Подозрения возникли из за того, что многие игры закрываются сразу после запуска.
Защитник виндовс сегодня нашел заразу: Trojan:Win32/Wacatac.B!ml
Я просканировал программой HiJackThis Fork by Alex Dragokas, Вот что она выдала:
Защитник виндовс сегодня нашел заразу: Trojan:Win32/Wacatac.B!ml
Я просканировал программой HiJackThis Fork by Alex Dragokas, Вот что она выдала:
Logfile of HiJackThis Fork by Alex Dragokas v.2.10.0.31
Platform: x64 Windows 10 (Home), 10.0.19045.3030 (ReleaseId: 2009, 22H2), Service Pack: 0
Time: 23.05.2023 - 13:17 (UTC+03:00)
Language: OS: Russian (0x419). Display: Russian (0x419). Non-Unicode: Russian (0x419)
Memory: 9605 MiB Free (41 %). CPU Loading: (3 %)
Elevated: Yes
Ran by: xxxxxxx (group: Administrators) on DESKTOP-xxxxxxxxxx, FirstRun: yes
Chrome: 113.0.5672.127
Internet Explorer: 11.789.19041.0
Default: "D:\Opera\Launcher.exe" -noautoupdate -- "%1"
Boot mode: Normal
Запущенные процессы:
Кол-во | Путь
1 C:\MalwHunt\Cloudscan\MHCloudSvc.exe
1 C:\MalwHunt\MalwareHunter.exe
1 C:\MalwHunt\mhtray.exe
1 C:\MalwHunt\PCBooster.exe
1 C:\MalwHunt\QuickSearch.exe
1 C:\MalwHunt\x64\MemfilesService.exe
1 C:\MalwHunt\x64\x64ProcessAssistSvc.exe
1 C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe
2 C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
1 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23032.196.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\NisSrv.exe
2 C:\Windows\explorer.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\backgroundTaskHost.exe
1 C:\Windows\System32\CompPkgSrv.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
1 C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_cc023ae97de64064\RstMwService.exe
1 C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_f3c201b4c28c14d0\WMIRegistrationService.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
2 C:\Windows\System32\mmc.exe
2 C:\Windows\System32\rundll32.exe
3 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SecurityHealthHost.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
66 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\SystemSettingsBroker.exe
1 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\Taskmgr.exe
2 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\SysWOW64\PnkBstrA.exe
32 D:\Opera\99.0.4788.13\opera.exe
1 D:\Opera\99.0.4788.13\opera_crashreporter.exe
1 E:\KerishDoct\KerishDoctor.exe
1 H:\AutorunOrga\AutorunOrganizer.exe
7 I:\sM\bin\cef\cef.win7x64\steamwebhelper.exe
1 I:\sM\steam.exe
1 L:\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Search Page] = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL: (default) = http://home.microsoft.com/access/autosearch.asp?p=%s
O4 - HKCU\..\StartupApproved\Run: [rt640x64.sys] = C:\Windows\System32\drivers\rt640x64.sys (2023/04/03)
O4 - HKLM\..\StartupApproved\Run: [SecurityHealth] = C:\WINDOWS\system32\SecurityHealthSystray.exe (2023/02/20)
O6 - IE Policy: HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions - present
O17 - DHCP DNS 1: 77.88.8.88 (Well-known DNS: Yandex.DNS)
O17 - DHCP DNS 2: 77.88.8.2 (Well-known DNS: Yandex.DNS)
O17 - DHCP DNS 3: 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2558e01c-7d6a-4c88-9549-7c554e52831e}: [NameServer] = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2558e01c-7d6a-4c88-9549-7c554e52831e}: [NameServer] = 77.88.8.2 (Well-known DNS: Yandex.DNS)
O17 - HKLM\System\CCS\Services\Tcpip\..\{2558e01c-7d6a-4c88-9549-7c554e52831e}: [NameServer] = 77.88.8.88 (Well-known DNS: Yandex.DNS)
O22 - BITS Job: (download) {143D9EFA-8090-46B8-9219-530B15C7AD60} - http://edgedl.me.gvt1.com/edgedl/re...gd_2960_all_acjymqsx6ukbzw4se2x6fojy2nyq.crx3 -> C:\Users\VlMir\AppData\Local\Temp\chrome_BITS_13496_1179380416\jflookgnkcckhobaglndicnbbgbonegd_2960_all_acjymqsx6ukbzw4se2x6fojy2nyq.crx3
O22 - BITS Job: (download) {F9AD7F4D-6B5B-425D-BCEC-8008A1796CD1} - http://edgedl.me.gvt1.com/edgedl/re...mnib_8008_all_kmhosvlxzxig5btpqlugdkeqty.crx3 -> C:\Users\VlMir\AppData\Local\Temp\chrome_BITS_6072_1771213609\hfnkpimlhhgieaddgfemjhofmfblmnib_8008_all_kmhosvlxzxig5btpqlugdkeqty.crx3
O22 - BITS Job: Fix all (including legit)
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\Windows\explorer.exe
O22 - Task (.job): Wise Turbo Checker.job - D:\Wise Care 365\WiseTurbo.exe
O22 - Tasks: (disabled) \Agent Activation Runtime\S-1-5-21-247158510-25864335-1668906915-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Tasks: (disabled) Driver Booster Scheduler - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\Scheduler.exe /scheduler (file missing)
O22 - Tasks: (disabled) Driver Booster SkipUAC (VlMir) - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\DriverBooster.exe /skipuac (file missing)
O22 - Tasks: (disabled) Driver Booster Update - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\AutoUpdate.exe /auto (file missing)
O22 - Tasks: (disabled) GoogleUpdateTaskMachineCore{56C16DB2-9CB8-4FBF-82BC-E88CA795D63E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Tasks: (disabled) GoogleUpdateTaskMachineUA{275FCC7C-0043-42F7-BA2C-7E370716296E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Tasks: (disabled) iTop Data Recovery SkipUAC (VlMir) - C:\Program Files (x86)\iTop Data Recovery\iTopDataRecovery.exe /skipUAC
O22 - Tasks: (disabled) iTop Data Recovery Update - C:\Program Files (x86)\iTop Data Recovery\AutoUpdate.exe /auto
O22 - Tasks: (disabled) OneDrive Reporting Task-S-1-5-21-247158510-25864335-1668906915-1001 - C:\Users\VlMir\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Tasks: (disabled) Opera GX scheduled assistant Autoupdate 1631635360 - G:\OperaG\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="G:\OperaG\assistant" $(Arg0)
O22 - Tasks: (disabled) Opera GX scheduled Autoupdate 1631635358 - G:\OperaG\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Tasks: (disabled) Opera scheduled assistant Autoupdate 1681373989 - D:\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="D:\Opera\assistant" $(Arg0) (file missing)
O22 - Tasks: (disabled) Opera scheduled Autoupdate 1681373984 - D:\Opera\launcher.exe --scheduledautoupdate $(Arg0) (file missing)
O22 - Tasks: (disabled) RunAsStdUser_mglauncherSteam_0.1177 - C:\SteamLibrary\steamapps\common\Warface\MGLauncher\MGL.exe -updated -lowermode -startedbysetup -fromsteam "installer=C:\SteamLibrary\steamapps\common\Warface\WarfaceMycomSteamLoader.exe" "game=0.1177" "-FromSteam" "-SteamAppId=291480" "-channel=47" /unique=1682246904_12031656
O22 - Tasks: (disabled) ShellAppRuntimeUnelevated_Task - C:\Windows\System32\ShellAppRuntime.exe /NoUACCheck
O22 - Tasks: (disabled) SmartDefrag_AutoAnalyze - C:\sMartdefrag\AutoDefrag.exe /AUTOANALYZE
O22 - Tasks: (disabled) SmartDefrag_Startup - C:\sMartdefrag\SmartDefrag.exe /STARTUP
O22 - Tasks: (disabled) SmartDefrag_Update - C:\sMartdefrag\AutoUpdate.exe /autorun
O22 - Tasks: (disabled) Soft Organizer Applications Updates Check - d:\SoftOrganiz\SoftOrganizer.exe -SilentUpdatesCheck
O22 - Tasks: (disabled) Software Updater Scheduler - D:\IObitSoft\Software Updater\SUInit.exe /scheduler
O22 - Tasks: (disabled) Software Updater SkipUAC(VlMir) - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /SkipUac
O22 - Tasks: (disabled) SU_AutoUpdate - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /Task_AutoUpdate
O22 - Tasks: (disabled) USER_ESRV_SVC_QUEENCREEK - C:\WINDOWS\System32\Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
O22 - Tasks: (disabled) Wise Turbo Checker - D:\Wise Care 365\WiseTurbo.exe
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Tasks: Autorun Organizer - H:\AutorunOrga\AutorunOrganizer.exe -Minimize
O22 - Tasks: Kerish Doctor - E:\KerishDoct\KerishDoctor.exe
O22 - Tasks: klcp_update - C:\KLiteCodec\Tools\CodecTweakTool.exe /verysilent /update /freq=30
O22 - Tasks_Migrated: (disabled) \Agent Activation Runtime\S-1-5-21-247158510-25864335-1668906915-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Tasks_Migrated: (disabled) iTop Data Recovery SkipUAC (VlMir) - C:\Program Files (x86)\iTop Data Recovery\iTopDataRecovery.exe /skipUAC
O22 - Tasks_Migrated: (disabled) iTop Data Recovery Update - C:\Program Files (x86)\iTop Data Recovery\AutoUpdate.exe /auto
O22 - Tasks_Migrated: (disabled) OneDrive Reporting Task-S-1-5-21-247158510-25864335-1668906915-1001 - C:\Users\VlMir\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Tasks_Migrated: (disabled) Opera GX scheduled assistant Autoupdate 1631635360 - G:\OperaG\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="G:\OperaG\assistant" $(Arg0)
O22 - Tasks_Migrated: (disabled) RunAsStdUser_mglauncherSteam_0.1177 - C:\SteamLibrary\steamapps\common\Warface\MGLauncher\MGL.exe -updated -lowermode -startedbysetup -fromsteam "installer=C:\SteamLibrary\steamapps\common\Warface\WarfaceMycomSteamLoader.exe" "game=0.1177" "-FromSteam" "-SteamAppId=291480" "-channel=47" /unique=1682246904_12031656
O22 - Tasks_Migrated: (disabled) ShellAppRuntimeUnelevated_Task - C:\Windows\System32\ShellAppRuntime.exe /NoUACCheck
O22 - Tasks_Migrated: (disabled) SmartDefrag_AutoAnalyze - C:\sMartdefrag\AutoDefrag.exe /AUTOANALYZE
O22 - Tasks_Migrated: (disabled) SmartDefrag_Startup - C:\sMartdefrag\SmartDefrag.exe /STARTUP
O22 - Tasks_Migrated: (disabled) SmartDefrag_Update - C:\sMartdefrag\AutoUpdate.exe /autorun
O22 - Tasks_Migrated: (disabled) Soft Organizer Applications Updates Check - d:\SoftOrganiz\SoftOrganizer.exe -SilentUpdatesCheck
O22 - Tasks_Migrated: (disabled) USER_ESRV_SVC_QUEENCREEK - C:\WINDOWS\System32\Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
O22 - Tasks_Migrated: (disabled) Wise Turbo Checker - D:\Wise Care 365\WiseTurbo.exe
O22 - Tasks_Migrated: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Tasks_Migrated: Autorun Organizer - H:\AutorunOrga\AutorunOrganizer.exe -Minimize
O22 - Tasks_Migrated: Driver Booster SkipUAC (VlMir) - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\DriverBooster.exe /skipuac (file missing)
O22 - Tasks_Migrated: Driver Booster Update - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\AutoUpdate.exe /auto (file missing)
O22 - Tasks_Migrated: GoogleUpdateTaskMachineCore{56C16DB2-9CB8-4FBF-82BC-E88CA795D63E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Tasks_Migrated: GoogleUpdateTaskMachineUA{275FCC7C-0043-42F7-BA2C-7E370716296E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Tasks_Migrated: Kerish Doctor - E:\KerishDoct\KerishDoctor.exe
O22 - Tasks_Migrated: klcp_update - C:\KLiteCodec\Tools\CodecTweakTool.exe /verysilent /update /freq=30
O22 - Tasks_Migrated: Opera GX scheduled Autoupdate 1631635358 - G:\OperaG\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Tasks_Migrated: Opera scheduled assistant Autoupdate 1681373989 - D:\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="D:\Opera\assistant" $(Arg0) (file missing)
O22 - Tasks_Migrated: Opera scheduled Autoupdate 1681373984 - D:\Opera\launcher.exe --scheduledautoupdate $(Arg0) (file missing)
O22 - Tasks_Migrated: Software Updater Scheduler - D:\IObitSoft\Software Updater\SUInit.exe /scheduler
O22 - Tasks_Migrated: Software Updater SkipUAC(VlMir) - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /SkipUac
O22 - Tasks_Migrated: SU_AutoUpdate - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /Task_AutoUpdate
O23 - Service R2: GUBootService - C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe
O23 - Service R2: Intel(R) Storage Middleware Service - (RstMwService) - C:\WINDOWS\System32\DriverStore\FileRepository\iaahcic.inf_amd64_cc023ae97de64064\RstMwService.exe
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
O23 - Service R2: PnkBstrA - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service R3: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
O23 - Service R3: Intel(R) Management Engine WMI Provider Registration - (WMIRegistrationService) - C:\WINDOWS\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_f3c201b4c28c14d0\WMIRegistrationService.exe
O23 - Service S2: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service S2: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService
O23 - Service S3: BattlEye Service - (BEService) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service S3: Chemtable Startup Checking - H:\AutorunOrga\StartupCheckingService.exe
O23 - Service S3: EABackgroundService - C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe -start
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService1d93f0d407031b0) - (GoogleChromeElevationService1d93f0d407031b0) - C:\Program Files\Google\Chrome\Application\113.0.5672.127\elevation_service.exe
O23 - Service S3: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_2ec86af404806919\IntelCpHDCPSvc.exe
O23 - Service S3: Intel(R) Graphics Command Center Service - (igccservice) - C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_86abb967c9462a29\OneApp.IGCC.WinService.exe
O23 - Service S3: Intel(R) Platform License Manager Service - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_367008a610747d24\lib\PlatformLicenseManagerService.exe
O23 - Service S3: IObit Uninstaller Service - (IObitUnSvr) - D:\IObit\Unin\IObit Uninstaller\IUService.exe Uninstaller\IUService.exe (file missing)
O23 - Service S3: OutlineService - C:\Program Files (x86)\Outline\OutlineService.exe
O23 - Service S3: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_dd4cb97d217df0bc\RtkAudUService64.exe
O23 - Service S3: Rockstar Game Library Service - (Rockstar Service) - D:\Rockstar Games\Launcher\RockstarService.exe
O23 - Service S3: Uncheater for BattleGrounds_GL - (ucldr_battlegrounds_gl) - C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe
O23 - Service S3: User Energy Server Service queencreek - (USER_ESRV_SVC_QUEENCREEK) - C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe "--run_as_user_process"
O23 - Service S3: Wise Boot Assistant - (WiseBootAssistant) - D:\Wise Care 365\BootTime.exe
O23 - Service S3: Служба Google Update (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Служба Google Update (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
--
End of file - Time spent: 22,6 sec. - 37946 bytes, CRC32: FFFFFFFF. Sign: ﵭ
Platform: x64 Windows 10 (Home), 10.0.19045.3030 (ReleaseId: 2009, 22H2), Service Pack: 0
Time: 23.05.2023 - 13:17 (UTC+03:00)
Language: OS: Russian (0x419). Display: Russian (0x419). Non-Unicode: Russian (0x419)
Memory: 9605 MiB Free (41 %). CPU Loading: (3 %)
Elevated: Yes
Ran by: xxxxxxx (group: Administrators) on DESKTOP-xxxxxxxxxx, FirstRun: yes
Chrome: 113.0.5672.127
Internet Explorer: 11.789.19041.0
Default: "D:\Opera\Launcher.exe" -noautoupdate -- "%1"
Boot mode: Normal
Запущенные процессы:
Кол-во | Путь
1 C:\MalwHunt\Cloudscan\MHCloudSvc.exe
1 C:\MalwHunt\MalwareHunter.exe
1 C:\MalwHunt\mhtray.exe
1 C:\MalwHunt\PCBooster.exe
1 C:\MalwHunt\QuickSearch.exe
1 C:\MalwHunt\x64\MemfilesService.exe
1 C:\MalwHunt\x64\x64ProcessAssistSvc.exe
1 C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe
2 C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
1 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23032.196.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2304.8-0\NisSrv.exe
2 C:\Windows\explorer.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\backgroundTaskHost.exe
1 C:\Windows\System32\CompPkgSrv.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
1 C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_cc023ae97de64064\RstMwService.exe
1 C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_f3c201b4c28c14d0\WMIRegistrationService.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
2 C:\Windows\System32\mmc.exe
2 C:\Windows\System32\rundll32.exe
3 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SecurityHealthHost.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
66 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\SystemSettingsBroker.exe
1 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\Taskmgr.exe
2 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\SysWOW64\PnkBstrA.exe
32 D:\Opera\99.0.4788.13\opera.exe
1 D:\Opera\99.0.4788.13\opera_crashreporter.exe
1 E:\KerishDoct\KerishDoctor.exe
1 H:\AutorunOrga\AutorunOrganizer.exe
7 I:\sM\bin\cef\cef.win7x64\steamwebhelper.exe
1 I:\sM\steam.exe
1 L:\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Search Page] = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL: (default) = http://home.microsoft.com/access/autosearch.asp?p=%s
O4 - HKCU\..\StartupApproved\Run: [rt640x64.sys] = C:\Windows\System32\drivers\rt640x64.sys (2023/04/03)
O4 - HKLM\..\StartupApproved\Run: [SecurityHealth] = C:\WINDOWS\system32\SecurityHealthSystray.exe (2023/02/20)
O6 - IE Policy: HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions - present
O17 - DHCP DNS 1: 77.88.8.88 (Well-known DNS: Yandex.DNS)
O17 - DHCP DNS 2: 77.88.8.2 (Well-known DNS: Yandex.DNS)
O17 - DHCP DNS 3: 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2558e01c-7d6a-4c88-9549-7c554e52831e}: [NameServer] = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2558e01c-7d6a-4c88-9549-7c554e52831e}: [NameServer] = 77.88.8.2 (Well-known DNS: Yandex.DNS)
O17 - HKLM\System\CCS\Services\Tcpip\..\{2558e01c-7d6a-4c88-9549-7c554e52831e}: [NameServer] = 77.88.8.88 (Well-known DNS: Yandex.DNS)
O22 - BITS Job: (download) {143D9EFA-8090-46B8-9219-530B15C7AD60} - http://edgedl.me.gvt1.com/edgedl/re...gd_2960_all_acjymqsx6ukbzw4se2x6fojy2nyq.crx3 -> C:\Users\VlMir\AppData\Local\Temp\chrome_BITS_13496_1179380416\jflookgnkcckhobaglndicnbbgbonegd_2960_all_acjymqsx6ukbzw4se2x6fojy2nyq.crx3
O22 - BITS Job: (download) {F9AD7F4D-6B5B-425D-BCEC-8008A1796CD1} - http://edgedl.me.gvt1.com/edgedl/re...mnib_8008_all_kmhosvlxzxig5btpqlugdkeqty.crx3 -> C:\Users\VlMir\AppData\Local\Temp\chrome_BITS_6072_1771213609\hfnkpimlhhgieaddgfemjhofmfblmnib_8008_all_kmhosvlxzxig5btpqlugdkeqty.crx3
O22 - BITS Job: Fix all (including legit)
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\Windows\explorer.exe
O22 - Task (.job): Wise Turbo Checker.job - D:\Wise Care 365\WiseTurbo.exe
O22 - Tasks: (disabled) \Agent Activation Runtime\S-1-5-21-247158510-25864335-1668906915-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Tasks: (disabled) Driver Booster Scheduler - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\Scheduler.exe /scheduler (file missing)
O22 - Tasks: (disabled) Driver Booster SkipUAC (VlMir) - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\DriverBooster.exe /skipuac (file missing)
O22 - Tasks: (disabled) Driver Booster Update - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\AutoUpdate.exe /auto (file missing)
O22 - Tasks: (disabled) GoogleUpdateTaskMachineCore{56C16DB2-9CB8-4FBF-82BC-E88CA795D63E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Tasks: (disabled) GoogleUpdateTaskMachineUA{275FCC7C-0043-42F7-BA2C-7E370716296E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Tasks: (disabled) iTop Data Recovery SkipUAC (VlMir) - C:\Program Files (x86)\iTop Data Recovery\iTopDataRecovery.exe /skipUAC
O22 - Tasks: (disabled) iTop Data Recovery Update - C:\Program Files (x86)\iTop Data Recovery\AutoUpdate.exe /auto
O22 - Tasks: (disabled) OneDrive Reporting Task-S-1-5-21-247158510-25864335-1668906915-1001 - C:\Users\VlMir\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Tasks: (disabled) Opera GX scheduled assistant Autoupdate 1631635360 - G:\OperaG\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="G:\OperaG\assistant" $(Arg0)
O22 - Tasks: (disabled) Opera GX scheduled Autoupdate 1631635358 - G:\OperaG\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Tasks: (disabled) Opera scheduled assistant Autoupdate 1681373989 - D:\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="D:\Opera\assistant" $(Arg0) (file missing)
O22 - Tasks: (disabled) Opera scheduled Autoupdate 1681373984 - D:\Opera\launcher.exe --scheduledautoupdate $(Arg0) (file missing)
O22 - Tasks: (disabled) RunAsStdUser_mglauncherSteam_0.1177 - C:\SteamLibrary\steamapps\common\Warface\MGLauncher\MGL.exe -updated -lowermode -startedbysetup -fromsteam "installer=C:\SteamLibrary\steamapps\common\Warface\WarfaceMycomSteamLoader.exe" "game=0.1177" "-FromSteam" "-SteamAppId=291480" "-channel=47" /unique=1682246904_12031656
O22 - Tasks: (disabled) ShellAppRuntimeUnelevated_Task - C:\Windows\System32\ShellAppRuntime.exe /NoUACCheck
O22 - Tasks: (disabled) SmartDefrag_AutoAnalyze - C:\sMartdefrag\AutoDefrag.exe /AUTOANALYZE
O22 - Tasks: (disabled) SmartDefrag_Startup - C:\sMartdefrag\SmartDefrag.exe /STARTUP
O22 - Tasks: (disabled) SmartDefrag_Update - C:\sMartdefrag\AutoUpdate.exe /autorun
O22 - Tasks: (disabled) Soft Organizer Applications Updates Check - d:\SoftOrganiz\SoftOrganizer.exe -SilentUpdatesCheck
O22 - Tasks: (disabled) Software Updater Scheduler - D:\IObitSoft\Software Updater\SUInit.exe /scheduler
O22 - Tasks: (disabled) Software Updater SkipUAC(VlMir) - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /SkipUac
O22 - Tasks: (disabled) SU_AutoUpdate - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /Task_AutoUpdate
O22 - Tasks: (disabled) USER_ESRV_SVC_QUEENCREEK - C:\WINDOWS\System32\Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
O22 - Tasks: (disabled) Wise Turbo Checker - D:\Wise Care 365\WiseTurbo.exe
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Tasks: Autorun Organizer - H:\AutorunOrga\AutorunOrganizer.exe -Minimize
O22 - Tasks: Kerish Doctor - E:\KerishDoct\KerishDoctor.exe
O22 - Tasks: klcp_update - C:\KLiteCodec\Tools\CodecTweakTool.exe /verysilent /update /freq=30
O22 - Tasks_Migrated: (disabled) \Agent Activation Runtime\S-1-5-21-247158510-25864335-1668906915-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Tasks_Migrated: (disabled) iTop Data Recovery SkipUAC (VlMir) - C:\Program Files (x86)\iTop Data Recovery\iTopDataRecovery.exe /skipUAC
O22 - Tasks_Migrated: (disabled) iTop Data Recovery Update - C:\Program Files (x86)\iTop Data Recovery\AutoUpdate.exe /auto
O22 - Tasks_Migrated: (disabled) OneDrive Reporting Task-S-1-5-21-247158510-25864335-1668906915-1001 - C:\Users\VlMir\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Tasks_Migrated: (disabled) Opera GX scheduled assistant Autoupdate 1631635360 - G:\OperaG\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="G:\OperaG\assistant" $(Arg0)
O22 - Tasks_Migrated: (disabled) RunAsStdUser_mglauncherSteam_0.1177 - C:\SteamLibrary\steamapps\common\Warface\MGLauncher\MGL.exe -updated -lowermode -startedbysetup -fromsteam "installer=C:\SteamLibrary\steamapps\common\Warface\WarfaceMycomSteamLoader.exe" "game=0.1177" "-FromSteam" "-SteamAppId=291480" "-channel=47" /unique=1682246904_12031656
O22 - Tasks_Migrated: (disabled) ShellAppRuntimeUnelevated_Task - C:\Windows\System32\ShellAppRuntime.exe /NoUACCheck
O22 - Tasks_Migrated: (disabled) SmartDefrag_AutoAnalyze - C:\sMartdefrag\AutoDefrag.exe /AUTOANALYZE
O22 - Tasks_Migrated: (disabled) SmartDefrag_Startup - C:\sMartdefrag\SmartDefrag.exe /STARTUP
O22 - Tasks_Migrated: (disabled) SmartDefrag_Update - C:\sMartdefrag\AutoUpdate.exe /autorun
O22 - Tasks_Migrated: (disabled) Soft Organizer Applications Updates Check - d:\SoftOrganiz\SoftOrganizer.exe -SilentUpdatesCheck
O22 - Tasks_Migrated: (disabled) USER_ESRV_SVC_QUEENCREEK - C:\WINDOWS\System32\Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
O22 - Tasks_Migrated: (disabled) Wise Turbo Checker - D:\Wise Care 365\WiseTurbo.exe
O22 - Tasks_Migrated: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Tasks_Migrated: Autorun Organizer - H:\AutorunOrga\AutorunOrganizer.exe -Minimize
O22 - Tasks_Migrated: Driver Booster SkipUAC (VlMir) - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\DriverBooster.exe /skipuac (file missing)
O22 - Tasks_Migrated: Driver Booster Update - C:\Program Files (x86)\IObit\Driver Booster\10.4.0\AutoUpdate.exe /auto (file missing)
O22 - Tasks_Migrated: GoogleUpdateTaskMachineCore{56C16DB2-9CB8-4FBF-82BC-E88CA795D63E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Tasks_Migrated: GoogleUpdateTaskMachineUA{275FCC7C-0043-42F7-BA2C-7E370716296E} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Tasks_Migrated: Kerish Doctor - E:\KerishDoct\KerishDoctor.exe
O22 - Tasks_Migrated: klcp_update - C:\KLiteCodec\Tools\CodecTweakTool.exe /verysilent /update /freq=30
O22 - Tasks_Migrated: Opera GX scheduled Autoupdate 1631635358 - G:\OperaG\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Tasks_Migrated: Opera scheduled assistant Autoupdate 1681373989 - D:\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="D:\Opera\assistant" $(Arg0) (file missing)
O22 - Tasks_Migrated: Opera scheduled Autoupdate 1681373984 - D:\Opera\launcher.exe --scheduledautoupdate $(Arg0) (file missing)
O22 - Tasks_Migrated: Software Updater Scheduler - D:\IObitSoft\Software Updater\SUInit.exe /scheduler
O22 - Tasks_Migrated: Software Updater SkipUAC(VlMir) - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /SkipUac
O22 - Tasks_Migrated: SU_AutoUpdate - d:\IObitSoft\Software Updater\SoftwareUpdater.exe /Task_AutoUpdate
O23 - Service R2: GUBootService - C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe
O23 - Service R2: Intel(R) Storage Middleware Service - (RstMwService) - C:\WINDOWS\System32\DriverStore\FileRepository\iaahcic.inf_amd64_cc023ae97de64064\RstMwService.exe
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
O23 - Service R2: PnkBstrA - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service R3: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
O23 - Service R3: Intel(R) Management Engine WMI Provider Registration - (WMIRegistrationService) - C:\WINDOWS\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_f3c201b4c28c14d0\WMIRegistrationService.exe
O23 - Service S2: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service S2: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService
O23 - Service S3: BattlEye Service - (BEService) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service S3: Chemtable Startup Checking - H:\AutorunOrga\StartupCheckingService.exe
O23 - Service S3: EABackgroundService - C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe -start
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService1d93f0d407031b0) - (GoogleChromeElevationService1d93f0d407031b0) - C:\Program Files\Google\Chrome\Application\113.0.5672.127\elevation_service.exe
O23 - Service S3: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_2ec86af404806919\IntelCpHDCPSvc.exe
O23 - Service S3: Intel(R) Graphics Command Center Service - (igccservice) - C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_86abb967c9462a29\OneApp.IGCC.WinService.exe
O23 - Service S3: Intel(R) Platform License Manager Service - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_367008a610747d24\lib\PlatformLicenseManagerService.exe
O23 - Service S3: IObit Uninstaller Service - (IObitUnSvr) - D:\IObit\Unin\IObit Uninstaller\IUService.exe Uninstaller\IUService.exe (file missing)
O23 - Service S3: OutlineService - C:\Program Files (x86)\Outline\OutlineService.exe
O23 - Service S3: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_dd4cb97d217df0bc\RtkAudUService64.exe
O23 - Service S3: Rockstar Game Library Service - (Rockstar Service) - D:\Rockstar Games\Launcher\RockstarService.exe
O23 - Service S3: Uncheater for BattleGrounds_GL - (ucldr_battlegrounds_gl) - C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe
O23 - Service S3: User Energy Server Service queencreek - (USER_ESRV_SVC_QUEENCREEK) - C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe "--run_as_user_process"
O23 - Service S3: Wise Boot Assistant - (WiseBootAssistant) - D:\Wise Care 365\BootTime.exe
O23 - Service S3: Служба Google Update (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Служба Google Update (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
--
End of file - Time spent: 22,6 sec. - 37946 bytes, CRC32: FFFFFFFF. Sign: ﵭ
Последнее редактирование модератором: