Kontrola logů, špatně se mi načítají stránky, některé vůbec,
Napsal: 21 zář 2021 15:27
Zdravím. Špatně se mi načítají stránky, některé vůbec, píše že server neodpovědel v čase apod.
Nepoužívám antivir, myslel jsem že je to v dnešní době zbytečné když neklikam na nějaký porno clickbait
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-09-2021
Ran by XXX (administrator) on XXX-PC (LENOVO 4384FV7) (21-09-2021 16:13:40)
Running from C:\Users\XXX\Desktop
Loaded Profiles: XXX & UpdatusUser
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Default browser: "C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --single-argument %1
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(DISPLAYLINK -> DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe
(DISPLAYLINK -> DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUI.exe
(DISPLAYLINK -> DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUserAgent.exe
(Intel Corporation - Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Lavasoft Software Canada Inc. -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
(Lavasoft Software Canada Inc. -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe
(Lavasoft Software Canada Inc. -> Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
(Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe
(Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Lenovo -> Lenovo.) C:\Windows\System32\LPlatSvc.exe <2>
(LITE-ON TECHNOLOGY CORP.) [File not signed] C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\Skdaemon.exe
(Maxthon Technology Co, Ltd. -> Maxthon Ltd.) C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe <13>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Power Software Limited -> Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Qualcomm Inc -> QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE <3>
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [442936 2020-10-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Run: [Enhanced Performance Keyboard] => C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\SKDaemon.exe [4013056 2014-08-17] (LITE-ON TECHNOLOGY CORP.) [File not signed]
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-15] (Conexant Systems, Inc. -> )
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [455872 2020-02-09] (Power Software Limited -> Power Software Ltd)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [9123248 2021-09-20] (Lavasoft Software Canada Inc. -> Lavasoft)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPSDNMON] => ""
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8619224 2016-01-15] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\yowindow.scr
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2020-02-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\EPSON XP-630 Series 64MonitorBE: C:\Windows\system32\E_YLMBPLE.DLL [180224 2014-03-05] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-10-29] (NVIDIA CORPORATION -> NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-10-29] (NVIDIA CORPORATION -> NVIDIA Corporation)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {07F9EF7A-1F22-4511-B818-EE6362BBBCAC} - System32\Tasks\Games\UpdateCheck_S-1-5-21-555042887-2286466740-3098252512-1000 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2012-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {29FF17AC-EA42-4AEB-BE92-127890972074} - System32\Tasks\TVT\ChangePWD => C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrcmd.exe [1272168 2013-09-25] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Limited Group Corporation)
Task: {2F81CFBE-2693-40B6-9754-B4FAB9153B89} - System32\Tasks\{72473BEC-643F-463F-AFB7-46DED0B91711} => C:\Windows\system32\pcalua.exe -a C:\Users\XXX\Desktop\DialogysInstall_PC.exe -d C:\Users\XXX\Desktop
Task: {3B91FC34-0AB6-4843-9DCE-5731B3407464} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: {46249C69-1762-409D-8318-3279892DBA49} - System32\Tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {49517535-8100-4FA3-AD29-D9AB16CF6F46} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [6628056 2016-01-15] (Piriform Ltd -> Piriform Ltd)
Task: {50110C47-559A-4DD3-8B4B-D80E5195AFAD} - System32\Tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {58DC4A38-9466-443F-B8AA-903E49316E4C} - System32\Tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {5B3FAEDE-8B3A-4273-AAEE-2B1C331B9CCB} - System32\Tasks\{34A296ED-6081-4403-A8B5-F7E8F256225C} => C:\Windows\system32\pcalua.exe -a C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe -d C:\Users\XXX\AppData\Local\Temp\7zS806E4871 -c C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe hhwnd=9832342 hasync hthankyoupage="http://www.gomlab.com/gom/installThanks ... r&lang=eng" title="GOM Player Setup" -> -a C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe -d C:\Users\XXX\AppData\Local\Temp\7zS806E4871 -c C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe hhwnd=9832342 hasync hthankyoupage="hxxp://www.gomlab.com/gom/installThanks.gom?pr ... r&lang=eng" title="GOM Player (the data entry has 7 more characters). <==== ATTENTION
Task: {968F1CAD-5227-4345-9FA0-6C6F5E95C3B4} - System32\Tasks\TVT\LaunchRnR => C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrcmd.exe [1272168 2013-09-25] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Limited Group Corporation)
Task: {B0C00EAD-68F6-44BB-88EC-A2302D4B1D30} - System32\Tasks\{5CC936AD-914B-404D-B40F-5FC717E65481} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\KONAMI\MetalGearSolid2 Substance\bin\MGS2SSetup.exe" -d "C:\Program Files (x86)\KONAMI\MetalGearSolid2 Substance\bin"
Task: {B2ABA462-A170-4CEC-9206-31F92E4AD5F7} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2916592 2014-07-28] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {B95E45FA-6E22-4186-8D04-AE8DB0A689AA} - System32\Tasks\TVT\UpdateRnR => C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsetsched.exe [593920 2013-09-25] () [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE:/EXE:{326805B2-8C58-4D3D-A4E5-E90D3768C8D5} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE:/EXE:{4AAB39D2-890A-4DC4-B515-785176BC5786} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE:/EXE:{C5E4CE44-5ED1-48B5-8A3C-4952643C058B} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{362D3F70-6BF6-47E7-B731-78954894A20C}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Profile 1
Edge Profile: C:\Users\XXX\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2021-09-21]
Edge Notifications: Profile 1 -> hxxps://meet.google.com
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2020-02-24] [Legacy] [not signed]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files (x86)\CCleaner Browser\Update\1.7.848.0\npCCleanerBrowserUpdate3.dll [No File]
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files (x86)\CCleaner Browser\Update\1.7.848.0\npCCleanerBrowserUpdate3.dll [No File]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 connect2hotspot; C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe [100680 2017-02-08] (Lenovo -> Lenovo)
R2 DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [3413424 2021-09-20] (Lavasoft Software Canada Inc. -> )
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe [11871976 2016-08-23] (DISPLAYLINK -> DisplayLink Corp.)
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [685496 2019-05-08] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
R2 LPlatSvc; C:\Windows\system32\LPlatSvc.exe [711248 2017-04-01] (Lenovo -> Lenovo.)
R2 QDLService2kLenovo; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe [1688384 2011-05-23] (Qualcomm Inc -> QUALCOMM, Inc.)
S3 ss_conn_launcher_service; C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe [182328 2020-04-27] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-04-27] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [934328 2020-04-27] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13271336 2021-09-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S4 ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [1028096 2010-08-31] (Lenovo Group Limited) [File not signed]
S3 TVT Backup Service; C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe [1526120 2013-09-25] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Group Limited)
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [22960 2021-09-20] (Lavasoft Software Canada Inc. -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BdDci; C:\Windows\System32\DRIVERS\bddci.sys [367096 2021-09-20] (Bitdefender SRL -> Bitdefender)
R2 rimspci; C:\Windows\System32\DRIVERS\rimspe64.sys [61952 2009-10-26] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
R3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
R3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166760 2020-04-27] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [43368 2020-04-27] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-30] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Information Product(ShenZhen China) Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-21 16:14 - 2021-09-21 16:15 - 000000000 ____D C:\rsit
2021-09-21 16:14 - 2021-09-21 16:15 - 000000000 ____D C:\Program Files\trend micro
2021-09-21 16:13 - 2021-09-21 16:18 - 000018118 _____ C:\Users\XXX\Desktop\FRST.txt
2021-09-21 16:13 - 2021-09-21 16:13 - 001222144 _____ C:\Users\XXX\Desktop\RSITx64.exe
2021-09-21 16:09 - 2021-09-21 16:09 - 002304512 _____ (Farbar) C:\Users\XXX\Desktop\FRST64.exe
2021-09-21 15:53 - 2021-09-21 16:16 - 000000000 ____D C:\FRST
2021-09-21 15:39 - 2021-09-21 15:39 - 000388608 _____ (Trend Micro Inc.) C:\Users\XXX\Downloads\HijackThis.exe
2021-09-21 14:58 - 2021-09-21 14:58 - 000002296 _____ C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxthon.lnk
2021-09-21 14:58 - 2021-09-21 14:58 - 000002259 _____ C:\Users\XXX\Desktop\Maxthon.lnk
2021-09-21 14:58 - 2021-09-21 14:58 - 000000000 ____D C:\Users\XXX\AppData\Roaming\VBox
2021-09-21 14:58 - 2021-09-21 14:58 - 000000000 ____D C:\Users\XXX\AppData\Local\vback
2021-09-21 14:57 - 2021-09-21 14:58 - 000000000 ____D C:\Users\XXX\AppData\Local\Maxthon
2021-09-20 07:44 - 2021-09-20 07:44 - 000367096 _____ (Bitdefender) C:\Windows\system32\Drivers\bddci.sys
2021-09-19 14:18 - 2021-09-19 15:53 - 000000000 ____D C:\Users\XXX\Downloads\Alphaville - First Harvest 1984 1992
2021-09-19 10:27 - 2021-09-19 09:33 - 124298470 _____ C:\Users\XXX\Desktop\06.-New Year's Day.flac
2021-09-02 09:27 - 2021-09-02 09:27 - 000001054 _____ C:\Users\Public\Desktop\BurnAware Free.lnk
2021-09-02 09:27 - 2021-09-02 09:27 - 000000000 ____D C:\Users\XXX\AppData\Roaming\Burnaware
2021-09-02 09:27 - 2021-09-02 09:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
2021-09-02 09:27 - 2021-09-02 09:27 - 000000000 ____D C:\Program Files (x86)\BurnAware Free
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-21 16:02 - 2020-02-24 14:59 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-09-21 16:02 - 2020-02-24 14:02 - 000000911 _____ C:\Windows\Tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786}.job
2021-09-21 16:01 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-09-21 15:45 - 2020-11-08 22:45 - 000000911 _____ C:\Windows\Tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B}.job
2021-09-21 15:39 - 2020-02-08 19:16 - 000000000 ____D C:\Users\XXX\AppData\Local\VirtualStore
2021-09-21 14:57 - 2020-02-24 13:57 - 000000911 _____ C:\Windows\Tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5}.job
2021-09-21 14:48 - 2009-07-14 06:45 - 000026176 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2021-09-21 14:48 - 2009-07-14 06:45 - 000026176 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2021-09-21 14:27 - 2020-02-20 14:08 - 000000000 ____D C:\Users\XXX\AppData\Roaming\Maxthon5
2021-09-21 14:15 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2021-09-21 13:59 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2021-09-19 16:01 - 2020-02-25 13:42 - 000001491 _____ C:\Users\XXX\Desktop\AudioExtractor.ini
2021-09-19 15:56 - 2021-04-26 11:13 - 000000000 ____D C:\Users\XXX\AppData\Roaming\uTorrent
2021-09-19 09:01 - 2020-07-01 16:29 - 000002221 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-19 09:01 - 2020-07-01 16:29 - 000002180 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-09-15 15:34 - 2020-02-24 19:29 - 000000000 ____D C:\Windows\system32\MRT
2021-09-15 15:29 - 2020-02-24 19:29 - 135637312 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-09-06 14:19 - 2020-02-09 12:03 - 000000000 ____D C:\Users\XXX\My Drivers
2021-09-01 12:00 - 2020-12-23 14:18 - 000000000 ____D C:\SWSHARE
2021-08-30 22:45 - 2020-02-24 17:56 - 000803176 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2021-08-24 16:40 - 2009-07-14 17:18 - 000668376 _____ C:\Windows\system32\perfh005.dat
2021-08-24 16:40 - 2009-07-14 17:18 - 000141004 _____ C:\Windows\system32\perfc005.dat
2021-08-24 16:40 - 2009-07-14 07:13 - 001582262 _____ C:\Windows\system32\PerfStringBackup.INI
==================== Files in the root of some directories ========
2020-09-18 11:27 - 2020-09-18 11:27 - 000195296 _____ () C:\Users\XXX\comcat5.dll
2020-04-08 11:23 - 2020-04-08 13:25 - 000001576 _____ () C:\Program Files (x86)\DialogysUninstWPS.bat
2020-04-08 11:23 - 2020-04-08 11:23 - 000000840 _____ () C:\Program Files (x86)\INSTALL.LOG
2020-04-08 11:23 - 2014-09-12 13:01 - 000176055 _____ () C:\Program Files (x86)\UninstScript.EXE
2020-12-23 11:55 - 2020-12-23 12:18 - 000013797 _____ () C:\Users\XXX\AppData\Local\WiDiSetupLog.20201223.105508.wdl
==================== FLock ==============================
2020-12-23 14:37 C:\RRbackups
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2021-09-19 16:22
==================== End of FRST.txt ========================
Logfile of random's system information tool 1.10 (written by random/random)
Run by XXX at 2021-09-21 16:14:28
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 90 GB (30%) free of 303 GB
Total RAM: 5940 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:15:29, on 21.9.2021
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19597)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE
C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files\trend micro\XXX.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE -startup
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-630 Series"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-630 Series"
O4 - HKCU\..\Run: [Web Companion] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
O4 - HKCU\..\Run: [EPSDNMON] ""
O4 - HKCU\..\Run: [EPLTarget\P0000000000000002] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE /EPT "EPLTarget\P0000000000000002" /M "XP-630 Series"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-555042887-2286466740-3098252512-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-555042887-2286466740-3098252512-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Connect2 Hotspot Service (connect2hotspot) - Lenovo - C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe
O23 - Service: DCIService - - C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonCustomerResearchParticipation - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V3 Service4(06) (EPSON_PM_RPCV4_06) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Platform Service (LPlatSvc) - Unknown owner - C:\Windows\system32\LPlatSvc.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Gobi 2000 Download Service (Lenovo) (QDLService2kLenovo) - QUALCOMM, Inc. - C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile USB Connectivity Launcher (ss_conn_launcher_service) - Unknown owner - C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
O23 - Service: SAMSUNG Mobile Connectivity Service V2 (ss_conn_service2) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
O23 - Service: TeamViewer - TeamViewer Germany GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WC Assistant (WCAssistantService) - Unknown owner - C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9501 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\LPlatSvc.exe
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\LPlatSvc.exe" -EM
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9a01b958-501c-4daa-8c9b-9def8f5a808f -SystemEventPortName:HostProcess-ecc18278-3157-48fc-b254-dbd69059ac1a -IoCancelEventPortName:HostProcess-2ecade95-2d3d-42d8-b764-fc8d6e8c2d50 -NonStateChangingEventPortName:HostProcess-748a65b5-8859-49f5-9aa5-ab9ebf9cb178 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:3e908f06-1663-4c3e-bbce-653bd355d5c5 -DeviceGroupId:
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUserAgent.exe" -dluPipeName dl.dlu.s3PULntKOo89YaUZMvXzmyW5g2TwTUr3u2xtQ1XWzu4CD0Ox2dPv1S1faO2hdea8 -monitorableAppPipeName dl.monitorable.app.SLAOKuflbxYTIiGqOeNjQSG8GfwHN42Mx2onFSeho0IeRiFB53Caq11dEifI0vt9
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUI.exe" -monitorableAppPipeName dl.monitorable.app.CnIrvWT7Qnctdvn6JtlpeQYEh5d97aadYVFV1LYc6u27NEDxyCgZd2GNMZxZkqtp
"C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe"
taskeng.exe {98D61294-A45F-494C-9D3C-60AE83103CF1}
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\splwow64.exe 8192
"C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\Skdaemon.exe"
"C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE" /EPT "EPLTarget\P0000000000000000" /M "XP-630 Series"
"C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE" /EPT "EPLTarget\P0000000000000001" /M "XP-630 Series"
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe" --minimize
"C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE" /EPT "EPLTarget\P0000000000000002" /M "XP-630 Series"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe"
"C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\system32\EscSvc64.exe
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE"
"C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
"C:\Program Files\PowerISO\PWRISOVM.EXE" -startup
"C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe"
"C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe --type=crashpad-handler "--user-data-dir=C:\Users\XXX\AppData\Local\Maxthon\Application\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\XXX\AppData\Local\Maxthon\Application\User Data\Crashpad" "--metrics-dir=C:\Users\XXX\AppData\Local\Maxthon\Application\User Data" --annotation=plat=Win64 --annotation=prod=Maxthon --annotation=ver=6.1.2.1000 --initial-client-data=0xc4,0xc8,0xcc,0x98,0xd0,0x7fee49170c8,0x7fee49170d8,0x7fee49170e8
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=gpu-process --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --no-sandbox --start-stack-profiler --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1124 /prefetch:2
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --service-sandbox-type=network --no-sandbox --mojo-platform-channel-handle=1328 /prefetch:8
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --service-sandbox-type=utility --no-sandbox --mojo-platform-channel-handle=1760 /prefetch:8
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --service-sandbox-type=utility --no-sandbox --mojo-platform-channel-handle=2312 /prefetch:8
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --extension-process --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3152 /prefetch:1
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3848 /prefetch:1
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer15_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer15_Logfile.log
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5000 /prefetch:1
C:\Windows\system32\sppsvc.exe
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=32 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5904 /prefetch:1
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Users\XXX\Desktop\FRST64.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k swprv
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=37 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1424 /prefetch:1
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3876 /prefetch:1
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\XXX\Desktop\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
======Scheduled tasks folder======
C:\Windows\tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5}.job - C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE /EXE:"{326805B2-8C58-4D3D-A4E5-E90D3768C8D5}" /F:"Update"
C:\Windows\tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786}.job - C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE /EXE:"{4AAB39D2-890A-4DC4-B515-785176BC5786}" /F:"Update"
C:\Windows\tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B}.job - C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE /EXE:"{C5E4CE44-5ED1-48B5-8A3C-4952643C058B}" /F:"Update"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho_64.dll [2021-09-16 524176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31 471536]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho.dll [2021-09-16 406928]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201CF130-E29C-4E5C-A73F-CD197DEFA6AE}]
E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27 238576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31 471536]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27 238576]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"EPPCCMON"=C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [2020-10-22 442936]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-12-22 168216]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-12-22 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-12-22 416024]
"Enhanced Performance Keyboard"=C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\SKDaemon.exe [2014-08-17 4013056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-15 307768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EPLTarget\P0000000000000000"=C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [2014-11-14 417776]
"EPLTarget\P0000000000000001"=C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [2014-11-14 417776]
"Web Companion"=C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [2021-09-20 9123248]
"EPSDNMON"= []
"EPLTarget\P0000000000000002"=C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [2014-11-14 417776]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-01-15 8619224]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2016-01-20 1087184]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2020-02-09 455872]
""= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-05-21 389632]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2021-09-21 16:14:28 ----D---- C:\rsit
2021-09-21 16:14:28 ----D---- C:\Program Files\trend micro
2021-09-21 15:53:09 ----D---- C:\FRST
2021-09-21 14:58:41 ----D---- C:\Users\XXX\AppData\Roaming\VBox
2021-09-20 07:44:04 ----A---- C:\Windows\system32\drivers\bddci.sys
2021-09-02 09:27:24 ----D---- C:\Users\XXX\AppData\Roaming\Burnaware
2021-09-02 09:27:02 ----D---- C:\Program Files (x86)\BurnAware Free
======List of files/folders modified in the last 1 month======
2021-09-21 16:14:28 ----RD---- C:\Program Files
2021-09-21 16:10:55 ----SHD---- C:\System Volume Information
2021-09-21 16:07:18 ----D---- C:\Windows\Temp
2021-09-21 16:02:16 ----D---- C:\Program Files (x86)\TeamViewer
2021-09-21 15:55:33 ----D---- C:\Windows\system32\config
2021-09-21 14:37:16 ----D---- C:\Windows
2021-09-21 14:27:59 ----D---- C:\Users\XXX\AppData\Roaming\Maxthon5
2021-09-21 14:27:40 ----RD---- C:\Program Files (x86)
2021-09-21 14:27:28 ----D---- C:\Windows\system32\Tasks
2021-09-21 14:15:17 ----D---- C:\Windows\system32\NDF
2021-09-21 14:15:17 ----D---- C:\Windows\Prefetch
2021-09-21 13:59:51 ----D---- C:\Windows\inf
2021-09-21 09:19:01 ----D---- C:\Windows\debug
2021-09-20 07:44:07 ----D---- C:\Windows\system32\drivers
2021-09-20 07:40:09 ----D---- C:\Windows\system32\wdi
2021-09-19 15:56:26 ----D---- C:\Users\XXX\AppData\Roaming\uTorrent
2021-09-19 15:55:40 ----D---- C:\Windows\SysWOW64
2021-09-19 15:55:40 ----D---- C:\Windows\System32
2021-09-15 15:30:09 ----D---- C:\Windows\system32\MRT
2021-09-15 15:29:41 ----AC---- C:\Windows\system32\MRT.exe
2021-09-01 12:00:18 ----D---- C:\SWSHARE
2021-08-30 22:45:38 ----N---- C:\Windows\system32\MpSigStub.exe
2021-08-24 16:40:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 dlkmdldr;dlkmdldr; C:\Windows\system32\drivers\dlkmdldr.sys [2016-08-23 27920]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2013-10-29 30496]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2017-06-07 138296]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BdDci;BdDci Service; C:\Windows\system32\DRIVERS\bddci.sys [2021-09-20 367096]
R2 rimspci;rimspci; C:\Windows\system32\DRIVERS\rimspe64.sys [2009-10-26 61952]
R3 bpenum;Intel(R) Centrino(R) WiMAX Enumerator; C:\Windows\system32\DRIVERS\bpenum.sys [2012-07-03 84480]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2019-07-30 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\drivers\bthpan.sys [2017-07-06 119296]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2019-07-30 80384]
R3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2020-02-25 54824]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-08-25 682624]
R3 dlkmd;dlkmd; C:\Windows\system32\drivers\dlkmd.sys [2016-08-23 457488]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\Windows\system32\DRIVERS\e1k62x64.sys [2011-07-20 342704]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-02-19 57848]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2017-04-01 82816]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-05-21 12229664]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-27 158976]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2020-12-23 40248]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2011-08-30 1225832]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2014-07-28 45296]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2014-07-28 461552]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2016-02-05 147904]
R3 TVTI2C;Lenovo SM bus driver; C:\Windows\system32\DRIVERS\Tvti2c.sys [2011-05-30 40248]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WinUsb;WinUSB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2019-07-30 556032]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2020-04-27 136040]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-02-25 197408]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 ss_conn_usb_driver2;SAMSUNG Mobile USB Connectivity Device Driver V2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [2020-04-27 43368]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2020-04-27 166760]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2019-12-10 42496]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 connect2hotspot;Connect2 Hotspot Service; C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe [2017-02-08 100680]
R2 DCIService;DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [2021-09-20 3413424]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DisplayLinkService;DisplayLinkManager; C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe [2016-08-23 11871976]
R2 EPSON_PM_RPCV4_06;EPSON V3 Service4(06); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [2013-04-15 152640]
R2 EpsonCustomerResearchParticipation;EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [2019-05-08 685496]
R2 EpsonScanSvc;Epson Scanner Service; C:\Windows\system32\EscSvc64.exe [2012-05-17 144560]
R2 IBMPMSVC;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2017-04-01 187984]
R2 LPlatSvc;Lenovo Platform Service; C:\Windows\system32\LPlatSvc.exe [2017-04-01 711248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-10-29 893216]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-10-29 1260320]
R2 QDLService2kLenovo;Qualcomm Gobi 2000 Download Service (Lenovo); C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe [2011-05-23 1688384]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2010-10-19 838928]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [2020-04-27 752224]
R2 ss_conn_service2;SAMSUNG Mobile Connectivity Service V2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [2020-04-27 934328]
R2 TeamViewer;TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2021-09-02 13271336]
R2 WCAssistantService;WC Assistant; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [2021-09-20 22960]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2019-03-28 132792]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2019-03-28 158912]
S2 edgeupdate;Služba Microsoft Edge Update (edgeupdate); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-07-01 224152]
S3 edgeupdatem;Služba Microsoft Edge Update (edgeupdatem); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-07-01 224152]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2019-12-17 116224]
S3 MicrosoftEdgeElevationService;Microsoft Edge Elevation Service (MicrosoftEdgeElevationService); C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\elevation_service.exe [2021-09-16 1651616]
S3 ss_conn_launcher_service;SAMSUNG Mobile USB Connectivity Launcher; C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe [2020-04-27 182328]
S3 TVT Backup Service;TVT Backup Service; C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe [2013-09-25 1526120]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2020-02-24 1255736]
S3 WiaRpc;@%SystemRoot%\system32\wiarpc.dll,-2; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2019-03-28 54912]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
S4 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2010-08-31 1028096]
-----------------EOF-----------------
Nepoužívám antivir, myslel jsem že je to v dnešní době zbytečné když neklikam na nějaký porno clickbait
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-09-2021
Ran by XXX (administrator) on XXX-PC (LENOVO 4384FV7) (21-09-2021 16:13:40)
Running from C:\Users\XXX\Desktop
Loaded Profiles: XXX & UpdatusUser
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Default browser: "C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --single-argument %1
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(DISPLAYLINK -> DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe
(DISPLAYLINK -> DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUI.exe
(DISPLAYLINK -> DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUserAgent.exe
(Intel Corporation - Mobile Wireless Group -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Lavasoft Software Canada Inc. -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
(Lavasoft Software Canada Inc. -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe
(Lavasoft Software Canada Inc. -> Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
(Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe
(Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Lenovo -> Lenovo.) C:\Windows\System32\LPlatSvc.exe <2>
(LITE-ON TECHNOLOGY CORP.) [File not signed] C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\Skdaemon.exe
(Maxthon Technology Co, Ltd. -> Maxthon Ltd.) C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe <13>
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Power Software Limited -> Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Qualcomm Inc -> QUALCOMM, Inc.) C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE <3>
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [EPPCCMON] => C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [442936 2020-10-22] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
HKLM\...\Run: [Enhanced Performance Keyboard] => C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\SKDaemon.exe [4013056 2014-08-17] (LITE-ON TECHNOLOGY CORP.) [File not signed]
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-15] (Conexant Systems, Inc. -> )
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [455872 2020-02-09] (Power Software Limited -> Power Software Ltd)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [9123248 2021-09-20] (Lavasoft Software Canada Inc. -> Lavasoft)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPSDNMON] => ""
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [417776 2014-11-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8619224 2016-01-15] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-555042887-2286466740-3098252512-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\yowindow.scr
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2020-02-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Print\Monitors\EPSON XP-630 Series 64MonitorBE: C:\Windows\system32\E_YLMBPLE.DLL [180224 2014-03-05] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\...\Print\Monitors\EpsonNet Print Port: C:\Windows\system32\enppmon.dll [500736 2016-09-14] (SEIKO EPSON CORPORATION) [File not signed]
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-10-29] (NVIDIA CORPORATION -> NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-10-29] (NVIDIA CORPORATION -> NVIDIA Corporation)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {07F9EF7A-1F22-4511-B818-EE6362BBBCAC} - System32\Tasks\Games\UpdateCheck_S-1-5-21-555042887-2286466740-3098252512-1000 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2012-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {29FF17AC-EA42-4AEB-BE92-127890972074} - System32\Tasks\TVT\ChangePWD => C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrcmd.exe [1272168 2013-09-25] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Limited Group Corporation)
Task: {2F81CFBE-2693-40B6-9754-B4FAB9153B89} - System32\Tasks\{72473BEC-643F-463F-AFB7-46DED0B91711} => C:\Windows\system32\pcalua.exe -a C:\Users\XXX\Desktop\DialogysInstall_PC.exe -d C:\Users\XXX\Desktop
Task: {3B91FC34-0AB6-4843-9DCE-5731B3407464} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: {46249C69-1762-409D-8318-3279892DBA49} - System32\Tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {49517535-8100-4FA3-AD29-D9AB16CF6F46} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [6628056 2016-01-15] (Piriform Ltd -> Piriform Ltd)
Task: {50110C47-559A-4DD3-8B4B-D80E5195AFAD} - System32\Tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {58DC4A38-9466-443F-B8AA-903E49316E4C} - System32\Tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE [690536 2013-11-22] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Task: {5B3FAEDE-8B3A-4273-AAEE-2B1C331B9CCB} - System32\Tasks\{34A296ED-6081-4403-A8B5-F7E8F256225C} => C:\Windows\system32\pcalua.exe -a C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe -d C:\Users\XXX\AppData\Local\Temp\7zS806E4871 -c C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe hhwnd=9832342 hasync hthankyoupage="http://www.gomlab.com/gom/installThanks ... r&lang=eng" title="GOM Player Setup" -> -a C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe -d C:\Users\XXX\AppData\Local\Temp\7zS806E4871 -c C:\Users\XXX\AppData\Local\Temp\7zS806E4871\GenericSetup.exe hhwnd=9832342 hasync hthankyoupage="hxxp://www.gomlab.com/gom/installThanks.gom?pr ... r&lang=eng" title="GOM Player (the data entry has 7 more characters). <==== ATTENTION
Task: {968F1CAD-5227-4345-9FA0-6C6F5E95C3B4} - System32\Tasks\TVT\LaunchRnR => C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrcmd.exe [1272168 2013-09-25] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Limited Group Corporation)
Task: {B0C00EAD-68F6-44BB-88EC-A2302D4B1D30} - System32\Tasks\{5CC936AD-914B-404D-B40F-5FC717E65481} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\KONAMI\MetalGearSolid2 Substance\bin\MGS2SSetup.exe" -d "C:\Program Files (x86)\KONAMI\MetalGearSolid2 Substance\bin"
Task: {B2ABA462-A170-4CEC-9206-31F92E4AD5F7} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2916592 2014-07-28] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {B95E45FA-6E22-4186-8D04-AE8DB0A689AA} - System32\Tasks\TVT\UpdateRnR => C:\Program Files (x86)\Common Files\Lenovo\Scheduler\tvtsetsched.exe [593920 2013-09-25] () [File not signed]
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE:/EXE:{326805B2-8C58-4D3D-A4E5-E90D3768C8D5} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE:/EXE:{4AAB39D2-890A-4DC4-B515-785176BC5786} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\Windows\Tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE:/EXE:{C5E4CE44-5ED1-48B5-8A3C-4952643C058B} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{362D3F70-6BF6-47E7-B731-78954894A20C}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Profile 1
Edge Profile: C:\Users\XXX\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2021-09-21]
Edge Notifications: Profile 1 -> hxxps://meet.google.com
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2020-02-24] [Legacy] [not signed]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=3 -> C:\Program Files (x86)\CCleaner Browser\Update\1.7.848.0\npCCleanerBrowserUpdate3.dll [No File]
FF Plugin-x32: @update.ccleanerbrowser.com/CCleaner Browser;version=9 -> C:\Program Files (x86)\CCleaner Browser\Update\1.7.848.0\npCCleanerBrowserUpdate3.dll [No File]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 connect2hotspot; C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe [100680 2017-02-08] (Lenovo -> Lenovo)
R2 DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [3413424 2021-09-20] (Lavasoft Software Canada Inc. -> )
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe [11871976 2016-08-23] (DISPLAYLINK -> DisplayLink Corp.)
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [685496 2019-05-08] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
R2 LPlatSvc; C:\Windows\system32\LPlatSvc.exe [711248 2017-04-01] (Lenovo -> Lenovo.)
R2 QDLService2kLenovo; C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe [1688384 2011-05-23] (Qualcomm Inc -> QUALCOMM, Inc.)
S3 ss_conn_launcher_service; C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe [182328 2020-04-27] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2020-04-27] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [934328 2020-04-27] (Samsung Electronics Co., Ltd. -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13271336 2021-09-02] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S4 ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [1028096 2010-08-31] (Lenovo Group Limited) [File not signed]
S3 TVT Backup Service; C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe [1526120 2013-09-25] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Group Limited)
R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [22960 2021-09-20] (Lavasoft Software Canada Inc. -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BdDci; C:\Windows\System32\DRIVERS\bddci.sys [367096 2021-09-20] (Bitdefender SRL -> Bitdefender)
R2 rimspci; C:\Windows\System32\DRIVERS\rimspe64.sys [61952 2009-10-26] (Microsoft Windows Hardware Compatibility Publisher -> REDC)
R3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
R3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
R3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166760 2020-04-27] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [43368 2020-04-27] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-30] (Lenovo Information Products (Shenzhen) Co.,Ltd -> Lenovo Information Product(ShenZhen China) Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-21 16:14 - 2021-09-21 16:15 - 000000000 ____D C:\rsit
2021-09-21 16:14 - 2021-09-21 16:15 - 000000000 ____D C:\Program Files\trend micro
2021-09-21 16:13 - 2021-09-21 16:18 - 000018118 _____ C:\Users\XXX\Desktop\FRST.txt
2021-09-21 16:13 - 2021-09-21 16:13 - 001222144 _____ C:\Users\XXX\Desktop\RSITx64.exe
2021-09-21 16:09 - 2021-09-21 16:09 - 002304512 _____ (Farbar) C:\Users\XXX\Desktop\FRST64.exe
2021-09-21 15:53 - 2021-09-21 16:16 - 000000000 ____D C:\FRST
2021-09-21 15:39 - 2021-09-21 15:39 - 000388608 _____ (Trend Micro Inc.) C:\Users\XXX\Downloads\HijackThis.exe
2021-09-21 14:58 - 2021-09-21 14:58 - 000002296 _____ C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxthon.lnk
2021-09-21 14:58 - 2021-09-21 14:58 - 000002259 _____ C:\Users\XXX\Desktop\Maxthon.lnk
2021-09-21 14:58 - 2021-09-21 14:58 - 000000000 ____D C:\Users\XXX\AppData\Roaming\VBox
2021-09-21 14:58 - 2021-09-21 14:58 - 000000000 ____D C:\Users\XXX\AppData\Local\vback
2021-09-21 14:57 - 2021-09-21 14:58 - 000000000 ____D C:\Users\XXX\AppData\Local\Maxthon
2021-09-20 07:44 - 2021-09-20 07:44 - 000367096 _____ (Bitdefender) C:\Windows\system32\Drivers\bddci.sys
2021-09-19 14:18 - 2021-09-19 15:53 - 000000000 ____D C:\Users\XXX\Downloads\Alphaville - First Harvest 1984 1992
2021-09-19 10:27 - 2021-09-19 09:33 - 124298470 _____ C:\Users\XXX\Desktop\06.-New Year's Day.flac
2021-09-02 09:27 - 2021-09-02 09:27 - 000001054 _____ C:\Users\Public\Desktop\BurnAware Free.lnk
2021-09-02 09:27 - 2021-09-02 09:27 - 000000000 ____D C:\Users\XXX\AppData\Roaming\Burnaware
2021-09-02 09:27 - 2021-09-02 09:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
2021-09-02 09:27 - 2021-09-02 09:27 - 000000000 ____D C:\Program Files (x86)\BurnAware Free
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-09-21 16:02 - 2020-02-24 14:59 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-09-21 16:02 - 2020-02-24 14:02 - 000000911 _____ C:\Windows\Tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786}.job
2021-09-21 16:01 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-09-21 15:45 - 2020-11-08 22:45 - 000000911 _____ C:\Windows\Tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B}.job
2021-09-21 15:39 - 2020-02-08 19:16 - 000000000 ____D C:\Users\XXX\AppData\Local\VirtualStore
2021-09-21 14:57 - 2020-02-24 13:57 - 000000911 _____ C:\Windows\Tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5}.job
2021-09-21 14:48 - 2009-07-14 06:45 - 000026176 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2021-09-21 14:48 - 2009-07-14 06:45 - 000026176 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2021-09-21 14:27 - 2020-02-20 14:08 - 000000000 ____D C:\Users\XXX\AppData\Roaming\Maxthon5
2021-09-21 14:15 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\system32\NDF
2021-09-21 13:59 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2021-09-19 16:01 - 2020-02-25 13:42 - 000001491 _____ C:\Users\XXX\Desktop\AudioExtractor.ini
2021-09-19 15:56 - 2021-04-26 11:13 - 000000000 ____D C:\Users\XXX\AppData\Roaming\uTorrent
2021-09-19 09:01 - 2020-07-01 16:29 - 000002221 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-09-19 09:01 - 2020-07-01 16:29 - 000002180 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-09-15 15:34 - 2020-02-24 19:29 - 000000000 ____D C:\Windows\system32\MRT
2021-09-15 15:29 - 2020-02-24 19:29 - 135637312 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-09-06 14:19 - 2020-02-09 12:03 - 000000000 ____D C:\Users\XXX\My Drivers
2021-09-01 12:00 - 2020-12-23 14:18 - 000000000 ____D C:\SWSHARE
2021-08-30 22:45 - 2020-02-24 17:56 - 000803176 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2021-08-24 16:40 - 2009-07-14 17:18 - 000668376 _____ C:\Windows\system32\perfh005.dat
2021-08-24 16:40 - 2009-07-14 17:18 - 000141004 _____ C:\Windows\system32\perfc005.dat
2021-08-24 16:40 - 2009-07-14 07:13 - 001582262 _____ C:\Windows\system32\PerfStringBackup.INI
==================== Files in the root of some directories ========
2020-09-18 11:27 - 2020-09-18 11:27 - 000195296 _____ () C:\Users\XXX\comcat5.dll
2020-04-08 11:23 - 2020-04-08 13:25 - 000001576 _____ () C:\Program Files (x86)\DialogysUninstWPS.bat
2020-04-08 11:23 - 2020-04-08 11:23 - 000000840 _____ () C:\Program Files (x86)\INSTALL.LOG
2020-04-08 11:23 - 2014-09-12 13:01 - 000176055 _____ () C:\Program Files (x86)\UninstScript.EXE
2020-12-23 11:55 - 2020-12-23 12:18 - 000013797 _____ () C:\Users\XXX\AppData\Local\WiDiSetupLog.20201223.105508.wdl
==================== FLock ==============================
2020-12-23 14:37 C:\RRbackups
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2021-09-19 16:22
==================== End of FRST.txt ========================
Logfile of random's system information tool 1.10 (written by random/random)
Run by XXX at 2021-09-21 16:14:28
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 90 GB (30%) free of 303 GB
Total RAM: 5940 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:15:29, on 21.9.2021
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19597)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE
C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files\trend micro\XXX.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho.dll
O2 - BHO: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O3 - Toolbar: E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE -startup
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-630 Series"
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE /EPT "EPLTarget\P0000000000000001" /M "XP-630 Series"
O4 - HKCU\..\Run: [Web Companion] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
O4 - HKCU\..\Run: [EPSDNMON] ""
O4 - HKCU\..\Run: [EPLTarget\P0000000000000002] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE /EPT "EPLTarget\P0000000000000002" /M "XP-630 Series"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-555042887-2286466740-3098252512-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-555042887-2286466740-3098252512-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Connect2 Hotspot Service (connect2hotspot) - Lenovo - C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe
O23 - Service: DCIService - - C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe
O23 - Service: DisplayLinkManager (DisplayLinkService) - DisplayLink Corp. - C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EpsonCustomerResearchParticipation - SEIKO EPSON CORPORATION - C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V3 Service4(06) (EPSON_PM_RPCV4_06) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Platform Service (LPlatSvc) - Unknown owner - C:\Windows\system32\LPlatSvc.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Gobi 2000 Download Service (Lenovo) (QDLService2kLenovo) - QUALCOMM, Inc. - C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile USB Connectivity Launcher (ss_conn_launcher_service) - Unknown owner - C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
O23 - Service: SAMSUNG Mobile Connectivity Service V2 (ss_conn_service2) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
O23 - Service: TeamViewer - TeamViewer Germany GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WC Assistant (WCAssistantService) - Unknown owner - C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9501 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\LPlatSvc.exe
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\LPlatSvc.exe" -EM
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-9a01b958-501c-4daa-8c9b-9def8f5a808f -SystemEventPortName:HostProcess-ecc18278-3157-48fc-b254-dbd69059ac1a -IoCancelEventPortName:HostProcess-2ecade95-2d3d-42d8-b764-fc8d6e8c2d50 -NonStateChangingEventPortName:HostProcess-748a65b5-8859-49f5-9aa5-ab9ebf9cb178 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:3e908f06-1663-4c3e-bbce-653bd355d5c5 -DeviceGroupId:
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUserAgent.exe" -dluPipeName dl.dlu.s3PULntKOo89YaUZMvXzmyW5g2TwTUr3u2xtQ1XWzu4CD0Ox2dPv1S1faO2hdea8 -monitorableAppPipeName dl.monitorable.app.SLAOKuflbxYTIiGqOeNjQSG8GfwHN42Mx2onFSeho0IeRiFB53Caq11dEifI0vt9
"taskhost.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkUI.exe" -monitorableAppPipeName dl.monitorable.app.CnIrvWT7Qnctdvn6JtlpeQYEh5d97aadYVFV1LYc6u27NEDxyCgZd2GNMZxZkqtp
"C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe"
taskeng.exe {98D61294-A45F-494C-9D3C-60AE83103CF1}
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\splwow64.exe 8192
"C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\Skdaemon.exe"
"C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE" /EPT "EPLTarget\P0000000000000000" /M "XP-630 Series"
"C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE" /EPT "EPLTarget\P0000000000000001" /M "XP-630 Series"
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe" --minimize
"C:\Windows\System32\spool\drivers\x64\3\E_YATIPLE.EXE" /EPT "EPLTarget\P0000000000000002" /M "XP-630 Series"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe"
"C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\system32\EscSvc64.exe
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE"
"C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
"C:\Program Files\PowerISO\PWRISOVM.EXE" -startup
"C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe"
"C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe --type=crashpad-handler "--user-data-dir=C:\Users\XXX\AppData\Local\Maxthon\Application\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\XXX\AppData\Local\Maxthon\Application\User Data\Crashpad" "--metrics-dir=C:\Users\XXX\AppData\Local\Maxthon\Application\User Data" --annotation=plat=Win64 --annotation=prod=Maxthon --annotation=ver=6.1.2.1000 --initial-client-data=0xc4,0xc8,0xcc,0x98,0xd0,0x7fee49170c8,0x7fee49170d8,0x7fee49170e8
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=gpu-process --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --no-sandbox --start-stack-profiler --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1124 /prefetch:2
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --service-sandbox-type=network --no-sandbox --mojo-platform-channel-handle=1328 /prefetch:8
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --service-sandbox-type=utility --no-sandbox --mojo-platform-channel-handle=1760 /prefetch:8
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --service-sandbox-type=utility --no-sandbox --mojo-platform-channel-handle=2312 /prefetch:8
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --extension-process --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3152 /prefetch:1
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3848 /prefetch:1
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer15_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer15_Logfile.log
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5000 /prefetch:1
C:\Windows\system32\sppsvc.exe
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=32 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5904 /prefetch:1
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Users\XXX\Desktop\FRST64.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k swprv
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=37 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1424 /prefetch:1
"C:\Users\XXX\AppData\Local\Maxthon\Application\Maxthon.exe" --type=renderer --no-sandbox --field-trial-handle=1120,4344957839458997396,2002663198858407903,131072 --lang=cs --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3876 /prefetch:1
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\XXX\Desktop\RSITx64.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
======Scheduled tasks folder======
C:\Windows\tasks\EPSON XP-630 Series Update {326805B2-8C58-4D3D-A4E5-E90D3768C8D5}.job - C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE /EXE:"{326805B2-8C58-4D3D-A4E5-E90D3768C8D5}" /F:"Update"
C:\Windows\tasks\EPSON XP-630 Series Update {4AAB39D2-890A-4DC4-B515-785176BC5786}.job - C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE /EXE:"{4AAB39D2-890A-4DC4-B515-785176BC5786}" /F:"Update"
C:\Windows\tasks\EPSON XP-630 Series Update {C5E4CE44-5ED1-48B5-8A3C-4952643C058B}.job - C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSPLE.EXE /EXE:"{C5E4CE44-5ED1-48B5-8A3C-4952643C058B}" /F:"Update"
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho_64.dll [2021-09-16 524176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31 471536]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\BHO\ie_to_edge_bho.dll [2021-09-16 406928]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201CF130-E29C-4E5C-A73F-CD197DEFA6AE}]
E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27 238576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2015-07-31 471536]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27 238576]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"EPPCCMON"=C:\Program Files (x86)\EPSON Software\Epson Printer Connection Checker\EPPCCMON.EXE [2020-10-22 442936]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-12-22 168216]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-12-22 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-12-22 416024]
"Enhanced Performance Keyboard"=C:\Program Files\Lenovo\USB Enhanced Performance Keyboard\SKDaemon.exe [2014-08-17 4013056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-15 307768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EPLTarget\P0000000000000000"=C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [2014-11-14 417776]
"EPLTarget\P0000000000000001"=C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [2014-11-14 417776]
"Web Companion"=C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [2021-09-20 9123248]
"EPSDNMON"= []
"EPLTarget\P0000000000000002"=C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIPLE.EXE [2014-11-14 417776]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-01-15 8619224]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2016-01-20 1087184]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2020-02-09 455872]
""= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-05-21 389632]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2021-09-21 16:14:28 ----D---- C:\rsit
2021-09-21 16:14:28 ----D---- C:\Program Files\trend micro
2021-09-21 15:53:09 ----D---- C:\FRST
2021-09-21 14:58:41 ----D---- C:\Users\XXX\AppData\Roaming\VBox
2021-09-20 07:44:04 ----A---- C:\Windows\system32\drivers\bddci.sys
2021-09-02 09:27:24 ----D---- C:\Users\XXX\AppData\Roaming\Burnaware
2021-09-02 09:27:02 ----D---- C:\Program Files (x86)\BurnAware Free
======List of files/folders modified in the last 1 month======
2021-09-21 16:14:28 ----RD---- C:\Program Files
2021-09-21 16:10:55 ----SHD---- C:\System Volume Information
2021-09-21 16:07:18 ----D---- C:\Windows\Temp
2021-09-21 16:02:16 ----D---- C:\Program Files (x86)\TeamViewer
2021-09-21 15:55:33 ----D---- C:\Windows\system32\config
2021-09-21 14:37:16 ----D---- C:\Windows
2021-09-21 14:27:59 ----D---- C:\Users\XXX\AppData\Roaming\Maxthon5
2021-09-21 14:27:40 ----RD---- C:\Program Files (x86)
2021-09-21 14:27:28 ----D---- C:\Windows\system32\Tasks
2021-09-21 14:15:17 ----D---- C:\Windows\system32\NDF
2021-09-21 14:15:17 ----D---- C:\Windows\Prefetch
2021-09-21 13:59:51 ----D---- C:\Windows\inf
2021-09-21 09:19:01 ----D---- C:\Windows\debug
2021-09-20 07:44:07 ----D---- C:\Windows\system32\drivers
2021-09-20 07:40:09 ----D---- C:\Windows\system32\wdi
2021-09-19 15:56:26 ----D---- C:\Users\XXX\AppData\Roaming\uTorrent
2021-09-19 15:55:40 ----D---- C:\Windows\SysWOW64
2021-09-19 15:55:40 ----D---- C:\Windows\System32
2021-09-15 15:30:09 ----D---- C:\Windows\system32\MRT
2021-09-15 15:29:41 ----AC---- C:\Windows\system32\MRT.exe
2021-09-01 12:00:18 ----D---- C:\SWSHARE
2021-08-30 22:45:38 ----N---- C:\Windows\system32\MpSigStub.exe
2021-08-24 16:40:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 dlkmdldr;dlkmdldr; C:\Windows\system32\drivers\dlkmdldr.sys [2016-08-23 27920]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2013-10-29 30496]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2018-01-01 213736]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2017-06-07 138296]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BdDci;BdDci Service; C:\Windows\system32\DRIVERS\bddci.sys [2021-09-20 367096]
R2 rimspci;rimspci; C:\Windows\system32\DRIVERS\rimspe64.sys [2009-10-26 61952]
R3 bpenum;Intel(R) Centrino(R) WiMAX Enumerator; C:\Windows\system32\DRIVERS\bpenum.sys [2012-07-03 84480]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2019-07-30 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\drivers\bthpan.sys [2017-07-06 119296]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2019-07-30 80384]
R3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2020-02-25 54824]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2010-08-25 682624]
R3 dlkmd;dlkmd; C:\Windows\system32\drivers\dlkmd.sys [2016-08-23 457488]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\Windows\system32\DRIVERS\e1k62x64.sys [2011-07-20 342704]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-02-19 57848]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2017-04-01 82816]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-05-21 12229664]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-27 158976]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2020-12-23 40248]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2011-08-30 1225832]
R3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys [2010-11-20 109056]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2014-07-28 45296]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2014-07-28 461552]
R3 TPM;Čip TPM; C:\Windows\system32\drivers\tpm.sys [2016-02-05 147904]
R3 TVTI2C;Lenovo SM bus driver; C:\Windows\system32\DRIVERS\Tvti2c.sys [2011-05-30 40248]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WinUsb;WinUSB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2019-07-30 556032]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2020-04-27 136040]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2015-02-25 197408]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 ss_conn_usb_driver2;SAMSUNG Mobile USB Connectivity Device Driver V2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [2020-04-27 43368]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2020-04-27 166760]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2019-12-10 42496]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 connect2hotspot;Connect2 Hotspot Service; C:\Program Files (x86)\Lenovo\Connect2\Connect2.Service.exe [2017-02-08 100680]
R2 DCIService;DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [2021-09-20 3413424]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DisplayLinkService;DisplayLinkManager; C:\Program Files\DisplayLink Core Software\8.0.778.0\DisplayLinkManager.exe [2016-08-23 11871976]
R2 EPSON_PM_RPCV4_06;EPSON V3 Service4(06); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [2013-04-15 152640]
R2 EpsonCustomerResearchParticipation;EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [2019-05-08 685496]
R2 EpsonScanSvc;Epson Scanner Service; C:\Windows\system32\EscSvc64.exe [2012-05-17 144560]
R2 IBMPMSVC;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2017-04-01 187984]
R2 LPlatSvc;Lenovo Platform Service; C:\Windows\system32\LPlatSvc.exe [2017-04-01 711248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-10-29 893216]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-10-29 1260320]
R2 QDLService2kLenovo;Qualcomm Gobi 2000 Download Service (Lenovo); C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe [2011-05-23 1688384]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2010-10-19 838928]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [2020-04-27 752224]
R2 ss_conn_service2;SAMSUNG Mobile Connectivity Service V2; C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [2020-04-27 934328]
R2 TeamViewer;TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2021-09-02 13271336]
R2 WCAssistantService;WC Assistant; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [2021-09-20 22960]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2019-03-28 132792]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2019-03-28 158912]
S2 edgeupdate;Služba Microsoft Edge Update (edgeupdate); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-07-01 224152]
S3 edgeupdatem;Služba Microsoft Edge Update (edgeupdatem); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-07-01 224152]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2019-12-17 116224]
S3 MicrosoftEdgeElevationService;Microsoft Edge Elevation Service (MicrosoftEdgeElevationService); C:\Program Files (x86)\Microsoft\Edge\Application\93.0.961.52\elevation_service.exe [2021-09-16 1651616]
S3 ss_conn_launcher_service;SAMSUNG Mobile USB Connectivity Launcher; C:\Windows\system32\Samsung\EasySetup\ss_conn_launcher.exe [2020-04-27 182328]
S3 TVT Backup Service;TVT Backup Service; C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe [2013-09-25 1526120]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2020-02-24 1255736]
S3 WiaRpc;@%SystemRoot%\system32\wiarpc.dll,-2; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2019-03-28 54912]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2019-03-28 136256]
S4 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [2010-08-31 1028096]
-----------------EOF-----------------