HKU\S-1-5-21-2540028857-2120196535-4242731766-1000\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize Task: {20E1A821-13C1-4FC9-A9A5-EB980351148A} - System32\Tasks\{240263E7-22FD-4248-A557-EC67005D8F8B} => C:\Windows\system32\pcalua.exe -a D:\setup.exe -d D:\ Task: {457FEA18-4E6B-46C5-9A7C-5CD4E09E8F5F} - System32\Tasks\{0D3C9B31-AFB5-4A1A-B4B3-65F1EEA136C2} => C:\Windows\system32\pcalua.exe -a C:\Users\Merlin\AppData\Local\Temp\Temp1_RTL8111BCRTL8112L_LAN_V735222009_Win7.zip\RTL8111BCRTL8112L_LAN_V735222009_Win7\AsusSetup.exe <==== ATTENTION Task: {5CED1006-723F-4945-A198-90119379EF7F} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe Task: {D0BE8D10-CC58-4BE6-973F-1C07C4B5D787} - System32\Tasks\{236274ED-A5C7-4A5B-A5FF-437947534D50} => C:\Windows\system32\pcalua.exe -a D:\Setup.exe -d D:\ Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task b61a981f-2726-4d17-a712-67fe3d57b1d3.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e5b83514-0ca1-4343-ae3d-ea191808687b.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2008-01-01] (Oracle America, Inc. -> Oracle Corporation) BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2008-01-01] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\ssv.dll [2019-06-12] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_211\bin\jp2ssv.dll [2019-06-12] (Oracle America, Inc. -> Oracle Corporation) Toolbar: HKU\S-1-5-21-2540028857-2120196535-4242731766-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-2540028857-2120196535-4242731766-1000 -> No Name - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No File FF SearchPlugin: C:\Users\Merlin\AppData\Roaming\Mozilla\Firefox\Profiles\7jd81ot7.default\searchplugins\bing-lavasoft.xml [2018-02-09] FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2011-06-20] (DivX, Inc. -> DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2008-01-01] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2008-01-01] (Oracle America, Inc. -> Oracle Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL) S2 HPSLPSVC; C:\Users\Merlin\AppData\Local\Temp\7zS2D2C\hpslpsvc64.dll [X] <==== ATTENTION S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X] S3 cpuz138; \??\C:\Users\Merlin\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] <==== ATTENTION S3 cpuz140; \??\C:\Users\Merlin\AppData\Local\Temp\cpuz140\cpuz140_x64.sys [X] <==== ATTENTION S1 MpKsl9639261c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0C3E840B-3548-4814-93AF-A572F41F7B42}\MpKsl9639261c.sys [X] S3 SWDUMon; system32\DRIVERS\SWDUMon.sys [X] CMD: type C:\Windows\ntbtlog.txt ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\PROGRA~1\MICROS~4\shellext.dll -> No File ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\PROGRA~1\MICROS~4\shellext.dll -> No File ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\PROGRA~1\MICROS~4\shellext.dll -> No File ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [119] FirewallRules: [{1090446C-F4F1-46B4-871D-BA4809D275E0}] => (Allow) C:\Users\Merlin\AppData\Local\Temp\7zSFDC9.tmp\SymNRT.exe No File FirewallRules: [{D1E64D68-0C4B-4C1D-AAA5-2CFE54F5F8B7}] => (Allow) C:\Users\Merlin\AppData\Local\Temp\7zSFDC9.tmp\SymNRT.exe No File FirewallRules: [{B080E22B-8D75-4BF9-ADC1-DB6E64814BD9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe No File CMD: netsh winsock reset CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" Reboot: