB45404915652A --renderer-client-id=8 --mojo-platform-channel-handle=3556 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=F8D2054E47F391906CEA1FE366F23045 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=F8D2054E47F391906CEA1FE366F23045 --renderer-client-id=9 --mojo-platform-channel-handle=3820 /prefetch:1
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
C:\WINDOWS\system32\cmd.exe /d /c "C:/Program Files (x86)/FreeDownloadManager.ORG/Free Download Manager/browsernativehost.exe" chrome-extension://ahmpjcflkgiildlgicmcieglgoilbfdp/ --parent-window=0 < \\.\pipe\chrome.nativeMessaging.in.9f556e59727220fd > \\.\pipe\chrome.nativeMessaging.out.9f556e59727220fd
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
"C:\Dolby PCEE4\pcee4.exe" -autostart
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=79911C28A6038A0DB57BE327E15E3C04 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=79911C28A6038A0DB57BE327E15E3C04 --renderer-client-id=19 --mojo-platform-channel-handle=8448 /prefetch:1
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=FFE5D7A22511D130E6D5B6CC38DE1732 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=FFE5D7A22511D130E6D5B6CC38DE1732 --renderer-client-id=23 --mojo-platform-channel-handle=9008 /prefetch:1
C:\WINDOWS\system32\igfxext.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"
"C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe"
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe
C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
"X:\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1304,7823350478094261034,12724994385032087082,131072 --service-pipe-token=D1F04240C82A61360FDB8EB80222E2AF --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=D1F04240C82A61360FDB8EB80222E2AF --renderer-client-id=35 --mojo-platform-channel-handle=2172 /prefetch:1
C:\WINDOWS\system32\wbem\wmiprvse.exe

====== Scheduled tasks folder ======

C:\WINDOWS\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Acer Aspire R7 Tutorial - "C:\ProgramData\OEM\Acer Aspire R7 Tutorial\EzelToastNotificationAgent.exe"
C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player NPAPI Notifier - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe -check plugin
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\ALU - C:\Program Files (x86)\Acer\Live Updater\updater.exe -auto
C:\WINDOWS\system32\tasks\ALUAgent - C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe
C:\WINDOWS\system32\tasks\AutoPico Daily Restart - "C:\Program Files\KMSpico\AutoPico.exe" /silent
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\DeviceDetector - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\WINDOWS\system32\tasks\Dolby Selector - C:\Dolby PCEE4\pcee4.exe -autostart
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineCore - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineUA - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\EZel Sensor Behavior - "C:\Program Files\Acer\Acer Ezel Sensor\Launcher.exe"
C:\WINDOWS\system32\tasks\FreeDownloadManagerNetworkMonitor - "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\HIDMonitor - C:\Program Files\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\WINDOWS\system32\tasks\IQOptionUpdateTask - C:\Program Files (x86)\IQ Option\\IQOptionUpdateTask.exe
C:\WINDOWS\system32\tasks\Launch Manager - "C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe"
C:\WINDOWS\system32\tasks\Launch Screen Grasp_First - "C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
C:\WINDOWS\system32\tasks\Maxthon Update - "C:\Program Files (x86)\Maxthon\Bin\MxEidolon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\Maxthon5 Update - "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\McAfee Remediation (Prepare) - C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe /prepare
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-214140026-2031469655-1353360597-1002 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\Power Management - "C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\WINDOWS\system32\tasks\Prelauncher - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\prelauncher_First - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{0AB33800-4EF1-4641-A068-6DFD21593135} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1002 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1009 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\WINDOWS\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default

"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files (x86)\McAfee\SiteAdvisor


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.144.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.144.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@unity3d.com/UnityPlayer64,version=1.0]
"Description"=Unity Player 4.6.6f2
"Path"=C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\addons.json
SCDL SoundCloud Downloader - extension - scdl@mrvv.net
FlashGot Mass Downloader - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
Skype - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\extensions.json
FlashGot - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} -
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} -
SCDL SoundCloud Downloader - webextension - scdl@mrvv.net -
YouTube Video and Audio Downloader - extension - feca4b87-3be4-43da-a1b1-137c24220968@jetpack -
Pocket - extension - firefox@getpocket.com -
Web Compat - extension - webcompat@mozilla.org -
Application Update Service Helper - extension - aushelper@mozilla.org -
Firefox Screenshots - extension - screenshots@mozilla.org -
Follow-on Search Telemetry - extension - followonsearch@mozilla.com -
Shield Recipe Client - extension - shield-recipe-client@mozilla.org -
Activity Stream - extension - activity-stream@mozilla.org -
Form Autofill - extension - formautofill@mozilla.org -
Photon onboarding - extension - onboarding@mozilla.org -
Skype Click to Call - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} -
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} -

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\pluginreg.dat
Plugin - Shockwave Flash - 28.0.0.161 - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll

=========Google Chrome=========

C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Slides 0.10
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Web Store 0.2
Extension ahmpjcflkgiildlgicmcieglgoilbfdp 1 Free Download Manager Chrome extension 2.1.42
Extension anbfhidldjknonaihbalghlebaijealk 0 Chrome Currency Converter 6.4.5
Extension aohghmighlieiainnegkcijnfilokake 1 Docs 0.10
Extension apdfllckaahabafndbhieahigkjlhalf 1 Google Drive 14.1
Extension bdokagampppgbnjfdlkfpphniapiiifn 0 SPOI Options (Please remove me) 1.8.164.3
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension cfhdojbkjhnklbpkdaibdccddilifddb 0 Adblock Plus 1.13.5
Extension chlffgpmiacpedhhbkiomidkjlcfhogd 1 Pushbullet 339
Extension ciagpekplgpbepdgggflgmahnjgiaced 1 Add to Amazon Wish List 1.0.0.11
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Google Search 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension elicpjhcidhpjomhibiffojpinpmmpil 1 Video Downloader professional 1.98.1
Extension elioihkkcdgakfbahdoddophfngopipi 1 Photo Zoom for Facebook 1.1428.5.3
Extension emjhialibnbffdaijfenohaloaboknmc
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Sheets 1.2
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Docs Offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 0 AdBlock 3.27.0
Extension gklhnpfkcfpkjcihhjbgmhgkcajamlmd 1 Download Ninja 1.8
Extension golhdmegajbopkkhfbjbilfecnjaobod
Extension icchipenjgneldmljlkfmgkpjamhifmf 1 Latest London Weather 1
Extension icokofncdmhjjncknidajbngmbfphpia 1 Smart TV Remote Controller 1.10
Extension igjjkeeamkpihpncmmbgdkhdnjpcfmfb
Extension jieopfhnlbjmbpckpdhfdedccdmngdac 1 Earth 1.6
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.73
Extension lifbcibllhkdhoafpjfnlhfpfgnpldfl 2 Skype Click to Call 7.4.0.9058
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension nbpagnldghgfoolbancepceaanlmhfmd 1 Hotword triggering 0.0.1.4
Extension nckgahadagoaajjgafhacjanaoiihapd 1 Google Hangouts 2018.123.418.2
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.7
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Chrome Web Store Payments 1.0.0.3
Extension nodkcjollmmjidmcnhloaoahmciabnai 1 Video Cutter 1.0.5
Extension obhijjefkkokfaiffkcemldacdabpeei 0 AIO Search 1.6.1
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh 1 Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 6518.129.0.1
Homepage: http://search.ominent.com/ws/?source=9f ... fd52a98d92
default_search_provider.search_url:
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl]
"Path"=C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=MAARJS
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}]
"URL"=http://uk.yhs4.search.yahoo.com/yhs/sea ... earchTerms}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=MAARJS

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-03-04 207016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-09-26 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-09-26 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4B8786-5502-4803-8EBC-F652A1153BB6}]
True Key Helper - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13D67BB7-DB5F-48AA-884D-7A5D94168509}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - True Key - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-03-26 13449288]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-03-08 1278024]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-10-01 448912]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2013-02-04 10592256]
"Greenshot"=C:\Program Files\Greenshot\Greenshot.exe [2015-04-19 540672]
"egui"=C:\Program Files\ESET\ESET Smart Security\ecmds.exe [2017-12-18 324352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2013-12-17 5973272]
"Discord"=C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe [2018-01-08 57821176]
"GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2018-03-20 1589592]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Intuit SyncManager"=C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [2014-09-29 3775800]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-03-15 3567936]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-07-21 587288]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
QuickBooks Update Agent.lnk - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
QuickBooks_Standard_21.lnk - C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE

C:\Users\Korki$\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Facebook Gameroom.lnk - C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
Send to OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages" = scecli
C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2018-03-18 20:13:49 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2018-03-15 15:20:48 ----A---- C:\WINDOWS\system32\appraiser.dll
2018-03-15 15:20:48 ----A---- C:\WINDOWS\system32\aeinv.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\invagent.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\generaltel.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\devinv.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\centel.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\acmigration.dll
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\aitstatic.exe
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\aepic.dll
2018-03-15 15:20:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2018-03-15 15:20:25 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2018-03-15 15:20:23 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2018-03-15 15:20:23 ----A---- C:\WINDOWS\system32\ieframe.dll
2018-03-15 15:20:22 ----A---- C:\WINDOWS\system32\jscript9.dll
2018-03-15 15:20:21 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2018-03-15 15:20:21 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\win32k.sys
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2018-03-15 15:20:19 ----A---- C:\WINDOWS\SYSWOW64\MSVidCtl.dll
2018-03-15 15:20:19 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\SYSWOW64\mmcndmgr.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\wininet.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\mmc.exe
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\authui.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\system32\msi.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\system32\iertutil.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2018-03-15 15:20:16 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\termsrv.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\localspl.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\urlmon.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\jscript.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\certutil.exe
2018-03-15 15:20:14 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\puiobj.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\msfeeds.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2018-03-15 15:20:13 ----A---- C:\WINDOWS\SYSWOW64\certutil.exe
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\scesrv.dll
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\system32\vbscript.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2018-03-15 15:20:11 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\winresume.exe
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\winload.exe
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\hal.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\SYSWOW64\TSpkg.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\TSpkg.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\prnntfy.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\msra.exe
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2018-03-15 15:20:09 ----A---- C:\WINDOWS\SYSWOW64\mmcbase.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\SYSWOW64\cic.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\puiapi.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\mmcbase.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\lsasrv.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\ULIAGPKX.SYS
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\NV_AGP.SYS
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\AGP440.sys
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\zipfldr.dll
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\msisadrv.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\isapnp.sys
2018-03-15 15:20:06 ----A---- C:\WINDOWS\SYSWOW64\zipfldr.dll
2018-03-15 15:20:06 ----A---- C:\WINDOWS\system32\certenc.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\mmcshext.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\certenc.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\system32\credssp.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\system32\cic.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\webcheck.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\mshtmled.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\dxtrans.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\compstui.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\mmcshext.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\iepeers.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\certcli.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\credssp.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\inetcomm.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-stable.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-dev.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-canary.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\DbxSvc.exe

====== List of files/folders modified in the last 1 month ======

2018-03-23 20:41:45 ----D---- C:\Program Files\trend micro
2018-03-23 20:41:18 ----D---- C:\WINDOWS\Temp
2018-03-23 20:02:00 ----D---- C:\WINDOWS\system32\sru
2018-03-22 22:55:09 ----D---- C:\WINDOWS\Prefetch
2018-03-22 21:46:27 ----SHD---- C:\System Volume Information
2018-03-22 21:43:43 ----D---- C:\WINDOWS\system32\config
2018-03-22 16:28:51 ----D---- C:\Program Files (x86)\IQ Option
2018-03-21 21:45:43 ----D---- C:\WINDOWS\Microsoft.NET
2018-03-20 19:48:10 ----SHD---- C:\WINDOWS\Installer
2018-03-20 19:48:10 ----SD---- C:\Users\Korki$\AppData\Roaming\Microsoft
2018-03-20 18:01:19 ----D---- C:\WINDOWS\system32\Tasks
2018-03-19 17:35:37 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2018-03-19 09:36:24 ----D---- C:\WINDOWS\rescache
2018-03-18 20:18:40 ----RD---- C:\WINDOWS\System32
2018-03-18 20:18:40 ----D---- C:\WINDOWS\Inf
2018-03-18 20:18:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2018-03-18 20:13:54 ----D---- C:\WINDOWS\WinSxS
2018-03-18 20:13:49 ----D---- C:\WINDOWS\SysWOW64
2018-03-18 20:12:48 ----D---- C:\WINDOWS\system32\DriverStore
2018-03-18 20:04:25 ----RD---- C:\WINDOWS\ToastData
2018-03-18 20:04:25 ----D---- C:\WINDOWS\system32\appraiser
2018-03-18 20:04:23 ----D---- C:\Program Files\Internet Explorer
2018-03-18 20:04:23 ----D---- C:\Program Files (x86)\Internet Explorer
2018-03-18 20:04:22 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2018-03-18 20:04:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\en-GB
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\cs-CZ
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\Boot
2018-03-18 20:04:16 ----D---- C:\WINDOWS\system32\drivers
2018-03-17 17:07:12 ----D---- C:\WINDOWS\system32\NDF
2018-03-16 22:05:59 ----D---- C:\Program Files (x86)\Dropbox
2018-03-16 20:17:24 ----D---- C:\WINDOWS
2018-03-16 20:17:19 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2018-03-16 20:16:50 ----D---- C:\Program Files (x86)\Common Files
2018-03-16 20:15:29 ----D---- C:\Program Files (x86)\Microsoft Office
2018-03-15 20:47:05 ----D---- C:\WINDOWS\CbsTemp
2018-03-15 20:46:06 ----D---- C:\WINDOWS\system32\MRT
2018-03-15 20:42:52 ----D---- C:\WINDOWS\debug
2018-03-15 20:42:45 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2018-03-15 20:42:36 ----AC---- C:\WINDOWS\system32\MRT.exe
2018-03-14 19:56:41 ----D---- C:\WINDOWS\system32\Macromed
2018-03-14 19:56:37 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2018-03-14 19:55:18 ----D---- C:\WINDOWS\system32\catroot2
2018-03-12 21:30:06 ----D---- C:\Users\Korki$\AppData\Roaming\vlc
2018-03-12 19:42:15 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-12 19:42:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-03-10 00:12:53 ----D---- C:\Program Files\Pale Moon
2018-03-04 19:23:09 ----D---- C:\WINDOWS\system32\wbem
2018-02-26 19:21:25 ----D---- C:\WINDOWS\AppReadiness

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [2018-01-19 107328]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-12-11 652344]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2017-06-30 381608]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2018-01-19 134368]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2018-01-19 180088]
R1 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2018-01-19 81880]
R1 epfwwfp;epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [2018-01-19 106304]
R1 StarPortLite;@oem46.inf,%DeviceDesc%;StarPort Storage Controller (Lite); C:\WINDOWS\System32\drivers\StarPortLite.sys [2013-02-04 120704]
R2 ekbdflt;ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [2018-01-19 50744]
R3 bcbtums;@oem38.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM42RLY;BCM42RLY; C:\WINDOWS\system32\drivers\BCM42RLY.sys [2013-02-01 23760]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-22 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2017-07-06 119296]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-22 81920]
R3 btwampfl;@oem38.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2014-02-04 166616]
R3 btwaudio;@oem16.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2013-03-15 186584]
R3 btwavdt;@oem17.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\System32\drivers\btwavdt.sys [2013-03-15 227032]
R3 btwl2cap;@oem3.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-26 40248]
R3 btwpanfl;BTW PAN filter driver; \??\C:\WINDOWS\system32\drivers\btwpanfl.sys [2013-01-20 44912]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2013-03-15 22744]
R3 ETD;@oem6.inf,%PS2.DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-03-05 356752]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-03-26 3376200]
R3 IntcDAud;@oem12.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-03-12 342528]
R3 iwdbus;@oem24.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 LMDriver;@oem2.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys [2013-01-10 21360]
R3 MEIx64;@oem15.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-13 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-05 11273504]
R3 RadioShim;@oem2.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys [2013-01-10 15704]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2015-08-01 167424]
R3 RSP2STOR;@oem9.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2013-01-23 288328]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-22 212736]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2018-02-15 15872]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-08-01 1201664]
S3 dbx;dbx; C:\WINDOWS\system32\DRIVERS\dbx.sys []
S3 dc3d;@oem52.inf,%dc3d.SvcDesc%;MS Hardware Device Detection Driver (USB); C:\WINDOWS\System32\drivers\dc3d.sys [2015-12-09 95024]
S3 dg_ssudbus;@oem48.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 ggflt;@oem40.inf,%SvcFltDesc%;SOMC USB Flash Driver Filter; C:\WINDOWS\System32\drivers\ggflt.sys [2016-02-17 16088]
S3 ggsemc;@oem38.inf,%SvcDesc%;SEMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsemc.sys [2013-02-13 27760]
S3 ggsomc;@oem40.inf,%SvcDesc%;SOMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsomc.sys [2016-02-17 30424]
S3 mfencrk;McAfee Inc. mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [2014-09-19 96600]
S3 ssudmdm;@oem57.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-11-22 44544]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-02-09 83984]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2013-03-22 959192]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2013-02-19 2615368]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2018-03-12 7962288]
R2 DbxSvc;DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [2018-03-15 51024]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2017-12-18 1940584]
R2 EzelSvc;EZel Sensor Service; C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe [2013-04-23 213032]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-11-15 2468496]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 IntelBCAsvc;Intel(R) Biometric and Context Agent Service; C:\Program Files\Intel\BCA\pabeSvc64.exe [2016-05-06 3026584]
R2 IQOptionUpdater;IQOptionUpdater; C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe [2018-03-22 2960904]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-14 165336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-14 279000]
R2 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2013-03-15 431656]
R2 NAUpdate;Nero Update; c:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-13 769432]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-08-29 920864]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2014-09-29 45056]
R2 Sage AutoUpdate Manager Service;Sage AutoUpdate Manager Service; C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe [2012-07-05 8192]
R2 Sage SData Service;Sage SData Service; C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe [2012-05-17 53248]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-08-25 7534864]
R2 TrueKey;Intel Security True Key; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [2016-07-22 908256]
R2 TrueKeyScheduler;Intel Security True Key Scheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [2016-07-22 15736]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-01-14 366040]
R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2013-03-15 662088]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 BcmBtRSupport;@oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04 143144]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S2 MxService;MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [2017-11-01 143648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-14 272384]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll" = %SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04 143144]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-03-04 194512]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2018-03-12 211632]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2014-09-29 65536]
S3 TrueKeyServiceHelper;Intel Security True Key Helper Service; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [2016-07-22 86864]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118195
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

korkis
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 157
Registrován: 16 zář 2007 14:37
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#3 Příspěvek od korkis »

# AdwCleaner 7.0.8.0 - Logfile created on Sat Mar 24 16:29:44 2018
# Updated on 2018/08/02 by Malwarebytes
# Database: 2018-03-23.1
# Running on Windows 8.1 (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Legacy, C:\Program Files (x86)\Common Files\Speedbit
PUP.Optional.UCBrowser, C:\Users\Korki$\AppData\Local\UCBrowser


***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{03F14321-8FED-4CBC-B01A-4B57FC199062}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{2C6F7E96-73BC-47A5-9F51-B67F0BAFE24D}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{4C58EB04-7B72-4D3D-A36E-66167A99BC31}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{4EE0B011-604C-47F3-8F2B-39F79640B85E}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{6C9945B7-1D19-46CB-88C0-45A24DF6CD6E}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{F7BCCFD4-2FA6-477D-A1B0-EF7500B3C49E}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{6BC38BF4-E84D-46E1-920B-42D31AEA617E}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\NCTAudioCompress3.DLL
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\NCTAudioFormatSettings3.DLL


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search
PUP.Optional.Legacy, Startpage found: http://search.ominent.com/ws/?source=9f ... fd52a98d92
PUP.Optional.Legacy, Startpage found: http://search.ominent.com/ws/?source=9f ... fd52a98d92
PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?ctid=CT33195 ... CA5F&SSPV=

/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271


*************************

C:/AdwCleaner/AdwCleaner[C1].txt - [3951 B] - [2015/12/8 18:28:20]
C:/AdwCleaner/AdwCleaner[S1].txt - [3713 B] - [2015/12/8 18:26:34]


########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118195
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#4 Příspěvek od Rudy »

V ADW ještě klikněte na mazání, restartujte a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

korkis
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 157
Registrován: 16 zář 2007 14:37
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#5 Příspěvek od korkis »

Logfile of random's system information tool 1.16 (written by random/random)
Run by Korki$ at 2018-03-24 20:05:08
Microsoft Windows 8.1
System drive C: has 22 GB (9%) free of 231 GB
Total RAM: 8007 MB (66% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:05:10, on 24/03/2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18817)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\Korki$_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer13.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: True Key Helper - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O2 - BHO: (no name) - {13D67BB7-DB5F-48AA-884D-7A5D94168509} - (no file)
O3 - Toolbar: True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Discord] C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
O4 - HKUS\S-1-5-18\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'Default user')
O4 - Startup: Facebook Gameroom.lnk = Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
O4 - Startup: Send to OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: intu-help-qb8 - {CD17C364-2EC8-4929-91A9-C4839A20E909} - C:\Program Files (x86)\Intuit\QuickBooks 2015\HelpAsyncPluggableProtocol.dll
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: @oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: EZel Sensor Service (EzelSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Biometric and Context Agent Service (IntelBCAsvc) - Intel(R) Corporation - C:\Program Files\Intel\BCA\pabeSvc64.exe
O23 - Service: IQOptionUpdater - Unknown owner - C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MxService - Maxthon International ltd. - C:\Program Files (x86)\Maxthon5\Bin\MxService.exe
O23 - Service: Nero Update (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Sage SData Service - Sage (UK) Limited - C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: Intel Security True Key (TrueKey) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
O23 - Service: Intel Security True Key Scheduler (TrueKeyScheduler) - McAfee, Inc. - C:\Program Files\TrueKey\McTkSchedulerService.exe
O23 - Service: Intel Security True Key Helper Service (TrueKeyServiceHelper) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Xperia Companion Service (XperiaCompanionService) - Sony - C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe

--
End of file - 14683 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\system32\nvvsvc.exe -session
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d755c926-b629-416f-a234-ae4c85eda462 -SystemEventPortName:HostProcess-17b387cc-1daa-414d-b543-2e5f4a02343e -IoCancelEventPortName:HostProcess-3220a7e5-9a38-4332-adf7-008a8a275f36 -NonStateChangingEventPortName:HostProcess-a4a2c066-9736-42ea-9f42-743e3a96ff86 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c0894152-d8ef-4a81-ad3c-96b664a54bf1 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\DbxSvc.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\dashost.exe
"C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Intel\BCA\pabeSvc64.exe"
C:\Program Files (x86)\IQ Option\IQOptionUpdater.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe"
"C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe"
"C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe"
"C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\WINDOWS\system32\taskeng.exe
"C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe"
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\OEM\EzelSensorBehavior\EzelSensorBehavior.exe
C:\OEM\EzelSensorBehavior\EzelAudio.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Dolby PCEE4\pcee4.exe" -autostart
"C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-76eebdc0-1aba-4764-84a2-cb39f8355ec7 -SystemEventPortName:HostProcess-0966df82-1f6d-4021-ae94-4097a0cb119c -IoCancelEventPortName:HostProcess-fca1c2fe-3e7b-4b90-a35c-28422f7c0730 -NonStateChangingEventPortName:HostProcess-2a7c7cab-db79-42bf-bc09-8d14ff5799f6 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e9e2ddd2-1e35-4f18-a733-c5a8d4e1d926 -DeviceGroupId:WpdFsGroup
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\WINDOWS\system32\igfxEM.exe
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
"C:\Program Files\Acer\Acer Launch Manager\LMTray.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe"
"C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Elantech\ETDTouch.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Program Files\Greenshot\Greenshot.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
"C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe" fbgames://windows_startup/
"C:\WINDOWS\system32\NOTEPAD.EXE" C:\AdwCleaner\AdwCleaner[C1].txt
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x118,0x11c,0x120,0x114,0x124,0x7ffd7829f1e8,0x7ffd7829f1f8,0x7ffd7829f208
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3504 --on-initialized-event-handle=460 --parent-handle=472 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --gpu-preferences=KAAAAAAAAAAABwAAAQAAAAAAAAAAAGAAAQAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --gpu-vendor-id=0x8086 --gpu-device-id=0x0166 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3958 --gpu-driver-date=9-30-2014 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x0fe4 --service-request-channel-token=388285C2DC37730976745679B36C93BB --mojo-platform-channel-handle=1336 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=96697E51F03D59A2FA376308C67C2A74 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=96697E51F03D59A2FA376308C67C2A74 --renderer-client-id=3 --mojo-platform-channel-handle=2496 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=C07D7E2A3CE3D6ED2A5791EA10A0A0F3 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=C07D7E2A3CE3D6ED2A5791EA10A0A0F3 --renderer-client-id=4 --mojo-platform-channel-handle=3080 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=3DDDC01CB9F857865E34D0542BD204B5 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=3DDDC01CB9F857865E34D0542BD204B5 --renderer-client-id=5 --mojo-platform-channel-handle=3244 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=36EDAAA6232C74159BD77E4F4FEB8967 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=36EDAAA6232C74159BD77E4F4FEB8967 --renderer-client-id=6 --mojo-platform-channel-handle=3376 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=ED7D0D226F1F8BD31BBD57E1459350B7 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=ED7D0D226F1F8BD31BBD57E1459350B7 --renderer-client-id=7 --mojo-platform-channel-handle=3408 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=0E403F4902263AC8A0D65A1370A690A4 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=0E403F4902263AC8A0D65A1370A690A4 --renderer-client-id=8 --mojo-platform-channel-handle=3544 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=43E4BCE553772CA1760FDF0A755636FB --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=43E4BCE553772CA1760FDF0A755636FB --renderer-client-id=9 --mojo-platform-channel-handle=3556 /prefetch:1
C:\WINDOWS\system32\cmd.exe /d /c "C:/Program Files (x86)/FreeDownloadManager.ORG/Free Download Manager/browsernativehost.exe" chrome-extension://ahmpjcflkgiildlgicmcieglgoilbfdp/ --parent-window=0 < \\.\pipe\chrome.nativeMessaging.in.4f1b71e1e69a248b > \\.\pipe\chrome.nativeMessaging.out.4f1b71e1e69a248b
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=1A81F4C6A38884F7A80C2D8626B1DA2B --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=1A81F4C6A38884F7A80C2D8626B1DA2B --renderer-client-id=22 --mojo-platform-channel-handle=7852 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=0C09018FD343974F013E64906E8F067C --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=0C09018FD343974F013E64906E8F067C --renderer-client-id=24 --mojo-platform-channel-handle=7412 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=BC11A2165A25EB8BB7DB15AAA375B8BD --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=BC11A2165A25EB8BB7DB15AAA375B8BD --renderer-client-id=21 --mojo-platform-channel-handle=7636 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=EAE26D93592428BCE9712E9EE67A11C4 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=EAE26D93592428BCE9712E9EE67A11C4 --renderer-client-id=26 --mojo-platform-channel-handle=8896 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=5960AE94937CB2F700277069F1FD6247 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=5960AE94937CB2F700277069F1FD6247 --renderer-client-id=28 --mojo-platform-channel-handle=9788 /prefetch:1
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
"C:\Program Files\TrueKey\McTkSchedulerService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
C:\WINDOWS\system32\igfxext.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.18384_none_fa1d93c39b41b41a\TiWorker.exe -Embedding
"C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Users\Korki$\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

====== Scheduled tasks folder ======

C:\WINDOWS\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Acer Aspire R7 Tutorial - "C:\ProgramData\OEM\Acer Aspire R7 Tutorial\EzelToastNotificationAgent.exe"
C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player NPAPI Notifier - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe -check plugin
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\ALU - C:\Program Files (x86)\Acer\Live Updater\updater.exe -auto
C:\WINDOWS\system32\tasks\ALUAgent - C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe
C:\WINDOWS\system32\tasks\AutoPico Daily Restart - "C:\Program Files\KMSpico\AutoPico.exe" /silent
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\DeviceDetector - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\WINDOWS\system32\tasks\Dolby Selector - C:\Dolby PCEE4\pcee4.exe -autostart
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineCore - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineUA - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\EZel Sensor Behavior - "C:\Program Files\Acer\Acer Ezel Sensor\Launcher.exe"
C:\WINDOWS\system32\tasks\FreeDownloadManagerNetworkMonitor - "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\HIDMonitor - C:\Program Files\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\WINDOWS\system32\tasks\IQOptionUpdateTask - C:\Program Files (x86)\IQ Option\\IQOptionUpdateTask.exe
C:\WINDOWS\system32\tasks\Launch Manager - "C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe"
C:\WINDOWS\system32\tasks\Launch Screen Grasp_First - "C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
C:\WINDOWS\system32\tasks\Maxthon Update - "C:\Program Files (x86)\Maxthon\Bin\MxEidolon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\Maxthon5 Update - "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\McAfee Remediation (Prepare) - C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe /prepare
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-214140026-2031469655-1353360597-1002 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\Power Management - "C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\WINDOWS\system32\tasks\Prelauncher - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\prelauncher_First - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{0AB33800-4EF1-4641-A068-6DFD21593135} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1002 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1009 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\WINDOWS\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default

"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files (x86)\McAfee\SiteAdvisor


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.144.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.144.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@unity3d.com/UnityPlayer64,version=1.0]
"Description"=Unity Player 4.6.6f2
"Path"=C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\addons.json
SCDL SoundCloud Downloader - extension - scdl@mrvv.net
FlashGot Mass Downloader - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
Skype - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\extensions.json
FlashGot - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} -
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} -
SCDL SoundCloud Downloader - webextension - scdl@mrvv.net -
YouTube Video and Audio Downloader - extension - feca4b87-3be4-43da-a1b1-137c24220968@jetpack -
Pocket - extension - firefox@getpocket.com -
Web Compat - extension - webcompat@mozilla.org -
Application Update Service Helper - extension - aushelper@mozilla.org -
Firefox Screenshots - extension - screenshots@mozilla.org -
Follow-on Search Telemetry - extension - followonsearch@mozilla.com -
Shield Recipe Client - extension - shield-recipe-client@mozilla.org -
Activity Stream - extension - activity-stream@mozilla.org -
Form Autofill - extension - formautofill@mozilla.org -
Photon onboarding - extension - onboarding@mozilla.org -
Skype Click to Call - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} -
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} -

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\pluginreg.dat
Plugin - Shockwave Flash - 28.0.0.161 - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll

=========Google Chrome=========

C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Slides 0.10
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Web Store 0.2
Extension ahmpjcflkgiildlgicmcieglgoilbfdp 1 Free Download Manager Chrome extension 2.1.42
Extension anbfhidldjknonaihbalghlebaijealk 0 Chrome Currency Converter 6.4.5
Extension aohghmighlieiainnegkcijnfilokake 1 Docs 0.10
Extension apdfllckaahabafndbhieahigkjlhalf 1 Google Drive 14.1
Extension bdokagampppgbnjfdlkfpphniapiiifn 0 SPOI Options (Please remove me) 1.8.164.3
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension cfhdojbkjhnklbpkdaibdccddilifddb 0 Adblock Plus 1.13.5
Extension chlffgpmiacpedhhbkiomidkjlcfhogd 1 Pushbullet 339
Extension ciagpekplgpbepdgggflgmahnjgiaced 1 Add to Amazon Wish List 1.0.0.11
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Google Search 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension elicpjhcidhpjomhibiffojpinpmmpil 1 Video Downloader professional 1.98.1
Extension elioihkkcdgakfbahdoddophfngopipi 1 Photo Zoom for Facebook 1.1428.5.3
Extension emjhialibnbffdaijfenohaloaboknmc
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Sheets 1.2
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Docs Offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 0 AdBlock 3.27.0
Extension gklhnpfkcfpkjcihhjbgmhgkcajamlmd 1 Download Ninja 1.8
Extension golhdmegajbopkkhfbjbilfecnjaobod
Extension icchipenjgneldmljlkfmgkpjamhifmf 1 Latest London Weather 1
Extension icokofncdmhjjncknidajbngmbfphpia 1 Smart TV Remote Controller 1.10
Extension igjjkeeamkpihpncmmbgdkhdnjpcfmfb
Extension jieopfhnlbjmbpckpdhfdedccdmngdac 1 Earth 1.6
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.73
Extension lifbcibllhkdhoafpjfnlhfpfgnpldfl 2 Skype Click to Call 7.4.0.9058
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension nbpagnldghgfoolbancepceaanlmhfmd 1 Hotword triggering 0.0.1.4
Extension nckgahadagoaajjgafhacjanaoiihapd 1 Google Hangouts 2018.123.418.2
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.7
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Chrome Web Store Payments 1.0.0.3
Extension nodkcjollmmjidmcnhloaoahmciabnai 1 Video Cutter 1.0.5
Extension obhijjefkkokfaiffkcemldacdabpeei 0 AIO Search 1.6.1
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh 1 Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 6518.129.0.1
Homepage: http://search.ominent.com/ws/?source=9f ... fd52a98d92
default_search_provider.search_url:
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl]
"Path"=C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=MAARJS
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}]
"URL"=http://uk.yhs4.search.yahoo.com/yhs/sea ... earchTerms}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=MAARJS

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-03-04 207016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-09-26 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-09-26 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4B8786-5502-4803-8EBC-F652A1153BB6}]
True Key Helper - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13D67BB7-DB5F-48AA-884D-7A5D94168509}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - True Key - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-03-26 13449288]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-03-08 1278024]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-10-01 448912]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2013-02-04 10592256]
"Greenshot"=C:\Program Files\Greenshot\Greenshot.exe [2015-04-19 540672]
"egui"=C:\Program Files\ESET\ESET Smart Security\ecmds.exe [2017-12-18 324352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2013-12-17 5973272]
"Discord"=C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe [2018-01-08 57821176]
"GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2018-03-20 1589592]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Intuit SyncManager"=C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [2014-09-29 3775800]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-03-15 3567936]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-07-21 587288]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
QuickBooks Update Agent.lnk - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
QuickBooks_Standard_21.lnk - C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE

C:\Users\Korki$\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Facebook Gameroom.lnk - C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
Send to OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages" = scecli
C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2018-03-18 20:13:49 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2018-03-15 15:20:48 ----A---- C:\WINDOWS\system32\appraiser.dll
2018-03-15 15:20:48 ----A---- C:\WINDOWS\system32\aeinv.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\invagent.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\generaltel.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\devinv.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\centel.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\acmigration.dll
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\aitstatic.exe
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\aepic.dll
2018-03-15 15:20:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2018-03-15 15:20:25 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2018-03-15 15:20:23 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2018-03-15 15:20:23 ----A---- C:\WINDOWS\system32\ieframe.dll
2018-03-15 15:20:22 ----A---- C:\WINDOWS\system32\jscript9.dll
2018-03-15 15:20:21 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2018-03-15 15:20:21 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\win32k.sys
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2018-03-15 15:20:19 ----A---- C:\WINDOWS\SYSWOW64\MSVidCtl.dll
2018-03-15 15:20:19 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\SYSWOW64\mmcndmgr.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\wininet.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\mmc.exe
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\authui.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\system32\msi.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\system32\iertutil.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2018-03-15 15:20:16 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\termsrv.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\localspl.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\urlmon.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\jscript.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\certutil.exe
2018-03-15 15:20:14 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\puiobj.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\msfeeds.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2018-03-15 15:20:13 ----A---- C:\WINDOWS\SYSWOW64\certutil.exe
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\scesrv.dll
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\system32\vbscript.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2018-03-15 15:20:11 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\winresume.exe
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\winload.exe
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\hal.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\SYSWOW64\TSpkg.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\TSpkg.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\prnntfy.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\msra.exe
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2018-03-15 15:20:09 ----A---- C:\WINDOWS\SYSWOW64\mmcbase.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\SYSWOW64\cic.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\puiapi.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\mmcbase.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\lsasrv.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\ULIAGPKX.SYS
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\NV_AGP.SYS
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\AGP440.sys
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\zipfldr.dll
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\msisadrv.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\isapnp.sys
2018-03-15 15:20:06 ----A---- C:\WINDOWS\SYSWOW64\zipfldr.dll
2018-03-15 15:20:06 ----A---- C:\WINDOWS\system32\certenc.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\mmcshext.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\certenc.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\system32\credssp.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\system32\cic.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\webcheck.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\mshtmled.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\dxtrans.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\compstui.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\mmcshext.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\iepeers.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\certcli.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\credssp.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\inetcomm.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-stable.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-dev.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-canary.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\DbxSvc.exe

====== List of files/folders modified in the last 1 month ======

2018-03-24 20:05:09 ----D---- C:\Program Files\trend micro
2018-03-24 20:03:04 ----D---- C:\WINDOWS\Prefetch
2018-03-24 20:02:49 ----D---- C:\WINDOWS\Temp
2018-03-24 20:01:03 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2018-03-24 20:00:42 ----D---- C:\WINDOWS\system32\sru
2018-03-24 19:56:19 ----D---- C:\Program Files (x86)\Common Files
2018-03-24 18:23:33 ----D---- C:\Program Files (x86)\IQ Option
2018-03-24 16:27:26 ----D---- C:\AdwCleaner
2018-03-23 21:51:23 ----D---- C:\WINDOWS\Microsoft.NET
2018-03-23 21:41:22 ----D---- C:\WINDOWS\AppReadiness
2018-03-23 21:09:53 ----D---- C:\Program Files (x86)\PicosmosTools
2018-03-23 21:06:49 ----D---- C:\Program Files (x86)\FormatFactory
2018-03-22 21:46:27 ----SHD---- C:\System Volume Information
2018-03-22 21:43:43 ----D---- C:\WINDOWS\system32\config
2018-03-20 19:48:10 ----SHD---- C:\WINDOWS\Installer
2018-03-20 19:48:10 ----SD---- C:\Users\Korki$\AppData\Roaming\Microsoft
2018-03-20 18:01:19 ----D---- C:\WINDOWS\system32\Tasks
2018-03-19 09:36:24 ----D---- C:\WINDOWS\rescache
2018-03-18 20:18:40 ----RD---- C:\WINDOWS\System32
2018-03-18 20:18:40 ----D---- C:\WINDOWS\Inf
2018-03-18 20:18:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2018-03-18 20:13:54 ----D---- C:\WINDOWS\WinSxS
2018-03-18 20:13:49 ----D---- C:\WINDOWS\SysWOW64
2018-03-18 20:12:48 ----D---- C:\WINDOWS\system32\DriverStore
2018-03-18 20:04:25 ----RD---- C:\WINDOWS\ToastData
2018-03-18 20:04:25 ----D---- C:\WINDOWS\system32\appraiser
2018-03-18 20:04:23 ----D---- C:\Program Files\Internet Explorer
2018-03-18 20:04:23 ----D---- C:\Program Files (x86)\Internet Explorer
2018-03-18 20:04:22 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2018-03-18 20:04:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\en-GB
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\cs-CZ
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\Boot
2018-03-18 20:04:16 ----D---- C:\WINDOWS\system32\drivers
2018-03-17 17:07:12 ----D---- C:\WINDOWS\system32\NDF
2018-03-16 22:05:59 ----D---- C:\Program Files (x86)\Dropbox
2018-03-16 20:17:24 ----D---- C:\WINDOWS
2018-03-16 20:17:19 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2018-03-16 20:15:29 ----D---- C:\Program Files (x86)\Microsoft Office
2018-03-15 20:47:05 ----D---- C:\WINDOWS\CbsTemp
2018-03-15 20:46:06 ----D---- C:\WINDOWS\system32\MRT
2018-03-15 20:42:52 ----D---- C:\WINDOWS\debug
2018-03-15 20:42:45 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2018-03-15 20:42:36 ----AC---- C:\WINDOWS\system32\MRT.exe
2018-03-14 19:56:41 ----D---- C:\WINDOWS\system32\Macromed
2018-03-14 19:56:37 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2018-03-14 19:55:18 ----D---- C:\WINDOWS\system32\catroot2
2018-03-12 21:30:06 ----D---- C:\Users\Korki$\AppData\Roaming\vlc
2018-03-12 19:42:15 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-12 19:42:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-03-10 00:12:53 ----D---- C:\Program Files\Pale Moon
2018-03-04 19:23:09 ----D---- C:\WINDOWS\system32\wbem

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [2018-01-19 107328]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-12-11 652344]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2017-06-30 381608]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2018-01-19 134368]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2018-01-19 180088]
R1 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2018-01-19 81880]
R1 epfwwfp;epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [2018-01-19 106304]
R1 StarPortLite;@oem46.inf,%DeviceDesc%;StarPort Storage Controller (Lite); C:\WINDOWS\System32\drivers\StarPortLite.sys [2013-02-04 120704]
R2 ekbdflt;ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [2018-01-19 50744]
R3 bcbtums;@oem38.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM42RLY;BCM42RLY; C:\WINDOWS\system32\drivers\BCM42RLY.sys [2013-02-01 23760]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-22 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2017-07-06 119296]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-22 81920]
R3 btwampfl;@oem38.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2014-02-04 166616]
R3 btwaudio;@oem16.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2013-03-15 186584]
R3 btwavdt;@oem17.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\System32\drivers\btwavdt.sys [2013-03-15 227032]
R3 btwl2cap;@oem3.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-26 40248]
R3 btwpanfl;BTW PAN filter driver; \??\C:\WINDOWS\system32\drivers\btwpanfl.sys [2013-01-20 44912]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2013-03-15 22744]
R3 ETD;@oem6.inf,%PS2.DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-03-05 356752]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-03-26 3376200]
R3 IntcDAud;@oem12.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-03-12 342528]
R3 iwdbus;@oem24.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 LMDriver;@oem2.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys [2013-01-10 21360]
R3 MEIx64;@oem15.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-13 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-05 11273504]
R3 RadioShim;@oem2.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys [2013-01-10 15704]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2015-08-01 167424]
R3 RSP2STOR;@oem9.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2013-01-23 288328]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-22 212736]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2018-02-15 15872]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-08-01 1201664]
S3 dbx;dbx; C:\WINDOWS\system32\DRIVERS\dbx.sys []
S3 dc3d;@oem52.inf,%dc3d.SvcDesc%;MS Hardware Device Detection Driver (USB); C:\WINDOWS\System32\drivers\dc3d.sys [2015-12-09 95024]
S3 dg_ssudbus;@oem48.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 ggflt;@oem40.inf,%SvcFltDesc%;SOMC USB Flash Driver Filter; C:\WINDOWS\System32\drivers\ggflt.sys [2016-02-17 16088]
S3 ggsemc;@oem38.inf,%SvcDesc%;SEMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsemc.sys [2013-02-13 27760]
S3 ggsomc;@oem40.inf,%SvcDesc%;SOMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsomc.sys [2016-02-17 30424]
S3 mfencrk;McAfee Inc. mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [2014-09-19 96600]
S3 ssudmdm;@oem57.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-11-22 44544]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-02-09 83984]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2013-03-22 959192]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2013-02-19 2615368]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2018-03-12 7962288]
R2 DbxSvc;DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [2018-03-15 51024]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2017-12-18 1940584]
R2 EzelSvc;EZel Sensor Service; C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe [2013-04-23 213032]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-11-15 2468496]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 IntelBCAsvc;Intel(R) Biometric and Context Agent Service; C:\Program Files\Intel\BCA\pabeSvc64.exe [2016-05-06 3026584]
R2 IQOptionUpdater;IQOptionUpdater; C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe [2018-03-22 2960904]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-14 165336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-14 279000]
R2 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2013-03-15 431656]
R2 NAUpdate;Nero Update; c:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-13 769432]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-08-29 920864]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2014-09-29 45056]
R2 Sage AutoUpdate Manager Service;Sage AutoUpdate Manager Service; C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe [2012-07-05 8192]
R2 Sage SData Service;Sage SData Service; C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe [2012-05-17 53248]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-08-25 7534864]
R2 TrueKey;Intel Security True Key; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [2016-07-22 908256]
R2 TrueKeyScheduler;Intel Security True Key Scheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [2016-07-22 15736]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-01-14 366040]
R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2013-03-15 662088]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 BcmBtRSupport;@oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04 143144]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S2 MxService;MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [2017-11-01 143648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-14 272384]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll" = %SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04 143144]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-03-04 194512]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2018-03-12 211632]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2014-09-29 65536]
S3 TrueKeyServiceHelper;Intel Security True Key Helper Service; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [2016-07-22 86864]

-----------------EOF-----------------

korkis
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 157
Registrován: 16 zář 2007 14:37
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#6 Příspěvek od korkis »

Logfile of random's system information tool 1.16 (written by random/random)
Run by Korki$ at 2018-03-24 20:05:08
Microsoft Windows 8.1
System drive C: has 22 GB (9%) free of 231 GB
Total RAM: 8007 MB (66% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:05:10, on 24/03/2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18817)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\Korki$_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer13.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: True Key Helper - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O2 - BHO: (no name) - {13D67BB7-DB5F-48AA-884D-7A5D94168509} - (no file)
O3 - Toolbar: True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Discord] C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
O4 - HKUS\S-1-5-18\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'Default user')
O4 - Startup: Facebook Gameroom.lnk = Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
O4 - Startup: Send to OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: intu-help-qb8 - {CD17C364-2EC8-4929-91A9-C4839A20E909} - C:\Program Files (x86)\Intuit\QuickBooks 2015\HelpAsyncPluggableProtocol.dll
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: @oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: EZel Sensor Service (EzelSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Biometric and Context Agent Service (IntelBCAsvc) - Intel(R) Corporation - C:\Program Files\Intel\BCA\pabeSvc64.exe
O23 - Service: IQOptionUpdater - Unknown owner - C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MxService - Maxthon International ltd. - C:\Program Files (x86)\Maxthon5\Bin\MxService.exe
O23 - Service: Nero Update (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Sage SData Service - Sage (UK) Limited - C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: Intel Security True Key (TrueKey) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
O23 - Service: Intel Security True Key Scheduler (TrueKeyScheduler) - McAfee, Inc. - C:\Program Files\TrueKey\McTkSchedulerService.exe
O23 - Service: Intel Security True Key Helper Service (TrueKeyServiceHelper) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Xperia Companion Service (XperiaCompanionService) - Sony - C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe

--
End of file - 14683 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\system32\nvvsvc.exe -session
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d755c926-b629-416f-a234-ae4c85eda462 -SystemEventPortName:HostProcess-17b387cc-1daa-414d-b543-2e5f4a02343e -IoCancelEventPortName:HostProcess-3220a7e5-9a38-4332-adf7-008a8a275f36 -NonStateChangingEventPortName:HostProcess-a4a2c066-9736-42ea-9f42-743e3a96ff86 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c0894152-d8ef-4a81-ad3c-96b664a54bf1 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\DbxSvc.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\system32\dashost.exe
"C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Intel\BCA\pabeSvc64.exe"
C:\Program Files (x86)\IQ Option\IQOptionUpdater.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe"
"C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe"
"C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe"
"C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\WINDOWS\system32\taskeng.exe
"C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe"
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\OEM\EzelSensorBehavior\EzelSensorBehavior.exe
C:\OEM\EzelSensorBehavior\EzelAudio.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Dolby PCEE4\pcee4.exe" -autostart
"C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-76eebdc0-1aba-4764-84a2-cb39f8355ec7 -SystemEventPortName:HostProcess-0966df82-1f6d-4021-ae94-4097a0cb119c -IoCancelEventPortName:HostProcess-fca1c2fe-3e7b-4b90-a35c-28422f7c0730 -NonStateChangingEventPortName:HostProcess-2a7c7cab-db79-42bf-bc09-8d14ff5799f6 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e9e2ddd2-1e35-4f18-a733-c5a8d4e1d926 -DeviceGroupId:WpdFsGroup
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\WINDOWS\system32\igfxEM.exe
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
"C:\Program Files\Acer\Acer Launch Manager\LMTray.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe"
"C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Elantech\ETDTouch.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Program Files\Greenshot\Greenshot.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
"C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe" fbgames://windows_startup/
"C:\WINDOWS\system32\NOTEPAD.EXE" C:\AdwCleaner\AdwCleaner[C1].txt
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Korki$\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x118,0x11c,0x120,0x114,0x124,0x7ffd7829f1e8,0x7ffd7829f1f8,0x7ffd7829f208
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3504 --on-initialized-event-handle=460 --parent-handle=472 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --gpu-preferences=KAAAAAAAAAAABwAAAQAAAAAAAAAAAGAAAQAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --gpu-vendor-id=0x8086 --gpu-device-id=0x0166 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3958 --gpu-driver-date=9-30-2014 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x0fe4 --service-request-channel-token=388285C2DC37730976745679B36C93BB --mojo-platform-channel-handle=1336 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=96697E51F03D59A2FA376308C67C2A74 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=96697E51F03D59A2FA376308C67C2A74 --renderer-client-id=3 --mojo-platform-channel-handle=2496 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=C07D7E2A3CE3D6ED2A5791EA10A0A0F3 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=C07D7E2A3CE3D6ED2A5791EA10A0A0F3 --renderer-client-id=4 --mojo-platform-channel-handle=3080 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=3DDDC01CB9F857865E34D0542BD204B5 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=3DDDC01CB9F857865E34D0542BD204B5 --renderer-client-id=5 --mojo-platform-channel-handle=3244 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=36EDAAA6232C74159BD77E4F4FEB8967 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=36EDAAA6232C74159BD77E4F4FEB8967 --renderer-client-id=6 --mojo-platform-channel-handle=3376 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=ED7D0D226F1F8BD31BBD57E1459350B7 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=ED7D0D226F1F8BD31BBD57E1459350B7 --renderer-client-id=7 --mojo-platform-channel-handle=3408 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=0E403F4902263AC8A0D65A1370A690A4 --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=0E403F4902263AC8A0D65A1370A690A4 --renderer-client-id=8 --mojo-platform-channel-handle=3544 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=43E4BCE553772CA1760FDF0A755636FB --lang=en-US --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=43E4BCE553772CA1760FDF0A755636FB --renderer-client-id=9 --mojo-platform-channel-handle=3556 /prefetch:1
C:\WINDOWS\system32\cmd.exe /d /c "C:/Program Files (x86)/FreeDownloadManager.ORG/Free Download Manager/browsernativehost.exe" chrome-extension://ahmpjcflkgiildlgicmcieglgoilbfdp/ --parent-window=0 < \\.\pipe\chrome.nativeMessaging.in.4f1b71e1e69a248b > \\.\pipe\chrome.nativeMessaging.out.4f1b71e1e69a248b
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=1A81F4C6A38884F7A80C2D8626B1DA2B --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=1A81F4C6A38884F7A80C2D8626B1DA2B --renderer-client-id=22 --mojo-platform-channel-handle=7852 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=0C09018FD343974F013E64906E8F067C --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=0C09018FD343974F013E64906E8F067C --renderer-client-id=24 --mojo-platform-channel-handle=7412 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=BC11A2165A25EB8BB7DB15AAA375B8BD --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=BC11A2165A25EB8BB7DB15AAA375B8BD --renderer-client-id=21 --mojo-platform-channel-handle=7636 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=EAE26D93592428BCE9712E9EE67A11C4 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=EAE26D93592428BCE9712E9EE67A11C4 --renderer-client-id=26 --mojo-platform-channel-handle=8896 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1320,12598738406800816246,336758549970992759,131072 --service-pipe-token=5960AE94937CB2F700277069F1FD6247 --lang=en-US --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --enable-compositor-image-animations --service-request-channel-token=5960AE94937CB2F700277069F1FD6247 --renderer-client-id=28 --mojo-platform-channel-handle=9788 /prefetch:1
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
"C:\Program Files\TrueKey\McTkSchedulerService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
C:\WINDOWS\system32\igfxext.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.18384_none_fa1d93c39b41b41a\TiWorker.exe -Embedding
"C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584
"C:\Users\Korki$\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

====== Scheduled tasks folder ======

C:\WINDOWS\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Acer Aspire R7 Tutorial - "C:\ProgramData\OEM\Acer Aspire R7 Tutorial\EzelToastNotificationAgent.exe"
C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player NPAPI Notifier - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe -check plugin
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\ALU - C:\Program Files (x86)\Acer\Live Updater\updater.exe -auto
C:\WINDOWS\system32\tasks\ALUAgent - C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe
C:\WINDOWS\system32\tasks\AutoPico Daily Restart - "C:\Program Files\KMSpico\AutoPico.exe" /silent
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\DeviceDetector - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\WINDOWS\system32\tasks\Dolby Selector - C:\Dolby PCEE4\pcee4.exe -autostart
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineCore - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineUA - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\EZel Sensor Behavior - "C:\Program Files\Acer\Acer Ezel Sensor\Launcher.exe"
C:\WINDOWS\system32\tasks\FreeDownloadManagerNetworkMonitor - "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\HIDMonitor - C:\Program Files\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\WINDOWS\system32\tasks\IQOptionUpdateTask - C:\Program Files (x86)\IQ Option\\IQOptionUpdateTask.exe
C:\WINDOWS\system32\tasks\Launch Manager - "C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe"
C:\WINDOWS\system32\tasks\Launch Screen Grasp_First - "C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
C:\WINDOWS\system32\tasks\Maxthon Update - "C:\Program Files (x86)\Maxthon\Bin\MxEidolon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\Maxthon5 Update - "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\McAfee Remediation (Prepare) - C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe /prepare
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-214140026-2031469655-1353360597-1002 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\Power Management - "C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\WINDOWS\system32\tasks\Prelauncher - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\prelauncher_First - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{0AB33800-4EF1-4641-A068-6DFD21593135} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1002 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1009 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\WINDOWS\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default

"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files (x86)\McAfee\SiteAdvisor


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.144.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.144.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@unity3d.com/UnityPlayer64,version=1.0]
"Description"=Unity Player 4.6.6f2
"Path"=C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\addons.json
SCDL SoundCloud Downloader - extension - scdl@mrvv.net
FlashGot Mass Downloader - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
Skype - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\extensions.json
FlashGot - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} -
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} -
SCDL SoundCloud Downloader - webextension - scdl@mrvv.net -
YouTube Video and Audio Downloader - extension - feca4b87-3be4-43da-a1b1-137c24220968@jetpack -
Pocket - extension - firefox@getpocket.com -
Web Compat - extension - webcompat@mozilla.org -
Application Update Service Helper - extension - aushelper@mozilla.org -
Firefox Screenshots - extension - screenshots@mozilla.org -
Follow-on Search Telemetry - extension - followonsearch@mozilla.com -
Shield Recipe Client - extension - shield-recipe-client@mozilla.org -
Activity Stream - extension - activity-stream@mozilla.org -
Form Autofill - extension - formautofill@mozilla.org -
Photon onboarding - extension - onboarding@mozilla.org -
Skype Click to Call - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} -
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} -

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\pluginreg.dat
Plugin - Shockwave Flash - 28.0.0.161 - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll

=========Google Chrome=========

C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Slides 0.10
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Web Store 0.2
Extension ahmpjcflkgiildlgicmcieglgoilbfdp 1 Free Download Manager Chrome extension 2.1.42
Extension anbfhidldjknonaihbalghlebaijealk 0 Chrome Currency Converter 6.4.5
Extension aohghmighlieiainnegkcijnfilokake 1 Docs 0.10
Extension apdfllckaahabafndbhieahigkjlhalf 1 Google Drive 14.1
Extension bdokagampppgbnjfdlkfpphniapiiifn 0 SPOI Options (Please remove me) 1.8.164.3
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension cfhdojbkjhnklbpkdaibdccddilifddb 0 Adblock Plus 1.13.5
Extension chlffgpmiacpedhhbkiomidkjlcfhogd 1 Pushbullet 339
Extension ciagpekplgpbepdgggflgmahnjgiaced 1 Add to Amazon Wish List 1.0.0.11
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Google Search 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension elicpjhcidhpjomhibiffojpinpmmpil 1 Video Downloader professional 1.98.1
Extension elioihkkcdgakfbahdoddophfngopipi 1 Photo Zoom for Facebook 1.1428.5.3
Extension emjhialibnbffdaijfenohaloaboknmc
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Sheets 1.2
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Docs Offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 0 AdBlock 3.27.0
Extension gklhnpfkcfpkjcihhjbgmhgkcajamlmd 1 Download Ninja 1.8
Extension golhdmegajbopkkhfbjbilfecnjaobod
Extension icchipenjgneldmljlkfmgkpjamhifmf 1 Latest London Weather 1
Extension icokofncdmhjjncknidajbngmbfphpia 1 Smart TV Remote Controller 1.10
Extension igjjkeeamkpihpncmmbgdkhdnjpcfmfb
Extension jieopfhnlbjmbpckpdhfdedccdmngdac 1 Earth 1.6
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.73
Extension lifbcibllhkdhoafpjfnlhfpfgnpldfl 2 Skype Click to Call 7.4.0.9058
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension nbpagnldghgfoolbancepceaanlmhfmd 1 Hotword triggering 0.0.1.4
Extension nckgahadagoaajjgafhacjanaoiihapd 1 Google Hangouts 2018.123.418.2
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.7
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Chrome Web Store Payments 1.0.0.3
Extension nodkcjollmmjidmcnhloaoahmciabnai 1 Video Cutter 1.0.5
Extension obhijjefkkokfaiffkcemldacdabpeei 0 AIO Search 1.6.1
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh 1 Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 6518.129.0.1
Homepage: http://search.ominent.com/ws/?source=9f ... fd52a98d92
default_search_provider.search_url:
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl]
"Path"=C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=MAARJS
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}]
"URL"=http://uk.yhs4.search.yahoo.com/yhs/sea ... earchTerms}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=MAARJS

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-03-04 207016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-09-26 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-09-26 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4B8786-5502-4803-8EBC-F652A1153BB6}]
True Key Helper - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13D67BB7-DB5F-48AA-884D-7A5D94168509}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - True Key - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-03-26 13449288]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-03-08 1278024]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-10-01 448912]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2013-02-04 10592256]
"Greenshot"=C:\Program Files\Greenshot\Greenshot.exe [2015-04-19 540672]
"egui"=C:\Program Files\ESET\ESET Smart Security\ecmds.exe [2017-12-18 324352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2013-12-17 5973272]
"Discord"=C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe [2018-01-08 57821176]
"GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2018-03-20 1589592]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Intuit SyncManager"=C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [2014-09-29 3775800]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-03-15 3567936]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-07-21 587288]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
QuickBooks Update Agent.lnk - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
QuickBooks_Standard_21.lnk - C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE

C:\Users\Korki$\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Facebook Gameroom.lnk - C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
Send to OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages" = scecli
C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2018-03-18 20:13:49 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2018-03-15 15:20:48 ----A---- C:\WINDOWS\system32\appraiser.dll
2018-03-15 15:20:48 ----A---- C:\WINDOWS\system32\aeinv.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\invagent.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\generaltel.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\devinv.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\centel.dll
2018-03-15 15:20:47 ----A---- C:\WINDOWS\system32\acmigration.dll
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\aitstatic.exe
2018-03-15 15:20:46 ----A---- C:\WINDOWS\system32\aepic.dll
2018-03-15 15:20:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2018-03-15 15:20:25 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2018-03-15 15:20:23 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2018-03-15 15:20:23 ----A---- C:\WINDOWS\system32\ieframe.dll
2018-03-15 15:20:22 ----A---- C:\WINDOWS\system32\jscript9.dll
2018-03-15 15:20:21 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2018-03-15 15:20:21 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\win32k.sys
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2018-03-15 15:20:20 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2018-03-15 15:20:19 ----A---- C:\WINDOWS\SYSWOW64\MSVidCtl.dll
2018-03-15 15:20:19 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\SYSWOW64\mmcndmgr.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\wininet.dll
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\mmc.exe
2018-03-15 15:20:18 ----A---- C:\WINDOWS\system32\authui.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\system32\msi.dll
2018-03-15 15:20:17 ----A---- C:\WINDOWS\system32\iertutil.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2018-03-15 15:20:16 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\termsrv.dll
2018-03-15 15:20:16 ----A---- C:\WINDOWS\system32\localspl.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\urlmon.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\jscript.dll
2018-03-15 15:20:15 ----A---- C:\WINDOWS\system32\certutil.exe
2018-03-15 15:20:14 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\puiobj.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\msfeeds.dll
2018-03-15 15:20:14 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2018-03-15 15:20:13 ----A---- C:\WINDOWS\SYSWOW64\certutil.exe
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\scesrv.dll
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2018-03-15 15:20:13 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\system32\vbscript.dll
2018-03-15 15:20:12 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2018-03-15 15:20:11 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\winresume.exe
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\winload.exe
2018-03-15 15:20:11 ----A---- C:\WINDOWS\system32\hal.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\SYSWOW64\TSpkg.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\TSpkg.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\prnntfy.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\msra.exe
2018-03-15 15:20:10 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2018-03-15 15:20:09 ----A---- C:\WINDOWS\SYSWOW64\mmcbase.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\SYSWOW64\cic.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\puiapi.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\mmcbase.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\lsasrv.dll
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\ULIAGPKX.SYS
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\NV_AGP.SYS
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\AGP440.sys
2018-03-15 15:20:09 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\zipfldr.dll
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\msisadrv.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2018-03-15 15:20:08 ----A---- C:\WINDOWS\system32\drivers\isapnp.sys
2018-03-15 15:20:06 ----A---- C:\WINDOWS\SYSWOW64\zipfldr.dll
2018-03-15 15:20:06 ----A---- C:\WINDOWS\system32\certenc.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\mmcshext.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\SYSWOW64\certenc.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\system32\credssp.dll
2018-03-15 15:20:05 ----A---- C:\WINDOWS\system32\cic.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\webcheck.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\mshtmled.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\dxtrans.dll
2018-03-15 15:20:04 ----A---- C:\WINDOWS\system32\compstui.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\mmcshext.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\iepeers.dll
2018-03-15 15:20:03 ----A---- C:\WINDOWS\system32\certcli.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\SYSWOW64\credssp.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\inetcomm.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2018-03-15 15:20:02 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-stable.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-dev.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-canary.sys
2018-03-15 11:50:28 ----A---- C:\WINDOWS\system32\DbxSvc.exe

====== List of files/folders modified in the last 1 month ======

2018-03-24 20:05:09 ----D---- C:\Program Files\trend micro
2018-03-24 20:03:04 ----D---- C:\WINDOWS\Prefetch
2018-03-24 20:02:49 ----D---- C:\WINDOWS\Temp
2018-03-24 20:01:03 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2018-03-24 20:00:42 ----D---- C:\WINDOWS\system32\sru
2018-03-24 19:56:19 ----D---- C:\Program Files (x86)\Common Files
2018-03-24 18:23:33 ----D---- C:\Program Files (x86)\IQ Option
2018-03-24 16:27:26 ----D---- C:\AdwCleaner
2018-03-23 21:51:23 ----D---- C:\WINDOWS\Microsoft.NET
2018-03-23 21:41:22 ----D---- C:\WINDOWS\AppReadiness
2018-03-23 21:09:53 ----D---- C:\Program Files (x86)\PicosmosTools
2018-03-23 21:06:49 ----D---- C:\Program Files (x86)\FormatFactory
2018-03-22 21:46:27 ----SHD---- C:\System Volume Information
2018-03-22 21:43:43 ----D---- C:\WINDOWS\system32\config
2018-03-20 19:48:10 ----SHD---- C:\WINDOWS\Installer
2018-03-20 19:48:10 ----SD---- C:\Users\Korki$\AppData\Roaming\Microsoft
2018-03-20 18:01:19 ----D---- C:\WINDOWS\system32\Tasks
2018-03-19 09:36:24 ----D---- C:\WINDOWS\rescache
2018-03-18 20:18:40 ----RD---- C:\WINDOWS\System32
2018-03-18 20:18:40 ----D---- C:\WINDOWS\Inf
2018-03-18 20:18:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2018-03-18 20:13:54 ----D---- C:\WINDOWS\WinSxS
2018-03-18 20:13:49 ----D---- C:\WINDOWS\SysWOW64
2018-03-18 20:12:48 ----D---- C:\WINDOWS\system32\DriverStore
2018-03-18 20:04:25 ----RD---- C:\WINDOWS\ToastData
2018-03-18 20:04:25 ----D---- C:\WINDOWS\system32\appraiser
2018-03-18 20:04:23 ----D---- C:\Program Files\Internet Explorer
2018-03-18 20:04:23 ----D---- C:\Program Files (x86)\Internet Explorer
2018-03-18 20:04:22 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2018-03-18 20:04:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\en-GB
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\cs-CZ
2018-03-18 20:04:22 ----D---- C:\WINDOWS\system32\Boot
2018-03-18 20:04:16 ----D---- C:\WINDOWS\system32\drivers
2018-03-17 17:07:12 ----D---- C:\WINDOWS\system32\NDF
2018-03-16 22:05:59 ----D---- C:\Program Files (x86)\Dropbox
2018-03-16 20:17:24 ----D---- C:\WINDOWS
2018-03-16 20:17:19 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2018-03-16 20:15:29 ----D---- C:\Program Files (x86)\Microsoft Office
2018-03-15 20:47:05 ----D---- C:\WINDOWS\CbsTemp
2018-03-15 20:46:06 ----D---- C:\WINDOWS\system32\MRT
2018-03-15 20:42:52 ----D---- C:\WINDOWS\debug
2018-03-15 20:42:45 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2018-03-15 20:42:36 ----AC---- C:\WINDOWS\system32\MRT.exe
2018-03-14 19:56:41 ----D---- C:\WINDOWS\system32\Macromed
2018-03-14 19:56:37 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2018-03-14 19:55:18 ----D---- C:\WINDOWS\system32\catroot2
2018-03-12 21:30:06 ----D---- C:\Users\Korki$\AppData\Roaming\vlc
2018-03-12 19:42:15 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-12 19:42:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-03-10 00:12:53 ----D---- C:\Program Files\Pale Moon
2018-03-04 19:23:09 ----D---- C:\WINDOWS\system32\wbem

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [2018-01-19 107328]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-12-11 652344]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2017-06-30 381608]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2018-01-19 134368]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2018-01-19 180088]
R1 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2018-01-19 81880]
R1 epfwwfp;epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [2018-01-19 106304]
R1 StarPortLite;@oem46.inf,%DeviceDesc%;StarPort Storage Controller (Lite); C:\WINDOWS\System32\drivers\StarPortLite.sys [2013-02-04 120704]
R2 ekbdflt;ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [2018-01-19 50744]
R3 bcbtums;@oem38.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM42RLY;BCM42RLY; C:\WINDOWS\system32\drivers\BCM42RLY.sys [2013-02-01 23760]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-22 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2017-07-06 119296]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-22 81920]
R3 btwampfl;@oem38.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2014-02-04 166616]
R3 btwaudio;@oem16.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2013-03-15 186584]
R3 btwavdt;@oem17.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\System32\drivers\btwavdt.sys [2013-03-15 227032]
R3 btwl2cap;@oem3.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-26 40248]
R3 btwpanfl;BTW PAN filter driver; \??\C:\WINDOWS\system32\drivers\btwpanfl.sys [2013-01-20 44912]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2013-03-15 22744]
R3 ETD;@oem6.inf,%PS2.DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-03-05 356752]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-03-26 3376200]
R3 IntcDAud;@oem12.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-03-12 342528]
R3 iwdbus;@oem24.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 LMDriver;@oem2.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys [2013-01-10 21360]
R3 MEIx64;@oem15.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-13 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-05 11273504]
R3 RadioShim;@oem2.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys [2013-01-10 15704]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2015-08-01 167424]
R3 RSP2STOR;@oem9.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2013-01-23 288328]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-22 212736]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2018-02-15 15872]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-08-01 1201664]
S3 dbx;dbx; C:\WINDOWS\system32\DRIVERS\dbx.sys []
S3 dc3d;@oem52.inf,%dc3d.SvcDesc%;MS Hardware Device Detection Driver (USB); C:\WINDOWS\System32\drivers\dc3d.sys [2015-12-09 95024]
S3 dg_ssudbus;@oem48.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 ggflt;@oem40.inf,%SvcFltDesc%;SOMC USB Flash Driver Filter; C:\WINDOWS\System32\drivers\ggflt.sys [2016-02-17 16088]
S3 ggsemc;@oem38.inf,%SvcDesc%;SEMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsemc.sys [2013-02-13 27760]
S3 ggsomc;@oem40.inf,%SvcDesc%;SOMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsomc.sys [2016-02-17 30424]
S3 mfencrk;McAfee Inc. mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [2014-09-19 96600]
S3 ssudmdm;@oem57.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-11-22 44544]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-02-09 83984]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2013-03-22 959192]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2013-02-19 2615368]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2018-03-12 7962288]
R2 DbxSvc;DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [2018-03-15 51024]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2017-12-18 1940584]
R2 EzelSvc;EZel Sensor Service; C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe [2013-04-23 213032]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-11-15 2468496]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 IntelBCAsvc;Intel(R) Biometric and Context Agent Service; C:\Program Files\Intel\BCA\pabeSvc64.exe [2016-05-06 3026584]
R2 IQOptionUpdater;IQOptionUpdater; C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe [2018-03-22 2960904]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-14 165336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-14 279000]
R2 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2013-03-15 431656]
R2 NAUpdate;Nero Update; c:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-13 769432]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-08-29 920864]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2014-09-29 45056]
R2 Sage AutoUpdate Manager Service;Sage AutoUpdate Manager Service; C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe [2012-07-05 8192]
R2 Sage SData Service;Sage SData Service; C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe [2012-05-17 53248]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-08-25 7534864]
R2 TrueKey;Intel Security True Key; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [2016-07-22 908256]
R2 TrueKeyScheduler;Intel Security True Key Scheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [2016-07-22 15736]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-01-14 366040]
R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2013-03-15 662088]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 BcmBtRSupport;@oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04 143144]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S2 MxService;MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [2017-11-01 143648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-14 272384]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll" = %SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04 143144]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-03-04 194512]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2018-03-12 211632]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2014-09-29 65536]
S3 TrueKeyServiceHelper;Intel Security True Key Helper Service; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [2016-07-22 86864]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118195
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#7 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13D67BB7-DB5F-48AA-884D-7A5D94168509}]/64
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

korkis
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 157
Registrován: 16 zář 2007 14:37
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#8 Příspěvek od korkis »

here we go...

All processes killed
========== FILES ==========
File/Folder C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore not found.
File/Folder C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA not found.
========== REGISTRY ==========
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B2FED01-B505-41B1-B898-2246C9BB5394}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0B2FED01-B505-41B1-B898-2246C9BB5394}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B2FED01-B505-41B1-B898-2246C9BB5394}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13D67BB7-DB5F-48AA-884D-7A5D94168509}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13D67BB7-DB5F-48AA-884D-7A5D94168509}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 313840 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default.migrated

User: filmy

User: Korki$
->Temp folder emptied: 195496421 bytes
->Temporary Internet Files folder emptied: 5631728 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 33602037 bytes
->Google Chrome cache emptied: 302169006 bytes
->Flash cache emptied: 315492 bytes

User: Public

User: rkvmaddfnvyi
->Temp folder emptied: 255445 bytes
->Temporary Internet Files folder emptied: 439801 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 313840 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5142352 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 1132 bytes
RecycleBin emptied: 261601 bytes

Total Files Cleaned = 519.00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Default.migrated

User: filmy

User: Korki$
->Flash cache emptied: 0 bytes

User: Public

User: rkvmaddfnvyi
->Flash cache emptied: 0 bytes

User: UpdatusUser

Total Flash Files Cleaned = 0.00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 03252018_202731

Files moved on Reboot...
C:\Users\Korki$\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Korki$\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 moved successfully.
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 moved successfully.
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 moved successfully.
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 moved successfully.
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Cache\index moved successfully.
C:\WINDOWS\temp\xperiacompanion\admin_log_2018_03_24T19_58_13Z.txt moved successfully.
C:\WINDOWS\temp\KORKIS-20180324-1957.log moved successfully.
File C:\WINDOWS\temp\officeclicktorun.exe_streamserver(201803241957487C4).log not found!

Registry entries deleted on Reboot...


Logfile of random's system information tool 1.16 (written by random/random)
Run by Korki$ at 2018-03-25 20:42:24
Microsoft Windows 8.1
System drive C: has 22 GB (10%) free of 231 GB
Total RAM: 8007 MB (79% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:42:28, on 25/03/2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18817)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\Program Files\trend micro\Korki$_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer13.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: True Key Helper - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O3 - Toolbar: True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Discord] C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
O4 - HKUS\S-1-5-18\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Free Download Manager] "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\fdm.exe" --minimized (User 'Default user')
O4 - Startup: Facebook Gameroom.lnk = Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
O4 - Startup: Send to OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: intu-help-qb8 - {CD17C364-2EC8-4929-91A9-C4839A20E909} - C:\Program Files (x86)\Intuit\QuickBooks 2015\HelpAsyncPluggableProtocol.dll
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: @oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: EZel Sensor Service (EzelSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Biometric and Context Agent Service (IntelBCAsvc) - Intel(R) Corporation - C:\Program Files\Intel\BCA\pabeSvc64.exe
O23 - Service: IQOptionUpdater - Unknown owner - C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MxService - Maxthon International ltd. - C:\Program Files (x86)\Maxthon5\Bin\MxService.exe
O23 - Service: Nero Update (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Sage SData Service - Sage (UK) Limited - C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: Intel Security True Key (TrueKey) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
O23 - Service: Intel Security True Key Scheduler (TrueKeyScheduler) - McAfee, Inc. - C:\Program Files\TrueKey\McTkSchedulerService.exe
O23 - Service: Intel Security True Key Helper Service (TrueKeyServiceHelper) - McAfee, Inc. - C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Xperia Companion Service (XperiaCompanionService) - Sony - C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe

--
End of file - 14200 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\wininit.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
"C:\WINDOWS\system32\nvvsvc.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e6c5286b-568f-463f-a553-31a31a401a39 -SystemEventPortName:HostProcess-aa389f3f-3ce7-452b-93ef-948e51d789a3 -IoCancelEventPortName:HostProcess-8a8308d0-582f-4cb3-a0c4-dd735b3d8821 -NonStateChangingEventPortName:HostProcess-08cd8a13-77c9-4610-bba6-71ead61ada42 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a50e546d-c38f-445c-820f-f7e7578c7fa3 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\DbxSvc.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
C:\WINDOWS\system32\dashost.exe
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files\Intel\BCA\pabeSvc64.exe"
C:\Program Files (x86)\IQ Option\IQOptionUpdater.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe"
"C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe"
"C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe"
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe"
"C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Dolby PCEE4\pcee4.exe" -autostart
"C:\Program Files\Sony\Xperia Companion\Service\XperiaCompanionService.exe"
C:\OEM\EzelSensorBehavior\EzelSensorBehavior.exe
C:\OEM\EzelSensorBehavior\EzelAudio.exe
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe"
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9d65de1f-9e1b-4cf5-839e-eb3bdd722bea -SystemEventPortName:HostProcess-74b3c745-0d67-43be-99b8-77a79ba7252a -IoCancelEventPortName:HostProcess-e1ef3288-d70a-467c-81b0-c7d0a8f6469b -NonStateChangingEventPortName:HostProcess-5b6d8b67-a291-462f-b8ad-3c6019bb6f9c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:19b5969f-def2-4910-9aaf-7484aa0d29e0 -DeviceGroupId:WpdFsGroup
"C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe"
"C:\Program Files\Acer\Acer Launch Manager\LMTray.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\igfxEM.exe
C:\WINDOWS\system32\igfxHK.exe
C:\WINDOWS\system32\igfxTray.exe
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\03252018_202731.log
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Elantech\ETDTouch.exe"
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Program Files\Greenshot\Greenshot.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe" fbgames://windows_startup/
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
"C:\Users\Korki$\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files\TrueKey\McTkSchedulerService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
C:\WINDOWS\system32\igfxext.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"
C:\Users\Korki$\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
"C:\WINDOWS\system32\RunDll32.exe" "C:\WINDOWS\system32\WerConCpl.dll", LaunchErcApp -queuereporting

====== Scheduled tasks folder ======

C:\WINDOWS\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Acer Aspire R7 Tutorial - "C:\ProgramData\OEM\Acer Aspire R7 Tutorial\EzelToastNotificationAgent.exe"
C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player NPAPI Notifier - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_113_Plugin.exe -check plugin
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\ALU - C:\Program Files (x86)\Acer\Live Updater\updater.exe -auto
C:\WINDOWS\system32\tasks\ALUAgent - C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe
C:\WINDOWS\system32\tasks\AutoPico Daily Restart - "C:\Program Files\KMSpico\AutoPico.exe" /silent
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\DeviceDetector - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\WINDOWS\system32\tasks\Dolby Selector - C:\Dolby PCEE4\pcee4.exe -autostart
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineCore - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\system32\tasks\DropboxUpdateTaskMachineUA - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\EZel Sensor Behavior - "C:\Program Files\Acer\Acer Ezel Sensor\Launcher.exe"
C:\WINDOWS\system32\tasks\FreeDownloadManagerNetworkMonitor - "C:\Program Files (x86)\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe"
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\HIDMonitor - C:\Program Files\Acer Incorporated\HID Monitor\HIDMonitor.exe
C:\WINDOWS\system32\tasks\IQOptionUpdateTask - C:\Program Files (x86)\IQ Option\\IQOptionUpdateTask.exe
C:\WINDOWS\system32\tasks\Launch Manager - "C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe"
C:\WINDOWS\system32\tasks\Launch Screen Grasp_First - "C:\Program Files (x86)\Acer\Screen Grasp\Launch Screen Grasp.exe"
C:\WINDOWS\system32\tasks\Maxthon Update - "C:\Program Files (x86)\Maxthon\Bin\MxEidolon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\Maxthon5 Update - "C:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe" -RunScheduledUpdate
C:\WINDOWS\system32\tasks\McAfee Remediation (Prepare) - C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe /prepare
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-214140026-2031469655-1353360597-1002 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\Power Management - "C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\WINDOWS\system32\tasks\Prelauncher - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\prelauncher_First - "C:\Program Files (x86)\Acer\Screen Grasp\InputTask.exe"
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{0AB33800-4EF1-4641-A068-6DFD21593135} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1002 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-214140026-2031469655-1353360597-1009 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\WINDOWS\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default

"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"=C:\Program Files (x86)\McAfee\SiteAdvisor


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.144.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.144.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@unity3d.com/UnityPlayer64,version=1.0]
"Description"=Unity Player 4.6.6f2
"Path"=C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\addons.json
SCDL SoundCloud Downloader - extension - scdl@mrvv.net
FlashGot Mass Downloader - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
Skype - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\extensions.json
FlashGot - extension - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} -
iMacros for Firefox - extension - {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} -
SCDL SoundCloud Downloader - webextension - scdl@mrvv.net -
YouTube Video and Audio Downloader - extension - feca4b87-3be4-43da-a1b1-137c24220968@jetpack -
Pocket - extension - firefox@getpocket.com -
Web Compat - extension - webcompat@mozilla.org -
Application Update Service Helper - extension - aushelper@mozilla.org -
Firefox Screenshots - extension - screenshots@mozilla.org -
Follow-on Search Telemetry - extension - followonsearch@mozilla.com -
Shield Recipe Client - extension - shield-recipe-client@mozilla.org -
Activity Stream - extension - activity-stream@mozilla.org -
Form Autofill - extension - formautofill@mozilla.org -
Photon onboarding - extension - onboarding@mozilla.org -
Skype Click to Call - extension - {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} -
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} -

C:\Users\Korki$\AppData\Roaming\Mozilla\Firefox\Profiles\p5dil3dz.default\pluginreg.dat
Plugin - Shockwave Flash - 28.0.0.161 - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll

=========Google Chrome=========

C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Slides 0.10
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Web Store 0.2
Extension ahmpjcflkgiildlgicmcieglgoilbfdp 1 Free Download Manager Chrome extension 2.1.42
Extension anbfhidldjknonaihbalghlebaijealk 0 Chrome Currency Converter 6.4.5
Extension aohghmighlieiainnegkcijnfilokake 1 Docs 0.10
Extension apdfllckaahabafndbhieahigkjlhalf 1 Google Drive 14.1
Extension bdokagampppgbnjfdlkfpphniapiiifn 0 SPOI Options (Please remove me) 1.8.164.3
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension cfhdojbkjhnklbpkdaibdccddilifddb 0 Adblock Plus 1.13.5
Extension chlffgpmiacpedhhbkiomidkjlcfhogd 1 Pushbullet 339
Extension ciagpekplgpbepdgggflgmahnjgiaced 1 Add to Amazon Wish List 1.0.0.11
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Google Search 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension elicpjhcidhpjomhibiffojpinpmmpil 1 Video Downloader professional 1.98.1
Extension elioihkkcdgakfbahdoddophfngopipi 1 Photo Zoom for Facebook 1.1428.5.3
Extension emjhialibnbffdaijfenohaloaboknmc
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Sheets 1.2
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Docs Offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 0 AdBlock 3.27.0
Extension gklhnpfkcfpkjcihhjbgmhgkcajamlmd 1 Download Ninja 1.8
Extension golhdmegajbopkkhfbjbilfecnjaobod
Extension icchipenjgneldmljlkfmgkpjamhifmf 1 Latest London Weather 1
Extension icokofncdmhjjncknidajbngmbfphpia 1 Smart TV Remote Controller 1.10
Extension igjjkeeamkpihpncmmbgdkhdnjpcfmfb
Extension jieopfhnlbjmbpckpdhfdedccdmngdac 1 Earth 1.6
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.73
Extension lifbcibllhkdhoafpjfnlhfpfgnpldfl 2 Skype Click to Call 7.4.0.9058
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension nbpagnldghgfoolbancepceaanlmhfmd 1 Hotword triggering 0.0.1.4
Extension nckgahadagoaajjgafhacjanaoiihapd 1 Google Hangouts 2018.123.418.2
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.7
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Chrome Web Store Payments 1.0.0.3
Extension nodkcjollmmjidmcnhloaoahmciabnai 1 Video Cutter 1.0.5
Extension obhijjefkkokfaiffkcemldacdabpeei 0 AIO Search 1.6.1
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh 1 Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 6518.129.0.1
Homepage: http://search.ominent.com/ws/?source=9f ... fd52a98d92
default_search_provider.search_url:
C:\Users\Korki$\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl]
"Path"=C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}]
"URL"=http://uk.yhs4.search.yahoo.com/yhs/sea ... earchTerms}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0B2FED01-B505-41B1-B898-2246C9BB5394}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-03-04 207016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-09-26 571968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-09-26 235584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4B8786-5502-4803-8EBC-F652A1153BB6}]
True Key Helper - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - True Key - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-07-15 988400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-03-05 2876816]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-03-26 13449288]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-03-08 1278024]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-10-01 448912]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2013-02-04 10592256]
"Greenshot"=C:\Program Files\Greenshot\Greenshot.exe [2015-04-19 540672]
"egui"=C:\Program Files\ESET\ESET Smart Security\ecmds.exe [2017-12-18 324352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2013-12-17 5973272]
"Discord"=C:\Users\Korki$\AppData\Local\Discord\app-0.0.300\Discord.exe [2018-01-08 57821176]
"GoogleChromeAutoLaunch_EB3CF8C25D82562B5618E776AB154FD6"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2018-03-20 1589592]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Intuit SyncManager"=C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [2014-09-29 3775800]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-03-15 3567936]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
QuickBooks Update Agent.lnk - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
QuickBooks_Standard_21.lnk - C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE

C:\Users\Korki$\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Facebook Gameroom.lnk - C:\Users\Korki$\AppData\Local\Facebook\Games\FacebookGameroom.exe
Send to OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages" = scecli
C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2018-03-25 20:27:31 ----D---- C:\_OTM
2018-03-18 21:13:49 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2018-03-15 16:20:48 ----A---- C:\WINDOWS\system32\appraiser.dll
2018-03-15 16:20:48 ----A---- C:\WINDOWS\system32\aeinv.dll
2018-03-15 16:20:47 ----A---- C:\WINDOWS\system32\invagent.dll
2018-03-15 16:20:47 ----A---- C:\WINDOWS\system32\generaltel.dll
2018-03-15 16:20:47 ----A---- C:\WINDOWS\system32\devinv.dll
2018-03-15 16:20:47 ----A---- C:\WINDOWS\system32\centel.dll
2018-03-15 16:20:47 ----A---- C:\WINDOWS\system32\acmigration.dll
2018-03-15 16:20:46 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2018-03-15 16:20:46 ----A---- C:\WINDOWS\system32\aitstatic.exe
2018-03-15 16:20:46 ----A---- C:\WINDOWS\system32\aepic.dll
2018-03-15 16:20:26 ----A---- C:\WINDOWS\system32\mshtml.dll
2018-03-15 16:20:25 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2018-03-15 16:20:23 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2018-03-15 16:20:23 ----A---- C:\WINDOWS\system32\ieframe.dll
2018-03-15 16:20:22 ----A---- C:\WINDOWS\system32\jscript9.dll
2018-03-15 16:20:21 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2018-03-15 16:20:21 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2018-03-15 16:20:20 ----A---- C:\WINDOWS\system32\win32k.sys
2018-03-15 16:20:20 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2018-03-15 16:20:20 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2018-03-15 16:20:19 ----A---- C:\WINDOWS\SYSWOW64\MSVidCtl.dll
2018-03-15 16:20:19 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2018-03-15 16:20:18 ----A---- C:\WINDOWS\SYSWOW64\mmcndmgr.dll
2018-03-15 16:20:18 ----A---- C:\WINDOWS\system32\wininet.dll
2018-03-15 16:20:18 ----A---- C:\WINDOWS\system32\mmc.exe
2018-03-15 16:20:18 ----A---- C:\WINDOWS\system32\authui.dll
2018-03-15 16:20:17 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2018-03-15 16:20:17 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2018-03-15 16:20:17 ----A---- C:\WINDOWS\system32\msi.dll
2018-03-15 16:20:17 ----A---- C:\WINDOWS\system32\iertutil.dll
2018-03-15 16:20:16 ----A---- C:\WINDOWS\SYSWOW64\mmc.exe
2018-03-15 16:20:16 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2018-03-15 16:20:16 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2018-03-15 16:20:16 ----A---- C:\WINDOWS\system32\termsrv.dll
2018-03-15 16:20:16 ----A---- C:\WINDOWS\system32\localspl.dll
2018-03-15 16:20:15 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2018-03-15 16:20:15 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2018-03-15 16:20:15 ----A---- C:\WINDOWS\system32\urlmon.dll
2018-03-15 16:20:15 ----A---- C:\WINDOWS\system32\jscript.dll
2018-03-15 16:20:15 ----A---- C:\WINDOWS\system32\certutil.exe
2018-03-15 16:20:14 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2018-03-15 16:20:14 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2018-03-15 16:20:14 ----A---- C:\WINDOWS\system32\puiobj.dll
2018-03-15 16:20:14 ----A---- C:\WINDOWS\system32\msfeeds.dll
2018-03-15 16:20:14 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2018-03-15 16:20:13 ----A---- C:\WINDOWS\SYSWOW64\certutil.exe
2018-03-15 16:20:13 ----A---- C:\WINDOWS\system32\scesrv.dll
2018-03-15 16:20:13 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2018-03-15 16:20:13 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2018-03-15 16:20:12 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2018-03-15 16:20:12 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2018-03-15 16:20:12 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2018-03-15 16:20:12 ----A---- C:\WINDOWS\system32\vbscript.dll
2018-03-15 16:20:12 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2018-03-15 16:20:11 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2018-03-15 16:20:11 ----A---- C:\WINDOWS\system32\winresume.exe
2018-03-15 16:20:11 ----A---- C:\WINDOWS\system32\winload.exe
2018-03-15 16:20:11 ----A---- C:\WINDOWS\system32\hal.dll
2018-03-15 16:20:10 ----A---- C:\WINDOWS\SYSWOW64\TSpkg.dll
2018-03-15 16:20:10 ----A---- C:\WINDOWS\system32\TSpkg.dll
2018-03-15 16:20:10 ----A---- C:\WINDOWS\system32\prnntfy.dll
2018-03-15 16:20:10 ----A---- C:\WINDOWS\system32\ntdll.dll
2018-03-15 16:20:10 ----A---- C:\WINDOWS\system32\msra.exe
2018-03-15 16:20:10 ----A---- C:\WINDOWS\system32\drivers\msiscsi.sys
2018-03-15 16:20:09 ----A---- C:\WINDOWS\SYSWOW64\mmcbase.dll
2018-03-15 16:20:09 ----A---- C:\WINDOWS\SYSWOW64\cic.dll
2018-03-15 16:20:09 ----A---- C:\WINDOWS\system32\puiapi.dll
2018-03-15 16:20:09 ----A---- C:\WINDOWS\system32\mmcbase.dll
2018-03-15 16:20:09 ----A---- C:\WINDOWS\system32\lsasrv.dll
2018-03-15 16:20:09 ----A---- C:\WINDOWS\system32\drivers\ULIAGPKX.SYS
2018-03-15 16:20:09 ----A---- C:\WINDOWS\system32\drivers\NV_AGP.SYS
2018-03-15 16:20:09 ----A---- C:\WINDOWS\system32\drivers\AGP440.sys
2018-03-15 16:20:09 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2018-03-15 16:20:08 ----A---- C:\WINDOWS\system32\zipfldr.dll
2018-03-15 16:20:08 ----A---- C:\WINDOWS\system32\drivers\msisadrv.sys
2018-03-15 16:20:08 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2018-03-15 16:20:08 ----A---- C:\WINDOWS\system32\drivers\isapnp.sys
2018-03-15 16:20:06 ----A---- C:\WINDOWS\SYSWOW64\zipfldr.dll
2018-03-15 16:20:06 ----A---- C:\WINDOWS\system32\certenc.dll
2018-03-15 16:20:05 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2018-03-15 16:20:05 ----A---- C:\WINDOWS\SYSWOW64\prnntfy.dll
2018-03-15 16:20:05 ----A---- C:\WINDOWS\SYSWOW64\mmcshext.dll
2018-03-15 16:20:05 ----A---- C:\WINDOWS\SYSWOW64\certenc.dll
2018-03-15 16:20:05 ----A---- C:\WINDOWS\system32\credssp.dll
2018-03-15 16:20:05 ----A---- C:\WINDOWS\system32\cic.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\system32\webcheck.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\system32\mshtmled.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\system32\dxtrans.dll
2018-03-15 16:20:04 ----A---- C:\WINDOWS\system32\compstui.dll
2018-03-15 16:20:03 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2018-03-15 16:20:03 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2018-03-15 16:20:03 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2018-03-15 16:20:03 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2018-03-15 16:20:03 ----A---- C:\WINDOWS\system32\mmcshext.dll
2018-03-15 16:20:03 ----A---- C:\WINDOWS\system32\iepeers.dll
2018-03-15 16:20:03 ----A---- C:\WINDOWS\system32\certcli.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\SYSWOW64\credssp.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\system32\inetcomm.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2018-03-15 16:20:02 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2018-03-15 12:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-stable.sys
2018-03-15 12:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-dev.sys
2018-03-15 12:50:28 ----A---- C:\WINDOWS\system32\drivers\dbx-canary.sys
2018-03-15 12:50:28 ----A---- C:\WINDOWS\system32\DbxSvc.exe

====== List of files/folders modified in the last 1 month ======

2018-03-25 20:42:27 ----D---- C:\Program Files\trend micro
2018-03-25 20:40:26 ----D---- C:\WINDOWS\Microsoft.NET
2018-03-25 20:35:02 ----RD---- C:\WINDOWS\System32
2018-03-25 20:35:02 ----D---- C:\WINDOWS\Inf
2018-03-25 20:35:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2018-03-25 20:33:39 ----D---- C:\WINDOWS\Temp
2018-03-25 20:32:04 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2018-03-25 20:31:43 ----D---- C:\WINDOWS\Prefetch
2018-03-25 20:00:00 ----D---- C:\WINDOWS\system32\sru
2018-03-25 01:58:10 ----D---- C:\Program Files (x86)\IQ Option
2018-03-24 20:56:19 ----D---- C:\Program Files (x86)\Common Files
2018-03-24 17:27:26 ----D---- C:\AdwCleaner
2018-03-23 22:41:22 ----D---- C:\WINDOWS\AppReadiness
2018-03-23 22:09:53 ----D---- C:\Program Files (x86)\PicosmosTools
2018-03-23 22:06:49 ----D---- C:\Program Files (x86)\FormatFactory
2018-03-22 22:46:27 ----SHD---- C:\System Volume Information
2018-03-22 22:43:43 ----D---- C:\WINDOWS\system32\config
2018-03-20 20:48:10 ----SHD---- C:\WINDOWS\Installer
2018-03-20 20:48:10 ----SD---- C:\Users\Korki$\AppData\Roaming\Microsoft
2018-03-20 19:01:19 ----D---- C:\WINDOWS\system32\Tasks
2018-03-19 10:36:24 ----D---- C:\WINDOWS\rescache
2018-03-18 21:13:54 ----D---- C:\WINDOWS\WinSxS
2018-03-18 21:13:49 ----D---- C:\WINDOWS\SysWOW64
2018-03-18 21:12:48 ----D---- C:\WINDOWS\system32\DriverStore
2018-03-18 21:04:25 ----RD---- C:\WINDOWS\ToastData
2018-03-18 21:04:25 ----D---- C:\WINDOWS\system32\appraiser
2018-03-18 21:04:23 ----D---- C:\Program Files\Internet Explorer
2018-03-18 21:04:23 ----D---- C:\Program Files (x86)\Internet Explorer
2018-03-18 21:04:22 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2018-03-18 21:04:22 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2018-03-18 21:04:22 ----D---- C:\WINDOWS\system32\en-GB
2018-03-18 21:04:22 ----D---- C:\WINDOWS\system32\cs-CZ
2018-03-18 21:04:22 ----D---- C:\WINDOWS\system32\Boot
2018-03-18 21:04:16 ----D---- C:\WINDOWS\system32\drivers
2018-03-17 18:07:12 ----D---- C:\WINDOWS\system32\NDF
2018-03-16 23:05:59 ----D---- C:\Program Files (x86)\Dropbox
2018-03-16 21:17:24 ----D---- C:\WINDOWS
2018-03-16 21:17:19 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2018-03-16 21:15:29 ----D---- C:\Program Files (x86)\Microsoft Office
2018-03-15 21:47:05 ----D---- C:\WINDOWS\CbsTemp
2018-03-15 21:46:06 ----D---- C:\WINDOWS\system32\MRT
2018-03-15 21:42:52 ----D---- C:\WINDOWS\debug
2018-03-15 21:42:45 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2018-03-15 21:42:36 ----AC---- C:\WINDOWS\system32\MRT.exe
2018-03-14 20:56:41 ----D---- C:\WINDOWS\system32\Macromed
2018-03-14 20:56:37 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2018-03-14 20:55:18 ----D---- C:\WINDOWS\system32\catroot2
2018-03-12 22:30:06 ----D---- C:\Users\Korki$\AppData\Roaming\vlc
2018-03-12 20:42:15 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-12 20:42:15 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-03-10 01:12:53 ----D---- C:\Program Files\Pale Moon
2018-03-04 20:23:09 ----D---- C:\WINDOWS\system32\wbem

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 edevmon;edevmon; C:\WINDOWS\system32\DRIVERS\edevmon.sys [2018-01-19 107328]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-12-11 652344]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2017-07-01 381608]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2018-01-19 134368]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2018-01-19 180088]
R1 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2018-01-19 81880]
R1 epfwwfp;epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [2018-01-19 106304]
R1 StarPortLite;@oem46.inf,%DeviceDesc%;StarPort Storage Controller (Lite); C:\WINDOWS\System32\drivers\StarPortLite.sys [2013-02-04 120704]
R2 ekbdflt;ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [2018-01-19 50744]
R3 bcbtums;@oem38.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-11-14 170712]
R3 BCM42RLY;BCM42RLY; C:\WINDOWS\system32\drivers\BCM42RLY.sys [2013-02-01 23760]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2013-07-01 8536752]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-22 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2017-07-06 119296]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-22 81920]
R3 btwampfl;@oem38.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2014-02-04 166616]
R3 btwaudio;@oem16.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2013-03-15 186584]
R3 btwavdt;@oem17.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\System32\drivers\btwavdt.sys [2013-03-15 227032]
R3 btwl2cap;@oem3.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwpanfl;BTW PAN filter driver; \??\C:\WINDOWS\system32\drivers\btwpanfl.sys [2013-01-20 44912]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2013-03-15 22744]
R3 ETD;@oem6.inf,%PS2.DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2013-03-05 356752]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-03-26 3376200]
R3 IntcDAud;@oem12.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-03-12 342528]
R3 iwdbus;@oem24.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 LMDriver;@oem2.inf,%LMDriver.SVCDESC%;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys [2013-01-10 21360]
R3 MEIx64;@oem15.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-13 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-05 11273504]
R3 RadioShim;@oem2.inf,%RadioShim.SVCDESC%;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys [2013-01-10 15704]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2015-08-01 167424]
R3 RSP2STOR;@oem9.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2013-01-23 288328]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;UMDF Reflector service for SensorsHIDClassDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;UMDF Reflector service for SensorsServiceDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2014-11-22 226304]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-22 212736]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2018-02-15 15872]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2015-08-01 1201664]
S3 dbx;dbx; C:\WINDOWS\system32\DRIVERS\dbx.sys []
S3 dc3d;@oem52.inf,%dc3d.SvcDesc%;MS Hardware Device Detection Driver (USB); C:\WINDOWS\System32\drivers\dc3d.sys [2015-12-09 95024]
S3 dg_ssudbus;@oem48.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 ggflt;@oem40.inf,%SvcFltDesc%;SOMC USB Flash Driver Filter; C:\WINDOWS\System32\drivers\ggflt.sys [2016-02-17 16088]
S3 ggsemc;@oem38.inf,%SvcDesc%;SEMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsemc.sys [2013-02-13 27760]
S3 ggsomc;@oem40.inf,%SvcDesc%;SOMC USB Flash Driver; C:\WINDOWS\System32\drivers\ggsomc.sys [2016-02-17 30424]
S3 mfencrk;McAfee Inc. mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [2014-09-19 96600]
S3 ssudmdm;@oem57.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-11-22 44544]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-02-09 83984]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2013-03-22 959192]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2013-02-19 2615368]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2018-03-13 7962288]
R2 DbxSvc;DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [2018-03-15 51024]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2017-12-18 1940584]
R2 EzelSvc;EZel Sensor Service; C:\Program Files\Acer\Acer Ezel Sensor\EzelSvc.exe [2013-04-23 213032]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-11-15 2468496]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160]
R2 IntelBCAsvc;Intel(R) Biometric and Context Agent Service; C:\Program Files\Intel\BCA\pabeSvc64.exe [2016-05-06 3026584]
R2 IQOptionUpdater;IQOptionUpdater; C:\Program Files (x86)\IQ Option\\IQOptionUpdater.exe [2018-03-22 2960904]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-01-14 165336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-01-14 279000]
R2 LMSvc;Launch Manager Service; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [2013-03-15 431656]
R2 NAUpdate;Nero Update; c:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-14 769432]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-08-29 920864]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2014-09-29 45056]
R2 Sage AutoUpdate Manager Service;Sage AutoUpdate Manager Service; C:\Program Files (x86)\Common Files\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe [2012-07-05 8192]
R2 Sage SData Service;Sage SData Service; C:\Program Files (x86)\Common Files\Sage SData\Sage.SData.Service.exe [2012-05-17 53248]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-08-25 7534864]
R2 TrueKey;Intel Security True Key; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [2016-07-22 908256]
R2 TrueKeyScheduler;Intel Security True Key Scheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [2016-07-22 15736]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2013-01-14 366040]
R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2013-03-15 662088]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 BcmBtRSupport;@oem38.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-11-14 2251992]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-05 143144]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S2 MxService;MxService; C:\Program Files (x86)\Maxthon5\Bin\MxService.exe [2017-11-01 143648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-14 272384]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll" = %SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-05 143144]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-01 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-03-04 194512]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2018-03-12 211632]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2014-09-29 65536]
S3 TrueKeyServiceHelper;Intel Security True Key Helper Service; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [2016-07-22 86864]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118195
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#9 Příspěvek od Rudy »

Log by již měl být OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

korkis
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 157
Registrován: 16 zář 2007 14:37
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#10 Příspěvek od korkis »

paráda :) díky moc :wink: :closed:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118195
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Out of the sky... 4 accounts... prosím o kontrolu

#11 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno