My $2000 DOLLAR PC is being HACKED - Virus, Trojan, Spyware, and Malware Removal Help
Common Information
Type Value
UUID 35dedf51-891f-46ae-b216-13aea891d1e7
Fingerprint 35d4bb18faceee97
Analysis status DONE
Considered CTI value 0
Text language
Published April 6, 2023, 6:51 p.m.
Added to db April 7, 2023, 6:07 a.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline My $2000 DOLLAR PC is being HACKED
Title My $2000 DOLLAR PC is being HACKED - Virus, Trojan, Spyware, and Malware Removal Help
Detected Hints/Tags/Attributes 89/2/321
Attributes
Details Type #Events CTI Value
Details Domain 2
nzxt.cam
Details Domain 1
www.cfos.de
Details Domain 37
java.com
Details Domain 87
regid.1991-06.com.microsoft
Details Domain 8
valorant.live
Details Domain 7
nortonlifelock.norton
Details Domain 2
choice.microsoft.com
Details Domain 2
choice.microsoft.com.nstac.net
Details Domain 2
df.telemetry.microsoft.com
Details Domain 2
oca.telemetry.microsoft.com
Details Domain 2
oca.telemetry.microsoft.com.nsatc.net
Details Domain 2
redir.metaservices.microsoft.com
Details Domain 2
reports.wes.df.telemetry.microsoft.com
Details Domain 2
services.wes.df.telemetry.microsoft.com
Details Domain 2
settings-sandbox.data.microsoft.com
Details Domain 2
settings-win.data.microsoft.com
Details Domain 2
sqm.df.telemetry.microsoft.com
Details Domain 2
sqm.telemetry.microsoft.com
Details Domain 3
sqm.telemetry.microsoft.com.nsatc.net
Details Domain 2
telecommand.telemetry.microsoft.com
Details Domain 2
telecommand.telemetry.microsoft.com.nsatc.net
Details Domain 2
telemetry.appex.bing.net
Details Domain 3
telemetry.microsoft.com
Details Domain 3
telemetry.urs.microsoft.com
Details Domain 2
vortex-sandbox.data.microsoft.com
Details Domain 2
vortex-win.data.microsoft.com
Details Domain 2
vortex.data.microsoft.com
Details Domain 5
watson.telemetry.microsoft.com
Details Domain 2
watson.telemetry.microsoft.com.nsatc.net
Details Domain 3
watson.ppe.telemetry.microsoft.com
Details Domain 2
wes.df.telemetry.microsoft.com
Details Domain 2
vortex-bn2.metron.live.com.nsatc.net
Details Domain 2
vortex-cy2.metron.live.com.nsatc.net
Details Domain 3
watson.live.com
Details Domain 5
watson.microsoft.com
Details Domain 2
feedback.search.microsoft.com
Details File 1
054043.png
Details File 1
054400.png
Details File 1
054828.png
Details File 3
amdrsserv.exe
Details File 4
radeonsoftware.exe
Details File 86
service.exe
Details File 6
cpuidremote64.exe
Details File 4
displayadapter.exe
Details File 27
c:\program files\nvidia corporation\nvcontainer\nvcontainer.exe
Details File 127
c:\windows\system32\rundll32.exe
Details File 3
amdrssrcext.exe
Details File 3
cncmd.exe
Details File 1260
explorer.exe
Details File 409
c:\windows\system32\cmd.exe
Details File 14
c:\program files\nvidia corporation\nvidia geforce experience\nvidia share.exe
Details File 306
services.exe
Details File 5
c:\program files\riot vanguard\vgk.sys
Details File 2
c:\windows\system32\drivers\vmdrv.sys
Details File 70
c:\windows\system32\drivers\wd\wdboot.sys
Details File 70
c:\windows\system32\drivers\wd\wdfilter.sys
Details File 70
c:\windows\system32\drivers\wd\wdnisdrv.sys
Details File 5
wpctrldrv.sys
Details File 1
c:\windows\system32\tasks\remediation  2023-04-07 01:37 - 2023-04-07 02:02 - 000002614 _____ c:\windows\ntbtlog.txt
Details File 1
c:\users\winte\downloads\shortcut.txt
Details File 1
c:\users\winte\downloads\frst.txt
Details File 1
c:\frst  2023-04-07 01:19 - 2023-04-07 01:20 - 000048777 _____ c:\users\winte\downloads\addition.txt
Details File 1
c:\users\winte\downloads\frst64.exe
Details File 108
0.exe
Details File 1
c:\users\winte\downloads\jre-8u361-windows-x64.exe
Details File 4
c:\windows\system32\windowsaccessbridge-64.dll
Details File 1
c:\users\winte\downloads\javauninstalltool.exe
Details File 1
c:\windows\system32\config\vsmidk  2023-04-06 20:59 - 2023-04-06 20:59 - 000490877 _____ c:\users\winte\downloads\690.pdf
Details File 1
c:\users\winte\downloads\kvrt.exe
Details File 1
c:\interaccel-master  2023-03-18 15:25 - 2023-03-18 15:25 - 3934367711 _____ c:\users\winte\downloads\concert.mp4
Details File 1
c:\programdata\nvidia  2023-04-07 01:31 - 2022-12-18 04:28 - 000000000 ____d c:\windows\system32\sleepstudy  2023-04-07 01:31 - 2022-12-17 14:50 - 000000000 ____d c:\users\winte\appdata\local\crashdumps  2023-04-07 01:30 - 2022-12-18 04:29 - 000000000 ____d c:\programdata\nvidia corporation  2023-04-07 01:17 - 2022-12-17 21:07 - 000000000 ____d c:\users\winte\appdata\roaming\l-connect3  2023-04-07 01:17 - 2022-12-17 13:41 - 000000000 ____d c:\users\winte\appdata\roaming\nzxt cam  2023-04-07 01:15 - 2022-12-17 13:40 - 000850360 _____ c:\windows\system32\perfstringbackup.ini
Details File 2
c:\windows\vgkbootstatus.dat
Details File 38
c:\dumpstack.log
Details File 40
c:\windows\tasks\sa.dat
Details File 2
c:\windows\system32\gigabytedownloadassistant.exe
Details File 3
c:\windows\system32\wpbbin.exe
Details File 2
c:\windows\system32\9earssurroundsound.dll
Details File 1
c:\users\winte\appdata\roaming\adobe  2023-04-03 21:54 - 2023-01-16 19:03 - 000000000 ____d c:\program files\common files\adobe  2023-03-31 01:36 - 2023-02-01 12:56 - 000000000 ____d c:\users\winte\onedrive\documents\sound recordings  2023-03-30 21:53 - 2022-12-17 13:35 - 000000000 ____d c:\users\winte  2023-03-29 21:13 - 2022-12-18 04:28 - 000000000 ____d c:\windows\system32\drivers\wd  2023-03-26 20:30 - 2022-12-18 04:25 - 000000000 ____d c:\windows\livekernelreports  2023-03-23 21:49 - 2023-03-07 19:38 - 000000000 ____d c:\users\winte\appdata\locallow\norton  2023-03-18 00:17 - 2022-12-18 04:28 - 000294600 _____ c:\windows\system32\fntcache.dat
Details File 59
c:\windows\system32\mrt.exe
Details File 54
c:\windows\syswow64\printconfig.dll
Details File 1
c:\program files\riot vanguard  2023-03-16 19:12 - 2022-12-17 13:57 - 000000000 ____d c:\programdata\norton  2023-03-16 19:04 - 2022-12-18 04:25 - 000000000 ____d c:\windows\system32\securityhealth  2023-03-16 00:12 - 2022-12-17 22:33 - 000000000 ____d c:\users\winte\appdata\local\unrealengine  2023-03-14 23:38 - 2023-02-26 21:17 - 000000015 _____ c:\users\winte\appdata\roaming\obs-virtualcam.txt
Details File 1
c:\users\winte\appdata\roaming\obs-virtualcam.txt
Details File 86
frst.txt
Details File 70
onedrivesetup.exe
Details File 34
win.rar
Details File 9
coresync_x64.dll
Details File 5
bushell.dll
Details File 6
navshext.dll
Details File 1
c:\program files\attribute changer\acshell.dll
Details File 29
nvshext.dll
Details File 4
c:\program files\corsair\corsair icue 4 software\siusbxp.dll
Details File 4
c:\programdata\microsoft\windows\start menu\desktop.ini
Details File 3
c:\programdata\microsoft\windows\start menu\programs\desktop.ini
Details File 8
c:\windows\system32\mscoree.dll
Details File 16
ssv.dll
Details File 15
jp2ssv.dll
Details File 2
settings-sandbox.dat
Details File 2
settings-win.dat
Details File 2
appex.bin
Details File 2
vortex-sandbox.dat
Details File 5
vortex-win.dat
Details File 3
vortex.dat
Details File 24
c:\windows\web\wallpaper\windows\img0.jpg
Details File 92
c:\windows\system32\svchost.exe
Details File 4
symamsi.dll
Details IPv4 1
22.23.1.21
Details IPv4 2
192.168.18.1
Details IPv4 48
204.79.197.200
Details IPv4 59
255.255.255.255
Details IPv4 619
0.0.0.0
Details IPv4 1
23.218.212.69
Details IPv4 1
204.160.124.125
Details IPv4 1
8.253.14.126
Details IPv4 1
8.254.25.126
Details IPv4 2
93.184.215.200
Details IPv4 1
198.78.194.252
Details IPv4 1
198.78.209.253
Details IPv4 1
8.254.23.254
Details IPv4 1
131.253.14.76
Details IPv4 1
22.22.6.10
Details IPv4 17
10.0.0.5
Details IPv4 4
10.0.1.5
Details IPv4 7
2.2.0.130
Details IPv4 1
1.2.0.119
Details IPv4 2
8.0.0.14
Details IPv4 2
5.22.0.0
Details IPv4 7
5.12.0.38
Details IPv4 8
1.0.7.0
Details IPv4 3
1.0.4.16
Details IPv4 3
1.0.10.1
Details IPv4 2
1.0.11.1
Details IPv4 8
1.0.1.8
Details IPv4 10
1.0.4.0
Details IPv4 3
1.3.51.0
Details IPv4 109
1.0.0.0
Details IPv4 5
2.0.36.0
Details IPv4 7
5.69.0.0
Details IPv4 1
1.4.0.29
Details IPv4 9
3.27.0.112
Details File 2
c:\program files\cfosspeed\spd.exe
Details File 4
c:\program files\corsair\corsair icue 4 software\cuellaccessservice.exe
Details File 3
c:\program files\corsair\corsair icue 4 software\icuedevicepluginhost.exe
Details File 198
msmpeng.exe
Details File 15
nortonsecurity.exe
Details File 7
nswscsvc.exe
Details File 44
container.exe
Details File 13
c:\windows\system32\driverstore\filerepository\nv_dispi.inf
Details File 35
c:\windows\system32\driverstore\filerepository\realtekservice.inf
Details File 35
rtkauduservice64.exe
Details File 1122
svchost.exe
Details File 13
gamebar.exe
Details File 9
gamebarftserver.exe
Details File 27
phoneexperiencehost.exe
Details File 14
widgetservice.exe
Details File 49
c:\windows\immersivecontrolpanel\systemsettings.exe
Details File 85
c:\windows\system32\dllhost.exe
Details File 67
c:\windows\system32\smartscreen.exe
Details File 1208
powershell.exe
Details File 35
c:\windows\system32\wlanext.exe
Details File 8
c:\windows\syswow64\wbem\wmiprvse.exe
Details File 2
c:\program files\cfosspeed\cfosspeed.exe
Details File 4
c:\program files\corsair\corsair icue 4 software\icue launcher.exe
Details File 5
c:\program files\riot vanguard\vgtray.exe
Details File 9
ccxprocess.exe
Details File 2
c:\program files\gigabyte\smart backup\rpmkickstartex.exe
Details File 128
msedge.exe
Details File 1
c:\program files\nzxt cam\nzxt cam.exe
Details File 99
steam.exe
Details File 1
wallpaper64.exe
Details File 11
epicgameslauncher.exe
Details File 156
1.exe
Details File 12
c:\windows\system32\musnotification.exe
Details File 20
c:\programdata\nvidia\nvcontainerdriverupdatecheck.log
Details File 18
c:\program files\nvidia corporation\nvbackend\nvtmrep.exe
Details File 1
c:\program files\nvidia corporation\nvidia broadcast\nvidia broadcast ui.exe
Details File 5
wscstub.exe
Details File 19
c:\program files\nvidia corporation\nvidia geforce experience\nvidia geforce experience.exe
Details File 8
symerr.exe
Details File 3
liquidsensord.exe
Details File 1
c:\users\winte\downloads\tron\resources\stage_1_tempclean\ccleaner\ccleaner.exe
Details File 4
dragon.exe
Details File 19
nvnodejslauncher.exe
Details File 1
c:\program files\gigabyte\control center\gbtcloudmatrix.exe
Details File 8
c:\program files\amd\cim\bin64\installmanagerapp.exe
Details File 3
c:\program files\common files\av\norton security\upgrade.exe
Details File 1
status.htm
Details File 1
c:\program files\gigabyte\control center\gcc.exe
Details File 1
c:\windows\system32\77bbc7ad-57bb-4521-9144-629a1691fb5a.ps1
Details File 1
c:\program files\l-connect 3\l-connect 3.exe
Details File 91
addition.txt
Details File 15
npdeployjava1.dll
Details File 15
npjp2.dll
Details File 1
c:\program files\gigabyte\control center\lib\gbt_vga\service\monitorservice-exec.exe
Details File 4
c:\windows\system32\corsairgamingaudiocfgservice64.exe
Details File 2
c:\program files\corsair\corsair icue 4 software\cueuniwillservice.exe
Details File 7
easyanticheat_eos.exe
Details File 4
easytuneengineservice.exe
Details File 16
epiconlineserviceshost.exe
Details File 2
oleddisplayservice.exe
Details File 4
ocbuttonservice.exe
Details File 5
c:\program files\riot vanguard\vgc.exe
Details File 87
nissrv.exe
Details File 2
c:\windows\system32\gigabyteupdateservice.exe
Details File 30
containerlocalsystem.log
Details File 8
c:\windows\system32\drivers\amdfendrmgr.sys
Details File 4
c:\windows\system32\drivers\amdgpio3.sys
Details File 3
c:\windows\system32\drivers\amdtools64.sys
Details File 1
170.inf
Details File 7
amdkmdag.sys
Details File 6
bhdrvx64.sys
Details File 5
ccsetx64.sys
Details File 2
c:\windows\system32\drivers\cfosspeed6.sys
Details File 5
c:\windows\system32\drivers\corsairgamingaudio64.sys
Details File 4
c:\program files\corsair\corsair icue 4 software\corsairllaccess64.sys
Details File 6
c:\windows\system32\drivers\corsairvbusdriver.sys
Details File 6
c:\windows\system32\drivers\corsairvhiddriver.sys
Details File 3
c:\windows\temp\cpuz154\cpuz154_x64.sys
Details File 5
c:\windows\system32\drivers\ctiio64.sys
Details File 5
eectrl64.sys
Details File 4
eraserutilrebootdrv.sys
Details File 4
c:\windows\system32\drivers\gdrv3.sys
Details File 1
c:\users\winte\appdata\local\temp\gpuz-v2.sys
Details File 5
idsvia64.sys
Details File 1
c:\windows\system32\drivers\keyboard.sys
Details File 1
c:\windows\system32\drivers\mouse.sys
Details File 6
c:\windows\system32\drivers\msio64.sys
Details File 4
c:\windows\system32\drivers\mtkbtfilterx.sys
Details File 4
c:\windows\system32\drivers\mtkwl6ex.sys
Details File 4
nsvst.sys
Details File 14
c:\windows\system32\driverstore\filerepository\nvmoduletracker.inf
Details File 14
nvmoduletracker.sys
Details File 1
c:\windows\system32\drivers\rawaccel.sys
Details File 2
c:\windows\system32\driverstore\filerepository\rt25cx21x64.inf
Details File 2
rt25cx21x64.sys
Details File 3
c:\windows\system32\drivers\rtf64x64.sys
Details File 3
c:\windows\system32\drivers\sivx64.sys
Details File 9
srtsp64.sys
Details File 5
srtspx64.sys
Details File 6
symefasi64.sys
Details File 5
symelam.sys
Details File 5
c:\windows\system32\drivers\symevent64x86.sys
Details File 6
symevnt.sys
Details File 5
ironx64.sys
Details File 6
symnets.sys
Details File 7
c:\windows\system32\drivers\vbaudio_cable64_win7.sys
Details IPv4 8
1.3.39.16
Details IPv4 13
1.1.0.1
Details IPv4 21
3.0.0.0
Details IPv4 34
2.10.91.91
Details IPv4 2
1.0.8.1
Details IPv4 4
1.0.2.18
Details Microsoft Patch Numbers 4
KB5023706
Details Microsoft Patch Numbers 1
KB5022497
Details Url 1
https://www.cfos.de/en/cfosspeed/documentation/status.htm?reg-12.00.2512
Details Url 2
https://go.microsoft.com/fwlink/?linkid=37020&name=settingsmodifier:win32
Details Windows Registry Key 68
HKLM\...\Run
Details Windows Registry Key 50
HKLM-x32\...\Run
Details Windows Registry Key 6
HKLM\...\RunOnce
Details Windows Registry Key 4
HKLM\...\Policies\Explorer
Details Windows Registry Key 44
HKLM\SOFTWARE\Policies\Microsoft\Windows
Details Windows Registry Key 19
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Details Windows Registry Key 1
HKLM\SOFTWARE\Policies\Microsoft\MRT
Details Windows Registry Key 8
HKLM\Software\Policies\...\system
Details Windows Registry Key 1
HKU\S-1-5-21-2297073907-4018794041-3882517032-1001\...\Run
Details Windows Registry Key 1
HKU\S-1-5-21-2297073907-4018794041-3882517032-1001\...\Policies\Explorer
Details Windows Registry Key 9
HKU\S-1-5-18\...\Run
Details Windows Registry Key 14
HKLM\SOFTWARE\Policies\Microsoft\Edge
Details Windows Registry Key 1
HKLM\System\...\Parameters\PersistentRoutes
Details Windows Registry Key 1
HKLM-x32\...\AEFT_23_0
Details Windows Registry Key 1
HKLM-x32\...\AUDT_23_0
Details Windows Registry Key 1
HKLM-x32\...\ILST_27_0
Details Windows Registry Key 1
HKLM-x32\...\AME_23_0_1
Details Windows Registry Key 1
HKLM-x32\...\S2T_yue_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_cmn_10_0_1_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_en_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_fr_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_de_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_hi_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_it_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_ja_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_ko_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_pt_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_ru_10_0_0_5
Details Windows Registry Key 1
HKLM-x32\...\S2T_es_10_0_0_5
Details Windows Registry Key 7
HKLM-x32\...\AMD_Chipset_IODrivers
Details Windows Registry Key 77
HKLM-x32
Details Windows Registry Key 10
HKLM\...\AMD
Details Windows Registry Key 1
HKLM\...\GenArts
Details Windows Registry Key 19
HKLM-x32\...\InstallShield_
Details Windows Registry Key 2
HKLM\...\GBT_MB_Update
Details Windows Registry Key 2
HKLM\...\GBT_RGB_Sync_Control
Details Windows Registry Key 1
HKLM\...\GBT_rgbMotherboard_UC
Details Windows Registry Key 1
HKLM\...\GBT_VGA
Details Windows Registry Key 2
HKLM\...\GIGABYTE
Details Windows Registry Key 1
HKLM\...\MBEasyTune
Details Windows Registry Key 2
HKLM\...\Gigabyte
Details Windows Registry Key 2
HKLM\...\MBStorage
Details Windows Registry Key 1
HKLM\...\9924ffa3-83bc-5a34-8cf3-c3a0a9f4d038
Details Windows Registry Key 1
HKLM\...\Magic
Details Windows Registry Key 2
HKLM\...\Maxon
Details Windows Registry Key 68
HKLM-x32\...\Microsoft
Details Windows Registry Key 1
HKU\S-1-5-21-2297073907-4018794041-3882517032-1001\...\OneDriveSetup.exe
Details Windows Registry Key 5
HKLM-x32\...\NGC
Details Windows Registry Key 1
HKLM\...\ac0666ae-ee66-5310-ac01-9d6348133b2d
Details Windows Registry Key 17
HKLM-x32\...\OBS
Details Windows Registry Key 2
HKLM\...\REAPER
Details Windows Registry Key 1
HKLM\...\ReaPlugs
Details Windows Registry Key 1
HKLM\...\ReelSmart
Details Windows Registry Key 5
HKLM\...\Riot
Details Windows Registry Key 1
HKU\S-1-5-21-2297073907-4018794041-3882517032-1001\...\roblox-player
Details Windows Registry Key 34
HKLM-x32\...\Steam
Details Windows Registry Key 1
HKLM\...\Twixtor
Details Windows Registry Key 1
HKU\S-1-5-21-2297073907-4018794041-3882517032-1001\...\Riot
Details Windows Registry Key 5
HKLM\...\VB
Details Windows Registry Key 30
HKLM\...\WinRAR
Details Windows Registry Key 1
HKU\S-1-5-21-2297073907-4018794041-3882517032-1001_Classes\CLSID
Details Windows Registry Key 32
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService
Details Windows Registry Key 32
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService
Details Windows Registry Key 41
HKLM\System\CurrentControlSet\Control\Session
Details Windows Registry Key 1
HKU\S-1-5-21-2297073907-4018794041-3882517032-1001\Control
Details Windows Registry Key 98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System