Finally finished, here is report after cleanup.
Program : RogueKiller Anti-Malware
Version : 15.4.0.0
x64 : Yes
Program Date : Mar 7 2022
Location : C:\Program Files\RogueKiller\RogueKiller64.exe
Premium : No
Company : Adlice Software
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : Marilyn
User is Admin : Yes
Date : 2022/03/30 16:59:48
Type : Removal
Aborted : No
Scan Mode : Standard
Duration : 6900
Found items : 19
Total scanned : 61981
Signatures Version : 20220328_121642
Truesight Driver : Yes
Updates Count : 2
Arguments : -minimize
************************* Warnings *************************
(31:2676) C:\Windows\System32, LONG_FOLDER_SCAN
[+] path : C:\Windows\System32
[+] message : LONG_FOLDER_SCAN
[+] int1 : 31
[+] int2 : 2676
************************* Removal *************************
[Tr.Gen (Malicious)] conhoy.exe -- %SystemRoot%\Temp\conhoy.exe -> Killed [Tree]
[+] scan_what : 1
[+] vendors : Tr.Gen
[+] Name : conhoy.exe
[+] value : %SystemRoot%\Temp\conhoy.exe
[+] Type : Process
[+] file_hash : 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 0
[+] status : 3
[+] status_str : Killed [Tree]
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Gen (Malicious)] conhoy.exe -- %SystemRoot%\Temp\conhoy.exe ->
[+] scan_what : 1
[+] vendors : Tr.Gen
[+] Name : conhoy.exe
[+] value : %SystemRoot%\Temp\conhoy.exe
[+] Type : Process
[+] file_hash : 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 1
[+] status : 340363200
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Ursu (Malicious)] rundll32.exe -- %SystemRoot%\debug\item.dat -> Killed [Tree]
[+] scan_what : 1
[+] vendors : Tr.Ursu
[+] Name : rundll32.exe
[+] value : %SystemRoot%\debug\item.dat
[+] Type : Process
[+] file_hash : 1E8441F0D32D3854E0B3801063F6015A9F09637D77B714F8E58FB8C198693A51
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 2
[+] status : 3
[+] status_str : Killed [Tree]
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Ursu (Malicious)] rundll32.exe -- %SystemRoot%\debug\item.dat ->
[+] scan_what : 1
[+] vendors : Tr.Ursu
[+] Name : rundll32.exe
[+] value : %SystemRoot%\debug\item.dat
[+] Type : Process
[+] file_hash : 1E8441F0D32D3854E0B3801063F6015A9F09637D77B714F8E58FB8C198693A51
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 3
[+] status : 340355088
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Miner.Gen (Malicious)] lsma22.exe -- %SystemRoot%\inf\aspnet\lsma22.exe -> Killed [Tree]
[+] scan_what : 1
[+] vendors : Miner.Gen
[+] Name : lsma22.exe
[+] value : %SystemRoot%\inf\aspnet\lsma22.exe
[+] Type : Process
[+] file_hash : BA1E190E87D89FF7943CCA039F357CA8E7C37255D51ACCF49393E2F9119DEC04
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 4
[+] status : 3
[+] status_str : Killed [Tree]
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Ursu (Malicious)] item.dat -- %SystemRoot%\debug\item.dat ->
[+] scan_what : 2
[+] vendors : Tr.Ursu
[+] Name : item.dat
[+] value : %SystemRoot%\debug\item.dat
[+] Type : DLL
[+] file_hash : 1E8441F0D32D3854E0B3801063F6015A9F09637D77B714F8E58FB8C198693A51
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 5
[+] status : 179689248
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Gen (Malicious)] \MicrosoftsWindowsy -- c:\windows\temp\conhoy.exe -> ERROR [80070002]
[+] scan_what : 0
[+] vendors : Tr.Gen
[+] Name : \MicrosoftsWindowsy
[+] value : c:\windows\temp\conhoy.exe
[+] Type : Task
[+] file_hash : 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 6
[+] status : 4
[+] status_str : ERROR [80070002]
[+] removed : No
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Ursu (Malicious)] \Mysa1 -- rundll32.exe (c:\windows\debug\item.dat,ServiceMain aaaa) -> ERROR [80070002]
[+] scan_what : 0
[+] vendors : Tr.Ursu
[+] Name : \Mysa1
[+] value : rundll32.exe (c:\windows\debug\item.dat,ServiceMain aaaa)
[+] Type : Task
[+] file_hash : F5691B8F200E3196E6808E932630E862F8F26F31CD949981373F23C9D87DB8B9
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 7
[+] status : 4
[+] status_str : ERROR [80070002]
[+] removed : No
[+] status_choice : 2
[+] malpe_score : 0
[Miner.Gen (Malicious)] \oka -- c:\windows\inf\aspnet\lsma22.exe -> ERROR [80070002]
[+] scan_what : 0
[+] vendors : Miner.Gen
[+] Name : \oka
[+] value : c:\windows\inf\aspnet\lsma22.exe
[+] Type : Task
[+] file_hash : BA1E190E87D89FF7943CCA039F357CA8E7C37255D51ACCF49393E2F9119DEC04
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 8
[+] status : 4
[+] status_str : ERROR [80070002]
[+] removed : No
[+] status_choice : 2
[+] malpe_score : 0
[PUP.Slimware (Potentially Malicious)] \{F49F3141-310E-4D17-964E-8CBAEDD01415} -- C:\Windows\system32\pcalua.exe (-a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {36488064-fdb3-451c-923b-fdd9d69c2554}) -> ERROR [80070002]
[+] scan_what : 0
[+] vendors : PUP.Slimware
[+] Name : \{F49F3141-310E-4D17-964E-8CBAEDD01415}
[+] value : C:\Windows\system32\pcalua.exe (-a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {36488064-fdb3-451c-923b-fdd9d69c2554})
[+] Type : Task
[+] file_hash : 7C0ABEB1D649BC7B5E0464F6E061A17D075F14785DC50F4C979DD23210106C0B
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 9
[+] status : 4
[+] status_str : ERROR [80070002]
[+] removed : No
[+] status_choice : 2
[+] malpe_score : 0
[PUP.WinZipDiskTools (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Nico Mak Computing -- -> Deleted
[+] scan_what : 2
[+] vendors : PUP.WinZipDiskTools
[+] Name : HKEY_LOCAL_MACHINE\Software\Nico Mak Computing
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 10
[+] status : 3
[+] status_str : Deleted
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[PUP.Auslogics (Potentially Malicious)] HKEY_USERS\.DEFAULT\Software\Auslogics -- -> Deleted
[+] scan_what : 2
[+] vendors : PUP.Auslogics
[+] Name : HKEY_USERS\.DEFAULT\Software\Auslogics
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 11
[+] status : 3
[+] status_str : Deleted
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[PUP.Auslogics (Potentially Malicious)] HKEY_USERS\S-1-5-18\Software\Auslogics -- -> Deleted
[+] scan_what : 2
[+] vendors : PUP.Auslogics
[+] Name : HKEY_USERS\S-1-5-18\Software\Auslogics
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 12
[+] status : 3
[+] status_str : Deleted
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[PUP.Gen1 (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ShopAtHome.com Helper -- -> Deleted
[+] scan_what : 2
[+] vendors : PUP.Gen1
[+] Name : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ShopAtHome.com Helper
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 13
[+] status : 3
[+] status_str : Deleted
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Ursu (Malicious)] item.dat -- %SystemRoot%\debug\item.dat -> Removed at reboot [5]
[+] scan_what : 1
[+] vendors : Tr.Ursu
[+] Name : item.dat
[+] value : %SystemRoot%\debug\item.dat
[+] Type : File/Folder
[+] file_hash : 1E8441F0D32D3854E0B3801063F6015A9F09637D77B714F8E58FB8C198693A51
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 14
[+] status : 5
[+] status_str : Removed at reboot [5]
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Miner.Gen (Malicious)] aspnet -- %SystemRoot%\inf\aspnet -> Removed at reboot [91]
[+] scan_what : 1
[+] vendors : Miner.Gen
[+] Name : aspnet
[+] value : %SystemRoot%\inf\aspnet
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 15
[+] status : 5
[+] status_str : Removed at reboot [91]
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Tr.Gen (Malicious)] conhoy.exe -- %SystemRoot%\Temp\conhoy.exe -> Deleted
[+] scan_what : 1
[+] vendors : Tr.Gen
[+] Name : conhoy.exe
[+] value : %SystemRoot%\Temp\conhoy.exe
[+] Type : File/Folder
[+] file_hash : 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 16
[+] status : 3
[+] status_str : Deleted
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[PUP.ByteFence (Potentially Malicious)] ByteFence Anti-Malware.lnk -- %_Marilyn_appdata%\Microsoft\Windows\Start Menu\ByteFence\ByteFence Anti-Malware.lnk (lnk => C:\Program Files\ByteFence\ByteFence.exe []) -> Deleted
[+] scan_what : 1
[+] vendors : PUP.ByteFence
[+] Name : ByteFence Anti-Malware.lnk
[+] value : %_Marilyn_appdata%\Microsoft\Windows\Start Menu\ByteFence\ByteFence Anti-Malware.lnk (lnk => C:\Program Files\ByteFence\ByteFence.exe [])
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 17
[+] status : 3
[+] status_str : Deleted
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[PUP.ShopAtHome (Potentially Malicious)] ShopAtHome -- %_Marilyn_appdata%\ShopAtHome -> Deleted
[+] scan_what : 1
[+] vendors : PUP.ShopAtHome
[+] Name : ShopAtHome
[+] value : %_Marilyn_appdata%\ShopAtHome
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 18
[+] status : 3
[+] status_str : Deleted
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
===============================================================
Task Scheduler is clean, conhoy.exe is not in C:\Windows\Temp. I'm going to do a normal boot and check them again, then enable a network connection and see what happens.
Edited by Ztruker, 30 March 2022 - 11:06 AM.