Prosím o kontrolu logu
Napsal: 17 čer 2015 13:57
V správcovi úloh mi beží veľa nejakých čínskych procesov.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2015-06-17 14:49:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 30 GB (28%) free of 110 GB
Total RAM: 8154 MB (81% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:50:16, on 17. 6. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe
C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\plugins\QMNetMon\QQPCNetFlow.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRealTimeSpeedup.exe
C:\PROGRAM FILES (X86)\RISING\RAV\RSTRAY.EXE
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hppp&ts ... XXZ2AKY9N1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=dsp ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=dsp ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=91284697_hao_pg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hppp&ts ... XXZ2AKY9N1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=91284697_hao_pg
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BDHOOK - {15DEE173-1BE9-4424-81E0-58A87076E9B1} - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\websafe\WebMonBHO.dll
O2 - BHO: WebGuard BHO Class - {1B2639A9-EE25-4AE7-A2E3-B308F08125C4} - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\WebGuardBHO.dll
O2 - BHO: QPMIEHelper - {50F4150A-48B2-417A-BE4C-C83F580FB904} - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll (file missing)
O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files (x86)\MiuiTab\SupTab.dll (file missing)
O2 - BHO: AFFAC708-93F0-E899-48CB-0B6F848DF109 Class - {AFFAC708-93F0-E899-48CB-0B6F848DF109} - C:\Program Files (x86)\BaiduAddr\{AFFAC708-93F0-E899-48CB-0B6F848DF109}\AddressBar.dll (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Rs] C:\Program Files (x86)\Rs\Rs.exe
O4 - HKLM\..\Run: [RSDTRAY] "C:\Program Files (x86)\Rising\RSD\popwndexe.exe"
O4 - HKLM\..\Run: [baidusdTray] "C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe" -stmd=3
O4 - HKLM\..\Run: [ QQPCTray] "C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe" /regrun
O4 - HKLM\..\Run: [RavTRAY] "C:\Program Files (x86)\Rising\RAV\rstray.exe" -system
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Q_Magazine_-_June_2015.pdf.lnk = C:\ProgramData\{15368ad3-cd1b-67a2-1536-68ad3cd12b4f}\Q_Magazine_-_June_2015.pdf.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: kuwo - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0C} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: BaiduHips - ????????(??)???? - C:\Program Files (x86)\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe
O23 - Service: BDKVRTP Service (BDKVRTP) - ????????(??)???? - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Rsd Service (RsMgrSvc) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe
O23 - Service: Rav Service (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RAV\ravmond.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8319 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe"
"C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe" -r
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRtp.exe" -r
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe" /elevated /regrun
"C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe" -stmd=3
"C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdUProxy64.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\plugins\QMNetMon\QQPCNetFlow.exe" /regrun /elevated
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRealTimeSpeedup.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Rising\RAV\ravmond.exe"
"C:\PROGRAM FILES (X86)\RISING\RAV\RSTRAY.EXE"
taskeng.exe {52C7C255-AF0B-483C-8DB8-81190B9706A2}
"C:\Users\Martin\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Bidaily Synchronize Task[973b].job - c:\programdata\{634e2d5b-2ed3-75ac-634e-e2d5b2edb56c}\download.exe --startup=1 --single
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}]
电脑管家网页防火墙 - C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\TSWebMon64.dat [2015-06-16 414560]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15DEE173-1BE9-4424-81E0-58A87076E9B1}]
WebMonBHO - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\websafe\WebMonBHO.dll [2015-06-08 490376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1B2639A9-EE25-4AE7-A2E3-B308F08125C4}]
WebGuardBHO - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\WebGuardBHO.dll [2015-06-16 490376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}]
Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
LuckyTab Class - C:\Program Files (x86)\MiuiTab\SupTab.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFFAC708-93F0-E899-48CB-0B6F848DF109}]
AFFAC708-93F0-E899-48CB-0B6F848DF109 Class - C:\Program Files (x86)\BaiduAddr\{AFFAC708-93F0-E899-48CB-0B6F848DF109}\AddressBar.dll []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Spotify Web Helper"=C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2015-06-10 2020920]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-11-20 767176]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
"Rs"=C:\Program Files (x86)\Rs\Rs.exe []
"RSDTRAY"=C:\Program Files (x86)\Rising\RSD\popwndexe.exe [2012-09-25 126808]
"baidusdTray"=C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe [2015-06-08 2526216]
" QQPCTray"=C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe [2015-06-16 355296]
"RavTRAY"=C:\Program Files (x86)\Rising\RAV\rstray.exe [2015-06-16 111000]
C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Q_Magazine_-_June_2015.pdf.lnk - C:\ProgramData\{15368ad3-cd1b-67a2-1536-68ad3cd12b4f}\Q_Magazine_-_June_2015.pdf.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-06-17 14:50:06 ----D---- C:\Program Files\trend micro
2015-06-17 14:49:58 ----D---- C:\rsit
2015-06-17 14:43:26 ----D---- C:\ProgramData\TXQMPC
2015-06-17 14:33:01 ----D---- C:\AdwCleaner
2015-06-16 19:31:16 ----N---- C:\Windows\SYSWOW64\vpatch.dll
2015-06-16 19:31:15 ----RD---- C:\RavBin
2015-06-16 19:31:03 ----A---- C:\Windows\SYSWOW64\BsMain.ini
2015-06-16 19:31:01 ----N---- C:\Windows\SYSWOW64\ravext.dll
2015-06-16 19:31:01 ----N---- C:\Windows\system32\ravext64.dll
2015-06-16 19:31:00 ----N---- C:\Windows\SYSWOW64\bsmain.exe
2015-06-16 19:31:00 ----N---- C:\Windows\system32\drivers\hvm.sys
2015-06-16 18:39:32 ----A---- C:\Windows\SYSWOW64\drivers\TS888x64.sys
2015-06-16 18:39:29 ----D---- C:\Program Files\Common Files\Tencent
2015-06-16 18:39:00 ----D---- C:\Program Files (x86)\Definitions
2015-06-16 18:20:09 ----A---- C:\Windows\system32\drivers\TSSKX64.sys
2015-06-16 18:02:09 ----A---- C:\Windows\system32\drivers\TAOKernel64.sys
2015-06-16 18:02:09 ----A---- C:\Windows\system32\drivers\TAOAccelerator64.sys
2015-06-16 18:02:07 ----A---- C:\Windows\system32\drivers\tfsfltX64.sys
2015-06-16 17:58:06 ----D---- C:\Program Files (x86)\Tencent
2015-06-16 17:58:01 ----D---- C:\Users\Martin\AppData\Roaming\Tencent
2015-06-16 17:58:01 ----D---- C:\ProgramData\Tencent
2015-06-16 17:56:36 ----A---- C:\Windows\system32\drivers\BDMWrench_x64.sys
2015-06-16 17:56:36 ----A---- C:\Windows\system32\drivers\BDDefense.sys
2015-06-16 17:56:35 ----A---- C:\Windows\system32\drivers\bd0003.sys
2015-06-16 17:56:34 ----A---- C:\Windows\system32\drivers\BDArKit.SYS
2015-06-16 17:56:33 ----A---- C:\Windows\system32\drivers\bd0002.sys
2015-06-16 17:56:30 ----D---- C:\Users\Martin\AppData\Roaming\Baidu
2015-06-16 17:56:25 ----D---- C:\ProgramData\Baidu
2015-06-16 17:56:25 ----D---- C:\Program Files (x86)\Baidu
2015-06-16 17:54:36 ----RSH---- C:\rising.ini
2015-06-16 17:54:35 ----N---- C:\Windows\system32\drivers\sysmon.sys
2015-06-16 17:54:35 ----N---- C:\Windows\system32\drivers\rsutils.sys
2015-06-16 17:54:35 ----N---- C:\Windows\system32\drivers\rsndisp.sys
2015-06-16 17:54:17 ----D---- C:\ProgramData\Rising
2015-06-16 17:54:17 ----D---- C:\Program Files (x86)\Rising
2015-06-16 17:54:08 ----D---- C:\Program Files (x86)\Rs
2015-06-16 17:53:56 ----A---- C:\Windows\prleth.sys
2015-06-16 17:53:56 ----A---- C:\Windows\hgfs.sys
2015-06-16 17:53:26 ----D---- C:\Program Files (x86)\CutterGeneration
2015-06-16 17:53:02 ----D---- C:\ProgramData\367494974035915134
2015-06-16 16:37:33 ----D---- C:\Users\Martin\AppData\Roaming\Isoplex
2015-06-01 12:27:31 ----D---- C:\Program Files (x86)\One Number
2015-06-01 12:06:59 ----D---- C:\Program Files (x86)\TampaTrim
2015-05-20 21:36:35 ----D---- C:\Users\Martin\AppData\Roaming\AMD
2015-05-20 21:36:09 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2015-05-20 21:35:46 ----D---- C:\ProgramData\Skype
2015-05-20 21:34:59 ----D---- C:\Users\Martin\AppData\Roaming\RHEng
2015-05-20 21:34:45 ----D---- C:\Users\Martin\AppData\Roaming\DivX
2015-05-20 21:32:59 ----D---- C:\ProgramData\DivX
======List of files/folders modified in the last 1 month======
2015-06-17 14:50:12 ----D---- C:\Windows\Temp
2015-06-17 14:50:06 ----RD---- C:\Program Files
2015-06-17 14:43:26 ----HD---- C:\ProgramData
2015-06-17 14:39:45 ----RD---- C:\Program Files (x86)
2015-06-17 14:39:45 ----D---- C:\Program Files (x86)\Common Files
2015-06-17 14:29:42 ----D---- C:\Windows\system32\Tasks
2015-06-16 19:31:16 ----D---- C:\Windows\SysWOW64
2015-06-16 19:31:01 ----D---- C:\Windows\System32
2015-06-16 19:31:00 ----D---- C:\Windows\system32\drivers
2015-06-16 18:47:00 ----SHD---- C:\Windows\Installer
2015-06-16 18:45:18 ----SHD---- C:\Config.Msi
2015-06-16 18:45:17 ----D---- C:\Windows\SYSWOW64\drivers
2015-06-16 18:44:55 ----D---- C:\Windows\inf
2015-06-16 18:44:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-16 18:39:29 ----D---- C:\Program Files\Common Files
2015-06-16 18:38:07 ----D---- C:\Windows
2015-06-16 18:36:46 ----SD---- C:\Users\Martin\AppData\Roaming\Microsoft
2015-06-16 18:36:03 ----SHD---- C:\System Volume Information
2015-06-16 18:20:07 ----D---- C:\Windows\Tasks
2015-06-16 18:08:32 ----D---- C:\Windows\system32\config
2015-06-16 18:02:02 ----RSD---- C:\Windows\Fonts
2015-06-16 17:58:15 ----D---- C:\Windows\winsxs
2015-06-15 20:22:46 ----D---- C:\Users\Martin\AppData\Roaming\Spotify
2015-06-11 11:27:42 ----D---- C:\Program Files (x86)\Opera
2015-06-10 19:46:31 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-06-02 18:21:05 ----A---- C:\Windows\Sandboxie.ini
2015-06-02 11:42:34 ----D---- C:\Windows\system32\catroot2
2015-05-31 10:48:15 ----A---- C:\Windows\WORDPAD.INI
2015-05-26 16:55:13 ----D---- C:\Windows\SoftwareDistribution
2015-05-26 16:49:23 ----D---- C:\Windows\Options
2015-05-26 16:48:12 ----D---- C:\Users\Martin\AppData\Roaming\FunUninstall
2015-05-25 11:23:54 ----D---- C:\Program Files (x86)\Google
2015-05-19 21:05:59 ----D---- C:\Users\Martin\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2012-04-22 213888]
R0 sysmon;sysmon; C:\Windows\system32\DRIVERS\sysmon.sys [2015-06-16 119256]
R1 bd0001;bd0001; C:\Windows\system32\DRIVERS\bd0001.sys [2015-06-08 202704]
R1 bd0002;bd0002; C:\Windows\system32\DRIVERS\bd0002.sys [2015-06-08 198600]
R1 BDDefense;BDDefense; C:\Windows\system32\drivers\BDDefense.sys [2015-06-08 103752]
R1 HyperVM;HyperVM; \??\C:\Windows\system32\drivers\hvm.sys [2015-06-16 41784]
R1 rsutils;rsutils; C:\Windows\system32\DRIVERS\rsutils.sys [2015-06-16 71760]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2012-04-22 60416]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-03 31232]
R3 TSSKX64;TSSKX64; C:\Windows\System32\drivers\tsskx64.sys [2015-06-16 38200]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2012-04-22 18432]
R4 bd0003;bd0003; C:\Windows\system32\DRIVERS\bd0003.sys [2015-06-08 69448]
R4 BDArKit;BAIDU Ark Kit Service; \??\C:\Windows\System32\Drivers\BDArKit.SYS [2015-06-08 152392]
R4 BDMWrench_x64;BDMWrench_x64; C:\Windows\system32\DRIVERS\BDMWrench_x64.sys [2015-06-08 62280]
R4 QMUdisk;QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QMUdisk64.sys [2015-06-16 62264]
R4 QQSysMonX64;QQSysMonX64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQSysMonX64.sys [2015-06-16 129336]
R4 TAOKernelDriver;Tencent Auto Optimize Platform.; C:\Windows\System32\Drivers\TAOKernel64.sys [2015-06-16 174392]
R4 TFsFlt;TFsFlt; C:\Windows\system32\Drivers\TFsFltX64.sys [2015-06-16 87864]
R4 TSCPM;TSCPM; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\tscpm64.sys [2015-06-16 42296]
S1 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S4 TAOAccelerator;Tencent TAOAccelerator driver.; \??\C:\Windows\system32\Drivers\TAOAccelerator64.sys [2015-06-16 99640]
S4 TSSysKit;TSSysKit; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\TSSysKit64.sys [2015-06-16 87352]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BaiduHips;BaiduHips; C:\Program Files (x86)\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe [2015-06-08 64008]
R2 BDKVRTP;BDKVRTP Service; C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe [2015-06-08 805896]
R2 RsMgrSvc;Rsd Service; C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe [2015-06-16 184088]
R2 RsRavMon;Rav Service; C:\Program Files (x86)\Rising\RAV\ravmond.exe [2014-05-15 277552]
R4 QQPCRtp;QQPCMgr RTP Service; C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRTP.exe [2015-06-16 297608]
S2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
S2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2014-11-20 344064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-06 267440]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2015-06-17 14:49:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 30 GB (28%) free of 110 GB
Total RAM: 8154 MB (81% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:50:16, on 17. 6. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe
C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\plugins\QMNetMon\QQPCNetFlow.exe
C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRealTimeSpeedup.exe
C:\PROGRAM FILES (X86)\RISING\RAV\RSTRAY.EXE
C:\Program Files\trend micro\Martin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hppp&ts ... XXZ2AKY9N1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=dsp ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=dsp ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=91284697_hao_pg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.oursurfing.com/?type=hppp&ts ... XXZ2AKY9N1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oursurfing.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oursurfing.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=91284697_hao_pg
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: BDHOOK - {15DEE173-1BE9-4424-81E0-58A87076E9B1} - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\websafe\WebMonBHO.dll
O2 - BHO: WebGuard BHO Class - {1B2639A9-EE25-4AE7-A2E3-B308F08125C4} - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\WebGuardBHO.dll
O2 - BHO: QPMIEHelper - {50F4150A-48B2-417A-BE4C-C83F580FB904} - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll (file missing)
O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files (x86)\MiuiTab\SupTab.dll (file missing)
O2 - BHO: AFFAC708-93F0-E899-48CB-0B6F848DF109 Class - {AFFAC708-93F0-E899-48CB-0B6F848DF109} - C:\Program Files (x86)\BaiduAddr\{AFFAC708-93F0-E899-48CB-0B6F848DF109}\AddressBar.dll (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Rs] C:\Program Files (x86)\Rs\Rs.exe
O4 - HKLM\..\Run: [RSDTRAY] "C:\Program Files (x86)\Rising\RSD\popwndexe.exe"
O4 - HKLM\..\Run: [baidusdTray] "C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe" -stmd=3
O4 - HKLM\..\Run: [ QQPCTray] "C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe" /regrun
O4 - HKLM\..\Run: [RavTRAY] "C:\Program Files (x86)\Rising\RAV\rstray.exe" -system
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Q_Magazine_-_June_2015.pdf.lnk = C:\ProgramData\{15368ad3-cd1b-67a2-1536-68ad3cd12b4f}\Q_Magazine_-_June_2015.pdf.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: kuwo - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0C} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: BaiduHips - ????????(??)???? - C:\Program Files (x86)\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe
O23 - Service: BDKVRTP Service (BDKVRTP) - ????????(??)???? - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Rsd Service (RsMgrSvc) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe
O23 - Service: Rav Service (RsRavMon) - Beijing Rising Information Technology Co., Ltd. - C:\Program Files (x86)\Rising\RAV\ravmond.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8319 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe"
"C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe" -r
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRtp.exe" -r
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe" /elevated /regrun
"C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe" -stmd=3
"C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdUProxy64.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\plugins\QMNetMon\QQPCNetFlow.exe" /regrun /elevated
"C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRealTimeSpeedup.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Rising\RAV\ravmond.exe"
"C:\PROGRAM FILES (X86)\RISING\RAV\RSTRAY.EXE"
taskeng.exe {52C7C255-AF0B-483C-8DB8-81190B9706A2}
"C:\Users\Martin\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Bidaily Synchronize Task[973b].job - c:\programdata\{634e2d5b-2ed3-75ac-634e-e2d5b2edb56c}\download.exe --startup=1 --single
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}]
电脑管家网页防火墙 - C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\TSWebMon64.dat [2015-06-16 414560]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15DEE173-1BE9-4424-81E0-58A87076E9B1}]
WebMonBHO - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\websafe\WebMonBHO.dll [2015-06-08 490376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1B2639A9-EE25-4AE7-A2E3-B308F08125C4}]
WebGuardBHO - C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\WebGuardBHO.dll [2015-06-16 490376]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}]
Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
LuckyTab Class - C:\Program Files (x86)\MiuiTab\SupTab.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFFAC708-93F0-E899-48CB-0B6F848DF109}]
AFFAC708-93F0-E899-48CB-0B6F848DF109 Class - C:\Program Files (x86)\BaiduAddr\{AFFAC708-93F0-E899-48CB-0B6F848DF109}\AddressBar.dll []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Spotify Web Helper"=C:\Users\Martin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2015-06-10 2020920]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-11-20 767176]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]
"Rs"=C:\Program Files (x86)\Rs\Rs.exe []
"RSDTRAY"=C:\Program Files (x86)\Rising\RSD\popwndexe.exe [2012-09-25 126808]
"baidusdTray"=C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdTray.exe [2015-06-08 2526216]
" QQPCTray"=C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCTray.exe [2015-06-16 355296]
"RavTRAY"=C:\Program Files (x86)\Rising\RAV\rstray.exe [2015-06-16 111000]
C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Q_Magazine_-_June_2015.pdf.lnk - C:\ProgramData\{15368ad3-cd1b-67a2-1536-68ad3cd12b4f}\Q_Magazine_-_June_2015.pdf.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-06-17 14:50:06 ----D---- C:\Program Files\trend micro
2015-06-17 14:49:58 ----D---- C:\rsit
2015-06-17 14:43:26 ----D---- C:\ProgramData\TXQMPC
2015-06-17 14:33:01 ----D---- C:\AdwCleaner
2015-06-16 19:31:16 ----N---- C:\Windows\SYSWOW64\vpatch.dll
2015-06-16 19:31:15 ----RD---- C:\RavBin
2015-06-16 19:31:03 ----A---- C:\Windows\SYSWOW64\BsMain.ini
2015-06-16 19:31:01 ----N---- C:\Windows\SYSWOW64\ravext.dll
2015-06-16 19:31:01 ----N---- C:\Windows\system32\ravext64.dll
2015-06-16 19:31:00 ----N---- C:\Windows\SYSWOW64\bsmain.exe
2015-06-16 19:31:00 ----N---- C:\Windows\system32\drivers\hvm.sys
2015-06-16 18:39:32 ----A---- C:\Windows\SYSWOW64\drivers\TS888x64.sys
2015-06-16 18:39:29 ----D---- C:\Program Files\Common Files\Tencent
2015-06-16 18:39:00 ----D---- C:\Program Files (x86)\Definitions
2015-06-16 18:20:09 ----A---- C:\Windows\system32\drivers\TSSKX64.sys
2015-06-16 18:02:09 ----A---- C:\Windows\system32\drivers\TAOKernel64.sys
2015-06-16 18:02:09 ----A---- C:\Windows\system32\drivers\TAOAccelerator64.sys
2015-06-16 18:02:07 ----A---- C:\Windows\system32\drivers\tfsfltX64.sys
2015-06-16 17:58:06 ----D---- C:\Program Files (x86)\Tencent
2015-06-16 17:58:01 ----D---- C:\Users\Martin\AppData\Roaming\Tencent
2015-06-16 17:58:01 ----D---- C:\ProgramData\Tencent
2015-06-16 17:56:36 ----A---- C:\Windows\system32\drivers\BDMWrench_x64.sys
2015-06-16 17:56:36 ----A---- C:\Windows\system32\drivers\BDDefense.sys
2015-06-16 17:56:35 ----A---- C:\Windows\system32\drivers\bd0003.sys
2015-06-16 17:56:34 ----A---- C:\Windows\system32\drivers\BDArKit.SYS
2015-06-16 17:56:33 ----A---- C:\Windows\system32\drivers\bd0002.sys
2015-06-16 17:56:30 ----D---- C:\Users\Martin\AppData\Roaming\Baidu
2015-06-16 17:56:25 ----D---- C:\ProgramData\Baidu
2015-06-16 17:56:25 ----D---- C:\Program Files (x86)\Baidu
2015-06-16 17:54:36 ----RSH---- C:\rising.ini
2015-06-16 17:54:35 ----N---- C:\Windows\system32\drivers\sysmon.sys
2015-06-16 17:54:35 ----N---- C:\Windows\system32\drivers\rsutils.sys
2015-06-16 17:54:35 ----N---- C:\Windows\system32\drivers\rsndisp.sys
2015-06-16 17:54:17 ----D---- C:\ProgramData\Rising
2015-06-16 17:54:17 ----D---- C:\Program Files (x86)\Rising
2015-06-16 17:54:08 ----D---- C:\Program Files (x86)\Rs
2015-06-16 17:53:56 ----A---- C:\Windows\prleth.sys
2015-06-16 17:53:56 ----A---- C:\Windows\hgfs.sys
2015-06-16 17:53:26 ----D---- C:\Program Files (x86)\CutterGeneration
2015-06-16 17:53:02 ----D---- C:\ProgramData\367494974035915134
2015-06-16 16:37:33 ----D---- C:\Users\Martin\AppData\Roaming\Isoplex
2015-06-01 12:27:31 ----D---- C:\Program Files (x86)\One Number
2015-06-01 12:06:59 ----D---- C:\Program Files (x86)\TampaTrim
2015-05-20 21:36:35 ----D---- C:\Users\Martin\AppData\Roaming\AMD
2015-05-20 21:36:09 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2015-05-20 21:35:46 ----D---- C:\ProgramData\Skype
2015-05-20 21:34:59 ----D---- C:\Users\Martin\AppData\Roaming\RHEng
2015-05-20 21:34:45 ----D---- C:\Users\Martin\AppData\Roaming\DivX
2015-05-20 21:32:59 ----D---- C:\ProgramData\DivX
======List of files/folders modified in the last 1 month======
2015-06-17 14:50:12 ----D---- C:\Windows\Temp
2015-06-17 14:50:06 ----RD---- C:\Program Files
2015-06-17 14:43:26 ----HD---- C:\ProgramData
2015-06-17 14:39:45 ----RD---- C:\Program Files (x86)
2015-06-17 14:39:45 ----D---- C:\Program Files (x86)\Common Files
2015-06-17 14:29:42 ----D---- C:\Windows\system32\Tasks
2015-06-16 19:31:16 ----D---- C:\Windows\SysWOW64
2015-06-16 19:31:01 ----D---- C:\Windows\System32
2015-06-16 19:31:00 ----D---- C:\Windows\system32\drivers
2015-06-16 18:47:00 ----SHD---- C:\Windows\Installer
2015-06-16 18:45:18 ----SHD---- C:\Config.Msi
2015-06-16 18:45:17 ----D---- C:\Windows\SYSWOW64\drivers
2015-06-16 18:44:55 ----D---- C:\Windows\inf
2015-06-16 18:44:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-16 18:39:29 ----D---- C:\Program Files\Common Files
2015-06-16 18:38:07 ----D---- C:\Windows
2015-06-16 18:36:46 ----SD---- C:\Users\Martin\AppData\Roaming\Microsoft
2015-06-16 18:36:03 ----SHD---- C:\System Volume Information
2015-06-16 18:20:07 ----D---- C:\Windows\Tasks
2015-06-16 18:08:32 ----D---- C:\Windows\system32\config
2015-06-16 18:02:02 ----RSD---- C:\Windows\Fonts
2015-06-16 17:58:15 ----D---- C:\Windows\winsxs
2015-06-15 20:22:46 ----D---- C:\Users\Martin\AppData\Roaming\Spotify
2015-06-11 11:27:42 ----D---- C:\Program Files (x86)\Opera
2015-06-10 19:46:31 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-06-02 18:21:05 ----A---- C:\Windows\Sandboxie.ini
2015-06-02 11:42:34 ----D---- C:\Windows\system32\catroot2
2015-05-31 10:48:15 ----A---- C:\Windows\WORDPAD.INI
2015-05-26 16:55:13 ----D---- C:\Windows\SoftwareDistribution
2015-05-26 16:49:23 ----D---- C:\Windows\Options
2015-05-26 16:48:12 ----D---- C:\Users\Martin\AppData\Roaming\FunUninstall
2015-05-25 11:23:54 ----D---- C:\Program Files (x86)\Google
2015-05-19 21:05:59 ----D---- C:\Users\Martin\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2012-04-22 213888]
R0 sysmon;sysmon; C:\Windows\system32\DRIVERS\sysmon.sys [2015-06-16 119256]
R1 bd0001;bd0001; C:\Windows\system32\DRIVERS\bd0001.sys [2015-06-08 202704]
R1 bd0002;bd0002; C:\Windows\system32\DRIVERS\bd0002.sys [2015-06-08 198600]
R1 BDDefense;BDDefense; C:\Windows\system32\drivers\BDDefense.sys [2015-06-08 103752]
R1 HyperVM;HyperVM; \??\C:\Windows\system32\drivers\hvm.sys [2015-06-16 41784]
R1 rsutils;rsutils; C:\Windows\system32\DRIVERS\rsutils.sys [2015-06-16 71760]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2012-04-22 60416]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-03 31232]
R3 TSSKX64;TSSKX64; C:\Windows\System32\drivers\tsskx64.sys [2015-06-16 38200]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2012-04-22 18432]
R4 bd0003;bd0003; C:\Windows\system32\DRIVERS\bd0003.sys [2015-06-08 69448]
R4 BDArKit;BAIDU Ark Kit Service; \??\C:\Windows\System32\Drivers\BDArKit.SYS [2015-06-08 152392]
R4 BDMWrench_x64;BDMWrench_x64; C:\Windows\system32\DRIVERS\BDMWrench_x64.sys [2015-06-08 62280]
R4 QMUdisk;QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QMUdisk64.sys [2015-06-16 62264]
R4 QQSysMonX64;QQSysMonX64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQSysMonX64.sys [2015-06-16 129336]
R4 TAOKernelDriver;Tencent Auto Optimize Platform.; C:\Windows\System32\Drivers\TAOKernel64.sys [2015-06-16 174392]
R4 TFsFlt;TFsFlt; C:\Windows\system32\Drivers\TFsFltX64.sys [2015-06-16 87864]
R4 TSCPM;TSCPM; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\tscpm64.sys [2015-06-16 42296]
S1 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S4 TAOAccelerator;Tencent TAOAccelerator driver.; \??\C:\Windows\system32\Drivers\TAOAccelerator64.sys [2015-06-16 99640]
S4 TSSysKit;TSSysKit; \??\C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\TSSysKit64.sys [2015-06-16 87352]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BaiduHips;BaiduHips; C:\Program Files (x86)\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe [2015-06-08 64008]
R2 BDKVRTP;BDKVRTP Service; C:\Program Files (x86)\Baidu\BaiduSd\4.0.0.6697\BaiduSdSvc.exe [2015-06-08 805896]
R2 RsMgrSvc;Rsd Service; C:\Program Files (x86)\Rising\RSD\RsMgrSvc.exe [2015-06-16 184088]
R2 RsRavMon;Rav Service; C:\Program Files (x86)\Rising\RAV\ravmond.exe [2014-05-15 277552]
R4 QQPCRtp;QQPCMgr RTP Service; C:\Program Files (x86)\Tencent\QQPCMgr\10.9.16350.226\QQPCRTP.exe [2015-06-16 297608]
S2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
S2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
S2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2014-11-20 344064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-06 267440]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
-----------------EOF-----------------