prosím o kontrolu logu
Napsal: 06 led 2020 18:12
Logfile of random's system information tool 1.10 (written by random/random)
Run by Pajiss at 2020-01-06 18:15:50
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 46 GB (19%) free of 238 GB
Total RAM: 4095 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:16:03, on 6.1.2020
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\WargamingErrorMonitor.exe
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files\trend micro\Pajiss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\browser\install\fs_ie_https\fs_ie_https.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EpicGamesLauncher] "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
O4 - HKCU\..\Run: [Wargaming.net Game Center] "C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe" --background ''
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'DefaultAppPool')
O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'DefaultAppPool')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: F-Secure Hoster (fshoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
O23 - Service: F-Secure Hoster (Restricted) (fsnethoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
O23 - Service: F-Secure Ultralight Hoster (fsulhoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe
O23 - Service: F-Secure Ultralight Network Hoster (fsulnethoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe
O23 - Service: F-Secure Ultralight ORSP Client (fsulorsp) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsorsp64.exe
O23 - Service: F-Secure Ultralight Protected Hoster (fsulprothoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulprothoster.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.88\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8136 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe" -hosterid:0
"C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe" -hosterid:2
"C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe" -app -hosterId:1
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe" -PointAppFamily:1400 -hosterID:2
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsorsp64.exe"
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulprothoster.exe" -hosterID:0 -PointAppFamily:1450
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe" --background ''
"C:\Program Files (x86)\Wargaming.net\GameCenter\WargamingErrorMonitor.exe" --pipe "parent_pid_2864biv1457d-4di1-di14-d1i4-4i5bd14vq17t" --superuserid "WGC" --self_crash_handling_folder "C:\Program Files (x86)\Wargaming.net\GameCenter\cat " --self_crash_handling_receiver_url "http://cat.wargaming.net " Logs " "
"C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe" --type=gpu-process --field-trial-handle=1788,5349356738440504109,12221741420577677481,131072 --disable-features=MimeHandlerViewInCrossProcessFrame --no-sandbox --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --log-severity=info --user-agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 WGC/19.08.00.7920" --lang=en-US --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --service-request-channel-token=5267108080941335425 --mojo-platform-channel-handle=1824 /prefetch:2
"C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe" --type=utility --field-trial-handle=1788,5349356738440504109,12221741420577677481,131072 --disable-features=MimeHandlerViewInCrossProcessFrame --lang=en-US --service-sandbox-type=network --no-sandbox --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --log-severity=info --user-agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 WGC/19.08.00.7920" --lang=en-US --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --service-request-channel-token=1796310706532718795 --mojo-platform-channel-handle=2104 /prefetch:8
"C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe" --type=renderer --no-sandbox --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --field-trial-handle=1788,5349356738440504109,12221741420577677481,131072 --disable-features=MimeHandlerViewInCrossProcessFrame --lang=en-US --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --log-severity=info --user-agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 WGC/19.08.00.7920" --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=2270597022342751070 --renderer-client-id=4 --mojo-platform-channel-handle=2164 /prefetch:1
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" "-lang=cs_CZ" "-cachedir=C:\Users\Pajiss\AppData\Local\Steam\htmlcache" "-steampid=2440" "-buildid=1576550254" "-steamid=0" "-steamuniverse=Public" "-clientui=C:\Program Files (x86)\Steam\clientui" --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --enable-media-stream --enable-smooth-scrolling --disable-accelerated-video-decode --enable-direct-write --disablehighdpi --force-device-scale-factor=1 --device-scale-factor=1 "--log-file=C:\Program Files (x86)\Steam\logs\cef_log.txt"
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Program Files (x86)\Steam\dumps" "--metrics-dir=C:\Users\Pajiss\AppData\Local\CEF\User Data" --url=http://crash.steampowered.com/submit --annotation=platform=win64 --annotation=product=cefwebhelper --annotation=version=1576550254 --initial-client-data=0x170,0x174,0x178,0x16c,0x17c,0x7fee214da70,0x7fee214da80,0x7fee214da90
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=gpu-process --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=cs-CZ --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --gpu-preferences=KAAAAAAAAADhAAAgAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --service-request-channel-token=5952726322897304540 --mojo-platform-channel-handle=1160 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=utility --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --lang=cs --service-sandbox-type=network --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=cs-CZ --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --service-request-channel-token=17979791314100046276 --mojo-platform-channel-handle=904 /prefetch:8
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --lang=cs --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=2039247663977087549 --renderer-client-id=6 --mojo-platform-channel-handle=2000 /prefetch:1
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --lang=cs --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=11102866616920347121 --renderer-client-id=8 --mojo-platform-channel-handle=2172 /prefetch:1
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\system32\Dwm.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0f695552-68b1-40fd-bba5-90acefee4961 -SystemEventPortName:HostProcess-73a3d7d9-3b36-4ec7-b55a-308e27aaa1d6 -IoCancelEventPortName:HostProcess-8d069fb9-74ba-4309-825c-d40595312cb4 -NonStateChangingEventPortName:HostProcess-05d882c5-f79a-479d-a4f3-7df95bdb6697 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:8a7968cc-5b26-4de6-ac9f-92e0b5c67992 -DeviceGroupId:WpdFsGroup
"C:\totalcmd\TOTALCMD64.EXE"
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe" -PointAppFamily:1400
3252
"C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /Play -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6d6083ae-9394-49c8-960f-a5ee66e5c20d -SystemEventPortName:HostProcess-e17c2b93-397b-4897-b35e-541a495ea429 -IoCancelEventPortName:HostProcess-8a99637c-38b6-47b6-9471-26d770d458b6 -NonStateChangingEventPortName:HostProcess-a631bde8-8c32-42f4-81e0-9ca4d970a23e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:34de2b19-7085-4a43-a5df-17a39698c4db -DeviceGroupId:
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --lang=cs --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=15562942489820225585 --renderer-client-id=14 --mojo-platform-channel-handle=2948 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Pajiss\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Pajiss\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Pajiss\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=79.0.3945.88 --initial-client-data=0x3c,0x40,0x44,0x38,0x48,0x7fede13dd08,0x7fede13dd18,0x7fede13dd28
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=5940 --on-initialized-event-handle=12 --parent-handle=168 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=7714407001761206510 --mojo-platform-channel-handle=956 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --service-sandbox-type=network --enable-audio-service-sandbox --service-request-channel-token=5255198476374092737 --mojo-platform-channel-handle=1160 /prefetch:8
C:\Windows\system32\wbem\wmiprvse.exe
c:\windows\system32\inetsrv\w3wp.exe -ap "DefaultAppPool" -v "v2.0" -l "webengine4.dll" -a \\.\pipe\iisipmc55125ae-f709-46a7-b3bf-0078a7716b98 -h "C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config" -w "" -m 0 -t 20
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\WmiApSrv.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --disable-oor-cors --enable-auto-reload --device-scale-factor=1.25 --num-raster-threads=1 --service-request-channel-token=5325922324807856038 --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2636 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --disable-oor-cors --enable-auto-reload --device-scale-factor=1.25 --num-raster-threads=1 --service-request-channel-token=15253928773028779514 --renderer-client-id=23 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2756 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --disable-oor-cors --enable-auto-reload --device-scale-factor=1.25 --num-raster-threads=1 --service-request-channel-token=6331926929464306878 --renderer-client-id=25 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=864 /prefetch:1
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe268_ Global\UsGthrCtrlFltPipeMssGthrPipe268 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Pajiss\Downloads\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45BBE08D-81C5-4A67-AF20-B2A077C67747}]
Browsing Protection by F-Secure - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\browser\install\fs_ie_https\fs_ie_https64.dll [2019-12-16 1639312]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45BBE08D-81C5-4A67-AF20-B2A077C67747}]
Browsing Protection by F-Secure - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\browser\install\fs_ie_https\fs_ie_https.dll [2019-12-16 1056656]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2019-12-16 3288016]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"EpicGamesLauncher"=C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent []
"Wargaming.net Game Center"=C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe [2019-12-18 2414456]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2014-03-13 779776]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-05-24 336384]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2020-01-06 18:15:50 ----D---- C:\Program Files\trend micro
2019-12-30 12:17:03 ----D---- C:\Program Files\Runtime Software
2019-12-30 12:03:01 ----D---- C:\Program Files (x86)\Unlocker
2019-12-17 13:41:08 ----D---- C:\Users\Pajiss\AppData\Roaming\uTorrent
2019-12-11 13:10:36 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2019-12-11 13:10:36 ----A---- C:\Windows\system32\poqexec.exe
2019-12-11 13:08:45 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2019-12-11 13:08:44 ----A---- C:\Windows\system32\win32k.sys
2019-12-11 13:08:44 ----A---- C:\Windows\system32\rdpcorets.dll
2019-12-11 13:08:44 ----A---- C:\Windows\system32\quartz.dll
2019-12-11 13:08:44 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2019-12-11 13:08:44 ----A---- C:\Windows\system32\appraiser.dll
2019-12-11 13:08:43 ----A---- C:\Windows\SYSWOW64\quartz.dll
2019-12-11 13:08:43 ----A---- C:\Windows\system32\winload.exe
2019-12-11 13:08:43 ----A---- C:\Windows\system32\mscms.dll
2019-12-11 13:08:43 ----A---- C:\Windows\system32\EOSNotify.exe
2019-12-11 13:08:42 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\SYSWOW64\mscms.dll
2019-12-11 13:08:42 ----A---- C:\Windows\SYSWOW64\icm32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\wow64win.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\t2embed.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\oleaut32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\icm32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\gdi32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\fontsub.dll
2019-12-11 13:08:41 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2019-12-11 13:08:41 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2019-12-11 13:08:41 ----A---- C:\Windows\system32\WcsPlugInService.dll
2019-12-11 13:08:41 ----A---- C:\Windows\system32\services.exe
2019-12-11 13:08:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2019-12-11 13:08:41 ----A---- C:\Windows\system32\ntdll.dll
2019-12-11 13:08:40 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2019-12-11 13:08:40 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2019-12-11 13:08:40 ----A---- C:\Windows\system32\hal.dll
2019-12-11 13:08:40 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\WcsPlugInService.dll
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2019-12-11 13:08:39 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2019-12-11 13:08:39 ----A---- C:\Windows\system32\CompatTelRunner.exe
2019-12-11 13:08:39 ----A---- C:\Windows\system32\atmfd.dll
2019-12-11 13:08:38 ----A---- C:\Windows\SYSWOW64\certcli.dll
2019-12-11 13:08:38 ----A---- C:\Windows\system32\ole32.dll
2019-12-11 13:08:38 ----A---- C:\Windows\system32\certcli.dll
2019-12-11 13:08:37 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\user32.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\rpcrt4.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\lsasrv.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\kerberos.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\videoprt.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\srvnet.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\srv.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\advapi32.dll
2019-12-11 13:08:36 ----A---- C:\Windows\SYSWOW64\user32.dll
2019-12-11 13:08:36 ----A---- C:\Windows\SYSWOW64\ole32.dll
2019-12-11 13:08:36 ----A---- C:\Windows\system32\smss.exe
2019-12-11 13:08:36 ----A---- C:\Windows\system32\kernel32.dll
2019-12-11 13:08:35 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\winsrv.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\srvsvc.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\schannel.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\rpcss.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\ncrypt.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\msv1_0.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\drivers\srv2.sys
2019-12-11 13:08:35 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\wow64.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\wdigest.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\sspicli.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\srcore.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\KernelBase.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\conhost.exe
2019-12-11 13:08:34 ----A---- C:\Windows\system32\bcrypt.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\schannel.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2019-12-11 13:08:33 ----A---- C:\Windows\system32\TSpkg.dll
2019-12-11 13:08:33 ----A---- C:\Windows\system32\rpchttp.dll
2019-12-11 13:08:33 ----A---- C:\Windows\system32\lsass.exe
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\processr.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\intelppm.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\appid.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\amdppm.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\amdk8.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\csrsrv.dll
2019-12-11 13:08:32 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\wow64cpu.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\sspisrv.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\sscore.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\cryptbase.dll
2019-12-11 13:08:31 ----A---- C:\Windows\SYSWOW64\srclient.dll
2019-12-11 13:08:31 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\srclient.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\setbcdlocale.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\secur32.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\rstrui.exe
2019-12-11 13:08:31 ----A---- C:\Windows\system32\lpk.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\drivers\npfs.sys
2019-12-11 13:08:31 ----A---- C:\Windows\system32\dciman32.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\appidsvc.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\appidapi.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\secur32.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\credssp.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\ntvdm64.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\credssp.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\comcat.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\auditpol.exe
2019-12-11 13:08:30 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\wow32.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\sscore.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\lpk.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\comcat.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2019-12-11 13:08:29 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-12-11 13:08:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-12-11 13:08:27 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-12-11 13:08:27 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-12-11 13:08:26 ----A---- C:\Windows\SYSWOW64\setup16.exe
2019-12-11 13:08:26 ----A---- C:\Windows\SYSWOW64\instnm.exe
2019-12-11 13:08:26 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2019-12-11 13:08:26 ----A---- C:\Windows\system32\apisetschema.dll
2019-12-11 13:08:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2019-12-11 13:08:25 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-12-11 13:08:25 ----A---- C:\Windows\SYSWOW64\user.exe
2019-12-11 13:08:25 ----A---- C:\Windows\system32\atmlib.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\oleres.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\oleres.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\msobjs.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\msaudite.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\adtschema.dll
2019-12-09 17:07:07 ----D---- C:\Program Files\Common Files\INCA Shared
2019-12-07 14:14:40 ----A---- C:\Windows\system32\drivers\fsbts.sys
2019-12-07 14:13:45 ----D---- C:\Program Files (x86)\F-Secure
2019-12-07 13:51:46 ----D---- C:\ProgramData\F-Secure
======List of files/folders modified in the last 1 month======
2020-01-06 18:15:50 ----RD---- C:\Program Files
2020-01-06 18:01:00 ----D---- C:\Program Files (x86)\Steam
2020-01-06 18:00:41 ----D---- C:\Windows\Temp
2020-01-06 18:00:00 ----RSD---- C:\Windows\assembly
2020-01-06 17:58:38 ----SHD---- C:\System Volume Information
2020-01-06 04:21:31 ----D---- C:\Windows\system32\config
2020-01-05 02:12:34 ----D---- C:\KMPlayer
2019-12-30 17:29:03 ----RD---- C:\Program Files (x86)
2019-12-30 17:29:03 ----HD---- C:\ProgramData
2019-12-30 12:32:36 ----D---- C:\Windows\System32
2019-12-30 12:32:36 ----D---- C:\Windows\inf
2019-12-30 12:32:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2019-12-30 12:05:00 ----D---- C:\Program Files (x86)\EA GAMES
2019-12-30 12:03:02 ----SHD---- C:\Windows\Installer
2019-12-30 12:03:02 ----SHD---- C:\Config.Msi
2019-12-29 23:20:01 ----D---- C:\Windows\Prefetch
2019-12-28 15:13:18 ----D---- C:\Windows\system32\catroot
2019-12-21 18:36:33 ----D---- C:\Windows\SysWOW64
2019-12-17 13:40:19 ----D---- C:\Users\Pajiss\AppData\Roaming\Azureus
2019-12-13 00:00:43 ----D---- C:\Windows\system32\catroot2
2019-12-12 12:40:48 ----D---- C:\mix
2019-12-11 21:07:43 ----D---- C:\Windows\rescache
2019-12-11 19:58:18 ----D---- C:\Windows\winsxs
2019-12-11 19:54:39 ----D---- C:\Windows\SYSWOW64\cs-CZ
2019-12-11 19:54:34 ----D---- C:\Windows\system32\drivers\en-US
2019-12-11 19:54:34 ----D---- C:\Windows\system32\drivers
2019-12-11 19:54:33 ----D---- C:\Windows\system32\cs-CZ
2019-12-11 19:54:30 ----D---- C:\Windows\system32\en-US
2019-12-11 19:54:28 ----D---- C:\Windows\AppPatch
2019-12-11 19:54:26 ----D---- C:\Windows\system32\Boot
2019-12-11 19:54:25 ----D---- C:\Windows\system32\DriverStore
2019-12-11 15:56:16 ----D---- C:\Windows\Microsoft.NET
2019-12-11 15:38:31 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2019-12-11 15:35:30 ----D---- C:\Windows\system32\MRT
2019-12-11 15:29:56 ----AC---- C:\Windows\system32\MRT.exe
2019-12-09 17:07:07 ----D---- C:\Program Files\Common Files
2019-12-09 17:00:24 ----D---- C:\Games1
2019-12-07 14:14:01 ----D---- C:\Windows\system32\Tasks
2019-12-07 13:53:47 ----D---- C:\Program Files\Microsoft Security Client
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 fsbts;fsbts; C:\Windows\system32\drivers\fsbts.sys [2019-12-07 57512]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2018-06-29 516096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2018-02-01 254528]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2018-01-08 61520]
R1 F-Secure UL HIPS;F-Secure Ultralight HIPS; \??\C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshs.sys [2019-12-11 102568]
R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-05-25 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-05-24 309760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2011-03-30 114704]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulgk.sys [2019-12-11 289448]
R3 fsni;fsni; \??\C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\fsni64.sys [2019-12-16 111472]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S1 fanio;FanIO driver; \??\C:\Windows\system32\drivers\fanio.sys [2007-02-16 22528]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2019-04-02 35856]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbrndis6;Adaptér USB RNDIS6; C:\Windows\system32\DRIVERS\usb80236.sys [2013-02-12 19968]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 wdm_usb;wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [2016-08-16 159936]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2019-09-10 88136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-05-24 204288]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-05-24 365568]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 fshoster;F-Secure Hoster; C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [2019-11-01 216464]
R2 fsnethoster;F-Secure Hoster (Restricted); C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [2019-11-01 216464]
R2 fsulhoster;F-Secure Ultralight Hoster; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe [2019-12-11 585288]
R2 fsulnethoster;F-Secure Ultralight Network Hoster; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe [2019-12-11 585288]
R2 fsulorsp;F-Secure Ultralight ORSP Client; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsorsp64.exe [2019-12-11 100240]
R2 fsulprothoster;F-Secure Ultralight Protected Hoster; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulprothoster.exe [2019-12-11 585288]
R2 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2019-03-28 132792]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2019-03-28 158912]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-12-25 153168]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.88\elevation_service.exe [2019-12-14 1113072]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-12-25 153168]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2019-05-12 8102192]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2018-03-23 1671968]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2017-12-28 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2019-03-28 54912]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
-----------------EOF-----------------
Run by Pajiss at 2020-01-06 18:15:50
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 46 GB (19%) free of 238 GB
Total RAM: 4095 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:16:03, on 6.1.2020
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\WargamingErrorMonitor.exe
C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe
C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files\trend micro\Pajiss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Browsing Protection by F-Secure - {45BBE08D-81C5-4A67-AF20-B2A077C67747} - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\browser\install\fs_ie_https\fs_ie_https.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EpicGamesLauncher] "C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe" -silent
O4 - HKCU\..\Run: [Wargaming.net Game Center] "C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe" --background ''
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'DefaultAppPool')
O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'DefaultAppPool')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: F-Secure Hoster (fshoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
O23 - Service: F-Secure Hoster (Restricted) (fsnethoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe
O23 - Service: F-Secure Ultralight Hoster (fsulhoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe
O23 - Service: F-Secure Ultralight Network Hoster (fsulnethoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe
O23 - Service: F-Secure Ultralight ORSP Client (fsulorsp) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsorsp64.exe
O23 - Service: F-Secure Ultralight Protected Hoster (fsulprothoster) - F-Secure Corporation - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulprothoster.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.88\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8136 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.35.422\GoogleCrashHandler64.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\system32\svchost.exe -k apphost
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe" -hosterid:0
"C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe" -hosterid:2
"C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe" -app -hosterId:1
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe" -PointAppFamily:1400 -hosterID:2
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsorsp64.exe"
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulprothoster.exe" -hosterID:0 -PointAppFamily:1450
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe" --background ''
"C:\Program Files (x86)\Wargaming.net\GameCenter\WargamingErrorMonitor.exe" --pipe "parent_pid_2864biv1457d-4di1-di14-d1i4-4i5bd14vq17t" --superuserid "WGC" --self_crash_handling_folder "C:\Program Files (x86)\Wargaming.net\GameCenter\cat " --self_crash_handling_receiver_url "http://cat.wargaming.net " Logs " "
"C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe" --type=gpu-process --field-trial-handle=1788,5349356738440504109,12221741420577677481,131072 --disable-features=MimeHandlerViewInCrossProcessFrame --no-sandbox --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --log-severity=info --user-agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 WGC/19.08.00.7920" --lang=en-US --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --service-request-channel-token=5267108080941335425 --mojo-platform-channel-handle=1824 /prefetch:2
"C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe" --type=utility --field-trial-handle=1788,5349356738440504109,12221741420577677481,131072 --disable-features=MimeHandlerViewInCrossProcessFrame --lang=en-US --service-sandbox-type=network --no-sandbox --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --log-severity=info --user-agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 WGC/19.08.00.7920" --lang=en-US --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --service-request-channel-token=1796310706532718795 --mojo-platform-channel-handle=2104 /prefetch:8
"C:\Program Files (x86)\Wargaming.net\GameCenter\dlls\wgc_renderer.exe" --type=renderer --no-sandbox --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --field-trial-handle=1788,5349356738440504109,12221741420577677481,131072 --disable-features=MimeHandlerViewInCrossProcessFrame --lang=en-US --log-file="C:\Program Files (x86)\Wargaming.net\GameCenter\logs\cef_20191230_173425_167.log" --log-severity=info --user-agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 WGC/19.08.00.7920" --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=2270597022342751070 --renderer-client-id=4 --mojo-platform-channel-handle=2164 /prefetch:1
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" "-lang=cs_CZ" "-cachedir=C:\Users\Pajiss\AppData\Local\Steam\htmlcache" "-steampid=2440" "-buildid=1576550254" "-steamid=0" "-steamuniverse=Public" "-clientui=C:\Program Files (x86)\Steam\clientui" --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --enable-media-stream --enable-smooth-scrolling --disable-accelerated-video-decode --enable-direct-write --disablehighdpi --force-device-scale-factor=1 --device-scale-factor=1 "--log-file=C:\Program Files (x86)\Steam\logs\cef_log.txt"
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Program Files (x86)\Steam\dumps" "--metrics-dir=C:\Users\Pajiss\AppData\Local\CEF\User Data" --url=http://crash.steampowered.com/submit --annotation=platform=win64 --annotation=product=cefwebhelper --annotation=version=1576550254 --initial-client-data=0x170,0x174,0x178,0x16c,0x17c,0x7fee214da70,0x7fee214da80,0x7fee214da90
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=gpu-process --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=cs-CZ --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --gpu-preferences=KAAAAAAAAADhAAAgAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --service-request-channel-token=5952726322897304540 --mojo-platform-channel-handle=1160 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=utility --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --lang=cs --service-sandbox-type=network --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --lang=cs-CZ --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --service-request-channel-token=17979791314100046276 --mojo-platform-channel-handle=904 /prefetch:8
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --lang=cs --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=2039247663977087549 --renderer-client-id=6 --mojo-platform-channel-handle=2000 /prefetch:1
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --lang=cs --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=11102866616920347121 --renderer-client-id=8 --mojo-platform-channel-handle=2172 /prefetch:1
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\system32\Dwm.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0f695552-68b1-40fd-bba5-90acefee4961 -SystemEventPortName:HostProcess-73a3d7d9-3b36-4ec7-b55a-308e27aaa1d6 -IoCancelEventPortName:HostProcess-8d069fb9-74ba-4309-825c-d40595312cb4 -NonStateChangingEventPortName:HostProcess-05d882c5-f79a-479d-a4f3-7df95bdb6697 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:8a7968cc-5b26-4de6-ac9f-92e0b5c67992 -DeviceGroupId:WpdFsGroup
"C:\totalcmd\TOTALCMD64.EXE"
"C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe" -PointAppFamily:1400
3252
"C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /Play -Embedding
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6d6083ae-9394-49c8-960f-a5ee66e5c20d -SystemEventPortName:HostProcess-e17c2b93-397b-4897-b35e-541a495ea429 -IoCancelEventPortName:HostProcess-8a99637c-38b6-47b6-9471-26d770d458b6 -NonStateChangingEventPortName:HostProcess-a631bde8-8c32-42f4-81e0-9ca4d970a23e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:34de2b19-7085-4a43-a5df-17a39698c4db -DeviceGroupId:
"C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe" --type=renderer --disable-accelerated-video-decode --force-device-scale-factor=1 --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --field-trial-handle=1084,17504305733881849863,12440239378562462696,131072 --disable-features=OutOfBlinkCors --enable-blink-features=ResizeObserver,Worklet,AudioWorklet --lang=cs --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --force-device-scale-factor=1 --disablehighdpi --buildid=1576550254 --steamid=0 --device-scale-factor=1 --num-raster-threads=1 --service-request-channel-token=15562942489820225585 --renderer-client-id=14 --mojo-platform-channel-handle=2948 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Pajiss\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Pajiss\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Pajiss\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=79.0.3945.88 --initial-client-data=0x3c,0x40,0x44,0x38,0x48,0x7fede13dd08,0x7fede13dd18,0x7fede13dd28
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=5940 --on-initialized-event-handle=12 --parent-handle=168 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=7714407001761206510 --mojo-platform-channel-handle=956 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --service-sandbox-type=network --enable-audio-service-sandbox --service-request-channel-token=5255198476374092737 --mojo-platform-channel-handle=1160 /prefetch:8
C:\Windows\system32\wbem\wmiprvse.exe
c:\windows\system32\inetsrv\w3wp.exe -ap "DefaultAppPool" -v "v2.0" -l "webengine4.dll" -a \\.\pipe\iisipmc55125ae-f709-46a7-b3bf-0078a7716b98 -h "C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config" -w "" -m 0 -t 20
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\WmiApSrv.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --disable-oor-cors --enable-auto-reload --device-scale-factor=1.25 --num-raster-threads=1 --service-request-channel-token=5325922324807856038 --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2636 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --disable-oor-cors --enable-auto-reload --device-scale-factor=1.25 --num-raster-threads=1 --service-request-channel-token=15253928773028779514 --renderer-client-id=23 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2756 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=944,15247789934403931715,11875967048198525303,131072 --lang=cs --disable-oor-cors --enable-auto-reload --device-scale-factor=1.25 --num-raster-threads=1 --service-request-channel-token=6331926929464306878 --renderer-client-id=25 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=864 /prefetch:1
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe268_ Global\UsGthrCtrlFltPipeMssGthrPipe268 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Pajiss\Downloads\RSITx64.exe"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45BBE08D-81C5-4A67-AF20-B2A077C67747}]
Browsing Protection by F-Secure - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\browser\install\fs_ie_https\fs_ie_https64.dll [2019-12-16 1639312]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45BBE08D-81C5-4A67-AF20-B2A077C67747}]
Browsing Protection by F-Secure - C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\browser\install\fs_ie_https\fs_ie_https.dll [2019-12-16 1056656]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2019-12-16 3288016]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"EpicGamesLauncher"=C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent []
"Wargaming.net Game Center"=C:\Program Files (x86)\Wargaming.net\GameCenter\wgc.exe [2019-12-18 2414456]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2014-03-13 779776]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-05-24 336384]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2020-01-06 18:15:50 ----D---- C:\Program Files\trend micro
2019-12-30 12:17:03 ----D---- C:\Program Files\Runtime Software
2019-12-30 12:03:01 ----D---- C:\Program Files (x86)\Unlocker
2019-12-17 13:41:08 ----D---- C:\Users\Pajiss\AppData\Roaming\uTorrent
2019-12-11 13:10:36 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2019-12-11 13:10:36 ----A---- C:\Windows\system32\poqexec.exe
2019-12-11 13:08:45 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2019-12-11 13:08:44 ----A---- C:\Windows\system32\win32k.sys
2019-12-11 13:08:44 ----A---- C:\Windows\system32\rdpcorets.dll
2019-12-11 13:08:44 ----A---- C:\Windows\system32\quartz.dll
2019-12-11 13:08:44 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2019-12-11 13:08:44 ----A---- C:\Windows\system32\appraiser.dll
2019-12-11 13:08:43 ----A---- C:\Windows\SYSWOW64\quartz.dll
2019-12-11 13:08:43 ----A---- C:\Windows\system32\winload.exe
2019-12-11 13:08:43 ----A---- C:\Windows\system32\mscms.dll
2019-12-11 13:08:43 ----A---- C:\Windows\system32\EOSNotify.exe
2019-12-11 13:08:42 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\SYSWOW64\mscms.dll
2019-12-11 13:08:42 ----A---- C:\Windows\SYSWOW64\icm32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\wow64win.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\t2embed.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\oleaut32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\icm32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\gdi32.dll
2019-12-11 13:08:42 ----A---- C:\Windows\system32\fontsub.dll
2019-12-11 13:08:41 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2019-12-11 13:08:41 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2019-12-11 13:08:41 ----A---- C:\Windows\system32\WcsPlugInService.dll
2019-12-11 13:08:41 ----A---- C:\Windows\system32\services.exe
2019-12-11 13:08:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2019-12-11 13:08:41 ----A---- C:\Windows\system32\ntdll.dll
2019-12-11 13:08:40 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2019-12-11 13:08:40 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2019-12-11 13:08:40 ----A---- C:\Windows\system32\hal.dll
2019-12-11 13:08:40 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\WcsPlugInService.dll
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2019-12-11 13:08:39 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2019-12-11 13:08:39 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2019-12-11 13:08:39 ----A---- C:\Windows\system32\CompatTelRunner.exe
2019-12-11 13:08:39 ----A---- C:\Windows\system32\atmfd.dll
2019-12-11 13:08:38 ----A---- C:\Windows\SYSWOW64\certcli.dll
2019-12-11 13:08:38 ----A---- C:\Windows\system32\ole32.dll
2019-12-11 13:08:38 ----A---- C:\Windows\system32\certcli.dll
2019-12-11 13:08:37 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\user32.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\rpcrt4.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\lsasrv.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\kerberos.dll
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\videoprt.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\srvnet.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\srv.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2019-12-11 13:08:37 ----A---- C:\Windows\system32\advapi32.dll
2019-12-11 13:08:36 ----A---- C:\Windows\SYSWOW64\user32.dll
2019-12-11 13:08:36 ----A---- C:\Windows\SYSWOW64\ole32.dll
2019-12-11 13:08:36 ----A---- C:\Windows\system32\smss.exe
2019-12-11 13:08:36 ----A---- C:\Windows\system32\kernel32.dll
2019-12-11 13:08:35 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\winsrv.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\srvsvc.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\schannel.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\rpcss.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\ncrypt.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\msv1_0.dll
2019-12-11 13:08:35 ----A---- C:\Windows\system32\drivers\srv2.sys
2019-12-11 13:08:35 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2019-12-11 13:08:34 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\wow64.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\wdigest.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\sspicli.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\srcore.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\KernelBase.dll
2019-12-11 13:08:34 ----A---- C:\Windows\system32\conhost.exe
2019-12-11 13:08:34 ----A---- C:\Windows\system32\bcrypt.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\schannel.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2019-12-11 13:08:33 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2019-12-11 13:08:33 ----A---- C:\Windows\system32\TSpkg.dll
2019-12-11 13:08:33 ----A---- C:\Windows\system32\rpchttp.dll
2019-12-11 13:08:33 ----A---- C:\Windows\system32\lsass.exe
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\processr.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\intelppm.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\appid.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\amdppm.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\drivers\amdk8.sys
2019-12-11 13:08:33 ----A---- C:\Windows\system32\csrsrv.dll
2019-12-11 13:08:32 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\wow64cpu.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\sspisrv.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\sscore.dll
2019-12-11 13:08:32 ----A---- C:\Windows\system32\cryptbase.dll
2019-12-11 13:08:31 ----A---- C:\Windows\SYSWOW64\srclient.dll
2019-12-11 13:08:31 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\srclient.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\setbcdlocale.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\secur32.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\rstrui.exe
2019-12-11 13:08:31 ----A---- C:\Windows\system32\lpk.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\drivers\npfs.sys
2019-12-11 13:08:31 ----A---- C:\Windows\system32\dciman32.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\appidsvc.dll
2019-12-11 13:08:31 ----A---- C:\Windows\system32\appidapi.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\secur32.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\credssp.dll
2019-12-11 13:08:30 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\ntvdm64.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\credssp.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\comcat.dll
2019-12-11 13:08:30 ----A---- C:\Windows\system32\auditpol.exe
2019-12-11 13:08:30 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-12-11 13:08:29 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\wow32.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\sscore.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\lpk.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\comcat.dll
2019-12-11 13:08:29 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2019-12-11 13:08:29 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-12-11 13:08:28 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-12-11 13:08:27 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-12-11 13:08:27 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-12-11 13:08:27 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-12-11 13:08:26 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-12-11 13:08:26 ----A---- C:\Windows\SYSWOW64\setup16.exe
2019-12-11 13:08:26 ----A---- C:\Windows\SYSWOW64\instnm.exe
2019-12-11 13:08:26 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2019-12-11 13:08:26 ----A---- C:\Windows\system32\apisetschema.dll
2019-12-11 13:08:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2019-12-11 13:08:25 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-12-11 13:08:25 ----A---- C:\Windows\SYSWOW64\user.exe
2019-12-11 13:08:25 ----A---- C:\Windows\system32\atmlib.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\oleres.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2019-12-11 13:08:24 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\oleres.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\msobjs.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\msaudite.dll
2019-12-11 13:08:24 ----A---- C:\Windows\system32\adtschema.dll
2019-12-09 17:07:07 ----D---- C:\Program Files\Common Files\INCA Shared
2019-12-07 14:14:40 ----A---- C:\Windows\system32\drivers\fsbts.sys
2019-12-07 14:13:45 ----D---- C:\Program Files (x86)\F-Secure
2019-12-07 13:51:46 ----D---- C:\ProgramData\F-Secure
======List of files/folders modified in the last 1 month======
2020-01-06 18:15:50 ----RD---- C:\Program Files
2020-01-06 18:01:00 ----D---- C:\Program Files (x86)\Steam
2020-01-06 18:00:41 ----D---- C:\Windows\Temp
2020-01-06 18:00:00 ----RSD---- C:\Windows\assembly
2020-01-06 17:58:38 ----SHD---- C:\System Volume Information
2020-01-06 04:21:31 ----D---- C:\Windows\system32\config
2020-01-05 02:12:34 ----D---- C:\KMPlayer
2019-12-30 17:29:03 ----RD---- C:\Program Files (x86)
2019-12-30 17:29:03 ----HD---- C:\ProgramData
2019-12-30 12:32:36 ----D---- C:\Windows\System32
2019-12-30 12:32:36 ----D---- C:\Windows\inf
2019-12-30 12:32:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2019-12-30 12:05:00 ----D---- C:\Program Files (x86)\EA GAMES
2019-12-30 12:03:02 ----SHD---- C:\Windows\Installer
2019-12-30 12:03:02 ----SHD---- C:\Config.Msi
2019-12-29 23:20:01 ----D---- C:\Windows\Prefetch
2019-12-28 15:13:18 ----D---- C:\Windows\system32\catroot
2019-12-21 18:36:33 ----D---- C:\Windows\SysWOW64
2019-12-17 13:40:19 ----D---- C:\Users\Pajiss\AppData\Roaming\Azureus
2019-12-13 00:00:43 ----D---- C:\Windows\system32\catroot2
2019-12-12 12:40:48 ----D---- C:\mix
2019-12-11 21:07:43 ----D---- C:\Windows\rescache
2019-12-11 19:58:18 ----D---- C:\Windows\winsxs
2019-12-11 19:54:39 ----D---- C:\Windows\SYSWOW64\cs-CZ
2019-12-11 19:54:34 ----D---- C:\Windows\system32\drivers\en-US
2019-12-11 19:54:34 ----D---- C:\Windows\system32\drivers
2019-12-11 19:54:33 ----D---- C:\Windows\system32\cs-CZ
2019-12-11 19:54:30 ----D---- C:\Windows\system32\en-US
2019-12-11 19:54:28 ----D---- C:\Windows\AppPatch
2019-12-11 19:54:26 ----D---- C:\Windows\system32\Boot
2019-12-11 19:54:25 ----D---- C:\Windows\system32\DriverStore
2019-12-11 15:56:16 ----D---- C:\Windows\Microsoft.NET
2019-12-11 15:38:31 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2019-12-11 15:35:30 ----D---- C:\Windows\system32\MRT
2019-12-11 15:29:56 ----AC---- C:\Windows\system32\MRT.exe
2019-12-09 17:07:07 ----D---- C:\Program Files\Common Files
2019-12-09 17:00:24 ----D---- C:\Games1
2019-12-07 14:14:01 ----D---- C:\Windows\system32\Tasks
2019-12-07 13:53:47 ----D---- C:\Program Files\Microsoft Security Client
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 fsbts;fsbts; C:\Windows\system32\drivers\fsbts.sys [2019-12-07 57512]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2018-06-29 516096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2018-02-01 254528]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2018-01-08 61520]
R1 F-Secure UL HIPS;F-Secure Ultralight HIPS; \??\C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshs.sys [2019-12-11 102568]
R2 speedfan;speedfan; \??\C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-05-25 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-05-24 309760]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2011-03-30 114704]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulgk.sys [2019-12-11 289448]
R3 fsni;fsni; \??\C:\Program Files (x86)\F-Secure\SAFE\Ultralight\nif\1576497283\fsni64.sys [2019-12-16 111472]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S1 fanio;FanIO driver; \??\C:\Windows\system32\drivers\fanio.sys [2007-02-16 22528]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2019-04-02 35856]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2017-05-18 166288]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbrndis6;Adaptér USB RNDIS6; C:\Windows\system32\DRIVERS\usb80236.sys [2013-02-12 19968]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 wdm_usb;wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [2016-08-16 159936]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2019-09-10 88136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-05-24 204288]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-05-24 365568]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 fshoster;F-Secure Hoster; C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [2019-11-01 216464]
R2 fsnethoster;F-Secure Hoster (Restricted); C:\Program Files (x86)\F-Secure\SAFE\fshoster32.exe [2019-11-01 216464]
R2 fsulhoster;F-Secure Ultralight Hoster; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe [2019-12-11 585288]
R2 fsulnethoster;F-Secure Ultralight Network Hoster; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fshoster64.exe [2019-12-11 585288]
R2 fsulorsp;F-Secure Ultralight ORSP Client; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsorsp64.exe [2019-12-11 100240]
R2 fsulprothoster;F-Secure Ultralight Protected Hoster; C:\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1576069576\fsulprothoster.exe [2019-12-11 585288]
R2 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2019-03-28 132792]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2019-03-28 158912]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-12-25 153168]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.88\elevation_service.exe [2019-12-14 1113072]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-12-25 153168]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2019-05-12 8102192]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2018-03-23 1671968]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2017-12-28 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2019-03-28 54912]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
-----------------EOF-----------------