Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.18
- Platform: x64 Windows 10 (Pro), 10.0.17763.504 (ReleaseId: 1809), Service Pack: 0
- Time: 26.05.2019 - 21:31 (UTC+01:00)
- Language: OS: English (0x409). Display: English (0x409). Non-Unicode: English (0x409)
- Elevated: Yes
- Ran by: Alistair (group: Administrator) on DESKTOP-6EPC1RV, FirstRun: no
- Chrome: 74.0.3729.169
- Edge: 11.0.17763.504
- Internet Explorer: 11.0.17763.1
- Default: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)
- Boot mode: Normal
- Running processes:
- Number | Path
- 2 C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
- 1 C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
- 1 C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe
- 1 C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\libs\node.exe
- 1 C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
- 1 C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
- 1 C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
- 1 C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
- 1 C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
- 1 C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
- 1 C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
- 1 C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
- 1 C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- 61 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- 1 C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
- 1 C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe
- 1 C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
- 1 C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
- 1 C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
- 1 C:\Program Files\7-Zip\7zFM.exe
- 2 C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
- 1 C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
- 1 C:\Program Files\Macrium\Common\MacriumService.exe
- 1 C:\Program Files\Macrium\Common\ReflectMonitor.exe
- 1 C:\Program Files\Macrium\Common\ReflectUI.exe
- 1 C:\Program Files\Microsoft SQL Server\110\LocalDB\Binn\sqlservr.exe
- 1 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
- 2 C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
- 1 C:\Program Files\NVIDIA Corporation\Display\nvsmartmaxapp.exe
- 1 C:\Program Files\NVIDIA Corporation\Display\nvsmartmaxapp64.exe
- 3 C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
- 3 C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
- 1 C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
- 1 C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
- 3 C:\Program Files\PuTTY\putty.exe
- 1 C:\Program Files\StableBit\DrivePool\DrivePool.Notifications.exe
- 1 C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe
- 1 C:\Program Files\SyncTrayzor\SyncTrayzor.exe
- 1 C:\Program Files\Veeam\Endpoint Backup\Veeam.EndPoint.Service.exe
- 1 C:\Program Files\Veeam\Endpoint Backup\Veeam.EndPoint.Tray.exe
- 1 C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r\AcrobatNotificationClient.exe
- 1 C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1902.42.0_x64__8wekyb3d8bbwe\Calculator.exe
- 1 C:\Program Files\WindowsApps\Microsoft.WindowsStore_11811.1001.27.0_x64__8wekyb3d8bbwe\WinStore.App.exe
- 1 C:\ProgramData\Battle.net\Agent\Agent.6700\Agent.exe
- 1 C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
- 1 C:\ProgramData\FLEXnet\Connect\11\agent.exe
- 1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1904.1-0\MsMpEng.exe
- 1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1904.1-0\NisSrv.exe
- 6 C:\Users\Alistair\AppData\Local\Discord\app-0.0.305\Discord.exe
- 1 C:\Users\Alistair\AppData\Local\Microsoft\OneDrive\OneDrive.exe
- 1 C:\Users\Alistair\AppData\Local\RuneLite\RuneLite.exe
- 1 C:\Users\Alistair\AppData\Local\Temp\7zO4FDD4D1F\HiJackThis.exe
- 4 C:\Users\Alistair\AppData\Roaming\Spotify\Spotify.exe
- 1 C:\Users\Alistair\AppData\Roaming\SyncTrayzor\syncthing.exe
- 1 C:\Users\Alistair\Desktop\HiJackThis\HiJackThis.exe
- 1 C:\Windows\ImmersiveControlPanel\SystemSettings.exe
- 1 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- 1 C:\Windows\SysWOW64\cmd.exe
- 1 C:\Windows\System32\ApplicationFrameHost.exe
- 1 C:\Windows\System32\CompPkgSrv.exe
- 1 C:\Windows\System32\MicrosoftEdgeCP.exe
- 1 C:\Windows\System32\MicrosoftEdgeSH.exe
- 7 C:\Windows\System32\RuntimeBroker.exe
- 1 C:\Windows\System32\SearchFilterHost.exe
- 1 C:\Windows\System32\SearchIndexer.exe
- 2 C:\Windows\System32\SearchProtocolHost.exe
- 1 C:\Windows\System32\SecurityHealthService.exe
- 1 C:\Windows\System32\SecurityHealthSystray.exe
- 1 C:\Windows\System32\SettingSyncHost.exe
- 1 C:\Windows\System32\SgrmBroker.exe
- 1 C:\Windows\System32\SystemSettingsBroker.exe
- 2 C:\Windows\System32\WUDFHost.exe
- 1 C:\Windows\System32\audiodg.exe
- 1 C:\Windows\System32\browser_broker.exe
- 3 C:\Windows\System32\cmd.exe
- 9 C:\Windows\System32\conhost.exe
- 2 C:\Windows\System32\csrss.exe
- 1 C:\Windows\System32\ctfmon.exe
- 1 C:\Windows\System32\dasHost.exe
- 2 C:\Windows\System32\dllhost.exe
- 1 C:\Windows\System32\dwm.exe
- 2 C:\Windows\System32\fontdrvhost.exe
- 1 C:\Windows\System32\igfxCUIService.exe
- 1 C:\Windows\System32\igfxEM.exe
- 1 C:\Windows\System32\lsass.exe
- 1 C:\Windows\System32\mmc.exe
- 2 C:\Windows\System32\notepad.exe
- 1 C:\Windows\System32\rundll32.exe
- 1 C:\Windows\System32\services.exe
- 1 C:\Windows\System32\sihost.exe
- 1 C:\Windows\System32\smartscreen.exe
- 1 C:\Windows\System32\smss.exe
- 1 C:\Windows\System32\spoolsv.exe
- 79 C:\Windows\System32\svchost.exe
- 2 C:\Windows\System32\taskhostw.exe
- 1 C:\Windows\System32\vds.exe
- 2 C:\Windows\System32\wbem\WmiPrvSE.exe
- 1 C:\Windows\System32\wbem\unsecapp.exe
- 1 C:\Windows\System32\wininit.exe
- 1 C:\Windows\System32\winlogon.exe
- 1 C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe
- 1 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
- 1 C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
- 1 C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
- 1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
- 1 C:\Windows\explorer.exe
- 1 G:\ROOT\Program Files (x86)\Arduino\java\bin\javaw.exe
- 2 G:\ROOT\Program Files (x86)\Battle.net\.Battle.net.exe.733.2880.temp
- 1 G:\ROOT\Program Files (x86)\Steam\Steam.exe
- 5 G:\ROOT\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
- 1 G:\ROOT\Program Files\KeePassXC\keepassxc-proxy.exe
- O1 - Hosts: 172.20.5.2 facebook.home.v2.pw
- O2 - HKLM\..\BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
- O2 - HKLM\..\BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
- O2-32 - HKLM\..\BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
- O2-32 - HKLM\..\BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
- O3 - HKLM\..\Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
- O3-32 - HKLM\..\Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
- O4 - HKCU\..\Run: [4F3C3CDF5914B8BD0422FA6A09A34E132DAEF785._service_run] = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --type=service /prefetch:8
- O4 - HKCU\..\Run: [Adobe Acrobat Synchronizer] = C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
- O4 - HKCU\..\Run: [OneDrive] = C:\Users\Alistair\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background (Microsoft)
- O4 - HKCU\..\Run: [Spotify] = C:\Users\Alistair\AppData\Roaming\Spotify\Spotify.exe --autostart --minimized
- O4 - HKCU\..\Run: [SyncTrayzor] = C:\Program Files\SyncTrayzor\SyncTrayzor.exe -minimized
- O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] = C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
- O4 - HKLM\..\Run: [AdobeGCInvoker-1.0] = C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe
- O4 - HKLM\..\Run: [Reflect UI] = C:\Program Files\Macrium\Common\ReflectUI.exe
- O4 - HKLM\..\Run: [SecurityHealth] = C:\Windows\system32\SecurityHealthSystray.exe
- O4 - HKLM\..\Run: [StableBit DrivePool Notifications] = C:\Program Files\StableBit\DrivePool\DrivePool.Notifications.exe
- O4 - HKLM\..\Run: [Veeam.EndPoint.Tray.exe] = C:\Program Files\Veeam\Endpoint Backup\Veeam.EndPoint.Tray.exe -NoControlPanel -CheckNumberOfRunningAgents
- O4-32 - HKLM\..\Run: [Acrobat Assistant 8.0] = C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe
- O4-32 - HKLM\..\Run: [Adobe Creative Cloud] = C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true
- O4-32 - HKLM\..\Run: [Discord] = C:\ProgramData\SquirrelMachineInstalls\Discord.exe --checkInstall
- O4-32 - HKLM\..\Run: [ISUSPM] = C:\ProgramData\FLEXnet\Connect\11\isuspm.exe -scheduler
- O4-32 - HKLM\..\Run: [Nuance OmniPage Ultimate-reminder] = G:\ROOT\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe -r "C:\ProgramData\ScanSoft\OmniPage Ultimate\Ereg\Ereg.ini"
- O4-32 - HKLM\..\Run: [OmniPage Preload] = G:\ROOT\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe /preload
- O17 - DHCP DNS 1: 8.8.8.8 (Well-known DNS: Google)
- O17 - DHCP DNS 2: 8.8.4.4 (Well-known DNS: Google)
- O17 - DHCP DNS 3: 172.20.5.6
- O17 - HKLM\System\CCS\Services\Tcpip\..\{ffbae7b9-cd2d-4e5b-bbb2-2149e9e1a87d}: [NameServer] = 8.8.4.4 (Well-known DNS: Google)
- O17 - HKLM\System\CCS\Services\Tcpip\..\{ffbae7b9-cd2d-4e5b-bbb2-2149e9e1a87d}: [NameServer] = 8.8.8.8 (Well-known DNS: Google)
- O21 - HKLM\..\ShellIconOverlayIdentifiers\ AccExtIco1: AccExtIco1 Class - {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} - C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
- O21 - HKLM\..\ShellIconOverlayIdentifiers\ AccExtIco2: AccExtIco2 Class - {853B7E05-C47D-4985-909A-D0DC5C6D7303} - C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
- O21 - HKLM\..\ShellIconOverlayIdentifiers\ AccExtIco3: AccExtIco3 Class - {42D38F2E-98E9-4382-B546-E24E4D6D04BB} - C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
- O23 - Service R2: Adobe Genuine Monitor Service - (AGMService) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
- O23 - Service R2: Adobe Genuine Software Integrity Service - (AGSService) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
- O23 - Service R2: Intel(R) Driver & Support Assistant - (DSAService) - C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
- O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\Windows\system32\igfxCUIService.exe
- O23 - Service R2: Macrium Service - (MacriumService) - C:\Program Files\Macrium\Common\MacriumService.exe
- O23 - Service R2: Microsoft Office Click-to-Run Service - (ClickToRunSvc) - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe /service
- O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
- O23 - Service R2: NVIDIA LocalSystem Container - (NvContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
- O23 - Service R2: NVIDIA Telemetry Container - (NvTelemetryContainer) - C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
- O23 - Service R2: StableBit DrivePool Service - (DrivePoolService) - C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe
- O23 - Service R2: Veeam Agent for Microsoft Windows - (VeeamEndpointBackupSvc) - C:\Program Files\Veeam\Endpoint Backup\Veeam.EndPoint.Service.exe
- O23 - Service R3: Intel(R) Driver & Support Assistant Updater - (DSAUpdateService) - C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
- O23 - Service R3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService
- O23 - Service S2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- O23 - Service S2: AdobeUpdateService - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
- O23 - Service S2: Google Update Service (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
- O23 - Service S3: Google Chrome Elevation Service - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\74.0.3729.169\elevation_service.exe
- O23 - Service S3: Google Update Service (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
- O23 - Service S3: Intel(R) Content Protection HECI Service - (cphs) - C:\Windows\SysWow64\IntelCpHeciSvc.exe
- O23 - Service S3: Intel(R) SUR QC Software Asset Manager - (Intel(R) SUR QC SAM) - C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
- O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
- O23 - Service S3: NVIDIA NetworkService Container - (NvContainerNetworkService) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
- O23 - Service S3: Office 64 Source Engine - (ose64) - c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
- --
- End of file - Time spent: 15 sec. - 31912 bytes, CRC32: FFFFFFFF. Sign: ้ฌกใง
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement