Advertisement
Guest User

Untitled

a guest
Jan 8th, 2022
161
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 14.73 KB | None | 0 0
  1. Boot mode: Normal
  2.  
  3. Running processes:
  4. Number | Path
  5. 9 C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
  6. 1 C:\Program Files\ESET\ESET Security\eguiProxy.exe
  7. 1 C:\Program Files\ESET\ESET Security\ekrn.exe
  8. 1 C:\Program Files\Shadow Defender\DefenderDaemon.exe
  9. 1 C:\Users\HOME\AppData\Local\Temp\irpb.exe
  10. 1 C:\Users\HOME\Desktop\HiJackThis\HiJackThis.exe
  11. 1 C:\Users\HOME\Desktop\IperiusRemote.exe
  12. 1 C:\Users\HOME\Desktop\ProcessExplorer\procexp64.exe
  13. 1 C:\Windows\System32\ApplicationFrameHost.exe
  14. 1 C:\Windows\System32\AutoModeDetect.exe
  15. 2 C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_0222c12a396c055f\DAX3API.exe
  16. 1 C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_b9fd1528982e300f\LenovoUtilityService.exe
  17. 2 C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3d345565ec73a109\RtkAudUService64.exe
  18. 1 C:\Windows\System32\DriverStore\FileRepository\u0361437.inf_amd64_b82dc71fab24f1f3\B361368\atieclxx.exe
  19. 1 C:\Windows\System32\DriverStore\FileRepository\u0361437.inf_amd64_b82dc71fab24f1f3\B361368\atiesrxx.exe
  20. 1 C:\Windows\System32\ETDCtrl.exe
  21. 1 C:\Windows\System32\ETDCtrlHelper.exe
  22. 1 C:\Windows\System32\ETDService.exe
  23. 1 C:\Windows\System32\ETDTouch.exe
  24. 1 C:\Windows\System32\FMService64.exe
  25. 1 C:\Windows\System32\LNBITSSvc.exe
  26. 4 C:\Windows\System32\RuntimeBroker.exe
  27. 1 C:\Windows\System32\SecurityHealthService.exe
  28. 1 C:\Windows\System32\SettingSyncHost.exe
  29. 1 C:\Windows\System32\SgrmBroker.exe
  30. 1 C:\Windows\System32\SynTPEnh.exe
  31. 1 C:\Windows\System32\SynTPEnhService.exe
  32. 1 C:\Windows\System32\audiodg.exe
  33. 1 C:\Windows\System32\cmd.exe
  34. 2 C:\Windows\System32\conhost.exe
  35. 2 C:\Windows\System32\csrss.exe
  36. 1 C:\Windows\System32\ctfmon.exe
  37. 1 C:\Windows\System32\dasHost.exe
  38. 1 C:\Windows\System32\dllhost.exe
  39. 1 C:\Windows\System32\drivers\AdminService.exe
  40. 1 C:\Windows\System32\drivers\QcomWlanSrvx64.exe
  41. 1 C:\Windows\System32\dwm.exe
  42. 2 C:\Windows\System32\fontdrvhost.exe
  43. 1 C:\Windows\System32\lsass.exe
  44. 1 C:\Windows\System32\oobe\UserOOBEBroker.exe
  45. 1 C:\Windows\System32\services.exe
  46. 1 C:\Windows\System32\sihost.exe
  47. 1 C:\Windows\System32\smartscreen.exe
  48. 1 C:\Windows\System32\smss.exe
  49. 22 C:\Windows\System32\svchost.exe
  50. 1 C:\Windows\System32\taskhostw.exe
  51. 2 C:\Windows\System32\wbem\WmiPrvSE.exe
  52. 1 C:\Windows\System32\wbem\unsecapp.exe
  53. 1 C:\Windows\System32\wininit.exe
  54. 1 C:\Windows\System32\winlogon.exe
  55. 1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
  56. 1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
  57. 1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe
  58. 1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
  59. 1 C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1371_none_7e1bd7147c8285b0\TiWorker.exe
  60. 1 C:\Windows\explorer.exe
  61. 1 C:\Windows\servicing\TrustedInstaller.exe
  62.  
  63. R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Start Page] = http://www.google.it/
  64. O1 - Hosts: Reset contents to default
  65. O1 - Hosts: 0.0.0.0 analytics.ff.avast.com
  66. O1 - Hosts: 0.0.0.0 analytics.ns1.ff.avast.com
  67. O1 - Hosts: 0.0.0.0 v7event.stats.avcdn.net
  68. O1 - Hosts: 0.0.0.0 v7.stats.avcdn.net
  69. O1 - Hosts: 0.0.0.0 flow.lavasoft.com
  70. O1 - Hosts: 0.0.0.0 telemetry.malwarebytes.com
  71. O1 - Hosts: 0.0.0.0 ws.mcafee.com
  72. O1 - Hosts: 0.0.0.0 analytics.ccs.mcafee.com
  73. O1 - Hosts: 0.0.0.0 analyticsdcs.ccs.mcafee.com
  74. O1 - Hosts: 0.0.0.0 carcharodon.trendmicro.com
  75. O1 - Hosts: 0.0.0.0 a.ads1.msn.com
  76. O1 - Hosts: 0.0.0.0 a.ads2.msads.net
  77. O1 - Hosts: 0.0.0.0 a.ads2.msn.com
  78. O1 - Hosts: 0.0.0.0 a.rad.msn.com
  79. O1 - Hosts: 0.0.0.0 a-0001.a-msedge.net
  80. O1 - Hosts: 0.0.0.0 a-0002.a-msedge.net
  81. O1 - Hosts: 0.0.0.0 a-0003.a-msedge.net
  82. O1 - Hosts: 0.0.0.0 a-0004.a-msedge.net
  83. O1 - Hosts: 0.0.0.0 a-0005.a-msedge.net
  84. O1 - Hosts: 0.0.0.0 a-0006.a-msedge.net
  85. O1 - Hosts: 0.0.0.0 a-0007.a-msedge.net
  86. O1 - Hosts: 0.0.0.0 a-0008.a-msedge.net
  87. O1 - Hosts: 0.0.0.0 a-0009.a-msedge.net
  88. O1 - Hosts: 0.0.0.0 ac3.msn.com
  89. O1 - Hosts: 0.0.0.0 ad.doubleclick.net
  90. O1 - Hosts: 0.0.0.0 adnexus.net
  91. O1 - Hosts: 0.0.0.0 adnxs.com
  92. O1 - Hosts: 0.0.0.0 ads.msn.com
  93. O1 - Hosts: 0.0.0.0 ads1.msads.net
  94. O1 - Hosts: 0.0.0.0 ads1.msn.com
  95. O1 - Hosts: 0.0.0.0 aidps.atdmt.com
  96. O1 - Hosts: 0.0.0.0 aka-cdn-ns.adtech.de
  97. O1 - Hosts: 0.0.0.0 a-msedge.net
  98. O1 - Hosts: 0.0.0.0 apps.skype.com
  99. O1 - Hosts: 0.0.0.0 az361816.vo.msecnd.net
  100. O1 - Hosts: 0.0.0.0 az512334.vo.msecnd.net
  101. O1 - Hosts: 0.0.0.0 b.ads1.msn.com
  102. O1 - Hosts: 0.0.0.0 b.ads2.msads.net
  103. O1 - Hosts: 0.0.0.0 b.rad.msn.com
  104. O1 - Hosts: 0.0.0.0 bs.serving-sys.com
  105. O1 - Hosts: 0.0.0.0 c.atdmt.com
  106. O1 - Hosts: 0.0.0.0 c.msn.com
  107. O1 - Hosts: 0.0.0.0 cdn.atdmt.com
  108. O1 - Hosts: 0.0.0.0 cds26.ams9.msecn.net
  109. O1 - Hosts: 0.0.0.0 compatexchange.cloudapp.net
  110. O1 - Hosts: 0.0.0.0 corpext.msitadfs.glbdns2.microsoft.com
  111. O1 - Hosts: 0.0.0.0 cs1.wpc.v0cdn.net
  112. O1 - Hosts: 0.0.0.0 db3aqu.atdmt.com
  113. O1 - Hosts: 0.0.0.0 ec.atdmt.com
  114. O1 - Hosts: 0.0.0.0 fe2.update.microsoft.com.akadns.net
  115. O1 - Hosts: 0.0.0.0 feedback.microsoft-hohm.com
  116. O1 - Hosts: 0.0.0.0 flex.msn.com
  117. O1 - Hosts: 0.0.0.0 g.msn.com
  118. O1 - Hosts: 0.0.0.0 h1.msn.com
  119. O1 - Hosts: 0.0.0.0 lb1.www.ms.akadns.net
  120. O1 - Hosts: 0.0.0.0 live.rads.msn.com
  121. O1 - Hosts: 0.0.0.0 m.adnxs.com
  122. O1 - Hosts: 0.0.0.0 m.hotmail.com
  123. O1 - Hosts: 0.0.0.0 msedge.net
  124. O1 - Hosts: 0.0.0.0 msftncsi.com
  125. O1 - Hosts: 0.0.0.0 msnbot-65-55-108-23.search.msn.com
  126. O1 - Hosts: 0.0.0.0 msntest.serving-sys.com
  127. O1 - Hosts: 0.0.0.0 pre.footprintpredict.com
  128. O1 - Hosts: 0.0.0.0 preview.msn.com
  129. O1 - Hosts: 0.0.0.0 pricelist.skype.com
  130. O1 - Hosts: 0.0.0.0 rad.live.com
  131. O1 - Hosts: 0.0.0.0 rad.msn.com
  132. O1 - Hosts: 0.0.0.0 s.gateway.messenger.live.com
  133. O1 - Hosts: 0.0.0.0 s0.2mdn.net
  134. O1 - Hosts: 0.0.0.0 schemas.microsoft.akadns.net
  135. O1 - Hosts: 0.0.0.0 secure.adnxs.com
  136. O1 - Hosts: 0.0.0.0 secure.flashtalking.com
  137. O1 - Hosts: 0.0.0.0 sls.update.microsoft.com.akadns.net
  138. O1 - Hosts: 0.0.0.0 static.2mdn.net
  139. O1 - Hosts: 0.0.0.0 statsfe1.ws.microsoft.com
  140. O1 - Hosts: 0.0.0.0 statsfe2.update.microsoft.com.akadns.net
  141. O1 - Hosts: 0.0.0.0 statsfe2.ws.microsoft.com
  142. O1 - Hosts: 0.0.0.0 survey.watson.microsoft.com
  143. O1 - Hosts: 0.0.0.0 view.atdmt.com
  144. O1 - Hosts: 0.0.0.0 www.msftncsi.com
  145. O1 - Hosts: 0.0.0.0 choice.microsoft.com
  146. O1 - Hosts: 0.0.0.0 choice.microsoft.com.nstac.net
  147. O1 - Hosts: 0.0.0.0 df.telemetry.microsoft.com
  148. O1 - Hosts: 0.0.0.0 oca.telemetry.microsoft.com
  149. O1 - Hosts: 0.0.0.0 oca.telemetry.microsoft.com.nsatc.net
  150. O1 - Hosts: 0.0.0.0 redir.metaservices.microsoft.com
  151. O1 - Hosts: 0.0.0.0 reports.wes.df.telemetry.microsoft.com
  152. O1 - Hosts: 0.0.0.0 services.wes.df.telemetry.microsoft.com
  153. O1 - Hosts: 0.0.0.0 settings-sandbox.data.microsoft.com
  154. O1 - Hosts: 0.0.0.0 settings-win.data.microsoft.com
  155. O1 - Hosts: 0.0.0.0 sqm.df.telemetry.microsoft.com
  156. O1 - Hosts: 0.0.0.0 sqm.telemetry.microsoft.com
  157. O1 - Hosts: 0.0.0.0 sqm.telemetry.microsoft.com.nsatc.net
  158. O1 - Hosts: 0.0.0.0 telecommand.telemetry.microsoft.com
  159. O1 - Hosts: 0.0.0.0 telecommand.telemetry.microsoft.com.nsatc.net
  160. O1 - Hosts: 0.0.0.0 telemetry.appex.bing.net
  161. O1 - Hosts: 0.0.0.0 telemetry.microsoft.com
  162. O1 - Hosts: 0.0.0.0 telemetry.urs.microsoft.com
  163. O1 - Hosts: 0.0.0.0 vortex-sandbox.data.microsoft.com
  164. O1 - Hosts: 0.0.0.0 vortex-win.data.microsoft.com
  165. O1 - Hosts: 0.0.0.0 vortex.data.microsoft.com
  166. O1 - Hosts: 0.0.0.0 watson.telemetry.microsoft.com
  167. O1 - Hosts: 0.0.0.0 watson.telemetry.microsoft.com.nsatc.net
  168. O1 - Hosts: 0.0.0.0 watson.ppe.telemetry.microsoft.com
  169. O1 - Hosts: 0.0.0.0 wes.df.telemetry.microsoft.com
  170. O1 - Hosts: 0.0.0.0 vortex-bn2.metron.live.com.nsatc.net
  171. O1 - Hosts: 0.0.0.0 vortex-cy2.metron.live.com.nsatc.net
  172. O1 - Hosts: 0.0.0.0 watson.live.com
  173. O1 - Hosts: 0.0.0.0 watson.microsoft.com
  174. O1 - Hosts: 0.0.0.0 feedback.search.microsoft.com
  175. O1 - Hosts: 0.0.0.0 feedback.windows.com
  176. O1 - Hosts: 0.0.0.0 corp.sts.microsoft.com
  177. O1 - Hosts: 0.0.0.0 diagnostics.support.microsoft.com
  178. O1 - Hosts: 0.0.0.0 i1.services.social.microsoft.com
  179. O1 - Hosts: 0.0.0.0 i1.services.social.microsoft.com.nsatc.net
  180. O1 - Hosts: 0.0.0.0 vortex-bn2.metron.live.com.nsatc.net
  181. O1 - Hosts: 0.0.0.0 vortex-cy2.metron.live.com.nsatc.net
  182. O1 - Hosts: 0.0.0.0 ca.telemetry.microsoft.com
  183. O1 - Hosts: 0.0.0.0 cache.datamart.windows.com
  184. O1 - Hosts: 0.0.0.0 diagnostics.support.microsoft.com
  185. O1 - Hosts: 0.0.0.0 spynet2.microsoft.com
  186. O1 - Hosts: 0.0.0.0 spynetalt.microsoft.com
  187. O4 - HKLM\..\Run: [RtkAudUService] = C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3d345565ec73a109\RtkAudUService64.exe -background
  188. O4 - HKLM\..\Run: [egui] = C:\Program Files\ESET\ESET Security\ecmds.exe /run /hide /proxy
  189. O17 - DHCP DNS 1: 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  190. O17 - DHCP DNS 2: 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  191. O17 - DHCP DNS 3: 192.168.1.254
  192. O17 - HKLM\System\CCS\Services\Tcpip\..\{19e2e284-7121-4819-8f90-cd60bf6b5789}: [NameServer] = 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  193. O17 - HKLM\System\CCS\Services\Tcpip\..\{19e2e284-7121-4819-8f90-cd60bf6b5789}: [NameServer] = 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  194. O17 - HKLM\System\CCS\Services\Tcpip\..\{6b76f73d-1a72-4fba-b78f-2bbfa8ca8978}: [NameServer] = 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  195. O17 - HKLM\System\CCS\Services\Tcpip\..\{6b76f73d-1a72-4fba-b78f-2bbfa8ca8978}: [NameServer] = 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  196. O17 - HKLM\System\CCS\Services\Tcpip\..\{82f6ebee-8687-4ce1-bbd0-82cf2e5f4763}: [NameServer] = 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  197. O17 - HKLM\System\CCS\Services\Tcpip\..\{82f6ebee-8687-4ce1-bbd0-82cf2e5f4763}: [NameServer] = 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  198. O17 - HKLM\System\CCS\Services\Tcpip\..\{82f6ebee-8687-4ce1-bbd0-82cf2e5f4763}: [NameServer] = 192.168.1.254
  199. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{00B49112-A4B2-446F-9813-CBB2C4D2740A}: [NameServer] = 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  200. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{00B49112-A4B2-446F-9813-CBB2C4D2740A}: [NameServer] = 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  201. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{19E2E284-7121-4819-8F90-CD60BF6B5789}: [NameServer] = 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  202. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{19E2E284-7121-4819-8F90-CD60BF6B5789}: [NameServer] = 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  203. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{6B76F73D-1A72-4FBA-B78F-2BBFA8CA8978}: [NameServer] = 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  204. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{6B76F73D-1A72-4FBA-B78F-2BBFA8CA8978}: [NameServer] = 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  205. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{82F6EBEE-8687-4CE1-BBD0-82CF2E5F4763}: [NameServer] = 1.0.0.1 (Well-known DNS: Cloudflare / APNIC)
  206. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{82F6EBEE-8687-4CE1-BBD0-82CF2E5F4763}: [NameServer] = 1.1.1.1 (Well-known DNS: Cloudflare / APNIC)
  207. O17 - HKLM\System\ControlSet002\Services\Tcpip\..\{82F6EBEE-8687-4CE1-BBD0-82CF2E5F4763}: [NameServer] = 192.168.1.254
  208. O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\Windows\system32\MusNotification.exe /RunOnAC RebootDialog (Microsoft)
  209. O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\Windows\system32\MusNotification.exe /RunOnBattery RebootDialog (Microsoft)
  210. O22 - Task: (disabled) BraveSoftwareUpdateTaskMachineCore - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /c
  211. O22 - Task: (disabled) BraveSoftwareUpdateTaskMachineUA - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /ua /installsource scheduler
  212. O22 - Task: (disabled) Driver Booster SkipUAC (HOME) - C:\Program Files (x86)\IObit\Driver Booster\9.0.1\DriverBooster.exe /skipuac
  213. O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
  214. O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
  215. O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork (Microsoft)
  216. O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\Windows\system32\usoclient.exe StartWork (Microsoft)
  217. O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
  218. O22 - Task: (update) \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\Windows\system32\MusNotification.exe (Microsoft)
  219. O23 - Service R2: AMD External Events Utility - C:\Windows\System32\DriverStore\FileRepository\u0361437.inf_amd64_b82dc71fab24f1f3\B361368\atiesrxx.exe
  220. O23 - Service R2: AtherosSvc - C:\Windows\System32\drivers\AdminService.exe
  221. O23 - Service R2: Dolby DAX API Service - (DolbyDAXAPI) - C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_0222c12a396c055f\DAX3API.exe
  222. O23 - Service R2: ELAN Service - (ETDService) - C:\Windows\System32\ETDService.exe
  223. O23 - Service R2: ESET Service - (ekrn) - C:\Program Files\ESET\ESET Security\ekrn.exe
  224. O23 - Service R2: Fortemedia APO Control Service - (FMAPOService) - C:\Windows\System32\FMService64.exe
  225. O23 - Service R2: Lenovo Fn and function keys service - (LenovoFnAndFunctionKeys) - C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_b9fd1528982e300f\LenovoUtilityService.exe
  226. O23 - Service R2: Lenovo Notebook ITS Service - (LITSSVC) - C:\Windows\System32\LNBITSSvc.exe
  227. O23 - Service R2: Qualcomm Atheros WLAN Driver Service - (QcomWlanSrv) - C:\Windows\System32\drivers\QcomWlanSrvx64.exe
  228. O23 - Service R2: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3d345565ec73a109\RtkAudUService64.exe
  229. O23 - Service R2: SynTPEnhService - C:\Windows\System32\SynTPEnhService.exe
  230. O23 - Service R3: ESET Firewall Helper - (ekrnEpfw) - C:\Program Files\ESET\ESET Security\ekrn.exe
  231. O23 - Service S3: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
  232. O23 - Service S3: Servizio Brave Update (bravem) - (bravem) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /medsvc
  233. O23 - Service S3: Shadow Defender Service - ({0CBD4F48-3751-475D-BE88-4F271385B672}) - C:\Program Files\Shadow Defender\Service.exe
  234.  
  235.  
  236. --
  237. End of file - Time spent: 11,7 sec. - 31180 bytes, CRC32: FFFFFFFF. Sign: ê‘šćŽš
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement