Prosím o pomoc
Napsal: 30 lis 2018 13:41
Dobrý den, nainstaloval jsem si novou verzi programu SUPER, který jsem měl rád a místo toho je to hromada nesmyslů, které se snažím zase odinstalovat. Chtěl bych vás poprosit o pomoc. Hijack this se nespustil protože jsem vypnul router aby to nebylo ještě horší. Děkuji
Log z RSIT :
Logfile of random's system information tool 1.09 (written by random/random)
Run by Kuba at 2018-11-30 13:14:45
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 27 GB (17%) free of 153 GB
Total RAM: 8054 MB (66% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Users\Kuba\AppData\Roaming\CRMSvc\CRMSvc.exe"
"taskhost.exe"
C:\Windows\system32\DbxSvc.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe"
rundll32.exe C:\Windows\wxyeltrpuaulyazux.wxy CaH
rundll32.exe C:\Windows\wxyeltrpuaulyazux.wxy CaH
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2020
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
igfxEM.exe
igfxHK.exe
igfxTray.exe
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\firefaceusb.exe"
"C:\Windows\System32\TotalMixFX.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\SunsetScreen\SunsetScreen.exe" /hidewindow
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\System32\rundll32.exe" "C:\Users\Kuba\AppData\Local\ntelix.dll",ntelix
"C:\Windows\System32\rundll32.exe" "C:\Users\Kuba\AppData\Local\ntelix.dll",ntelix
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" -type:crashpad-handler --no-upload-gzip --no-rate-limit --capture-python --no-identify-client-via-url --database=C:\Users\Kuba\AppData\Local\Dropbox\Crashpad --metrics-dir=0 --url=https://d.dropbox.com/report_crashpad_minidump --https-pin=0x23,0xf2,0xed,0xff,0x3e,0xde,0x90,0x25,0x9a,0x9e,0x30,0xf4,0xa,0xf8,0xf9,0x12,0xa5,0xe5,0xb3,0x69,0x4e,0x69,0x38,0x44,0x3,0x41,0xf6,0x6,0xe,0x1,0x4f,0xfa --https-pin=0xaf,0xf9,0x88,0x90,0x6d,0xde,0x12,0x95,0x5d,0x9b,0xeb,0xbf,0x92,0x8f,0xdc,0xc3,0x1c,0xce,0x32,0x8d,0x5b,0x93,0x84,0xf2,0x1c,0x89,0x41,0xca,0x26,0xe2,0x3,0x91 --https-pin=0x5a,0x88,0x96,0x47,0x22,0xe,0x54,0xd6,0xbd,0x8a,0x16,0x81,0x72,0x24,0x52,0xb,0xb5,0xc7,0x8e,0x58,0x98,0x4b,0xd5,0x70,0x50,0x63,0x88,0xb9,0xde,0xf,0x7,0x5f --https-pin=0xfe,0xa2,0xb7,0xd6,0x45,0xfb,0xa7,0x3d,0x75,0x3c,0x1e,0xc9,0xa7,0x87,0xc,0x40,0xe1,0xf7,0xb0,0xc5,0x61,0xe9,0x27,0xb9,0x85,0xbf,0x71,0x18,0x66,0xe3,0x6f,0x22 --https-pin=0x76,0xee,0x85,0x90,0x37,0x4c,0x71,0x54,0x37,0xbb,0xca,0x6b,0xba,0x60,0x28,0xea,0xdd,0xe2,0xdc,0x6d,0xbb,0xb8,0xc3,0xf6,0x10,0xe8,0x51,0xf1,0x1d,0x1a,0xb7,0xf5 --https-pin=0x6d,0xbf,0xae,0x0,0xd3,0x7b,0x9c,0xd7,0x3f,0x8f,0xb4,0x7d,0xe6,0x59,0x17,0xaf,0x0,0xe0,0xdd,0xdf,0x42,0xdb,0xce,0xac,0x20,0xc1,0x7c,0x2,0x75,0xee,0x20,0x95 --https-pin=0x1e,0xa3,0xc5,0xe4,0x3e,0xd6,0x6c,0x2d,0xa2,0x98,0x3a,0x42,0xa4,0xa7,0x9b,0x1e,0x90,0x67,0x86,0xce,0x9f,0x1b,0x58,0x62,0x14,0x19,0xa0,0x4,0x63,0xa8,0x7d,0x38 --https-pin=0x87,0xaf,0x34,0xd6,0x6f,0xb3,0xf2,0xfd,0xf3,0x6e,0x9,0x11,0x1e,0x9a,0xba,0x2f,0x6f,0x44,0xb2,0x7,0xf3,0x86,0x3f,0x3d,0xb,0x54,0xb2,0x50,0x23,0x90,0x9a,0xa5 --https-pin=0xbc,0xfb,0x44,0xaa,0xb9,0xad,0x2,0x10,0x15,0x70,0x6b,0x41,0x21,0xea,0x76,0x1c,0x81,0xc9,0xe8,0x89,0x67,0x59,0xf,0x6f,0x94,0xae,0x74,0x4d,0xc8,0x8b,0x78,0xfb --https-pin=0xab,0x98,0x49,0x52,0x76,0xad,0xf1,0xec,0xaf,0xf2,0x8f,0x35,0xc5,0x30,0x48,0x78,0x1e,0x5c,0x17,0x18,0xda,0xb9,0xc8,0xe6,0x7a,0x50,0x4f,0x4f,0x6a,0x51,0x32,0x8f --https-pin=0x49,0x5,0x46,0x66,0x23,0xab,0x41,0x78,0xbe,0x92,0xac,0x5c,0xbd,0x65,0x84,0xf7,0xa1,0xe1,0x7f,0x27,0x65,0x2d,0x5a,0x85,0xaf,0x89,0x50,0x4e,0xa2,0x39,0xaa,0xaa --https-pin=0x56,0x32,0xd9,0x7b,0xfa,0x77,0x5b,0xf3,0xc9,0x9d,0xde,0xa5,0x2f,0xc2,0x55,0x34,0x10,0x86,0x40,0x16,0x72,0x9c,0x52,0xdd,0x65,0x24,0xc8,0xa9,0xc3,0xb4,0x48,0x9f --https-pin=0x2a,0x8f,0x2d,0x8a,0xf0,0xeb,0x12,0x38,0x98,0xf7,0x4c,0x86,0x6a,0xc3,0xfa,0x66,0x90,0x54,0xe2,0x3c,0x17,0xbc,0x7a,0x95,0xbd,0x2,0x34,0x19,0x2d,0xc6,0x35,0xd0 --https-pin=0x32,0xb6,0x4b,0x66,0x72,0x7a,0x20,0x63,0xe4,0x6,0x6f,0x3b,0x95,0x8c,0xb0,0xaa,0xee,0x57,0x6a,0x5e,0xce,0xfd,0x95,0x33,0x99,0xbb,0x88,0x74,0x73,0x1d,0x95,0x87 --https-pin=0xf5,0x3c,0x22,0x5,0x98,0x17,0xdd,0x96,0xf4,0x0,0x65,0x16,0x39,0xd2,0xf8,0x57,0xe2,0x10,0x70,0xa5,0x9a,0xbe,0xd9,0x7,0x94,0x0,0xd9,0xf6,0x95,0x50,0x69,0x0 --https-pin=0x67,0xdc,0x4f,0x32,0xfa,0x10,0xe7,0xd0,0x1a,0x79,0xa0,0x73,0xaa,0xc,0x9e,0x2,0x12,0xec,0x2f,0xfc,0x3d,0x77,0x9e,0xa,0xa7,0xf9,0xc0,0xf0,0xe1,0xc2,0xc8,0x93 --https-pin=0x19,0x6,0xc6,0x12,0x4d,0xbb,0x43,0x85,0x78,0xd0,0xe,0x6,0x6d,0x50,0x54,0xc6,0xc3,0x7f,0xf,0xa6,0x2,0x8c,0x5,0x54,0x5e,0x9,0x94,0xed,0xda,0xec,0x86,0x29 --https-pin=0x1d,0x75,0xd0,0x83,0x1b,0x9e,0x8,0x85,0x39,0x4d,0x32,0xc7,0xa1,0xbf,0xdb,0x3d,0xbc,0x1c,0x28,0xe2,0xb0,0xe8,0x39,0x1f,0xb1,0x35,0x98,0x1d,0xbc,0x5b,0xa9,0x36 --annotation=host_int_account1_boot=28474061088 --annotation=machine_id=1595302a-1642-4ed3-b227-87ebd588664b --annotation=platform=win --annotation=platform_version=7 --initial-client-data=0xe0,0xe4,0xe8,0xdc,0xec,0x6aa7dda4,0x6aa7ddb4,0x6aa7ddc4
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" -type:exit-monitor -session-token:eeb16034-3a9f-4ee2-9a13-fac079967c15 -target-handle:244 -target-shutdown-event:236 -target-restart-event:220 "-target-command-line:\"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe\" /systemstartup" -python-version:3.5.4 -method:collectupload -handler-pipe:\\.\pipe\crashpad_2384_KDZJIITPLUHCMJXS
"C:\Windows\system32\taskmgr.exe" /4
ctfmon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\ProxyGate\PGNet.exe" /chknet-upd
C:\Windows\system32\cmd.exe /c ""C:\Windows\Microsoft.NET\Framework\v2.0.50727\del.bat""
\??\C:\Windows\system32\conhost.exe "-390643256-1281031488-859664424770272984-140041976674259051411960239831915690712
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\wuauclt.exe"
"taskhost.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\msiexec.exe /V
C:\Windows\system32\wbem\wmiprvse.exe
taskhost.exe $(Arg0)
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Kuba\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\DropboxUpdateTaskMachineCore.job
C:\Windows\tasks\DropboxUpdateTaskMachineUA.job
C:\Windows\tasks\Online Application V2G5.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\77htdns3.default-1478886535918
prefs.js - "browser.startup.homepage" - "http://page-ups.com/all/"
"{29049BEC-CF6D-49FF-8F3F-95D886658152}"=C:\Windows\Installer\{10F78416-E991-4176-98C2-BB92DCD6BD13}\{29049BEC-CF6D-49FF-8F3F-95D886658152}.xpi
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe� Flash� Player 31.0.0.153 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_153.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe� Flash� Player 31.0.0.153 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_153.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocn� slu瀊a pro p鴌hl釟en� k tu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2018-09-13 380904]
"FirefaceUsbTray1"=C:\Windows\system32\firefaceusb.exe [2014-08-12 97792]
"FirefaceMixTray2"=C:\Windows\system32\TotalMixFX.exe [2014-06-14 22900952]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1353680]
"Wondershare Helper Compact.exe"=C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"SunsetScreen"=C:\Program Files (x86)\SunsetScreen\SunsetScreen.exe [2017-07-10 783984]
"6028390"=C:\Users\Kuba\AppData\Roaming\k2pvrhap3nc\b1w3d4nnxul.exe [2018-11-30 554244]
"9658578"=C:\Users\Kuba\AppData\Roaming\15451hedamq\fjorqoanx3i.exe [2018-11-30 554244]
"ntelix"=C:\Users\Kuba\AppData\Local\ntelix.dll [2018-11-30 16384]
"8965497"=C:\Users\Kuba\AppData\Roaming\wim11vgkqpe\mvzq5mb5oyt.exe [2018-11-30 554244]
"8907442"=C:\Users\Kuba\AppData\Roaming\2iab3jajwii\3czl14utddt.exe [2018-11-30 554244]
"6130961"=C:\Users\Kuba\AppData\Roaming\xl50bgvo3tq\mrvd23y1vji.exe [2018-11-30 554244]
"6075169"=C:\Users\Kuba\AppData\Roaming\nsuy20tfyqv\rnzqhsmurak.exe [2018-11-30 554244]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZDWlan.EXE]
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Client Utility\ZDWlan.EXE [2009-01-14 491520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TP-LINK Wireless Configuration Utility.lnk]
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe [2011-08-17 788992]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-11-28 3806016]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2017-09-12 2133728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\ProgramData\Kolnixo\SingleEco.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.I420"=MSH263.DRV
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux8"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux9"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux7"=wdmaud.drv
"VIDC.SP54"=SP5X_32.DLL
"VIDC.SP55"=SP5X_32.DLL
"VIDC.SP56"=SP5X_32.DLL
"VIDC.SP57"=SP5X_32.DLL
"VIDC.SP58"=SP5X_32.DLL
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2018-11-30 13:14:45 ----D---- C:\rsit
2018-11-30 12:58:40 ----D---- C:\Program Files (x86)\DjpYILTWU
2018-11-30 12:57:19 ----D---- C:\Windows\SYSWOW64\SSL
2018-11-30 12:55:50 ----D---- C:\Program Files (x86)\Lavasoft
2018-11-30 12:55:01 ----D---- C:\Program Files (x86)\ProxyGate
2018-11-30 12:54:52 ----D---- C:\ProgramData\Lavasoft
2018-11-30 12:54:41 ----D---- C:\Program Files\5PDUBJ6VHO
2018-11-30 12:54:13 ----D---- C:\Users\Kuba\AppData\Roaming\xl50bgvo3tq
2018-11-30 12:54:06 ----D---- C:\Users\Kuba\AppData\Roaming\nsuy20tfyqv
2018-11-30 12:54:05 ----D---- C:\Users\Kuba\AppData\Roaming\2iab3jajwii
2018-11-30 12:53:45 ----D---- C:\Program Files\1XU1GHZ8LT
2018-11-30 12:52:53 ----D---- C:\Users\Kuba\AppData\Roaming\wim11vgkqpe
2018-11-30 12:52:53 ----D---- C:\Program Files\BJBGG2DL46
2018-11-30 12:52:16 ----D---- C:\Program Files\97EA0VNV5M
2018-11-30 12:47:18 ----D---- C:\ProgramData\Logic Cramble
2018-11-30 12:46:55 ----D---- C:\ProgramData\75f49cc0-6115-0
2018-11-30 12:46:40 ----D---- C:\ProgramData\Kolnixo
2018-11-30 12:46:36 ----D---- C:\ProgramData\75f49cc0-7667-1
2018-11-30 12:46:26 ----D---- C:\ProgramData\423e3873-6901-0
2018-11-30 12:46:15 ----D---- C:\ProgramData\423e3873-58d1-1
2018-11-30 12:46:02 ----D---- C:\ProgramData\b199a7fe-d3aa-4ff9-9d61-b5dd5debd99d
2018-11-30 12:46:00 ----D---- C:\Users\Kuba\AppData\Roaming\One System Care
2018-11-30 12:46:00 ----D---- C:\Program Files (x86)\OneSystemCare
2018-11-30 12:45:12 ----D---- C:\Users\Kuba\AppData\Roaming\15451hedamq
2018-11-30 12:45:06 ----D---- C:\Users\Kuba\AppData\Roaming\CRMSvc
2018-11-30 12:45:00 ----D---- C:\Program Files\8P8WWGG5M8
2018-11-30 12:44:48 ----D---- C:\Program Files\EHXNQX91Y6
2018-11-30 12:44:43 ----D---- C:\Program Files\STXGDJLCBB
2018-11-30 12:44:38 ----D---- C:\Users\Kuba\AppData\Roaming\k2pvrhap3nc
2018-11-30 12:44:34 ----D---- C:\ProgramData\PrefsSecure
2018-11-30 12:44:21 ----D---- C:\Program Files\1K1VXM1KCT
2018-11-30 12:44:20 ----D---- C:\Program Files (x86)\cleanComputerNew
2018-11-30 12:44:14 ----D---- C:\Program Files\J785UGPWRB
2018-11-30 12:44:12 ----D---- C:\Program Files (x86)\bestDownloader
2018-11-30 12:44:06 ----D---- C:\Users\Kuba\AppData\Roaming\Microleaves
2018-11-30 12:43:57 ----D---- C:\Program Files (x86)\tvhjwryp55b
2018-11-30 12:43:57 ----D---- C:\Program Files (x86)\3xcla1myci4
2018-11-30 12:42:51 ----D---- C:\Program Files (x86)\Skaty
2018-11-30 12:42:29 ----D---- C:\Users\Kuba\AppData\Roaming\Browsers
2018-11-30 12:42:28 ----D---- C:\Users\Kuba\AppData\Roaming\SPI
2018-11-29 11:33:44 ----A---- C:\Windows\uninstaller.dat
2018-11-29 11:33:44 ----A---- C:\Windows\MzNjYTZk.exe
2018-11-28 14:09:04 ----A---- C:\Windows\system32\drivers\dbx-stable.sys
2018-11-28 14:09:04 ----A---- C:\Windows\system32\drivers\dbx-dev.sys
2018-11-28 14:09:04 ----A---- C:\Windows\system32\drivers\dbx-canary.sys
2018-11-28 14:09:04 ----A---- C:\Windows\system32\DbxSvc.exe
======List of files/folders modified in the last 1 month======
2018-11-30 13:14:45 ----D---- C:\Program Files\trend micro
2018-11-30 13:14:28 ----D---- C:\Windows\Temp
2018-11-30 13:13:52 ----D---- C:\Windows\system32\drivers
2018-11-30 13:13:47 ----RD---- C:\Program Files
2018-11-30 13:12:36 ----SHD---- C:\Windows\Installer
2018-11-30 13:12:31 ----RD---- C:\Program Files (x86)
2018-11-30 13:11:17 ----SHD---- C:\System Volume Information
2018-11-30 13:09:42 ----D---- C:\Windows\SysWOW64
2018-11-30 13:09:40 ----D---- C:\Windows\system32\DriverStore
2018-11-30 13:09:35 ----D---- C:\Windows\inf
2018-11-30 13:09:31 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2018-11-30 13:09:31 ----D---- C:\Windows\twain_32
2018-11-30 13:09:31 ----D---- C:\Windows
2018-11-30 13:04:59 ----D---- C:\Windows\Tasks
2018-11-30 13:04:59 ----D---- C:\Windows\system32\Tasks
2018-11-30 12:54:52 ----D---- C:\ProgramData
2018-11-30 12:54:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-11-30 12:54:01 ----HD---- C:\Windows\system32\GroupPolicy
2018-11-30 12:50:30 ----D---- C:\Program Files (x86)\TeamViewer
2018-11-30 12:47:31 ----SHD---- C:\$RECYCLE.BIN
2018-11-30 12:47:31 ----D---- C:\ProgramData\AMD
2018-11-30 12:44:02 ----SD---- C:\Users\Kuba\AppData\Roaming\Microsoft
2018-11-30 12:43:04 ----D---- C:\Windows\Prefetch
2018-11-30 12:40:24 ----D---- C:\Windows\system32\config
2018-11-30 12:33:53 ----D---- C:\Program Files (x86)\eRightSoft
2018-11-30 12:24:46 ----D---- C:\Users\Kuba\AppData\Roaming\vlc
2018-11-29 21:16:31 ----D---- C:\Program Files (x86)\Dropbox
2018-11-29 21:16:21 ----D---- C:\Windows\System32
2018-11-27 02:33:44 ----N---- C:\Windows\system32\MpSigStub.exe
2018-11-26 21:35:07 ----D---- C:\Windows\system32\NDF
2018-11-21 11:03:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2018-11-21 11:03:03 ----D---- C:\Windows\system32\Macromed
2018-11-21 11:03:02 ----D---- C:\Windows\SYSWOW64\Macromed
2018-11-20 10:08:51 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-11-17 01:13:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2018-11-14 23:50:13 ----D---- C:\Windows\system32\catroot2
2018-11-05 10:03:13 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 295000]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2018-06-29 516096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-16 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 athr;Wireless PCI Adapter Driver Service; C:\Windows\system32\DRIVERS\athrx.sys [2011-04-11 1579520]
R3 firefaceu64;RME Fireface USB Audio Device; C:\Windows\system32\drivers\fireface_usb_64.sys [2014-08-12 102144]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2018-09-13 4933624]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-01-11 64624]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 135928]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-04-10 849992]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 MpKsl8cd54226;MpKsl8cd54226; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6C0882C5-A646-4035-8C10-0B4338A770C4}\MpKsl8cd54226.sys []
S1 MpKsla16eeeb5;MpKsla16eeeb5; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6C0882C5-A646-4035-8C10-0B4338A770C4}\MpKsla16eeeb5.sys []
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-11-29 13201920]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-11-29 624128]
S3 ASAPIW2K;ASAPIW2K; C:\Windows\System32\Drivers\ASAPIW2K.sys []
S3 athrusb;Atheros Wireless LAN USB device driver; C:\Windows\system32\DRIVERS\athrxusb.sys [2008-07-29 1075712]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 GPCIDrv;GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys []
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-03-31 460048]
S3 KemperProfiler;Kemper Profiler; C:\Windows\system32\DRIVERS\KemperProfiler.sys [2018-03-22 85320]
S3 lp16_usb;lp16_usb; C:\Windows\System32\Drivers\lp16_usb_x64.sys [2017-02-27 124536]
S3 lp16_usb_avs;lp16_usb_avs; C:\Windows\System32\Drivers\lp16_usb_avs_x64.sys [2017-02-27 82040]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 rspLLL;rspLLL; C:\Windows\system32\DRIVERS\rspLLL64.sys [2013-10-21 25504]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2015-06-17 54784]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 ZD1211BU(TP-LINK);TP-LINK Wireless USB Adapter Driver(TP-LINK); C:\Windows\system32\DRIVERS\zd1211Bu.sys [2009-01-05 602880]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-08-13 83984]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-11-29 239616]
R2 CRMSvc;CRMSvc; C:\Users\Kuba\AppData\Roaming\CRMSvc\CRMSvc.exe [2018-11-30 1517568]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DbxSvc;DbxSvc; C:\Windows\system32\DbxSvc.exe [2018-11-28 51024]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2018-09-13 343016]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 119864]
R2 NIHardwareService;NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2013-11-27 11878704]
R2 NmM0ODQ3NjE;NmM0ODQ3NjE; C:\Windows\wxyeltrpuaulyazux.wxy [2018-11-30 1409536]
R2 TeamViewer;TeamViewer 13; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2018-07-23 11644144]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 361816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-08-30 103552]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-08-30 124024]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-07 143144]
S2 pgt_svc;PG Manager; C:\Program Files (x86)\ProxyGate\MainService.exe [2017-02-22 2285664]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-11-21 335872]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2018-09-13 376296]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-07 143144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2018-08-23 116224]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-12-13 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-08-30 50808]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-11-20 216528]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-08-30 139896]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-08-30 139896]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-08-30 139896]
-----------------EOF-----------------
Log z RSIT :
Logfile of random's system information tool 1.09 (written by random/random)
Run by Kuba at 2018-11-30 13:14:45
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 27 GB (17%) free of 153 GB
Total RAM: 8054 MB (66% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Users\Kuba\AppData\Roaming\CRMSvc\CRMSvc.exe"
"taskhost.exe"
C:\Windows\system32\DbxSvc.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe"
rundll32.exe C:\Windows\wxyeltrpuaulyazux.wxy CaH
rundll32.exe C:\Windows\wxyeltrpuaulyazux.wxy CaH
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2020
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
igfxEM.exe
igfxHK.exe
igfxTray.exe
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\firefaceusb.exe"
"C:\Windows\System32\TotalMixFX.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\SunsetScreen\SunsetScreen.exe" /hidewindow
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\System32\rundll32.exe" "C:\Users\Kuba\AppData\Local\ntelix.dll",ntelix
"C:\Windows\System32\rundll32.exe" "C:\Users\Kuba\AppData\Local\ntelix.dll",ntelix
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" -type:crashpad-handler --no-upload-gzip --no-rate-limit --capture-python --no-identify-client-via-url --database=C:\Users\Kuba\AppData\Local\Dropbox\Crashpad --metrics-dir=0 --url=https://d.dropbox.com/report_crashpad_minidump --https-pin=0x23,0xf2,0xed,0xff,0x3e,0xde,0x90,0x25,0x9a,0x9e,0x30,0xf4,0xa,0xf8,0xf9,0x12,0xa5,0xe5,0xb3,0x69,0x4e,0x69,0x38,0x44,0x3,0x41,0xf6,0x6,0xe,0x1,0x4f,0xfa --https-pin=0xaf,0xf9,0x88,0x90,0x6d,0xde,0x12,0x95,0x5d,0x9b,0xeb,0xbf,0x92,0x8f,0xdc,0xc3,0x1c,0xce,0x32,0x8d,0x5b,0x93,0x84,0xf2,0x1c,0x89,0x41,0xca,0x26,0xe2,0x3,0x91 --https-pin=0x5a,0x88,0x96,0x47,0x22,0xe,0x54,0xd6,0xbd,0x8a,0x16,0x81,0x72,0x24,0x52,0xb,0xb5,0xc7,0x8e,0x58,0x98,0x4b,0xd5,0x70,0x50,0x63,0x88,0xb9,0xde,0xf,0x7,0x5f --https-pin=0xfe,0xa2,0xb7,0xd6,0x45,0xfb,0xa7,0x3d,0x75,0x3c,0x1e,0xc9,0xa7,0x87,0xc,0x40,0xe1,0xf7,0xb0,0xc5,0x61,0xe9,0x27,0xb9,0x85,0xbf,0x71,0x18,0x66,0xe3,0x6f,0x22 --https-pin=0x76,0xee,0x85,0x90,0x37,0x4c,0x71,0x54,0x37,0xbb,0xca,0x6b,0xba,0x60,0x28,0xea,0xdd,0xe2,0xdc,0x6d,0xbb,0xb8,0xc3,0xf6,0x10,0xe8,0x51,0xf1,0x1d,0x1a,0xb7,0xf5 --https-pin=0x6d,0xbf,0xae,0x0,0xd3,0x7b,0x9c,0xd7,0x3f,0x8f,0xb4,0x7d,0xe6,0x59,0x17,0xaf,0x0,0xe0,0xdd,0xdf,0x42,0xdb,0xce,0xac,0x20,0xc1,0x7c,0x2,0x75,0xee,0x20,0x95 --https-pin=0x1e,0xa3,0xc5,0xe4,0x3e,0xd6,0x6c,0x2d,0xa2,0x98,0x3a,0x42,0xa4,0xa7,0x9b,0x1e,0x90,0x67,0x86,0xce,0x9f,0x1b,0x58,0x62,0x14,0x19,0xa0,0x4,0x63,0xa8,0x7d,0x38 --https-pin=0x87,0xaf,0x34,0xd6,0x6f,0xb3,0xf2,0xfd,0xf3,0x6e,0x9,0x11,0x1e,0x9a,0xba,0x2f,0x6f,0x44,0xb2,0x7,0xf3,0x86,0x3f,0x3d,0xb,0x54,0xb2,0x50,0x23,0x90,0x9a,0xa5 --https-pin=0xbc,0xfb,0x44,0xaa,0xb9,0xad,0x2,0x10,0x15,0x70,0x6b,0x41,0x21,0xea,0x76,0x1c,0x81,0xc9,0xe8,0x89,0x67,0x59,0xf,0x6f,0x94,0xae,0x74,0x4d,0xc8,0x8b,0x78,0xfb --https-pin=0xab,0x98,0x49,0x52,0x76,0xad,0xf1,0xec,0xaf,0xf2,0x8f,0x35,0xc5,0x30,0x48,0x78,0x1e,0x5c,0x17,0x18,0xda,0xb9,0xc8,0xe6,0x7a,0x50,0x4f,0x4f,0x6a,0x51,0x32,0x8f --https-pin=0x49,0x5,0x46,0x66,0x23,0xab,0x41,0x78,0xbe,0x92,0xac,0x5c,0xbd,0x65,0x84,0xf7,0xa1,0xe1,0x7f,0x27,0x65,0x2d,0x5a,0x85,0xaf,0x89,0x50,0x4e,0xa2,0x39,0xaa,0xaa --https-pin=0x56,0x32,0xd9,0x7b,0xfa,0x77,0x5b,0xf3,0xc9,0x9d,0xde,0xa5,0x2f,0xc2,0x55,0x34,0x10,0x86,0x40,0x16,0x72,0x9c,0x52,0xdd,0x65,0x24,0xc8,0xa9,0xc3,0xb4,0x48,0x9f --https-pin=0x2a,0x8f,0x2d,0x8a,0xf0,0xeb,0x12,0x38,0x98,0xf7,0x4c,0x86,0x6a,0xc3,0xfa,0x66,0x90,0x54,0xe2,0x3c,0x17,0xbc,0x7a,0x95,0xbd,0x2,0x34,0x19,0x2d,0xc6,0x35,0xd0 --https-pin=0x32,0xb6,0x4b,0x66,0x72,0x7a,0x20,0x63,0xe4,0x6,0x6f,0x3b,0x95,0x8c,0xb0,0xaa,0xee,0x57,0x6a,0x5e,0xce,0xfd,0x95,0x33,0x99,0xbb,0x88,0x74,0x73,0x1d,0x95,0x87 --https-pin=0xf5,0x3c,0x22,0x5,0x98,0x17,0xdd,0x96,0xf4,0x0,0x65,0x16,0x39,0xd2,0xf8,0x57,0xe2,0x10,0x70,0xa5,0x9a,0xbe,0xd9,0x7,0x94,0x0,0xd9,0xf6,0x95,0x50,0x69,0x0 --https-pin=0x67,0xdc,0x4f,0x32,0xfa,0x10,0xe7,0xd0,0x1a,0x79,0xa0,0x73,0xaa,0xc,0x9e,0x2,0x12,0xec,0x2f,0xfc,0x3d,0x77,0x9e,0xa,0xa7,0xf9,0xc0,0xf0,0xe1,0xc2,0xc8,0x93 --https-pin=0x19,0x6,0xc6,0x12,0x4d,0xbb,0x43,0x85,0x78,0xd0,0xe,0x6,0x6d,0x50,0x54,0xc6,0xc3,0x7f,0xf,0xa6,0x2,0x8c,0x5,0x54,0x5e,0x9,0x94,0xed,0xda,0xec,0x86,0x29 --https-pin=0x1d,0x75,0xd0,0x83,0x1b,0x9e,0x8,0x85,0x39,0x4d,0x32,0xc7,0xa1,0xbf,0xdb,0x3d,0xbc,0x1c,0x28,0xe2,0xb0,0xe8,0x39,0x1f,0xb1,0x35,0x98,0x1d,0xbc,0x5b,0xa9,0x36 --annotation=host_int_account1_boot=28474061088 --annotation=machine_id=1595302a-1642-4ed3-b227-87ebd588664b --annotation=platform=win --annotation=platform_version=7 --initial-client-data=0xe0,0xe4,0xe8,0xdc,0xec,0x6aa7dda4,0x6aa7ddb4,0x6aa7ddc4
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" -type:exit-monitor -session-token:eeb16034-3a9f-4ee2-9a13-fac079967c15 -target-handle:244 -target-shutdown-event:236 -target-restart-event:220 "-target-command-line:\"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe\" /systemstartup" -python-version:3.5.4 -method:collectupload -handler-pipe:\\.\pipe\crashpad_2384_KDZJIITPLUHCMJXS
"C:\Windows\system32\taskmgr.exe" /4
ctfmon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\ProxyGate\PGNet.exe" /chknet-upd
C:\Windows\system32\cmd.exe /c ""C:\Windows\Microsoft.NET\Framework\v2.0.50727\del.bat""
\??\C:\Windows\system32\conhost.exe "-390643256-1281031488-859664424770272984-140041976674259051411960239831915690712
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\wuauclt.exe"
"taskhost.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\msiexec.exe /V
C:\Windows\system32\wbem\wmiprvse.exe
taskhost.exe $(Arg0)
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Kuba\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\DropboxUpdateTaskMachineCore.job
C:\Windows\tasks\DropboxUpdateTaskMachineUA.job
C:\Windows\tasks\Online Application V2G5.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Kuba\AppData\Roaming\Mozilla\Firefox\Profiles\77htdns3.default-1478886535918
prefs.js - "browser.startup.homepage" - "http://page-ups.com/all/"
"{29049BEC-CF6D-49FF-8F3F-95D886658152}"=C:\Windows\Installer\{10F78416-E991-4176-98C2-BB92DCD6BD13}\{29049BEC-CF6D-49FF-8F3F-95D886658152}.xpi
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe� Flash� Player 31.0.0.153 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_153.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe� Flash� Player 31.0.0.153 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_153.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocn� slu瀊a pro p鴌hl釟en� k tu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2018-09-13 380904]
"FirefaceUsbTray1"=C:\Windows\system32\firefaceusb.exe [2014-08-12 97792]
"FirefaceMixTray2"=C:\Windows\system32\TotalMixFX.exe [2014-06-14 22900952]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1353680]
"Wondershare Helper Compact.exe"=C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-11-21 7063832]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"SunsetScreen"=C:\Program Files (x86)\SunsetScreen\SunsetScreen.exe [2017-07-10 783984]
"6028390"=C:\Users\Kuba\AppData\Roaming\k2pvrhap3nc\b1w3d4nnxul.exe [2018-11-30 554244]
"9658578"=C:\Users\Kuba\AppData\Roaming\15451hedamq\fjorqoanx3i.exe [2018-11-30 554244]
"ntelix"=C:\Users\Kuba\AppData\Local\ntelix.dll [2018-11-30 16384]
"8965497"=C:\Users\Kuba\AppData\Roaming\wim11vgkqpe\mvzq5mb5oyt.exe [2018-11-30 554244]
"8907442"=C:\Users\Kuba\AppData\Roaming\2iab3jajwii\3czl14utddt.exe [2018-11-30 554244]
"6130961"=C:\Users\Kuba\AppData\Roaming\xl50bgvo3tq\mrvd23y1vji.exe [2018-11-30 554244]
"6075169"=C:\Users\Kuba\AppData\Roaming\nsuy20tfyqv\rnzqhsmurak.exe [2018-11-30 554244]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZDWlan.EXE]
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Client Utility\ZDWlan.EXE [2009-01-14 491520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TP-LINK Wireless Configuration Utility.lnk]
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe [2011-08-17 788992]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2018-11-28 3806016]
"Wondershare Helper Compact.exe"=C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2017-09-12 2133728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\ProgramData\Kolnixo\SingleEco.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.I420"=MSH263.DRV
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux8"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux9"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux7"=wdmaud.drv
"VIDC.SP54"=SP5X_32.DLL
"VIDC.SP55"=SP5X_32.DLL
"VIDC.SP56"=SP5X_32.DLL
"VIDC.SP57"=SP5X_32.DLL
"VIDC.SP58"=SP5X_32.DLL
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2018-11-30 13:14:45 ----D---- C:\rsit
2018-11-30 12:58:40 ----D---- C:\Program Files (x86)\DjpYILTWU
2018-11-30 12:57:19 ----D---- C:\Windows\SYSWOW64\SSL
2018-11-30 12:55:50 ----D---- C:\Program Files (x86)\Lavasoft
2018-11-30 12:55:01 ----D---- C:\Program Files (x86)\ProxyGate
2018-11-30 12:54:52 ----D---- C:\ProgramData\Lavasoft
2018-11-30 12:54:41 ----D---- C:\Program Files\5PDUBJ6VHO
2018-11-30 12:54:13 ----D---- C:\Users\Kuba\AppData\Roaming\xl50bgvo3tq
2018-11-30 12:54:06 ----D---- C:\Users\Kuba\AppData\Roaming\nsuy20tfyqv
2018-11-30 12:54:05 ----D---- C:\Users\Kuba\AppData\Roaming\2iab3jajwii
2018-11-30 12:53:45 ----D---- C:\Program Files\1XU1GHZ8LT
2018-11-30 12:52:53 ----D---- C:\Users\Kuba\AppData\Roaming\wim11vgkqpe
2018-11-30 12:52:53 ----D---- C:\Program Files\BJBGG2DL46
2018-11-30 12:52:16 ----D---- C:\Program Files\97EA0VNV5M
2018-11-30 12:47:18 ----D---- C:\ProgramData\Logic Cramble
2018-11-30 12:46:55 ----D---- C:\ProgramData\75f49cc0-6115-0
2018-11-30 12:46:40 ----D---- C:\ProgramData\Kolnixo
2018-11-30 12:46:36 ----D---- C:\ProgramData\75f49cc0-7667-1
2018-11-30 12:46:26 ----D---- C:\ProgramData\423e3873-6901-0
2018-11-30 12:46:15 ----D---- C:\ProgramData\423e3873-58d1-1
2018-11-30 12:46:02 ----D---- C:\ProgramData\b199a7fe-d3aa-4ff9-9d61-b5dd5debd99d
2018-11-30 12:46:00 ----D---- C:\Users\Kuba\AppData\Roaming\One System Care
2018-11-30 12:46:00 ----D---- C:\Program Files (x86)\OneSystemCare
2018-11-30 12:45:12 ----D---- C:\Users\Kuba\AppData\Roaming\15451hedamq
2018-11-30 12:45:06 ----D---- C:\Users\Kuba\AppData\Roaming\CRMSvc
2018-11-30 12:45:00 ----D---- C:\Program Files\8P8WWGG5M8
2018-11-30 12:44:48 ----D---- C:\Program Files\EHXNQX91Y6
2018-11-30 12:44:43 ----D---- C:\Program Files\STXGDJLCBB
2018-11-30 12:44:38 ----D---- C:\Users\Kuba\AppData\Roaming\k2pvrhap3nc
2018-11-30 12:44:34 ----D---- C:\ProgramData\PrefsSecure
2018-11-30 12:44:21 ----D---- C:\Program Files\1K1VXM1KCT
2018-11-30 12:44:20 ----D---- C:\Program Files (x86)\cleanComputerNew
2018-11-30 12:44:14 ----D---- C:\Program Files\J785UGPWRB
2018-11-30 12:44:12 ----D---- C:\Program Files (x86)\bestDownloader
2018-11-30 12:44:06 ----D---- C:\Users\Kuba\AppData\Roaming\Microleaves
2018-11-30 12:43:57 ----D---- C:\Program Files (x86)\tvhjwryp55b
2018-11-30 12:43:57 ----D---- C:\Program Files (x86)\3xcla1myci4
2018-11-30 12:42:51 ----D---- C:\Program Files (x86)\Skaty
2018-11-30 12:42:29 ----D---- C:\Users\Kuba\AppData\Roaming\Browsers
2018-11-30 12:42:28 ----D---- C:\Users\Kuba\AppData\Roaming\SPI
2018-11-29 11:33:44 ----A---- C:\Windows\uninstaller.dat
2018-11-29 11:33:44 ----A---- C:\Windows\MzNjYTZk.exe
2018-11-28 14:09:04 ----A---- C:\Windows\system32\drivers\dbx-stable.sys
2018-11-28 14:09:04 ----A---- C:\Windows\system32\drivers\dbx-dev.sys
2018-11-28 14:09:04 ----A---- C:\Windows\system32\drivers\dbx-canary.sys
2018-11-28 14:09:04 ----A---- C:\Windows\system32\DbxSvc.exe
======List of files/folders modified in the last 1 month======
2018-11-30 13:14:45 ----D---- C:\Program Files\trend micro
2018-11-30 13:14:28 ----D---- C:\Windows\Temp
2018-11-30 13:13:52 ----D---- C:\Windows\system32\drivers
2018-11-30 13:13:47 ----RD---- C:\Program Files
2018-11-30 13:12:36 ----SHD---- C:\Windows\Installer
2018-11-30 13:12:31 ----RD---- C:\Program Files (x86)
2018-11-30 13:11:17 ----SHD---- C:\System Volume Information
2018-11-30 13:09:42 ----D---- C:\Windows\SysWOW64
2018-11-30 13:09:40 ----D---- C:\Windows\system32\DriverStore
2018-11-30 13:09:35 ----D---- C:\Windows\inf
2018-11-30 13:09:31 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2018-11-30 13:09:31 ----D---- C:\Windows\twain_32
2018-11-30 13:09:31 ----D---- C:\Windows
2018-11-30 13:04:59 ----D---- C:\Windows\Tasks
2018-11-30 13:04:59 ----D---- C:\Windows\system32\Tasks
2018-11-30 12:54:52 ----D---- C:\ProgramData
2018-11-30 12:54:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2018-11-30 12:54:01 ----HD---- C:\Windows\system32\GroupPolicy
2018-11-30 12:50:30 ----D---- C:\Program Files (x86)\TeamViewer
2018-11-30 12:47:31 ----SHD---- C:\$RECYCLE.BIN
2018-11-30 12:47:31 ----D---- C:\ProgramData\AMD
2018-11-30 12:44:02 ----SD---- C:\Users\Kuba\AppData\Roaming\Microsoft
2018-11-30 12:43:04 ----D---- C:\Windows\Prefetch
2018-11-30 12:40:24 ----D---- C:\Windows\system32\config
2018-11-30 12:33:53 ----D---- C:\Program Files (x86)\eRightSoft
2018-11-30 12:24:46 ----D---- C:\Users\Kuba\AppData\Roaming\vlc
2018-11-29 21:16:31 ----D---- C:\Program Files (x86)\Dropbox
2018-11-29 21:16:21 ----D---- C:\Windows\System32
2018-11-27 02:33:44 ----N---- C:\Windows\system32\MpSigStub.exe
2018-11-26 21:35:07 ----D---- C:\Windows\system32\NDF
2018-11-21 11:03:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2018-11-21 11:03:03 ----D---- C:\Windows\system32\Macromed
2018-11-21 11:03:02 ----D---- C:\Windows\SYSWOW64\Macromed
2018-11-20 10:08:51 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-11-17 01:13:21 ----A---- C:\Windows\system32\PerfStringBackup.INI
2018-11-14 23:50:13 ----D---- C:\Windows\system32\catroot2
2018-11-05 10:03:13 ----D---- C:\temp
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 295000]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2018-06-29 516096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-16 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 athr;Wireless PCI Adapter Driver Service; C:\Windows\system32\DRIVERS\athrx.sys [2011-04-11 1579520]
R3 firefaceu64;RME Fireface USB Audio Device; C:\Windows\system32\drivers\fireface_usb_64.sys [2014-08-12 102144]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2018-09-13 4933624]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-01-11 64624]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 135928]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2013-04-10 849992]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 MpKsl8cd54226;MpKsl8cd54226; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6C0882C5-A646-4035-8C10-0B4338A770C4}\MpKsl8cd54226.sys []
S1 MpKsla16eeeb5;MpKsla16eeeb5; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6C0882C5-A646-4035-8C10-0B4338A770C4}\MpKsla16eeeb5.sys []
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-11-29 13201920]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-11-29 624128]
S3 ASAPIW2K;ASAPIW2K; C:\Windows\System32\Drivers\ASAPIW2K.sys []
S3 athrusb;Atheros Wireless LAN USB device driver; C:\Windows\system32\DRIVERS\athrxusb.sys [2008-07-29 1075712]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 GPCIDrv;GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys []
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-03-31 460048]
S3 KemperProfiler;Kemper Profiler; C:\Windows\system32\DRIVERS\KemperProfiler.sys [2018-03-22 85320]
S3 lp16_usb;lp16_usb; C:\Windows\System32\Drivers\lp16_usb_x64.sys [2017-02-27 124536]
S3 lp16_usb_avs;lp16_usb_avs; C:\Windows\System32\Drivers\lp16_usb_avs_x64.sys [2017-02-27 82040]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 rspLLL;rspLLL; C:\Windows\system32\DRIVERS\rspLLL64.sys [2013-10-21 25504]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2015-06-17 54784]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 ZD1211BU(TP-LINK);TP-LINK Wireless USB Adapter Driver(TP-LINK); C:\Windows\system32\DRIVERS\zd1211Bu.sys [2009-01-05 602880]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-08-13 83984]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-11-29 239616]
R2 CRMSvc;CRMSvc; C:\Users\Kuba\AppData\Roaming\CRMSvc\CRMSvc.exe [2018-11-30 1517568]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DbxSvc;DbxSvc; C:\Windows\system32\DbxSvc.exe [2018-11-28 51024]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2018-09-13 343016]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 119864]
R2 NIHardwareService;NIHardwareService; C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2013-11-27 11878704]
R2 NmM0ODQ3NjE;NmM0ODQ3NjE; C:\Windows\wxyeltrpuaulyazux.wxy [2018-11-30 1409536]
R2 TeamViewer;TeamViewer 13; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2018-07-23 11644144]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 361816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-08-30 103552]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-08-30 124024]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-07 143144]
S2 pgt_svc;PG Manager; C:\Program Files (x86)\ProxyGate\MainService.exe [2017-02-22 2285664]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-11-21 335872]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2018-09-13 376296]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-07 143144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2018-08-23 116224]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-12-13 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-08-30 50808]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-11-20 216528]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-08-30 139896]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-08-30 139896]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-08-30 139896]
-----------------EOF-----------------